| Secure passwords are long, unpredictable credentials, generated at random rather than composed by hand, kept unique to every account, and stored in a password manager so they never have to be remembered or reused. Length and randomness matter far more than the old habit of swapping a letter for a symbol. |
One reused password can take down an entire business, and it usually goes something like this. A staff member signs up to a marketing tool with the same login they use for company email. Months later that tool is breached, the credentials are sold, and within hours an attacker is reading your invoices, resetting your banking access, and emailing your clients from a trusted address. No firewall was touched. Nobody was hacked in the dramatic sense. Someone simply walked in through a door that was left the same everywhere.
What makes a password secure?
Secure passwords are long, unique to a single account, and random enough that no cracking tool or educated guess can reproduce them. Everything else is detail. Length gives you resistance to brute-force attempts, uniqueness stops one breach from spreading, and randomness defeats the pattern-matching that modern cracking software relies on.
Complexity rules miss the point. For years, businesses forced staff to add a capital letter, a number, and a symbol, and the result was a workforce that all chose the same shapes. “Password1!” satisfies every rule and is still one of the first combinations any attacker tries. Secure passwords work by being hard to predict, which a compliance checklist cannot guarantee.
How do you create a secure password?
Use your business’s approved password manager to generate a long, random password that you use for one account only. Let the generator do the choosing so familiar words, dates and patterns do not creep in.
Open the password generator
In your approved password manager.
Generate a unique password of at least 16 characters
If the service accepts fewer, use its maximum and flag the restriction with your IT provider.
Use a randomly generated passphrase when you must remember it
Such as your password manager’s master password. Let a passphrase generator choose the words, rather than building a sentence yourself.
Save account passwords in the appropriate business vault
Keep individual logins in your own work vault. Where a shared account is necessary, use a shared vault restricted to the people who need access.
Protect the sign-in and set up recovery
Use a business-approved passkey where supported, or enable the strongest available multi-factor authentication. Make sure you can recover access if your usual device is lost.
Generated password
For every account your password manager can store and fill. Long, random, and nothing to remember.
Random passphrase
For the few you must type yourself, like your password manager’s master password. Random words, not a familiar phrase.
Passkey
For services that support it, with approved storage and recovery. Nothing to type, and it resists fake login pages. More on passkeys below.
Why do “strong” passwords still get cracked?
Most passwords fail because people are predictable in the same ways, and attackers have turned that predictability into software. When you follow a familiar rule, you usually land on a familiar answer, and cracking tools check those familiar answers in the first fraction of a second.
Three habits do most of the damage. The first is adding a number or symbol at the end, because “1”, “!”, and a birth year are the first things a tool appends. The second is the obvious phrase, such as “letmein” or “ilovecoffee”, which sit in every cracking dictionary. The third is character substitution, where an “E” becomes “3” and an “O” becomes “0”. That trick felt clever in 2005. Today the tools expand every common substitution automatically, so “P@ssw0rd” offers almost no extra protection over “Password”.
If you want unpredictability, let a password manager generate the password rather than inventing a pattern of your own, and avoid anything tied to you personally. Birthdays, pet names, sports teams, and street names all show up in the data attackers scrape from social media before they even start guessing. For a business, multiply that by every staff member, and the odds that at least one predictable password is sitting on your systems right now climb quickly.
How long should a secure password be?
Secure passwords should be at least 16 characters long. NIST now requires a minimum of 15 characters where a password is the only thing protecting an account, and permits eight only when the password sits behind multi-factor authentication, so 16 clears that bar with room to spare. Extra length helps only while the password stays unpredictable, because a long but familiar phrase is still easy to guess. NIST’s guidance on password strength treats length as the primary factor and finds that character-composition rules deliver far less than people assume, because users answer them predictably by turning “password” into “Password1!”. Short passwords are the biggest weakness, because an eight-character password leaves an attacker very little to work through, whatever symbols it contains. How quickly one actually falls depends on how the service stored it and what hardware is aimed at it, and a well-run login page also limits how many guesses anyone gets. The point is that added length raises that cost far more than added punctuation does.
Length beats complexity because of simple mathematics. Each character you add expands the number of possible combinations enormously, which is why a long string of ordinary words outperforms a short string of exotic ones. This is also why the tired complexity rules have aged so badly. They pushed people toward short, hard-to-remember passwords when the real win in building secure passwords was always in making them longer.
Passphrase or random string: which is safer?
A long passphrase of unrelated words is easier to remember and, at sufficient length, as strong as a shorter random string. That is why passphrases are now the recommended approach for anything a human needs to type. The key word is unrelated. “CorrectHorseBatteryStaple” works because the words have no logical connection, while “SummerHolidayInFiji” does not, because it reads like a sentence a guesser could assemble.
For any password a human never has to type, a fully random string generated by software is the stronger choice, and there is no reason to compromise. Use a passphrase for the handful of master credentials you must recall, such as the login to your password manager, and let random generation handle everything else. That combination gives you secure passwords that stay memorable where you need them and reach maximum strength everywhere else.
How should a business manage secure passwords at scale?
