A strong password is long, unique to one account and hard to predict. That matters because a password rarely fails in isolation.
Reuse a familiar password on a small service, then on email, finance or cloud storage, and someone else’s breach can become access to your business.
Break that chain with a strong password: use a passphrase of four or more random words and at least 15 characters when a person needs to remember it.
Let a password manager generate and store a different long, random password for every other account.
Multi-factor authentication (MFA) adds a second check for the accounts that matter most, so a stolen password alone is not enough to sign in.
Let’s look at what each of these means in practice.
What is a Strong Password?
A strong password is a long, unique and unpredictable credential for one account, usually in one of two useful formats:
- A random-word passphrase for a password you need to remember or type.
- A generated random password for an account stored in your password manager.
Whichever format you use, length and randomness make the password hard to guess.
Uniqueness stops one exposed password from opening your other accounts, while safe storage and MFA protect the wider sign-in process.
What Makes a Password Strong?
A strong password passes four checks: it is long, random, unique and unrelated to personal or business information.
Because each quality closes a different weakness, use this quick check before creating or approving a password:
| Check | What to Use | What to Avoid |
|---|---|---|
| Length | At least 15 characters | Short passwords that only meet a website minimum |
| Randomness | Random words or generated characters | Familiar words with predictable symbols or numbers |
| Uniqueness | One password for one account | Reuse or small account-specific variations |
| No personal clues | Words unrelated to you or your business | Names, dates, projects, teams or company terms |
Length of at Least 15 Characters
Use at least 15 characters wherever the service supports it. This matches ACSC public passphrase guidance and makes automated guessing harder.
Treat that length as the minimum; four random words will often exceed it naturally.
Randomness Instead of Predictable Substitutions
Choose genuinely random words or characters. Attackers already test substitutions such as a to @, a capital at the start and a year or symbol at the end.
And, please C0mpanyName2026! therefore follows a familiar pattern even though it looks complex.
A Different Password for Every Account
Give every account a completely different password.
Avoid variations such as BasePassword-Xero and BasePassword-Email because attackers test related patterns after finding one working credential.
No Personal Details or Dictionary Words
Avoid names, birthdays, company terms, project names, quotes and single dictionary words. Ordinary words are suitable when four or more are selected randomly. The risk comes from personal details, familiar phrases and meaningful word sequences.
What Does a Strong Password Look Like?
A strong password usually looks like either a random-word passphrase or a long generated string. That gives you two secure formats to use and one familiar-looking pattern to avoid:
- Four or more random words: Best for passwords you need to remember. Choose unrelated words that add up to at least 15 characters.
- A generated character string: Best for accounts stored in a password manager. The password should be long, random and unique to that account.
- A familiar word with substitutions: Avoid passwords such as
P@ssw0rd123orSummer2026!. Adding symbols or numbers does not help when the pattern is easy to predict.
The examples below show how the two secure formats work. They are public examples, so generate your own credential rather than reusing them.
A Passphrase Built from Four or More Random Words
A strong passphrase combines at least four unrelated random words and reaches at least 15 characters. For instance:
harbour-moss-cello-lantern
Do not use that example as a real password. Select your own words randomly and avoid sentences, lyrics, quotes or themed lists.
This format suits the few credentials you must remember, especially your password manager’s master password.
A Randomly Generated String from a Password Generator
A password generator creates a long random string for an account you do not need to memorise, such as:
v7#Qm2!zL9@pR4$xT8&c
Use the generator inside your approved password manager and let the vault store the result. Never copy a password from an article or enter a live password into an untrusted online generator.
Passwords that Look Strong but are Not
Some passwords meet a website’s character rules while remaining predictable. Avoid these common patterns:
P@ssw0rd!: Common substitutions.Winter2026!: A season followed by the current year.CompanyName123!: Public business information.PurpleElephant: A familiar two-word combination.BasePassword-Xero: One reused base with an account label.
Generate a new credential instead of modifying any of these patterns.
What is the Difference Between a Strong Password and a Passphrase?
A strong password is the security standard: it is long, unique to one account and hard to predict. A passphrase is a password format made from several unrelated words.
The following table separates the security standard from the password format:
| Area | Strong Password | Passphrase |
|---|---|---|
| What it is | A password that meets security requirements | A password format made from words |
| What it needs | Length, uniqueness and unpredictability | Four or more unrelated words with enough total length |
| When it applies | Every account | Passwords a person needs to remember or type |
| Common mistake | Reusing a password or following a familiar pattern | Using a quote, lyric, personal reference or complete sentence |
A passphrase meets the strong-password standard when it is long enough, genuinely random and used for one account only.
Use a random-word passphrase when you need to remember or type the credential yourself.
