Business accounts are linked together. A single weak password on an email, Slack, Google Workspace, Microsoft 365 or GitHub account can give an attacker access to customer data, invoices and internal files, and business email compromise, where criminals use a real mailbox to request payments, is one of the most costly forms of cybercrime. Attackers know that one reused or guessable password inside a company is often enough.

Every person should have their own login with a unique random password of at least 16 characters, generated and stored in a team password manager. When a login truly has to be shared, share it through the password manager rather than by email or chat, so access can be removed later. Keep administrator accounts separate from everyday accounts and protect them with the strongest options available, such as passkeys or security keys.

Current NIST guidance (SP 800-63B) advises against forcing staff to change passwords on a fixed schedule, which mostly leads to predictable variations. Instead, require two-factor authentication or single sign-on, check passwords against known breach lists, and change credentials immediately when someone leaves the team or a compromise is suspected.

Try the generator

24

Your settings are remembered on this device only. Privacy Policy.

Example password patterns

1

Two random words joined with a hyphen, plus a 2-digit number and a symbol — e.g. Word-Word##!

2

A short phrase you'll remember (4 words), separators between each word, no spaces — e.g. Word_Word_Word_Word

3

Acronym from a movie quote or song line + the year you first heard it + a symbol — e.g. FirstLettersYYYY!

4

Three uncommon words concatenated, with a digit and a symbol — e.g. WordWordWord#9

5

Mix of casing and one substitution per word (don't overdo it — substitutions don't add much entropy) — e.g. wOrd-wOrd-99!

6

Let our generator pick the whole string — the most secure option. Click Generate above.

Frequently Asked Questions

Should we force employees to change passwords every 90 days?
No, according to NIST SP 800-63B. Forced periodic changes lead people to make small, predictable edits like adding a number. It is more effective to require long unique passwords, block passwords that appear in breach lists, enforce two-factor authentication, and require a change only when there is evidence of compromise or when someone with access leaves.
What is the safest way to share a password with a coworker?
Use a business password manager that supports shared vaults. It encrypts the password, shows who has access and lets you revoke access later. Avoid sending passwords over email, chat or spreadsheets, where they stay readable in message history. Where possible, give each person their own account instead of sharing one.

Related Tools

Continue your security workflow with these tools