The Raven Group
Digital Infrastructure
Intelligence Systems
Consulting
Insights
About
Schedule Consultation
Schedule
The Raven Group
InsightsAbout
Schedule Consultation
The Raven Group
The Raven GroupInfrastructure consultancy · AI-native partner

We operate the digital infrastructure behind small and mid-sized businesses — quietly, and well.

Direct line

+1 303-351-1691hello@theravengroup.com

Denver, Colorado · operating since 1993

Services
  • Digital Infrastructure→
  • Networking & Security→
  • Apple & Business→
  • Consulting→
  • Managed Websites→
AI & Intelligence
  • Intelligence Systems→
  • AI Systems & Automation→
  • Cogneros→
  • Cerebra→
  • HomeOS by TRG→
Company
  • About→
  • Our Story→
  • Philosophy→
  • Clients→
  • Case Studies→
Insights
  • All Insights→
  • AI→
  • Infrastructure→
  • Strategy→
  • Security→
Get Started
  • Get in Touch→
  • Account & Billing→
Assessments & tools
  • AI Opportunity Assessment
  • ·AI Readiness Assessment
  • ·Infrastructure Audit
  • ·Website Infrastructure Score
  • ·Book an Infrastructure Review
Serving Denver & Colorado
  • Denver Web Infrastructure
  • ·Denver AI Consulting
  • ·Colorado AI Consulting
  • ·Denver Apple Consultant
  • ·Denver UniFi Consultant
  • ·Denver Managed Websites
  • ·Denver Business Technology
Live in Denver, CO·© 2026 The Raven Group
PrivacyTermsAccessibility
  1. Home
  2. ›Insights
  3. ›Security
Security

Why password rotation is a security anti-pattern

July 30, 2025·3 min read

If your IT policy still requires users to change their password every 60 or 90 days, you're enforcing a security practice that NIST officially recommended against in 2017. The reason: forced rotation produces predictable, weaker passwords. Faced with making up a new one twelve times a year, humans pick patterns they can predict — last password + 1, last password + season, last password + month. The attacker who breaches your system with one password can usually guess the next two.

The data on this is settled. Studies from Carleton University, Microsoft Research, and the FTC all converge: forced rotation does not improve security against modern attacks. Phishing, credential stuffing, and database breaches don't care how recent your password is. They steal the current one. Rotation only helps in one scenario — that a password has already been compromised and the user doesn't know yet — and that scenario is much better addressed by breach monitoring (HaveIBeenPwned-style services) and multi-factor authentication.

What works instead: long, unique passwords (managed by a password manager), MFA on every account that supports it, breach monitoring that alerts users when their password appears in a leak, and a clear path to change the password instantly when it does. This is more secure than 90-day rotation by a wide margin, and it has the bonus property of users not actively hating IT for it.

Worth saying out loud: many compliance frameworks (PCI-DSS, HIPAA in some interpretations) still have rotation requirements buried in the language. If you're stuck with one, the move is to push the rotation interval as long as policy permits (often a year), and pair it with a real password manager and MFA. The auditor gets their checkbox; the users get to keep their working memory. Eventually those frameworks will catch up to NIST, and the day they do, you'll already be ahead.

Want to talk about something in this post? Get in touch.More on Security
More on Security
  • The strongest password policy is the one that lets you stop typing passwords

    Thirty years of "longer, more complex, rotated more often" produced sticky notes and password reuse. The actual move in 2026 is to stop typing passwords altogether.

    April 26, 20263 min read
  • Incident response when you don't have an IR team

    Most small businesses won't have a dedicated incident response team. The playbook still works — it's just shorter.

    December 12, 20253 min read