Which is why in a lot of corporate systems, the password history is set to 13 last passwords. a) it prevents a 0-9 rotation, and b) it also prevents people rolling passwords based on month name or number.
pls don't hack me
As the implementer, I've argued many times about it, but the ITSec bods always think they know best.