How often should I actually change my passwords?
Why scheduled password changes were abandoned by the people who invented the advice, the four events that genuinely require a change, and what to do instead of a calendar reminder.
- Difficulty
- beginner
- Time
- 7 min
- Read
- 3 min
Short answer
Not on a schedule. Routine forced changes were dropped from UK and international security guidance years ago because they make passwords weaker, not stronger — people make small predictable edits to something they can remember. Change a password when there is a reason: a breach, a suspicion, a reused password, or a shared one after circumstances change.
The ninety-day password change is one of the most persistent pieces of obsolete advice in the field. It came from an era of shared systems and offline cracking, and the organisations that promoted it — including the UK's National Cyber Security Centre — now explicitly advise against it, because the evidence showed it backfiring.
Step by step
- Understand why the old rule failed.Forced regular changes push people towards passwords they can remember and edit — a word plus a month, a number incremented each time. That pattern is trivially predictable, and it makes every password in the estate weaker rather than stronger.
- Change a password when it has been breached.If a service tells you it was breached, or a breach-checking service lists your address, change that password and change it anywhere you reused it. That is the real trigger.
- Change it when you suspect compromise.An unexpected login alert, a code you did not request, an unfamiliar device in the account activity, or a message sent from your account that you did not send.
- Change it when it is reused.Any password used on more than one site should be replaced with unique ones, starting with the accounts that matter most. This is worth doing steadily rather than in one weekend.
- Change it when circumstances change.A shared password after a relationship ends, a housemate moves out, or a family member no longer needs access. Nothing technical has failed; the trust arrangement has changed.
- Change it when it is weak or old enough to be guessable.A short password, a dictionary word, a family name, a date — those need replacing regardless of age. A long unique random password does not become worse with time.
- Spend the effort on the things that do help.Uniqueness, length, a password manager, two-factor on the accounts that matter, and passkeys where they are offered. Any of those beats a rotation schedule several times over.
- Check the accounts rather than the calendar.Once a year, review the sign-in activity, connected devices and recovery details on your important accounts. That is a far better use of the same twenty minutes.
Tips
- If your employer forces regular changes, that is their policy rather than current best practice; use a password manager to generate a genuinely new one each time rather than editing the last one.
- The one password worth deliberately making strong and memorable is the master password on your manager, because it is the only one you will type.
- Changing a password does not end existing sessions on many services. Use "sign out everywhere" after any suspected compromise.
Common mistakes
- Incrementing a number at the end — It is the most predicted pattern there is, and anyone with the old password can guess the new one in a handful of attempts.
- Changing everything on a schedule and reusing across sites to cope — Reuse is a far bigger risk than age. The schedule causes the reuse.
- Ignoring a breach notice because you changed the password recently — Recency is irrelevant if the specific password leaked. Change that one.
Questions people ask
Is it true that experts no longer recommend regular changes?
Yes. The UK National Cyber Security Centre and international standards bodies both advise against routine forced expiry, and recommend changing on evidence of compromise instead.
What about my banking password?
Same principle. Make it long, unique and stored in a manager, protect the account with a strong second factor, and change it on evidence rather than on a timer.
Should I change passwords after a device is lost?
Change the passwords for anything that was signed in on it, and use sign out everywhere. That is a compromise event, so yes.