Latest NIST guidance advises against changing passwords yearly and recommends using three random words instead of complex characters for better security.

The NCSC wants developers to get serious on software security
The NCSC’s new Software Security Code of Practice has been praised by cyber professionals as a significant advancement in enhancing software supply chain security.