In this VMblog Q&A with Darren Siegel, cybersecurity expert at Specops Software, we discuss password predictions for 2024, what the data from the annual 2024 Specops Breached Password Report revealed, and how threat intel helps with password security.
VMblog: How do you see password security evolving in 2024?
Darren Siegel: Passwords have been around for decades but as our digital presence expands, our use of passwords evolves. I see three key changes happening this year.
- Passwordless technology will continue to push the password further from the top of mind, but it will remain a backup authentication even for those that deploy it, increasing the importance of protecting the now thought-of-even-less password.
- As an increasing number of organizations move toward longer times between password expiration or even never-expiring passwords as recommended by NIST and other reputable sources, the need for continuous monitoring will inevitably rise.
- In July 2023, the Securities and Exchange Commission (SEC) approved new disclosure rules that will result in a rise of reported attacks. It’s estimated that 80% of successful data breaches are the result of compromised login credentials. Disclosed attacks can have a significant impact on stock prices but an upside for IT teams is that the threat of this may mean increased buy-in on preventive measures.
VMblog: How will the cyberattacks of 2023 affect password security in 2024?
Siegel: In the latter half of 2023, there was prevalence of highly successful and high-profile social engineering attacks. A prime example of this is the attack on MGM resorts, when an attacker found an employee’s information on LinkedIn and impersonated them in a call to MGM’s IT help desk to obtain credentials to access and infect the systems. These high-profile attacks have sparked a concern for potential copycat attempts and has highlighted the urgency for implementing appropriate safeguards against such social engineering attacks on the service desk within IT departments and among C-level executives. It is imperative for organizations to prioritize securing authentication and mitigating social engineering threats in order to safeguard their critical assets and reduce the risk of potential financial and reputational damages.
VMblog: What does the 2024 Breached Password Report tell us about password security?
Siegel: What the 2024 Specops Breached Password Report tells us is that the password is still a major risk of attack entry for all types of organizations. The report shares the latest research into the trends and patterns of weak and compromised passwords. In 2023, our research group conducted frequent analysis on leaked password information and real-time cyber-attacks.
The report discusses weak password patterns and how they are exploited while exposing the hidden risk of compromised passwords. There’s data on keyboard walk patterns, the strength of longer passwords, the time it takes to crack passwords using different technology, and baffling stats such as: After analyzing 1.8 million breached administrator credentials, 40,000 admin portal accounts were found to be using ‘admin‘ as a password.
The 2024 Breached Password Report consolidates the key discoveries from our research, including some previously unreleased information to provide organizations with a comprehensive understanding of the patterns and developments in breached passwords, as well as offer guidance on enhancing security measures.
If you’re looking to grab some stats to help you make the case for the password security program you want to implement or just want to see the latest insights to help you create a stronger password policy, I highly recommend giving it a read.
VMblog: What are the key takeaways for organizations to implement to increase their password security in 2024?
Siegel: The constant threat of stolen credentials, password reuse and evolving cyberattacks are going to continue to rise and threats will become more sophisticated. Passwords will remain a form of authentication and vital for organizations to protect.
The biggest key takeaway is that no matter how long, complex, or strong a password is, if it is compromised – it is a risk. So continuous scanning and monitoring for known compromised passwords is critical to any modern security program.
Also, organizations can tighten up their password policy. Tools like Specops Password Policy helps organizations easily implement custom dictionaries to block common words, complexity requirements, length-based aging to promote longer passwords, compliance standards, continuously block compromised passwords and more.
VMblog: How can continuous scanning for compromised passwords benefit organizations?
Siegel: In the 2024 Breached Password Report we shared how one survey uncovered that 45% of organizations who only check for compromised passwords during expiry or reset events average only two checks for compromised passwords per year.
By continuously scanning for compromised passwords organizations mitigate the risk of password reuse along with other internal and external unauthorized access risks. The continuous scan function of Specops Password Policy conducts daily evaluations using the Specops Breached Password Protection service. This service is updated daily with passwords obtained from honeypot networks, recently uncovered password breaches, and an all-new source of compromised password data is powered by the threat intelligence unit of Specops Software’s parent company, Outpost24. The threat intel data can detect both leaked credentials in underground markets, and stolen credentials obtained by malware. There are continuous searches that capture credentials obtained by malware in real-time. As a result, IT experts have reliable and current access to one of the most comprehensive databases of compromised passwords available.
Click here to try Specops Password Policy for free and see how the continuous scan feature can enhance your password security for 2024.
##






