
A lot of businesses believe that passwords as the weakest form of protection. But you should consider them as the unavoidable first defense-line, whether they are used at the lowest or highest level of a system. And the more solid this line stands, the more protected your business is. This article will get you trough a sort of checklist about the best way you can address the usage or passwords.
First, you should absolutely be convinced as a rule of thumb that passwords, as daunting as they may seem, are not obsolete at all. And if you are a system administrator, it is your mission to make sure that all the end-users and organization members are convinced of their worth too.
All employees must know the consequences of a breach in safety. Say it loud and clear, write it everywhere, remind them orally each time you have an occasion, because there is no big plan that is not split into small chunks. The smallest chunk, obviously, is the individual level of each employee.
When talking about the "risk" concept, you must know that the only absolute security resides in strict isolation; and very little systems can afford being completely isolated. As you must ensure that each entry point is properly secured with strong passwords, you also must protect your network by using any technique, strategy and tactic you may know: setting-up firewalls, disabling USB ports, disabling "autorun", setting strong antivirus and anti-malware policies, and so on.
In a general manner, the only question that should drive all your decisions when it comes to security is “does "THIS" SPECIFIC SERVICE requires "THIS" AMOUNT OF EFFORTS TO BE PROTECTED?”. The answer is the following: security is just entirely about balancing risks and costs (efforts, money, time, etc.). Nothing more, nothing less.
Your privacy and your users one should always remain your (and their) top priority. Data security of the entire company is at stake, and thus indirectly everyone's jobs. Whether it is connected to the WWW internet or simply having a USB port or an SD Card slot, absolutely every computer, smartphone or tablet is vulnerable to intrusion. You certainly do not want illegitimate people having access to your company data, tools, and secrets.
Your time and resource are limited, so you should wisely choose how to use them. The goal of any protection plan consist of toughen the security of all your infrastructure parts, nothing else. There is no reason to ignore any of them, and even low security services or minor ones need some care.
Some systems can afford a weak protection, or no protection at all. where there is either little to no risk of being compromised, then it is perfectly fine and acceptable to follow a less stringent security policy. However, if your organization or company have decided to restrain the access to a service, that is probably not by chance. So you should carefully review the risks, and balance them with the costs of implementing and managing a password strategy. Additionally, some other security measures will have to be implemented.
Security is finding the right balance between risks and costs.
This equation implies accurately taking into account the ease of use for end users, the time that you or your team will need to manage these passwords, and the damage that can eventually be caused by an intrusion, whether external or by an internal employee or collaborator of the company. This will ensure that your systems are strong enough to keep safely distanced from the vindictiveness of personal vendettas originating from any eventual spiteful and disgruntled personnel.
To make it simple: if the risk of exposure is minimal, then the security can be too. Otherwise, you simply should protect yourself, every time. If you are not sure of which security measures you should implement, there are many good and qualified security auditors and consultants that can help you in the task of evaluating them, and give you valuable insights. A good and strong password will always help you to reduce your attack surface.
This kind of threat is especially true if you manage a network of several or multiple computers and workstations, each with access to many tools: one small flaw at the lowest level can allow an attacker to access plenty of information, take control of other stations, and gain cascading access to other tools, therefore causing very large damage to your organization. This will harm the future of everything and everyone. Sometimes very seriously.
Keep in mind that every member of your organization is linked to the others through your network. Protecting one computer or one account equals to protecting all the others. And that is only efficient if all computers and accounts do the same!
We strongly enjoin you to be particularly finicky with the way you configure any remote access software. Teamviewer, AnyDesk, WebEx, VNC Connect, LogMeIn, Microsoft Remote Desktop, Apple Remote Desktop (and many other ones) can all be configured to provide and allow permanent access to a device, most of the time through a fixed password. The best defense is to not install any of them! But in the case this is a necessity, the security tip here is to choose a strong password and to change it regularly. Seeing your mouse moving by itself (that is to say : controlled by an unknown person) is definitely something that you want to stay away from !
A password is only a part of a global security strategy. A good password will be nothing if you do not perform security updates on your operating systems, thus leaving security breaches and small gaps that hackers will be very happy to capitalize on. The first tip seems obvious: Apply updates as soon as they are made available by the software manufacturers and editors (ISVs) in order to avoid "Zero-Day" attacks .
Some very sensitive passwords have to be regularly changed, such as the 'root user' under linux-based systems, or the 'Administrator' account on Windows-based system. This is particularly true for enterprise or company servers, data servers, and web servers. But do not ignore your backup servers: their passwords need to be regularly updated too.
First, it is critical you understand that your password is only a part of a security strategy. A good password will be nothing if your do not perform security updates on your operating system, leaving security breaches and your system vulnerable to worms, malware, viruses and other forms of attacks.
Because your company regularly use several passwords at different levels and on many services, such as FTP, SSH, RDP, Hosting account, Email postmaster accounts, you need to be methodical and well organized.
