Me 5 seconds after my corpo mandated password change: Hey did you know mandated periodic password changes aren't considered good cybersecurity practice and in fact actually weaken password security? Just a funny little fact I thought you should know.
"ISO 27001 requires it, so our hands are tied"
It's actually ISO 27002 that had these guidelines and they removed them in 2022