No one ever got directly hacked because their password was too strong, but lots of people have had passwords guessed by brute force.
So put the two together. Its beneficial to have strong passwords because they can be presented as evidence of due diligence and there is no security risk to enforcing them. There may be some business risk(people fleeing because they don't like your password policy) but someone needs to quantify that its a problem for it to be considered in the calculus.
Your content free, one sentence response not withstanding. Is there something specific you'd like clarification about?
>How exactly does taking steps that have previously been used in civil suits to demonstrate due diligence such enforcing password requirements going to demonstrate due diligence?
Well I'm glad you asked billy! The answer is tautology. Thanks for playing.
This argument is stupid. You want to talk about yak shaving, theoretical nonsense. FWIW I agree with you and think that password requirements are dumb, but you live in the real world. These are the legal realities of IT policy.