Weak passwords bringing business headaches

November 29, 2011 15:55
As IT departments in all industries continue to craft elaborate strategies to guard against online security threats, a number of organizations seem to be overlooking the fundamentals of password protection.

As IT departments in all industries continue to craft elaborate strategies to guard against online security threats, a number of organizations seem to be overlooking the fundamentals of password protection.

The recent network breach discovered at an Illinois water treatment plan came as a surprise to many in the information security community. But perhaps most disturbing was one hacker's revelation in a Threatpost interview that suggested critical control infrastructure for the facility was guarded by a mere three-character password.

According to InfoWorld contributor Roger Grimes, the default administrator credentials favored by hardware and software vendors may be to blame for problems seen across all industries.

"The better vendors force users to choose a new password when logging in for the first time, require strong password and force adequate password updates after that," Grimes wrote in his latest column. "The worst vendors have products with hard-coded administrative passwords that cannot be changed."

To enforce strong security across company networks, IT administrators must ensure they have the ability to manage fundamental security controls for all utilities. Although it can be exhaustive for larger organizations, experts recommend using password manager software to develop and store unique passwords for all systems and ensure security without sacrificing convenience.

Data Security

March 06, 2012 While everyday computer users may think their systems are secure, recent events serve as a warning that no ...

March 05, 2012 A majority of companies continue to fear the devastation online security breaches can inflict on their ...

March 05, 2012 One widely observed problem in a recent online security survey was the systematic weakness of passwords ...

March 02, 2012 Companies are apparently justified for feeling nervous regarding the increased scope of online security ...

March 02, 2012 When data becomes threatened, a timely response is critical. However, recent online security findings ...

March 01, 2012 The hacker group known as Swagg Security recently conducted a cyberattack against Apple's manufacturing ...

March 01, 2012 Users of an adult entertainment website were targeted during a high-profile online security breach that ...