Guide · Data security

Passwords at work: what still applies and what is outdated

Regular changes, special characters, complexity rules: which password requirements do more harm than good by today's standards – and what matters instead.

By Dipl.-Ing. Mohamed Khater, Founder and Managing Director, since 1992 · · 8 min read

Why forced password changes were abolished

For decades the rule was: passwords must be changed every 90 days and contain upper- and lower-case letters, digits and special characters. Both rules are now considered outdated – the BSI (German Federal Office for Information Security) dropped its recommendation for regular changes years ago.

The reason is observed behaviour. People who have to change their password every three months do not come up with a new one; they add a digit. Summer2024! becomes Summer2025!. For an attacker who knows an old password, that is no obstacle. And because nobody can remember four different complex passwords a year, they end up on notes under the keyboard.

So passwords are now only changed for a reason: if there is a suspicion that a third party has learned them, after a data breach has become known, and when people who knew the password leave.

What applies instead

Length beats complexity

Four rules that actually make a difference – and that people can stick to in everyday work.

  • At least twelve characters, preferably more. Every additional character multiplies the effort needed to guess the password. One more special character achieves far less than four more characters of length.
  • Three or four unrelated words. CoffeeTractorCloudPliers is easier to remember and harder to guess than C0ff33!. The words must have no connection to each other and nothing to do with the person.
  • A separate password for every service. This is the most important rule of all. If a provider is hacked, attackers try the same credentials everywhere. Without a password manager this is impossible to sustain – which is why one is part of the package.
  • Two factors wherever available. A second factor makes a stolen password largely worthless. For email, remote access, banking and all administrative access, it is non-negotiable.

Tool

Password managers at work

The most common concern is: if everything is in one place, isn't that particularly dangerous? The answer: the alternative is more dangerous.

Why it is more secure

The alternative is not secure passwords kept in people's heads, but the same three passwords everywhere, notes in desk drawers and lists in Excel files on the network drive. A password manager replaces exactly that.

  • One strong password instead of many weak ones
  • Encrypted vault instead of an Excel list

Shared credentials

Some credentials belong to the business, not to a person: banking portals, government accounts, vendor portals. A password manager with team features shares them selectively and logs who has used them.

  • Sharing access instead of passing on passwords
  • Revoke access selectively when someone leaves

What to look out for

The vault should be encrypted in such a way that even the provider cannot see inside. An emergency arrangement is also important: what happens if the only person with the master password is unavailable?

  • Put emergency access in writing
  • Running it in-house is possible

The uncomfortable part: shared credentials

Every business has credentials that several people use. They are the area with the greatest risk and the least attention.

  • Keep a list of which shared credentials exist and who knows them. Without this list, you cannot tell what needs to be changed when someone leaves.
  • Issue personal accounts wherever possible. A shared login is always the worse solution – nobody can be identified, and nobody feels responsible.
  • Change shared passwords when someone leaves. Without exception, even when the parting is amicable. It is not about mistrust, but about good housekeeping.
  • Do not forget the credentials that do not belong to any person: router, firewall, phone system, printers, network storage. In our experience, that is where the password from the initial setup is still in place.
  • Think of external access: tax advisers, tradespeople, service providers – including your IT service provider. They belong on the list too.

Frequently asked questions

What we are often asked about this

Should we switch off forced password changes?

In most cases yes, but not on its own. What makes sense is the combination: remove the forced change, and in return increase the minimum length, introduce two-factor authentication and provide a password manager.

If you only switch off the forced change and change nothing else, you make things worse. Also check whether requirements from your customers or from a certification stand in the way – some audit catalogues still lag behind the recommendation.

What should we do after a data breach has become known?

Change the affected password and check all other services where the same or a similar one was used. This is exactly why the rule “a separate password for every service” is so important – it limits the damage to one service.

Also check whether forwarding rules or other rules have been set up in the affected account, and revoke active sessions.

Are passkeys the successor to passwords?

They are currently the most promising route. A passkey is bound to a device and cannot be captured through a fake login page – which removes the most common method of attack.

The catch is adoption: not every line-of-business application supports them, and the question of what happens if a device is lost must be settled beforehand. For the major services, it is already worth getting started today.

How long should the password manager's master password be?

It is the only password anyone has to remember – so it can be long. Four to five unrelated words are a good benchmark.

The emergency arrangement is important: a master password that only one person knows is a business continuity risk. Deposit it sealed in a secure place.

Dipl.-Ing. Mohamed Khater

Dipl.-Ing. Mohamed Khater founded INFONET Computer GmbH in Cologne in 1992. When we take over an IT environment, we regularly find password lists in spreadsheets on open network drives – usually created because nobody provided a better solution.

Further reading

Free security check

Where are your passwords kept?

We look at which credentials exist, how they are secured and where factory settings are still active. In our experience, the appointment with the most surprises.

+49 221 984300-0Switchboard and support hotline

[email protected]Reply within 4 hours on working days

Robert-Perthel-Straße 7250739 Köln – Bilderstöckchen

Mon–Fri 9 am–6 pmEmergency support outside these hours by arrangement