Cybersecurity
Passwords, MFA, and the myth of the disciplined employee
Every password policy ever written assumes an employee who does not exist.
This person memorizes forty unique passwords, each sixteen characters, none reused, all rotated quarterly. They have never written one on a sticky note. They have never appended 2024! to an old one.
This person is fictional, and security that depends on a fictional person is a story you tell yourself.
Why people reuse passwords
People reuse passwords because the alternative was never humanly possible. Blaming them is like blaming someone for not memorizing the phone book.
Reuse is exactly what attackers count on. When one site is breached, the stolen password gets tried everywhere else, automatically, at scale, for free. It costs an attacker nothing to try, and it can cost you a great deal when it works.
Use a password manager
The fix is a tool. Posters and reminders to try harder have had decades to work.
You remember one strong password. The manager remembers the other forty, generates them properly, and fills them in. It’s the approach that holds up when real people use it.
Length beats complexity
Four random words are stronger and far easier to use than P@ssw0rd!. Complexity requirements mostly produce predictable substitutions (a becomes @, o becomes 0), and attackers have known about those for twenty years.
Then turn on MFA and stop worrying quite so much
Here’s the good news. With multi-factor authentication switched on, a stolen password on its own is nearly worthless.
Start with email, since it’s the account that resets every other account. Then banking, then anything with customer data.
Yes, it’s mildly annoying. So is a seatbelt, and nobody proposes removing seatbelts because they’re inconvenient.
The practical version
- Roll out a password manager to the whole team. One afternoon.
- Turn on MFA for email, first, today.
- Change the reused passwords you already know about. You know the ones.
- Stop requiring 90-day rotation. It produces
Winter2026!and everyone knows it.
Want to know where you actually stand? We do free, no-pressure security checks for small businesses across the East Bay, covering backups, accounts and defenses. We tell you plainly what to fix first.
On password length over forced complexity and against arbitrary rotation, see NIST SP 800-63B.