The correct answer is routine password rotation, but of course that's stupidly hard to do.
Instead, that energy is better spent on requiring strong passwords and people using password managers and two-factor.
There are other options for securing/managing infrastructure access (e.g. PKI, Hashicorp Vault), but if you're using passwords, it's a good idea to rotate them if only to encourage good practices around automation.