{"id":46495,"date":"2020-03-17T14:18:09","date_gmt":"2020-03-17T14:18:09","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/2020\/03\/17\/expert-discussion-what-best-practice-approach-should-businesses-take-to-password-security\/"},"modified":"2020-03-23T13:27:40","modified_gmt":"2020-03-23T13:27:40","slug":"expert-discussion-what-best-practice-approach-should-businesses-take-to-password-security","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2020\/03\/17\/expert-discussion-what-best-practice-approach-should-businesses-take-to-password-security\/","title":{"rendered":"What best practice approach should businesses take to password security?"},"content":{"rendered":"\n<p>Password protection is a critical component of a strong business cybersecurity strategy. Kevin Curran, Senior Member of the IEEE and Professor of Cybersecurity at Ulster University, says that the number one rule for companies to manage passwords securely is for their employees to use different passwords across all sites. However, in doing this, individuals often forget their passwords, which not only impacts their productivity in the workplace, but also results in a headache for IT teams. Businesses must have a reputable password manager, which will create complex, strong passwords, and store them in an encrypted file. <\/p>\n\n\n\n<p><em>We hear from a number of experts who offer their opinions on the subject of password security. <\/em><\/p>\n\n\n\n<p><strong>Richard Meeus, Security Technology and Strategy Director, EMEA at Akamai<\/strong>: &#8220;Fundamentally, passwords suck. They have been a thorn in the side of IT professionals for decades, from when 40% of a helpdesk\u2019s time was spent helping users change their passwords, to poor advice in asking users to update their password every 90 days, and make it really complex \u2013 <em>every single time<\/em>.<\/p>\n\n\n\n<p>&#8220;The fact that passwords are so ubiquitous and seen as the default mechanism for user authentication means they are often used without considering the wider picture. This is evident in our public health service, where a myriad of systems with different accounts creates significant delays when staff need to login. Single Sign On (SSO), a technology that\u2019s been around for many years, is being used to try and address this delay. But, if it still revolves around a username and password, then staff are still tasked with remembering a complex password. The NHS is looking to adopt Multi-Factor Authentication (MFA) \u2013 a process that\u2019s more secure as it only grants a user access once they present two or more pieces of evidence. Users can prove their identity by passing a combination of verification stages, providing something they know, something they have, or something they are. As a result, we\u2019re now able to take this to the stage where a password is no longer necessary \u2013 users could sign-on with something they &#8216;have&#8217;, such as a hardware token, and something they &#8216;are&#8217;, using their fingerprint.<\/p>\n\n\n\n<p>&#8220;We have adopted this internally here at Akamai and we use a combination of push authentication to mobile devices, along with certificates on company laptops to provide a password-less experience.<\/p>\n\n\n\n<p>&#8220;Moving away from passwords, or at least complementing them with another factor of authentication, is important considering the volume of data breaches we witness on a daily basis. As users, we\u2019re fundamentally lazy and will often reuse passwords across many sites. Witness the recent &#8216;attacks&#8217; on two high street retailers, where stolen usernames and passwords from previous beaches were used to perform an Account Takeover (ATO), where the criminals seek to monetise whatever is within the account \u2013 normally in the form of cashing out on vouchers or gift cards. The fact they were both high street retailers with significant online business adds interest from an attacker\u2019s perspective. Normally a &#8216;credential stuffer&#8217;, somebody who takes these breached usernames and passwords and tries to find ones that work on a new site, can expect a 1-2% hit rate. If these cybercriminals target the same verticals, the hit rate can be significantly higher. If one were to do a Venn diagram of the users at both stores, there would be a high probability of significant overlap \u2013 ensuring the attackers get more bang for their buck.<\/p>\n\n\n\n<p>&#8220;For businesses, reducing passwords, implementing SSO and adding MFA is an important step. However, if that can\u2019t be done, due to lower IT management budgets or the operational nature of the business, then password managers are essential to ensure good, random, unique passwords are utilised.&#8221;<\/p>\n\n\n\n<p><strong>Stuart Sharp, VP of Solution Engineering at OneLogin<\/strong>: &#8220;According to a recent PwC report, 80% of UK CEOs are worried about the risk of cyberthreats to their business, making it the issue they are most concerned about. Rather than living and working in a state of perennial fear of hackers, businesses should modernise their approach to password security best practices.<\/p>\n\n\n\n<p>&#8220;When it comes to security, humans are the weakest link. According to a recent CybSafe analysis of data from the UK Information Commissioner\u2019s Office (ICO), human error caused 90% of data breaches in 2019.&nbsp;This incredibly high percentage demonstrates the importance of managing the risk associated with human behaviour when addressing cyberthreats.&nbsp; Employees using weak or reused passwords across multiple sites and services (including personal and professional accounts) is one of the riskiest forms of user behaviour an organisation faces. In fact, the World Economic Forum found that four out of five data breaches are caused by weak\/stolen passwords.&nbsp; <\/p>\n\n\n\n<p>&#8220;Although organisations have reacted to the \u2018password risk\u2019 and invested in cybersecurity training to make sure they stay compliant, they often overlook ways to help staff by improving the experience of their users.&nbsp; With Identity-as-a-Service (IDaaS) now readily available, even small organisations can introduce a cloud-based identity system, so users will have a single set of corporate credentials for applications, networks and devices. Some even offer users a convenient, secure password vault for personal applications as well. These modern platforms allow users to log in once to access all their applications and provide them with the ability to easily and securely manage their own passwords and devices.&nbsp;They allow companies to enforce strong password policies and MFA while radically reducing the need for IT help desks to manually reset passwords or manage user devices. It also helps organisations combat shadow IT by offering fast onboarding of business applications with a Single Sign On experience.