Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› Why do arbitrary password rules often create more…
Authentication, Authorisation & Trust

Why do arbitrary password rules often create more risk than they reduce?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 30, 2026 Domain: Authentication, Authorisation & Trust

Arbitrary rules often encourage users to optimize for compliance instead of security. When people are forced to satisfy character mixes, frequent expirations, or other rigid checks, they commonly choose shorter, predictable, or slightly modified passwords. That behavior increases reuse and makes credentials easier to guess or crack, especially when attackers already know common patterns and breached passwords.

Why rigid password composition rules backfire

Arbitrary password rules change user behaviour more than they improve attacker resistance. When people have to satisfy character classes, forced rotation, or awkward length rules, they tend to pick passwords that are easier to remember but weaker in practice: predictable substitutions, reused patterns, or a small family of variants across systems. The control looks strict, but it often pushes risk into user workarounds.

That failure mode matters because password strength is not just about meeting a policy checklist, it is about resisting guessing, reuse, and automated cracking. A policy that encourages memorability hacks can reduce actual entropy while creating a false sense of assurance for the organisation.

What actually gets worse when users optimise for compliance

Arbitrary rules usually reward the wrong outcome. A user may satisfy a complexity prompt by appending digits, capitalising the first letter, or making a single predictable change every time a password is reset. Those patterns are easy for attackers to anticipate, especially when they already have breached-password dictionaries and common transformation rules.

The other common effect is reuse. If one system demands a long random password and another forces frequent changes, users often converge on a manageable pattern and carry it across accounts. That increases the blast radius of a single compromise and makes credential stuffing more effective.

The practical problem is that the rule is measured at entry time, while the attacker benefits from the resulting pattern over time. A policy can pass the compliance gate yet still make the account easier to compromise than a simpler rule focused on length, uniqueness, and real-world protection against guessing.

Better password policy puts fewer burdens on memory and more on resistance

Strong password policy is usually about reducing predictable behaviour, not increasing ceremony. The most defensible controls are the ones that help users choose unique, high-entropy credentials and then reduce the damage if one secret is exposed. That includes encouraging password managers, blocking known-compromised passwords, and avoiding unnecessary forced changes that teach users to rotate into patterns.

Modern guidance also treats length as more valuable than arbitrary composition. A long passphrase is often easier for users to remember and harder for attackers to crack than a short string that merely satisfies mixed-case and symbol requirements.

Where organisations still rely on passwords, the goal should be to make them boring and hard to guess, not clever and rule-compliant. Policy should support secure user behaviour, not force users into visible pattern generation.

Risk and Threat Considerations

Rigid password rules can create predictable password families, lower effective entropy, and increase reuse across accounts. That raises the likelihood that a breached or guessed password will work elsewhere, especially when attackers test common substitutions and reused patterns at scale.

Failure mechanism: Users satisfy the rule instead of improving resistance, so they choose short, memorable, incremented, or partially reused passwords that are easier to guess or crack.

Impact: The organisation gets weaker credentials, more successful credential stuffing, and a larger compromise blast radius when one password is exposed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST SP 800-53 Rev 5, CIS Controls v8 and OWASP ASVS set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesPassword policy and authenticator guidance are central to this question.
Recommendation — Prefer longer, user-manageable secrets and block compromised passwords instead of relying on arbitrary composition rules.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementControls password lifecycle and requirements that shape credential strength and reuse.
IA-2 — Identification and Authentication (Organizational Users)The issue affects how users authenticate with passwords and related authenticators.
Recommendation — Set authenticator requirements that reduce reuse and avoid rules that encourage predictable password patterns. Align user authentication policy with usable, resistant authenticators rather than brittle composition checks.
CIS Controls v8CIS-5 — Account ManagementPassword policy sits within account and credential management practices that affect exposure.
Recommendation — Enforce credential hygiene with unique passwords and compromised-password blocking, not arbitrary complexity rules.
ISO/IEC 27001:2022A.5.17 — Authentication informationThis subject is about protecting and managing authentication information such as passwords.
Recommendation — Apply authentication-information controls that support strong, unique secrets and safe handling.
OWASP ASVSV6 — AuthenticationThe question concerns password handling and authentication strength in practice.
V9 — Self-contained TokensCredential strength and token-like secret handling are relevant where passwords are treated as reusable secrets.
Recommendation — Use authentication requirements that improve resistance to guessing and reuse rather than cosmetic complexity. Design secret handling to reduce predictability and reuse across authenticated sessions and accounts.

Practitioner Guidance

What to prioritise: Remove policy requirements that mainly train users to create predictable patterns, and replace them with controls that reduce reuse and exposure. Focus on length, banned-password checks, and password-manager adoption before adding complexity gates.

What to verify: Look at real password behaviour, not policy text alone. If users are reusing the same base word with small edits, the policy is producing compliance theatre rather than meaningful security.

Practitioner takeaway: The best password policy is the one that makes the safe choice the easy choice, because rules that force people to game the system usually end up protecting less, not more.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org