A security company should know this. It's been strictly recommended against in the NIST guidelines (and others) for nearing a decade now. I start to really question the expertise of any security company that parrots this outdated advice. What else are they not keeping up on?
Focus on monitoring, alerting, educating, etc. Force password changes only when there are indicators of compromise.