Join our Newsletter — 33% off our NHI Course

What do organisations get wrong when they tell users not to write down passwords and not to reuse them?

The mistake is giving advice that ignores how people actually manage many credentials over time. If password reuse is prohibited, users need a practical way to store and retrieve unique secrets. Without password managers, certificate-based authentication, or a credible transition plan away from passwords, the guidance becomes contradictory and unworkable.

Why password rules fail when they ignore storage and retrieval

The core error is treating password advice as if people manage one or two credentials, when most users are juggling many accounts, changing devices, and recovering access under time pressure. If you forbid reuse and also tell people not to write anything down, you have not removed the problem, you have pushed it into memory failure, insecure workarounds, and support burden.

That is why modern guidance has to pair password rules with a realistic storage method. A password manager gives users a controlled way to keep unique secrets without forcing them to rely on memory alone, and certificate-based authentication can reduce the password burden altogether. The advice only works when the operational path is as clear as the policy.

What organisations miss about human behaviour and secret sprawl

Users do not experience password policy as a neat abstract rule, they experience it as a daily task across email, payroll, banking, internal tools, and recovery channels. When organisations assume perfect memory, they ignore the fact that secret reuse, password reset loops, and personal note-taking are predictable responses to overloaded credential management.

Good policy design starts from the actual lifecycle of credentials: creation, storage, retrieval, rotation, and recovery. If an organisation wants unique passwords everywhere, it must also provide a way to manage them at scale, and it must make sure the approved method is easier than the unsafe alternatives. That is where managers, single sign-on, and stronger authenticators become part of the control, not an optional extra.

One reason this gap matters is that reused or poorly stored passwords are easy prey for credential stuffing and related account-takeover patterns. NHIMG’s 23andMe credential stuffing 2023 case shows how reused credentials can turn a single weakness into broad downstream exposure.

What better guidance looks like in practice

Better guidance does not stop at “do not write it down” or “do not reuse passwords.” It tells users what to do instead, and it gives the organisation a support model that makes the safer behaviour practical. The replacement can be a password manager, passwordless or certificate-based authentication where feasible, or a staged migration that reduces the number of passwords users must remember.

That is also why password policy needs to be aligned with account recovery and helpdesk processes. If users cannot retrieve a unique secret when they need it, they will create their own retrieval system, often outside the organisation’s visibility. A policy that is technically strict but operationally unusable is usually less secure than a policy that is slightly more permissive but actually adopted.

NHIMG’s Password Security and Password Manager Guide covers the modern policy direction, including password managers, breached-password defences, and the transition away from shared or reused secrets.

Risk and Threat Considerations

When organisations give impossible password advice, the usual failure is not immediate non-compliance, it is compensating behaviour: users choose weaker memorisation patterns, store secrets in unsafe places, or recycle credentials across systems. That increases the chance of account compromise and expands the blast radius of one stolen password.

Failure mechanism: If the policy bans reuse but does not supply a trusted storage or passwordless alternative, users create their own insecure inventory of secrets, which attackers can exploit through phishing, malware, or credential stuffing.

Impact: The result is more account takeover risk, more helpdesk resets, more password fatigue, and weaker security than the policy was meant to create.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST SP 800-63 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management Passwords, managers, and rotation are core authenticator lifecycle concerns.
Recommendation — Provide approved storage, rotation, and revocation processes for authenticators.
NIST SP 800-63 Digital Identity Guidelines The question concerns realistic password use and migration toward stronger authentication.
Recommendation — Adopt phishing-resistant authenticators and reduce dependence on memorized secrets.
CIS Controls v8 CIS-5 — Account Management Account hygiene and credential handling are central to preventing reuse and unsafe workarounds.
Recommendation — Standardize account handling, credential rules, and recovery processes that users can actually follow.
ISO/IEC 27001:2022 A.5.17 — Authentication information Password handling and storage are directly governed as authentication information.
Recommendation — Define secure handling rules for authentication information and approved user workflows.

Practitioner Guidance

What to verify: Check whether the organisation has a sanctioned way for users to store, retrieve, and rotate unique credentials without relying on memory alone. If not, the password rule is probably broken by design.

Decision rule: If users must manage more than a small number of credentials, pair uniqueness requirements with password manager support, SSO where possible, and a clear path to phishing-resistant authentication for higher-risk accounts.

Common mistake: Treating password policy as a user-discipline problem instead of an authentication design problem. The control fails when the organisation expects perfect behaviour but provides no practical system for achieving it.

Practitioner takeaway: A workable password policy reduces user burden while improving security; if your guidance depends on memory and prohibition alone, it is setting people up to fail.