Rotating Your Passwords Every 90 Days Isn't Security. It's Theater.

Caiber September 15, 2026

The 90-day password rotation rule has stuck around for decades, largely on inertia rather than evidence. Forcing people to change a password every few months mostly produces slightly different versions of the same password, not meaningfully stronger security.

Rotation on a timer solves the wrong problem

Scheduled rotation assumes the danger is a password slowly getting guessed over time. That's rarely how modern compromise actually happens. Credentials get phished, leaked in a breach elsewhere, or lifted from a device, all events with no relationship whatsoever to whether today happens to be day 90.

What actually matters is how fast you can react, not how often you rotate on schedule

The real question isn't "when did we last rotate this," it's "if this credential were compromised right now, how quickly would it stop working." Time-bound, just-in-time access answers that question by design. A calendar-based rotation policy doesn't answer it at all.

If your current password policy is built entirely around a countdown timer, it's worth asking what specific threat that timer is actually defending against.