Business passwords do not need routine forced changes if they remain secure; they should be changed promptly when compromise is suspected, alongside the use of unique strong passwords and multi-factor authentication.
Password managers can help staff create and store unique passwords without reusing them across services. Accounts with elevated privileges need especially careful protection.
For wider guidance, see the NCSC guidance on securing important online accounts and Kazzoo’s IT Security service in Leicester.
Why should businesses use multi-factor authentication?
How can a business make its email more secure?
How can a business improve its cybersecurity?