A business manages secure passwords at scale with a password manager. It generates long random logins, stores them encrypted, and fills them in automatically, which removes the human bottleneck behind most credential failures: nobody has to invent or recall anything.

It also gives an administrator visibility the business almost never has otherwise, including which accounts still use weak or duplicate passwords, and a way to share credentials without emailing them around.
Choosing one, rolling it out, getting staff to actually use it, and what it costs are covered properly in our guide to setting up a password manager.
Why does every account need its own password?
Every account needs its own password because reuse lets one breach spread everywhere through credential stuffing, an automated attack that tries stolen logins across other services. One leaked login then becomes a key to dozens of accounts. The moment one site leaks your details, criminals test that same combination against email, banking, cloud storage, and payroll, and reuse turns a minor leak into a full compromise.
This is the single most damaging password habit in business, and it is also the easiest to fix. Once every login is unique, a breach at one supplier stays contained to that one account. A password manager takes uniqueness off your team’s plate, because no one has to remember the difference between two hundred logins. The software holds them all, which removes the only real reason anyone reused a password in the first place.
When client information is exposed, the cost is not only lost revenue and a damaged reputation. The Privacy Act 2020 brings notification obligations when a breach has caused serious harm or is likely to, and the cheapest defence against all of it is the one most often neglected: a unique password on every account, held in a password manager rather than in somebody’s memory. The wider controls sit across our cyber security services.
What are the most common secure password mistakes?
The most common secure password mistakes are reusing one login across accounts, choosing passwords that are too short, and leaning on predictable patterns that cracking tools try first. Each mistake feels harmless on its own, and each one leaves an easy way in.
Reuse does the most damage, because it links every account together, so one breach unlocks the rest. Short passwords come next, since length is the main defence between your account and a brute-force attempt. Predictable patterns round out the list, whether that is a birth year at the end, a keyboard run such as “qwerty”, or a favourite team anyone can find on your social media. Fixing all three is the fastest route to secure passwords across a business, and a password manager handles every one of them at once, generating long logins, keeping each account separate, and removing the temptation to fall back on a memorable pattern.
Where do secure passwords stop and MFA and identity control begin?
Secure passwords protect the credential itself, while multi-factor authentication and identity and access management protect the account around it, and a well-defended business uses all three together. A strong password is the lock, MFA is the second key required even after the lock is picked, and identity control decides who is allowed near the door at all.

This distinction matters because no password is uncrackable forever. Multi-factor authentication adds a second proof of identity, such as a code or an approval on your phone, so that a stolen password alone is not enough to get in. Identity and access management goes wider still, governing which staff can reach which systems, tightening permissions to only what each role needs, and switching access off cleanly when people change roles or leave. Passwords are the foundation, and these controls are the walls built on top of it. The linked guides cover those upper layers in full.
How do attackers steal even secure passwords?
Attackers often bypass password strength entirely by tricking staff into handing credentials over through phishing, using fake login pages that look identical to the real thing. The strongest password in the world offers no protection if you type it into a convincing counterfeit of your own email sign-in page.

Phishing is now the most common route to a stolen credential, and modern attempts are far more polished than the clumsy scams of a decade ago. A message arrives that looks like it came from Microsoft, your bank, or a supplier you deal with weekly, and it carries a link to a page that copies the genuine login screen pixel for pixel. The defence is part habit and part technology: check the address bar before you sign in anywhere, treat unexpected login prompts with suspicion, and pause when a message pushes you to act urgently. Combined with MFA, this awareness closes the gap that even secure passwords leave open.
Where do passkeys fit?
A passkey replaces the password on services that support it. Instead of a secret you type, it uses a cryptographic key tied to the legitimate service. A convincing copy of the login page cannot trick your passkey into authenticating to the real account. Passwords and one-time codes do not provide that protection, which is why not every authentication method is equally resistant to phishing.
Your business still has to manage the devices and accounts holding those passkeys, set up recovery for a lost phone, and revoke access when somebody leaves. You may also need to manage both passkeys and passwords, because not every service supports passkeys.
For how they work, where to use them and what to plan before rollout, read our business guide to passkeys.
How often should business passwords change?
Business passwords no longer need to change on a fixed monthly schedule, and current guidance is to change them only when there is a reason. NIST Special Publication 800-63B now states that verifiers must not require subscribers to change passwords periodically, and should force a change only where there is evidence the credential has been compromised. Common triggers are a suspected breach, a shared credential, or a staff departure. Forced monthly resets were abandoned by most security bodies because they pushed people toward weak, predictable variations like adding a rising number to the end.
The modern approach is to make each password strong and unique from the start, then change it in response to events rather than the calendar. Rotate immediately if a service reports a breach, if a password was ever shared, or when someone leaves the business and held access to shared logins. For the handful of highest-value accounts, such as banking and administrator logins, a periodic review every few months remains sensible. The principle is simple: keep secure passwords strong and unique, and change them only when there is a real reason to.
Your secure password checklist
Use this as a quick secure-password audit for yourself and your team:
- Use a unique password for every single account, with no exceptions.
- Turn on multi-factor authentication everywhere it is offered.