To make the passphrase meet the strong-password standard, we suggest to follow the ACSC’s guidance on creating strong passphrases password:
- Choose at least four unrelated words with a total length of 15 characters or more.
- Avoid lyrics, quotations, personal references and complete sentences.
- Do not reuse the passphrase for another account.
How do Passwords Get Stolen?
Passwords are usually stolen through four routes: deception, automated guessing, leaked credentials and malware on a device.
Each route is a different cyberattack method, so each calls for a different mix of password, authentication and device controls. Let’s walk through it.
Phishing
Phishing steals passwords through a fake sign-in page or a request designed to make someone disclose them.
This form of social engineering can imitate Microsoft 365, a bank or a supplier.
MFA blocks many password-only takeovers, while security keys and suitable passkeys provide stronger phishing resistance.
Brute Force and Password Spraying
Brute-force attacks test many passwords against one account, while password spraying tests a few common passwords across many accounts.
You can use long random credentials, MFA, compromised-password blocking and sensible sign-in limits, then monitor repeated failures for signs of an attack.
Credential Stuffing After a Data Breach
Credential stuffing uses email-and-password pairs exposed in one breach to access other services.
A unique password for every account contains the damage because the stolen credential has nowhere else to work. Replace reused passwords and common base patterns first.
Malware that Records Keystrokes
Keylogging malware records what someone types, and other malware may steal browser data or authentication tokens.
A password manager reduces manual typing, while patching, endpoint protection such as antivirus, restricted privileges and monitoring protect the device and active session.
How Do You Manage Strong Passwords Across Every Account?
You can manage passwords across every account using three controls: an approved password manager, MFA on important accounts, and agreed response steps for exposed credentials.
Together, these controls form a password management process your team can follow and demonstrate.
Storing Passwords in a Password Manager
A business password manager generates unique credentials and stores them in an encrypted vault. Choose one that gives your team:
- Business ownership and administrator roles
- MFA for the vault
- User groups and role-based access
- Controlled sharing and audit logs
- Reliable onboarding, offboarding and recovery
- Support for your devices and identity platform
Also, protect the master password with its own random-word passphrase and MFA. Document recovery access so one employee or personal account does not control the vault.
Adding Multi Factor Authentication to Important Accounts
Add MFA first to email, the password manager, administrator accounts, finance systems, cloud platforms, remote access and services holding sensitive customer data.
Use phishing-resistant MFA for higher-risk access where practical, and remove old recovery methods during offboarding.
Replacing a Password that Has Been Exposed
Replace an exposed password immediately and treat the event as a possible account compromise:
- Use a trusted, updated device to change the password.
- Sign out active sessions and revoke remembered devices or tokens.
- Replace the password anywhere it was reused or closely copied.
- Check recovery details, MFA enrolments, forwarding rules and permissions.
- Review sign-in logs and notify your security or incident owner, or the managed security services provider monitoring your environment.
- Record the exposure, actions and any notification decision.
Always contain the account first, then follow approved logging and incident procedures to investigate what the attacker may have accessed.
Why Do Weak Passwords Put Australian Businesses at Risk?
Weak passwords put Australian businesses at risk because one stolen credential can give an attacker access to the systems, funds and data your team relies on.
Once an attacker gains access to an account, the impact can spread well beyond that first login:
- Business email can be exploited for fraud, including messages that impersonate staff, suppliers or executives.
- Cloud files and customer records may be exposed, turning a single compromised account into a broader data breach.
- Finance and business software can be disrupted, delaying payments, blocking access to key systems or interrupting delivery work.
- Customer confidence can be damaged, particularly when you must explain what information was accessible.
For your reference, Australian breach reporting shows that compromised credentials are a recurring part of serious cyber incidents.
In its Notifiable Data Breaches Report for July to December 2024, the OAIC recorded:
- 84 cyber incident notifications involving phishing and compromised credentials
- 51 involving compromised or stolen credentials by an unknown method
- 16 involving brute‑force attacks with compromised credentials
Also, it’s important to note that these figures do not confirm every incident began with a weak password.
They highlight how often stolen credentials feature in reportable incidents, and why password strength is a business risk rather than just a login rule.
What do Australian Cybersecurity Frameworks Require for Passwords?
Australian frameworks take different approaches to password security:
- The Essential Eight focuses on multi-factor authentication
- The SMB1001 sets tiered requirements for passwords, access and supporting evidence.
The difference is easier to see when you compare the Essential Eight and SMB1001 requirements side by side.
Essential Eight Requirements for Passphrases and Multi-factor Authentication
The Essential Eight sets MFA requirements by maturity level, but it does not prescribe a separate passphrase requirement.
