Cybersecurity advisors continue to identify that the use of strong passwords is one of the first lines of defence in protecting your employees from falling victim to a cyber attack.
Passwords that can be easily guessed, or that are shared across multiple systems, are the targets of brute force attacks, which exist to access your networks and compromise your business data.
Unfortunately, Australian's are listed among the worst in the world for their password hygiene practices, with the 3rd Annual Global Password Security Report by LastPass finding that:
Further to this, data from their recent Psychology of Passwords survey shows that:
So, what can you do to ensure that your employees are creating strong passwords to protect your business?
To mitigate cybersecurity incidents caused by password breaches, the Australian Cyber Security Centre (ACSC) advises the following:
In previous articles, we have discussed the fundamentals of how to create a secure password. Let's touch on them again below.
1. The longer the better: At a minimum, you should have 8 characters in your password or passphrase, however, we recommend 12 or more.
2. Complexity: Adding numbers and characters greatly increases the strength of a password, as does a combination of lower and upper case letters.
3. Avoid repetition: Try to avoid creating a complex password, then incrementing it by one character each time you’re asked to change it. And remember - it is essential not to use the same password across multiple devices and systems. This is where the use of a password manager program can come in handy.
4. Avoid obvious words/phrases: It concerns us that we still have to say it, but don't create passwords using obvious phrases like “Password1", "QWERTY", "asdfjkl", "abc123". Dictionary brute force cyber attacks start with these obvious phrases.
5. Don’t write it down: Don’t record your password anywhere, especially not on a post-it note on your desk!
The ACSC also recommends prevention techniques such as clearly documenting cybersecurity policies and cybersecurity awareness training for all employees.
The purpose of Cybersecurity awareness training is to educate staff about cyber threats and attacks they may be subjected to each day, including the importance of good password hygiene.
Cybersecurity awareness training also ensures that you and your employees understand the part everyone must play in protecting your organisation and client’s data.
If you want to educate your employees on how to create and maintain secure passwords, our staff education programs and policy and procedure reviews can help. Our Business Technology Consultants are specialists in improving your internal cybersecurity.
If you need advice on how you can ensure your cybersecurity strategy is fit for purpose, our team of Cybersecurity experts are ready to help. Contact our team on 1300 307 907 today.