In short
Password fatigue comes from the rules, not from careless staff. Forced complexity and ninety-day resets push people towards predictable patterns and reuse. NIST SP 800-63B now advises against both and favours length instead. A password manager gives every account a long, unique password nobody has to remember. None of it stops phishing, because a password handed over on a fake login page works no matter how strong it is.
Your team has a dozen logins, a rule demanding eight characters with a capital and a symbol, and a reset every ninety days. So they use Summer2026!, then Autumn2026!, and write the awkward ones on a note stuck to the monitor. The rule produced that behaviour, and blaming the staff will not change it.
Password fatigue is a design problem, not a discipline problem
Password fatigue is the exhaustion that comes from being asked to invent, memorise and rotate more secrets than a person can hold. It shows up as reuse, as small predictable variations, as passwords shared in a group chat, and as a notebook in the top drawer of the reception desk.
Every one of those is a rational response to an impossible instruction. Nobody can remember twenty distinct strings of random characters and change a quarter of them every quarter. When a policy demands something people cannot do, they find a way around it, and the way around it is worse than what the policy was trying to prevent.
The useful question is not how to make your team try harder. It is how to remove the memory problem, so the rule becomes possible to follow.
Why complexity rules made passwords weaker
Composition rules look like they add strength. In practice they narrow it. Told to add a capital, almost everyone capitalises the first letter. Told to add a number, they put it at the end. Told to add a symbol, they choose an exclamation mark. Cracking software knows all three habits and tests them first.
Forced rotation compounds the problem. When someone must change a password every ninety days, they pick something they can increment. Password1 becomes Password2. The season changes, the year stays. A stolen password is usually used within hours, so a quarterly reset rarely lands in time to matter, and the cost is a predictable pattern across the whole organisation.
This is settled guidance rather than a contrary opinion. NIST SP 800-63B, the US federal standard most security frameworks follow, advises against imposing composition rules and against forcing periodic changes unless there is evidence of compromise. It favours length instead, together with screening new passwords against lists of ones already breached.
A long passphrase of ordinary words beats a short scramble of symbols on both counts. It is harder to crack and easier to remember, which means it is also less likely to end up on a note.
What a password manager actually changes
A password manager is an encrypted vault. Your team memorises one strong passphrase, and the vault holds everything else: long, random, different on every site, filled in automatically when the page loads.
Three things change the day it goes in.
Reuse stops being a risk. When a supplier's website is breached and its passwords leak, the leak covers that one site. Today, if the same password opens your email, your bank and your practice system, one supplier's bad week becomes yours.
The memory problem disappears. You can raise the standard, because nobody is being asked to carry it in their head. Thirty random characters cost your team the same effort as eight.
Sharing becomes visible. Shared logins exist in every business: the reception account, the supplier portal, the social media page. Move them into a shared vault and access is granted and withdrawn per person, rather than by circulating a password you can never take back.
There is a quieter benefit. Autofill matches the stored web address, so if someone lands on a convincing copy of a login page at a similar address, the manager stays silent. That silence is a warning worth noticing.
The objections we hear, answered
All the eggs in one basket
A fair worry with an unfair conclusion. The alternative on offer is the same password across thirty baskets, which is where most businesses stand today. The vault is encrypted so the provider cannot read it, and the one passphrase protecting it should be long, unique and covered by multi-factor authentication.
What if the vault provider is breached
Assume it will happen, and judge the design rather than the promise. A vault encrypted on the device before it leaves means a stolen copy is worthless without the passphrase. Ask whoever recommends a product whether that is how it works, and choose one that publishes independent security audits.
The shared reception computer
Shared accounts are the hardest part of any rollout, and a vault handles them better than a note under the keyboard. Longer term, each person should sign in as themselves so the audit trail means something. We covered that problem, and the hardware that solves it, in our piece on passkeys and conditional access.
None of this stops phishing
Here is the part that gets missed. Password strength protects you against guessing and cracking. Phishing does no guessing. It asks, and your employee answers.
A forty-character random password typed into a convincing fake login page is worth what Password1 is worth, because in both cases the attacker now holds it. The same goes for the six-digit code that follows: current phishing kits relay it to the real site within seconds and keep the session that comes back. We set out what that looks like afterwards in spotting a hijacked mailbox early, and the routes that bypass your mail filtering altogether in phishing by phone, text and QR code.
So treat the password work and the phishing work as two jobs. A password manager closes reuse and cracking. Phishing-resistant sign-in, meaning passkeys or hardware security keys, closes the handing-over. A written verification rule closes what neither covers.
If you do one thing after reading this, make it the second one, for the accounts that can move money.
What to do this month
- Drop the ninety-day reset for standard accounts and require length instead. Fifteen characters, or a passphrase of four unrelated words.
- Remove composition rules that push everyone towards the same shape.
- Roll out a password manager to one team first, with the shared logins loaded before you begin, so the first experience is easier than what they had.
- List the accounts that can move money or change bank details, and move those to passkeys or security keys.
- Write the verification rule down. No change to bank details, payroll or an authentication method without a phone call to a number you already hold.
The Irish National Cyber Security Centre publishes plain guidance you can hand to staff alongside your own.
None of this is a large project. It is a policy change, a rollout, and one conversation about which accounts matter most. If you would like help sequencing it, that work sits inside our managed IT service. Get in touch and we will start with the accounts that would hurt most.
Is it safe to keep all our passwords in one password manager?
Safer than the alternative, which for most businesses is one password reused everywhere. The vault is encrypted on your device before it is stored, so the provider cannot read its contents. Protect it with a long passphrase used nowhere else and multi-factor authentication, and choose a product that publishes independent security audits.
Should we still force staff to change passwords every 90 days?
No, not as a routine rule. NIST SP 800-63B advises against forced periodic changes unless there is evidence a password has been compromised, because people respond by incrementing what they already use. Change a password immediately when it appears in a breach, when someone leaves, or when an account shows signs of misuse.
Does a password manager protect us from phishing?
Not on its own. A password manager stops reuse and makes cracking impractical, but phishing works by persuading someone to type the password into a fake page, and a strong password is handed over as easily as a weak one. Autofill offers partial help, because it will not fill a lookalike address. Passkeys close the gap properly.
What happens if the person who set up the password manager leaves?
Use a business plan rather than personal accounts, and make sure at least two people hold administrative rights over the organisation's vault. Business products include account recovery so an administrator can restore access when someone leaves or forgets their passphrase. Store the emergency recovery kit somewhere physical, such as a safe, and test it once a year.
Are passkeys a replacement for a password manager, or do we need both?
Both, for now. Passkeys are stronger and should cover your most important sign-ins, starting with anything that moves money or holds administrative rights. Most business systems still require a password, particularly older line-of-business applications and supplier portals, so the vault continues to do useful work for everything passkeys have not reached yet.