In today’s digital landscape, password security is more critical than ever. Recent guidelines from the Center for Internet Security (CIS), the National Institute of Standards and Technology (NIST), and the Federal Financial Institutions Examination Council (FFIEC) highlight an essential shift: password length now trumps complexity. While we used to rely on a mix of special characters, numbers, and case sensitivity, research shows that longer passwords—even without complex symbols—offer significantly better security. A password between 12 to 16 characters, made up of simple, easy-to-remember phrases, provides much stronger protection against hackers.

 

Password Strength: Character Count Matters

To understand just how much stronger a longer password is, here’s a comparison of a 10-character password vs. a 16-character password:

Password Length & ComplexityPotential CombinationsTime to Crack (at 1 billion guesses per second)
10-character password (uppercase, lowercase, numbers, special characters)95 quadrillion (9.5 x 10¹⁵)Approximately 2 hours
16-character password (lowercase letters only)4.4 quadrillion (4.4 x 10¹⁹)1,400 years
16-character password (mixed character set)20 octillion (2.0 x 10²⁸)Approximately 4 trillion years

 

Why Length Over Complexity?

The move toward longer passwords stems from the fact that complexity can lead to poor password habits. Users often create passwords that are hard to remember, leading them to reuse passwords across multiple accounts or use predictable patterns. Longer passwords, especially when unique, are easier to recall and harder for attackers to crack. Both CIS and NIST recommend focusing on length for stronger protection without causing frustration from overly complex requirements.

 

Rethinking Password Expiration Policies

Another change in password guidance is the shift away from frequent password changes. Previously, many standards required users to change passwords every 90 days. However, NIST has found that frequent changes often lead to weaker passwords, as users make only small adjustments (like adding a number at the end). Now, it’s recommended to only change passwords after a known breach or security incident. This reduces the risk of weak password creation and improves overall security.

 

Checking for Compromised Passwords

Many passwords have already been compromised and are accessible on the dark web. It’s crucial to check for compromised passwords and alert users before they change theirs. Free resources like Have I Been Pwned allow individuals to search for compromised email addresses and passwords. Some services scan the dark web for compromised company accounts. Additionally, tools exist that compare user passwords against compromised databases during password resets, ensuring weak passwords like dictionary words or repetitive patterns are blocked.

 

Adopt These Practices for Stronger Security

By focusing on password length, minimizing frequent password changes, and leveraging tools to detect compromised passwords, organizations can significantly improve their cybersecurity. These updated standards help protect your business in today’s ever-evolving threat landscape.

 

Working With Kalmer Solutions

Kalmer Solutions provides managed IT services for the modern workforce. Based in Jonesboro, Arkansas, we support our clients with virtual CIO services, technology upgrades, cloud-based computing, IT support, cybersecurity, the fulfillment of compliance requirements, and more. Our goal is to become your trusted IT partner and add long-term strategic value. Contact us today to learn more about how working with us can transform your business.