You Don't Need To Lift Weights To Have Strong Passwords

17 March 2024 | Blog | By:

Passwords are still a most common way to secure our online accounts and our organisation’s computer systems and data. If the cyber attacker is able to compromise your organisation’s password, they will have access to your systems and data, so it is important that your passwords are not easy to compromise.

What Should You Know ?

‘Weak’ password is the term used to describe passwords that are short in the length, contain commonly used words, or easy to guess or figure-out. Examples of ‘Weak’ passwords are 1234, 123456, password123, passw0rd, abc123, qwerty, the name of your pet, the name of your school or the like.

For convenience, people generally are in the poor habit of reusing the same password across multiple online personal accounts and their work-place systems. This poor practice, provides the cyber attacker with a ‘helping hand’, if say one of your online passwords is compromised (i.e. because known), the cyber attacker, will always try the already compromised password as part of their way into your other online accounts and work-place systems. The cyber attackers also have tools, such as specialised software programs to automate the task of ‘cracking passwords’.

‘Strong passwords’ are more difficult for cyber attackers to compromise, even with the use of automated tools and software. Typically, a strong password is between 10 and 15 keyboard characters in length, remember, the golden rule, that the longer the password, the more difficult, it will be for the cyber attacker to compromise.

The trouble with ‘strong’ passwords is remembering them, so that you don’t have to write it down. A tip is to think about three words that are meaningful and memorable to you and then include one or two numbers in between that are memorable to you.

What Should You Do?

As part of a regularised programme of staff awareness, staff should be advised that they should never reuse passwords across multiple online accounts and work-place systems. The staff awareness should also include, staff being advised to immediately change their password, if it is suspected that their password has been compromised.

If the work-place systems can enforce a regular change of passwords or a minimum password length, then these features should be enabled by the IT Department or other relevant person.

Where Two-Factor Authentication (2FA) is available, this should always be enabled on online accounts and work-place systems.

The organization should consider implementing appropriate security systems or enable features in existing systems, to monitor and detect any suspicious login attempts and take appropriate action.

Report to RCIPS, call 911

Last updated: