What NIST says about passwords in 2025
NIST dropped forced ninety-day resets and the symbol-and-number rules years ago. Length is what holds up. This scene teaches SP 800-63B, the guidance most workplaces still have not caught up to.
Six in ten breaches last year involved a person, according to the Verizon 2025 DBIR, and stolen passwords led the way. A firewall cannot stop an employee from handing over a login. Training can. DMS keeps a dated record of who finished, so when your insurer asks at renewal whether you train your people, you can prove you do.
Every employee takes the all-staff core first. Finance, executives, HR, developers, and IT then get a track built around how their job gets targeted. Below is one all-staff scene on passwords. The captions carry it, so turn the sound off if you are at your desk.
NIST dropped forced ninety-day resets and the symbol-and-number rules years ago. Length is what holds up. This scene teaches SP 800-63B, the guidance most workplaces still have not caught up to.
Finance moves money. IT holds the admin keys. Each track covers the attack those people face, from wire fraud to credential theft.
Business email compromise and the call back that stops a fraudulent wire before it leaves.
Targeted impersonation and voice phishing, including the urgent ask that lands while you travel.
Opening resumes and files from people you do not know, without letting an attacker in.
Secure development habits, drawn from real incidents like Log4Shell.
Protecting elevated access, from MFA fatigue to admin credentials left in code.
The sample is one scene from a real module. The platform tracks completion and issues a certificate to everyone who finishes.
The Verizon 2025 Data Breach Investigations Report found the human element in roughly six of every ten breaches, with stolen and misused credentials a leading way in. That is the gap firewalls do not close. NIST treats awareness and role-based training as a managed program in SP 800-50 Revision 1, and maps it to the Awareness and Training controls, AT-1, AT-2, and AT-3, in SP 800-53. DMS is that program, ready to run.
Source: NIST SP 800-63B, Digital Identity Guidelines, Section 3.1.1.2. Our all-staff module teaches it.
Security awareness training is not a nice to have in these frameworks. It is named, by citation, in each one. DMS gives you the training and the dated, per-employee records that show it happened.
A security awareness and training program for the workforce.
A formal security awareness program for all personnel.
Security awareness training for staff, a binding requirement.
Regular cybersecurity awareness training for personnel.
Information security awareness, education, and training.
The Awareness and Training control family, literacy and role-based.
Cyber-insurance applications now ask whether you run security awareness training. The honest answer needs evidence. Every employee who finishes a cycle earns a certificate like this one, and your admin can export a twelve month proof packet to hand your broker at renewal.
Sample certificate. Name and company are illustrative.
Sign up as the admin and invite your team by email. Employees sign in with a magic link, so there are no passwords for them to forget or reuse.
Everyone takes the all-staff core. Finance, executives, HR, developers, and IT also get the track for their role. You buy a pool of seats and reassign them as people join or leave.
Your twelve month packet is ready to download at renewal. It carries each employee's completion date, quiz score, and certificate. That is the evidence the insurance form asks for.
Sign up as the admin and invite your team. Every employee who finishes earns a certificate, and your twelve month proof packet is ready the day your broker asks for it.
Start your organization