If you are responsible of the publication of your own website (or your company website) through FTP, or maintaining their emails accounts, it is very likely that will have to manage a bunch of very-sensitive passwords. First, you must understand that you are in charge of an absolutely critical part of your business, on which his image and reputation or even economical survival all depends.
Remember that industrial spying has existed for a long time, and is today highly facilitated by the ever-increasing number of technological tools available to everyone, including (of course) the most wrong hands. Such espionage can come from businesses in your country of origin, but increasingly more and more foreign countries and competitors of which you completely ignore the existence.
As passwords are only a part of your whole infrastructure protection plan, you must widen the scope : ACL, firewall rules, system updates, granular right for users categories, … The DoD Cyber Exchange regularly publish recommendations in Security Technical Implementation Guides (STIGS) about the ways to secure specific softwares. You can browse the list and download checklists from the UCF website . Their list is very comprehensive!
Your hosting account is usually provided by your hosting company with a predefined password. But if you decide to change it (and we encourage you to do so), you have to be sure that you choose a secure one.
Hackers are particularly fond of passwords with high levels of privileges. Indeed, from the time they gain access to your password, they can do almost anything they want: order new web services, order unwanted costly software packages (that's even worse if you're working in a big company with a pre-paid account), suspend or terminate your website or hosting account, or even deface it.
They can muddle your resources just for fun, or use their illegitimately acquired access to come back later and perpetrate other unwanted actions such as access your company data, coming again in the future, completely delete all you customers' data, change all the other passwords. The worst case is when hackers put malwares and malicious scripts on your website, or create new directories containing cheap counterfeit product listing (this one is very popular). The latter will be absolutely devastating for your reputation and your SEO.
You regularly hear about heavily relayed scandals of stolen and exposed users personal data and passwords, such as the mishaps that happened to Yahoo in 2013 , Adult Friend Finder, or even Uber in Late 2016. The point these attacks have in common is that they were made possible with some high-level login credentials being stolen or guessed at a certain stage of the attack. So double-check the security of your web hosting credentials.
In addition to your hosting account, you have to ensure that the FTP publishing password is long and secure enough. You should also consider using secure FTP protocols to publish your website, as the standard FTP protocol is old and vulnerable and has loopholes that can be easily exploited by an average hacker (sFTP , or FTP over SSL are more secure and recommended). 24 to 36 character-length complex passwords are required (and you can use our website to generate one as often as necessary). Should you have the slightest doubt concerning the fact that your security has been compromised, you should immediately generate a new password.
If, unfortunately (for you), and by chance (for him), a hacker breaks your FTP website password, he won his day! He can simply and purely delete your website and all of its content, corrupt and deface your home page, steal your databases, upload new content, inject malware (harmful pieces of code), viruses, or even all variety of illegal content. All of these noxious activities are performed by “bandit bots” (automated computers). Only a small portion of these hacking processes are human-driven.
You should never use a password that is the same as your domain name, company name, just as you must totally avoid using your own name or your boss name. If you do some tests or have to maintain “staging” accesses to development version of your website, you must have the same level of requirements: It is absolutely out of question to use passwords such as “password” or “test”. Confining the development versions and critical folders of your website with a password-protected directory is a good idea and the most secure way to keep out of sight of anyone.
Having strong passwords for EVERY email address (including postmaster@yourdomain.com) is not enough. You should consider securing your whole mail server to ban several IP's, setup and configure strong anti-spam services, and, more importantly, ensure your mail server is not an open-relay . This type of vulnerability is more common than you can think, so double-check you mail server configuration.
An improperly configured mail server can lead your company to be totally switched off, and disconnected from the world. Even if only 1 email account password has been found by a hacker, it will be used to send out tons and tons of spam, and punishment will be immediate: your website and all staff email accounts will be blocked, and, the worst 'bonus': your company's mail server IP address will be blacklisted , preventing you from communicating with anyone, blocking your website and services… in a nutshell: totally paralyzing your activity.
Making your IP un-blacklisted is really a big job that can take several weeks, and will leave marks for several months, if not more. As several RBL are very finical, in some cases, your IP will never be unblacklisted!
It is also important to note that in several countries and jurisdictions, just sending out SPAM is illegal , that you did it on your own, or you have been hacked. This can lead to you having to defend against accusations that might be addressed to you or your company; in some of the most critical cases, fines and / or prison sentences are foreseen. It is therefore crucial that you pay a serious attention to the passwords assigned to each email address.
First, you must ensure that all critical zones are password-protected. It starts with your own computers and administration tools. Unfortunately, administrator and service team account passwords are rarely changed! Yet it is a serious mistake because your tools potentially control all the others, and they represent first-class entry points for hackers. Administrative tools are primarily targeted because they allow a high degree of control over the entire network, and therefore a high power of nuisance. If a skillful intruder succeeds in entering your SysAdmin tools, this can (will) be devastating!