- Check the address bar before entering credentials on any login page.
- Change a password the moment you suspect it has been exposed.
How do you build a secure password habit across a team?
You build a secure password habit by removing the friction, which in practice means giving every staff member a password manager and a short, clear standard to follow. Knowledge is rarely the problem, since most people already know what secure passwords look like. Consistency is the problem, and a password manager plus a clear policy is how you get it, day after day.
Set three expectations and keep them simple: use the password manager for every login, never reuse a password, and turn on multi-factor authentication wherever it is offered. Run a short password audit twice a year to clear out weak or duplicated logins and close off old accounts nobody uses. When the manager does the hard part, following the standard costs staff no extra effort, so the corner-cutting stops on its own. Strong habits at one desk only protect the business when everyone follows the same routine, from the front desk to the corner office.
How can an IT provider help manage secure passwords?
If managing password security across a team feels like more than you want to take on, you do not have to do it alone. Exodesk helps New Zealand businesses roll out password managers, enforce unique credentials, and layer multi-factor authentication and access controls so that secure password habits become the default rather than a hope. We have supported Christchurch and Dunedin organisations since 1989, and we build security that staff will actually use.
Talk to our team about locking down your logins, and we will help you turn scattered, reused passwords into a managed system that protects your revenue, your reputation, and your clients. You can also connect with us on LinkedIn to stay across the latest security insights.
Frequently Asked Questions
What is the easiest way to manage many secure passwords?
A password manager is the simplest option for most people and businesses. It stores every login in an encrypted vault, generates new ones on demand, and fills them in for you, so the only password you ever have to remember is the one that unlocks the manager itself.
How long should a secure password be?
Sixteen characters is a sensible minimum for secure passwords. NIST requires at least 15 where the password is the only protection on an account, and allows eight only when it sits behind multi-factor authentication. Length protects you far more effectively than adding an extra symbol to a short password, but only while the password stays unpredictable, so let a generator produce it.
Is a long passphrase better than a short random string?
A long passphrase of unrelated words is easier to remember and, at enough length, just as strong. “CloudyTurtlePlaysPiano” outperforms “P@ssw0rd123” comfortably, as long as the words have no logical connection to each other or to you.
Are password generators safe to use?
Reputable password generators are safe and are one of the best tools available. Built into a trusted password manager, they create long, random logins locally and store them encrypted, without sending anything unprotected across the internet.
Should I still change my passwords every month?
Fixed monthly changes are no longer recommended by most security bodies. Change a password when there is a genuine reason, such as a suspected breach, a shared login, or a staff departure, and keep every password strong and unique from the start instead.
Can I write my passwords down?
Writing passwords on a note left near your desk is risky, but a password manager solves the problem entirely. If you must record a master password on paper, keep it in a locked, offline location that only you can reach, and never store it digitally in plain text.
What happens if an employee leaves the company?
Access should be revoked immediately, and this is where businesses often stop too early. Switching off someone’s password manager account removes their route to the vault, but it does not change any password they already knew, and it does not end sessions that are still signed in. Shared credentials need rotating, application and email access needs removing at the source, and active sessions need terminating. A password manager with individual accounts and central control makes the first step straightforward, and the rest belongs in a written offboarding process.
Does character substitution like “3” for “E” actually help?
Character substitution offers almost no protection anymore. Cracking tools automatically expand every common swap, so “P@ssw0rd” is treated as barely different from “Password”. Secure passwords rely on length and randomness, not on predictable substitutions.
Do secure passwords replace the need for multi-factor authentication?
No control replaces MFA. A strong password protects the credential, while multi-factor authentication protects the account even if that credential is stolen. The two work together, and every important business account should have both.
How can a small business improve password security across the whole team?
The most effective step is rolling out a password manager for everyone, paired with a simple standard: unique passwords for every account and MFA on important systems. Exodesk can set this up for businesses anywhere in New Zealand, with teams based in Christchurch and Dunedin, and manage it on an ongoing basis.
How much does a business password manager cost?
Business password managers usually cost a few dollars per user each month, billed annually on most plans. That figure is small next to the cost of a single breach, and per-user pricing falls further for larger teams. Exodesk can recommend and set up the right option for your business.
The Bottom Line
Attackers rely on habits. They look for the reused login, the predictable pattern, and the short password, because those are the easy ways in. Secure passwords close them off, and a password manager keeps the whole system running with almost no effort once it is in place.
Passwords deserve to be treated as keys to your business. Get the credential right, add multi-factor authentication on top, and stay alert to fake login pages, and you make your business much harder to breach. When you get this foundation right, your data is safer, your clients are more confident, and one leaked password stays a small problem instead of becoming a very expensive one.
Do you know which accounts still share a password?
Most businesses cannot answer that from memory, and the reused login is the one attackers count on. A free IT assessment reviews what can genuinely be checked: your password manager health report, which accounts have multi-factor authentication enforced, where logins are being shared, and which accounts should have been closed when somebody left. Nobody has to hand over a password, and no assessment can read credentials held outside those systems.
Or read more about our cyber security services.

