Over 99.9 percent of account compromise attacks are blocked by multi-factor authentication (Microsoft Security Blog). But before you pat yourself on the back for enabling MFA, consider this: a staggering number of breaches still start with a weak or reused password. In 2024, the FBI's IC3 received 859,532 complaints with reported losses of $16.6 billion (FBI IC3). The truth is, passwords are still the keys to the kingdom, and most of us are using flimsy ones.
The Scenario: You're the IT Admin for a 50-Person Law Firm
Imagine you're the IT administrator for a growing law firm. You've got 50 attorneys and staff, each with a corporate email, access to client files, and a payroll system. Last week, a partner received a phishing email that looked like a DocuSign request. They didn't click, but it got you thinking: what's stopping a determined attacker from getting in? You've read about ransomware and business email compromise (BEC) — the FBI reported BEC losses of $2.77 billion in 2024 (FBI IC3). You decide to audit your password policy.
You open your group policy editor and see the old settings: minimum 8 characters, complexity required, password expires every 90 days. You've heard that's outdated. NIST SP 800-63B, the federal guideline, now recommends passwords of at least 15 characters when used alone, and at least 8 when paired with MFA. CISA, echoing that, says 'longer is stronger' and recommends at least 16 characters. You're inclined to set 16, but you worry about user backlash. Then you remember the NSA/CISA advisory listing 'poor credential hygiene' — including passwords shorter than 15 characters — among the top ten most common network misconfigurations. That settles it: you'll set the minimum to 16 characters.
Why Complexity Rules Are a Trap
You also notice your policy requires a mix of uppercase, lowercase, numbers, and symbols. NIST explicitly forbids mandatory complexity rules. Why? Because when users are forced to add a number and symbol, they just tack on '1!' to the end of a common word. That's predictable. The NCSC points out that letter-to-symbol swaps like 'o' to '0' add almost no real strength. Instead, NIST and CISA both recommend long, random passphrases. CISA suggests 4 to 7 unrelated words, with spaces allowed. The NCSC champions 'three random words' as a memorable way to get length.
So you draft a new policy: minimum 16 characters, no complexity requirement, but a blocklist of common passwords and a check against breached passwords using a service like Have I Been Pwned. NIST requires screening passwords against a blocklist of known compromised values. You also decide to allow spaces and Unicode characters, as NIST advises. You'll store passwords salted and hashed — that's non-negotiable.
You know some staff will complain. To make it easier, you'll deploy a password manager. CISA recommends password managers to generate and store unique, random passwords for every account. That eliminates password reuse, which Microsoft says enables credential-stuffing attacks. You'll also remind staff that writing down a password is acceptable if kept somewhere safe, per NCSC guidance — but a password manager is better.
MFA Is Not a Silver Bullet
Now, you're also rolling out MFA. Microsoft says enabling MFA blocks 99.9% of account attacks. But you've read CISA's fact sheet on phishing-resistant MFA. Traditional MFA — SMS codes, push notifications — can be bypassed through phishing, push bombing, SS7 exploits, and SIM swapping. SMS codes are especially vulnerable to SIM swapping, where an attacker convinces your carrier to port your number. So you decide to use phishing-resistant MFA: hardware security keys (FIDO2) or passkeys for the most sensitive systems, and authenticator apps for the rest. CISA ranks phishing-resistant MFA as the gold standard. You'll skip SMS entirely unless it's a last resort.
But here's the thing: even with MFA, you need strong passwords. Because if an attacker gets a password hash from a breach, they can crack it offline. A 12-character random password might take days, but a 16-character one takes centuries. The NSA/CISA misconfiguration guide specifically calls out passwords shorter than 15 characters as crackable.
What About the Human Element?
Verizon's 2024 DBIR found that 68% of breaches involve a non-malicious human element — someone falls for a phishing email or reuses a password. You can't train away every mistake, but you can make the right choice the easy choice. By enforcing 16-character passphrases and using a password manager, you're not just setting a rule — you're building a culture.
You also check Have I Been Pwned for your domain. You find that 12 of your 50 employees have email addresses in known breaches. You require them to change those passwords immediately. You also set up a process to check new hires.
Finally, you test your policy. You try to set a password of 'Summer2024!' — it's rejected because it's on a blocklist. You try 'correcthorsebatterystaple' (spaces included) — accepted, and it's 25 characters. You feel good.
What I'd Actually Do
If you're an IT admin, set your minimum password length to 16 characters. Don't be swayed by the '12 is enough' crowd. NIST says 15 when no MFA, but CISA says 16 — so go with 16. Pair it with a password manager and phishing-resistant MFA. And please, stop forcing password changes every 90 days. NIST explicitly forbids mandatory periodic changes — they reduce security because people pick weaker passwords or increment numbers. Instead, only require a change when you suspect a compromise.
For individuals, the same logic applies. Use a password manager, generate 16-character random passwords, and enable MFA on every account that supports it. Start with email, banking, and cloud accounts. And check Have I Been Pwned to see if you've been in a breach. If you have, change that password now.
Passwords aren't dead. They're the front door, and MFA is the deadbolt. Make the door strong.
Sources
- CISA (Secure Our World) - https://www.cisa.gov/secure-our-world
- NIST SP 800-63B - https://pages.nist.gov/800-63-4/sp800-63b.html
- NSA/CISA Top Ten Misconfigurations - https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-278a
- NCSC Three Random Words - https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/three-random-words
- Have I Been Pwned - https://haveibeenpwned.com/About
Comments (0)
Please sign in to post a comment.
Don't have an account? Create one
No comments yet. Be the first to comment!