In fact, it is not uncommon that many software solutions and services are shipped by default with weak or "standard" passwords. Some tools in Linux or Windows (especially Windows Server 2003) are supplied with standard passwords that hackers know and will obviously test first! Similarly, if you install Microsoft SQL Server, some user accounts are pre-configured with standard passwords. You have to change them all for stronger ones before any other action.
Resist the temptation to set-up basic passwords to save your time. Or prepare for hard times!
When they are with the responsibility to deal with a lot of end users (employees, managers, suppliers, partners, collaborators), too many system administrators will be reluctant to implement complex passwords. Historically, passwords becoming more complex for end users are directly proportionate to calls to the help desk for reminders on these passwords.
Too often, sysadmins fear that too many people will forget their password if it is too complex, and will constantly complain, disturb them, calling and asking them to remind their password, or change it to a simpler one. You must erase this thought from your mind, and resist the temptation of setting-up too short and weak passwords. Instead, prefer long but easy to pronounce and to remember passwords. Our online generator offers a function that generates easy-to-pronounce passwords: have your users use it! Ensure to provide them with an automated "I Forgot my password" feature, and you will really enjoy having the time to achieve more interesting tasks! In the end, rather than the whole, a very little number of people will loose their password to critical workstations/tools that does not allow self-changing ("aka. "I have lost my password").
If you think that your organization is too small to need strong password policies, or if you consider that this topic is not a "real" problem your company need to worry about, we invite you to refer to reading twice the paragraph "What is the 'risk' concept?"
Concerning “Brute-Force” attacks, they have other bad consequences, even if they fail to access your server: they can slow you down, and even paralyze your system! Be sure to read our article on this specific topic, and learn more about the tools you can implement to protect your system against such a threat.
Every system administrator should sometimes think like a manager, or a basic employee. After all, IT services, tools, and devices have only one single goal: help people gain in productivity. Time is gone when people were reluctant to using technological tools. They are now using (and sometimes abusing!) a multitude of file-sharing services like WeTransfer or Dropbox, cloud-based services (like Google docs), instant messaging apps, and a large range of external tools out of your perimeter. That's a chance for your organization, but can be an hindrance to a peaceful management of your IT system as an admin.
This phenomenon is not new, some employees have always been using their company computer at home, but today sees the growth of many other usages in such proportions that it's becoming "DE FACTO part of your IT perimeter". Besides, employees and collaborators are using your company devices for personal purposes (private Email accounts, Facebook, Twitter, private browsing, ...). People are not only exclusively using the company computer to access sensitive data, but many other devices and endpoints, such as personal smartphones and private tablets originally designed for their personal use or leisure. As a system administrator, you should be aware of that fact.
In the nineties, it still was possible to erect walls around your network in order to protect your company data. That's not true anymore. In this context, one of the best protections you can provide is a strong password-policy, including a regular change of all the passwords used in your IT infrastructure. Our generator can help your employees generating new passwords themselves.
Only 10% of services and tools will directly originate from inside of your company IT scope. 90% will fall outside.
As a lot of apps used on tablets and smartphones have a low security level, or very poor if not inexistent built-in encryption policy, it maximizes the risks. This loss of control over the way employees are working with your company data is a real concern. Based on a Gartner study, before 2030, 90% of computer services and technological tools that people will use will originate from outside of your company IT scope. That is to say that only 10% of the access to data will be done from within your corporate network or devices.
A lot of dedicated tools and software already exists to help you control your fleet of devices, and manage the multiple end access points your employees are using to connect to your company data. But these types of tools can be very expensive and hard to configure and/or manage, and not every organization can afford such systems nor have the technical human resources trained to properly set them up. Moreover, these access controls, authentication or encryption systems are only available for the devices your company directly control, that is to say… 15% at this time, and only 10% by the end of this decade. That's is to say… not a lot!
The cloud in this regard has a particularly obvious impact. Studies show a strong correlation between cloud-usage and data-breach risks. When the cloud usage grows by 10%, the probability of data breach increases by 30%.
So yes, for sure, trying to create processes and strong frameworks to manage your IT system will help you reduce risks, but the best way to protect your data is to focus on a "good old strong password", everywhere, for every person, at every level!
Constantly being prompted to choose a complex password is very annoying... but it was designed to protect you rather than annoy you: Discover why!
Even if your passwords are all strong and regularly changed, Brute-force attacks are a plague, because they abuse your system resources constantly, even when they fail. Discover how to detect, slow-down and circumvent such attacks.
NOTE: Your changes will be applied from the next page you will visit/load.
By using this website, you consent that we use technologies such as anonymous statistics and cookies to improve your browsing experience on our site, customise content and advertising, and analyse our traffic. This anonymous information may be shared with our trusted social media, advertising and analytics partners.