As of now, every time a customer gets a new (random and unsecure) password sent via email, they are able to login with it straight away, with no signposting towards how they can actually reset their password to a memorable one.
My idea is that after a customer is sent their new password and logs in with it, they are automatically redirected to the "Change Your Password" page, so they can pick their own secure and memorable password and not have to redo the password reset every time they login.
You can see details and illustrated examples in the attachment.