← Back to Blog Cybersecurity

Password Security — Moving Beyond "P@ssw0rd123

Published: 8 May 2026 | Updated: 20 July 2026 | CT Bedfordview
Password security concept with digital padlock on laptop

Despite years of warnings, weak passwords remain one of the biggest security risks for businesses. In 2025, the most common passwords were still "123456", "password", and "qwerty". Adding a capital letter and a number — "P@ssw0rd123" — does almost nothing to stop modern attack tools.

It's time to do better.

The Problem with Human-Generated Passwords

People choose passwords they can remember. That means:

Attackers know this. Modern password-cracking tools can test billions of combinations per second. A typical eight-character password can be cracked in under 8 hours using consumer-grade hardware.

The Solution: Password Managers

A password manager generates, stores, and fills in strong, unique passwords for every account. Your team only needs to remember one master password.

Benefits

Recommended Options

Better Than Passwords: Passphrases

For situations where you must create a memorable password, use a passphrase:

Correct•Horse•Battery•Staple

A four-word passphrase with 20+ characters is exponentially harder to crack than "P@ssw0rd123" and far easier to remember. Each additional word multiplies the difficulty dramatically.

Business Password Policy

Implement these rules:

Why Password Security Matters for POPIA

Beyond protecting your business from hackers, strong password practices are increasingly relevant to POPIA compliance. The Information Regulator expects businesses to implement appropriate technical measures to protect personal information — and weak password policies are one of the first things they'll flag in an investigation. Implementing a password manager across your organisation is a concrete, demonstrable step toward meeting your POPIA obligations.

Password Security FAQ

Q: How often should employees change their passwords?

A: The old advice of changing passwords every 90 days is now outdated. Current best practice, endorsed by both Microsoft and the National Institute of Standards and Technology (NIST), is to only change passwords when there's evidence of compromise. Frequent forced changes lead to weaker passwords and bad habits. Instead, focus on length, uniqueness, and enabling 2FA.

Q: What about single sign-on (SSO)?

A: SSO is excellent for both security and user experience. It reduces the number of passwords your team needs to remember and allows you to enforce consistent security policies across all applications. Microsoft 365 includes Azure AD SSO, which integrates with thousands of business applications.

Need help rolling out a password manager for your team? CT Bedfordview can set up Bitwarden or 1Password and train your staff. Contact us.