&nbsp; <\/p>\n\n\n\n<p>&#8220;Password best practice isn\u2019t rocket science and plays a critical part in the security of a business.&nbsp;Organisations must go beyond traditional best practice methods and look at the tools and solutions available to create a process that both increases security and improves the end-user\u2019s experience, making strong authentication simple and seamless to use.\u201d<\/p>\n\n\n\n<p><strong>Jonathan Knudsen, Senior Security Strategist at Synopsys<\/strong>: &#8220;It was more than six years ago that the Defense Advanced Research Project Agency (DARPA), a research and development arm of the Department of Defense (DoD), issued a &#8216;broad agency announcement&#8217; seeking&nbsp;research proposals for developing biometric authentication&nbsp;through analysis of various activities and behaviours \u2014 keystroke patterns, mouse use, sentence structure and use of language \u2014 that add up to what the agency calls a &#8216;cognitive fingerprint&#8217;.<\/p>\n\n\n\n<p>&#8220;Those mechanisms go beyond &#8216;something you know&#8217; (the&nbsp;password) and&nbsp;&#8216;something you have&#8217; (a token or wearable) to enhanced &#8216;something you are&#8217; biometric authentication (fingerprint, voice, face, retina). Implemented correctly, a user&#8217;s biometric measures are stored only on the user\u2019s device.&nbsp;Passwords are &#8216;shared secrets&#8217; that reside on both the device and on a server that, as we all know, can get hacked in various ways.&nbsp;To compromise biometric&nbsp;authentication, an attacker would need physical access to the device.<\/p>\n\n\n\n<p>&#8220;But between now and when&nbsp;passwords really do become as rare as phone booths, be sure to use a&nbsp;password&nbsp;manager, which holds all your&nbsp;passwords in a &#8216;container&#8217; locked by a master key that only the user knows. That means all you have to do is create one really complex&nbsp;password&nbsp;that you can remember. The manager will also help you create unique&nbsp;passwords for new websites or apps.<\/p>\n\n\n\n<p>&#8220;Passwords are convenient for software creators but hard for humans to use correctly. Being human, we want to use the same password for every service, which is a terrible idea. We want to use passwords that are easy to remember, which is a terrible idea. We see passwords as a hurdle that must be jumped before we can actually start getting work done.<\/p>\n\n\n\n<p>&#8220;Authentication, or proving identity, is always based on something you know, something you have, or something you are. Multi-factor authentication combines these. For example, a website might require you to supply a password (something you know) and also send a text message to your phone (something you have). Some apps these days will also rely on a fingerprint (something you are).<\/p>\n\n\n\n<p>&#8220;Passwords are definitely on the decline, as fingerprint sensors become widespread in smartphones, a variety of USB authentication devices (something you have) are available, and smartcards now function as a physical manifestation of a private cryptographic key. These newer authentication methods will be easier for humans to use correctly, as the concept of the security of a USB device, a smartcard, or a fingerprint is much easier to understand than the problem of remembering a password, or knowing how to pick a password that is hard to guess.&#8221;<\/p>\n\n\n\n<p><strong>David Emm, Principal Security Researcher at Kaspersky<\/strong>: <\/p>\n\n\n\n<p>&#8220;Businesses continue to invest heavily in security solutions but it\u2019s essential for corporate security measures to cover not only external attacks, but internal weaknesses within an organisation. Due to human error, negligence and a simple lack of knowledge, staff often choose weak passwords, thereby making themselves the weakest link in the security chain. This applies particularly to businesses &#8211; one employee with a weak password could open the door to an attacker, compromising the entire network.<\/p>\n\n\n\n<p>&#8220;Passwords provide one of the first lines of defence against cyberattacks and are frequently the only thing protecting confidential business plans, intellectual property, communications, network access and customer data. Therefore, it is so important to establish and implement a password security policy that includes both technical protection and education for employees. However, simply advising and exhorting businesses to follow good security practices is not enough.<\/p>\n\n\n\n<p>&#8220;In order to ensure that passwords are secure and to help minimise the risk of a data breach, IT staff should enforce the following practices:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Prevent the re-use of old passwords<strong> <\/strong>\u2013 why go back to using an old key when you\u2019ve gone to the trouble of changing the locks? Make sure to prevent the use of usernames as a password<\/li><li>Enforce minimum length and use of a combination of letters, numbers and non-alpha-numeric characters. Make every password at least 15 characters long &#8211; the longer the better<\/li><li>Implement a password manager such as Kaspersky Password Manager, to help staff to create complex passwords<\/li><li>Store passwords securely \u2013 for example, use secure hashing and salting algorithms, so that a breach of the network doesn\u2019t reveal staff passwords<\/li><li>Use two-factor authentication, especially for logging in to strategic resources within the organisation<\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Password protection is a critical component of a strong business cybersecurity strategy. Kevin Curran, Senior Member of the IEEE and Professor of Cybersecurity at Ulster University, says that the number one rule for companies to manage passwords securely is for their employees to use different passwords across all sites. However, in doing this, individuals often [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":46496,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,6,13],"tags":[5700,364,9979,99,11502],"class_list":["post-46495","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-insights","category-top-stories","tag-akamai","tag-kaspersky","tag-onelogin","tag-password-security","tag-synopsys"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/46495","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=46495"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/46495\/revisions"}],"predecessor-version":[{"id":46498,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/46495\/revisions\/46498"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/46496"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=46495"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=46495"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=46495"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}