Way back in 2003, NIST published some bad advice on passwords. It was so bad in fact that in 2017, they rescinded their earlier advice and updated their password recommendations. Gone were the complex, 8-character passwords that must change every 90 days. In were longer (14+) character length passwords, that were non-complex, and non-expiring.
The theory, this time backed up by empirical evidence, was that by favoring humans with something memorable, they would not write it down AND they would still have a password to strong to brute force with a computer or human guessing at it. If you’re accessing a website today and it insists on a complex password that is only 8 characters long and expires frequently, you’re dealing with a dinosaur of cybersecurity company. Skip the website and find one that reflects current best practices over 20 year old tom-foolery.
In addition to adopting long and strong passwords, every company out there (SMB and MSP) should adopt the following best practices.
CyberHoot believes that for many small to medium sized businesses and MSPs, you can greatly improve your defenses and chances of not becoming another victim of cyberattack if you follow the advice above.
We hope you’re enjoying Cybersecurity Awareness Month (CAM). Visit or subscribe to CyberHoot’s Facebook, LinkedIn, or Twitter pages to get daily updates throughout the month.
NIST’s new password rules – what you need to know: Sophos Naked Security Analysis
https://youtu.be/FZW24W-Wsws
Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.
OAuth tokens don't expire when employees leave, passwords change, or apps go rogue. Your security program needs...
Read more
Most breaches don't start with a hacker in a hoodie cracking code at 3am. They start with your username and a...
Read more
Article Updates: As of May 6th 2026, every major U.S. AI lab, including Google DeepMind, Microsoft, xAI,...
Read moreGet sharper eyes on human risks, with the positive approach that beats traditional phish testing.