The MFA requirement expands as maturity levels rise under the Essential Eight Maturity Model:
- Maturity Level One applies MFA to organisational, third-party and customer-facing online services that handle sensitive data. It also covers non-sensitive third-party services where MFA is available.
- Maturity Level Two extends MFA to privileged and unprivileged users of systems, adds phishing-resistant MFA for specified access and requires central MFA event logging.
- Maturity Level Three adds MFA for users of data repositories and strengthens phishing-resistant MFA requirements.
These MFA requirements sit within a model assessed across all eight strategies. If a tender asks for a maturity level, password practice is only one part of the evidence.
SMB1001 Password Requirements Across Certification Tiers
SMB1001:2026 builds password and sign-in controls from basic password hygiene at Bronze to broader management and assurance at higher tiers.
Each tier carries the earlier controls forward, so the progression looks like this:
| SMB1001 tier | Password and authentication focus |
|---|---|
| Level 1, Bronze | Basic password practice, including routine password changes. |
| Level 2, Silver | A business password manager, MFA for employee email, individual accounts and tighter administrative access. |
| Level 3, Gold | Wider password-manager use and MFA across business applications and social media accounts. |
| Levels 4 and 5, Platinum and Diamond | The lower-tier identity controls carried into stronger governance, assurance and independent verification. |
The table shows the password and authentication progression, not every requirement in the standard.
If SMB1001 is your target, use the current SMB1001 material from Dynamic Standards International to confirm the exact controls, evidence and certification scope for your chosen tier.
How do Password Practices Affect a Cyber Insurance Application?
Password practices can affect a cyber insurance application because insurers may ask how your business protects access to systems that could lead to a loss.
The exact questions can vary, but MFA, password policies and account access are common areas of scrutiny.
To illustrate, we saw that an Australian mid‑market cyber insurance proposal form asks whether MFA protects remote, privileged, backup and cloud access, and whether the business uses a password policy, password‑manager software or single sign‑on.
Those questions test whether the practices you describe are operating in the accounts that matter. To answer them credibly, keep records that match the controls you say are in place:
- Your current password and authentication policy.
- An MFA coverage report, including any approved exceptions.
- Password-manager or single sign-on deployment records.
- Records showing how privileged access is assigned and removed when staff change roles or leave.
- Records showing how exposed credentials are disabled and replaced.
This password evidence is only one part of a wider cyber insurance assessment. You still need to confirm the insurer’s definitions and evidence requirements with your broker or insurer.
Strengthen Password Security with Redscale
Strengthen Password Security with Redscale
Insurers are not the only ones asking. A client review or tender wants the same answer, who can access email, cloud tools and privileged systems and how that access is controlled.
When that answer lives across browsers, spreadsheets and personal accounts, the review stalls.
Redscale’s password management service helps you get credentials under control, gives each person their own access, and builds the records you can hand straight to a client, tender or insurer. If your requirement reaches SMB1001, the same team closes your remaining gaps and prepares your evidence through SMB1001 certification support.
Book a free discussion with Redscale and walk away knowing exactly what your business needs to meet password requirements under Essential Eight and SMB1001.
FAQ
What is an Example of a Strong Password?
A strong password can be a passphrase such as “harbour-moss-cello-lantern” four unrelated words with more than 15 characters. Do not use this public example; generate your own random words instead.
How Many Characters Should a Strong Password Be?
Use at least 15 characters for general passphrases, following ACSC guidance to make a strong password. Longer is better when the service supports it, especially when four or more random words form the passphrase.
Do Passwords Still Need to be Changed Every 90 Days?
No, the passwords do not need a universal 90-day change schedule. Because user credentials should be changed when they are compromised or suspected of compromise, while a contract, insurer condition or certification control may set a different requirement.
Is a Password Manager Safe to Use in a Business?
Yes, a reputable business password manager is safer than storing credentials in browsers, spreadsheets or shared documents. Because a reputable business password manager gives your team controlled generation, encrypted storage, sharing and offboarding. Still, protect the vault with a unique master passphrase and MFA, restrict administrator access, and document recovery procedures.
What Should You Do if a Password Appears in a Data Breach?
When your password appears in a data breach, you should replace the password immediately, revoke active sessions and change it everywhere it was reused. Then check recovery settings, MFA enrolments, sign-in logs and account changes before following your incident process for any notification decision.
How Does Redscale Help Businesses Enforce Strong Password Policies?
Redscale helps your business turn password rules into a managed process for storage, individual access, secure sharing, MFA and offboarding. Where SMB1001 is a customer or tender requirement, Redscale can extend that work to remediation and certification evidence.






