ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

teissTalk: Weak passwords – the hidden threat lurking in your organisation

On 29 April 2025, teissTalk host Thom Langford was joined by Shannon Muller, Cyber security Specialist, Microsoft; Jay Vinda, Cyber Risk Engineering and Emerging Solutions Lead, Mosaic Insurance; and Darren James, Senior Product Manager, Specops.

 

Views on news


With the addition of some 85 million compromised passwords to the Specops breached password protection service on March 18, detected through a combination of honeypots and threat intelligence sources, the time to start taking password security seriously has long since passed. Specops has revealed that the top ten passwords observed in RDP port brute force attacks are: 123456, 1234, Password1,12345, P@ssw0rd, password, Password123, Welcome1, 12345678 and Aa123456. Hackers often target RDP passwords to get access to remote and hybrid workers. If an RDP port is exposed, then it is fair game for the brute-force password hackers.


Getting passwords right


Changing criteria for creating passwords is the easy part, enforcing and monitoring good practice is much harder. Users’ password fatigue is also working against compliance with password creation rules. There is also mistrust about password managers, as, if the password manager provider is breached, all the user’s passwords will get stolen at the same time. A good strategy for companies to get employees involved is incentivising them to think of company data as if it was their own. Bigger corporations tend to offer better tools for password management, such as SSOs (single sign-in passwords) or corporate password managers. However, a company’s security can’t exclusively rely on user passwords if it is multi-layered. The problem should be addresses on a network level, too by forcing every device on the network to prove that it’s a corporate managed device.  All corporate sub-systems must be protected by at least two factors to make the whole network safe. 


Security will improve considerably when all websites have required MFA from their customers, sometimes even at the expense of the user experience. Although security that doesn’t impact customer experience comes at a cost, it can also be seen as a business opportunity and highlighted as a selling point. When passwords have become too hard to crack, criminals will probably target the service desk by, for example, requesting password changes as seen in the case of Scattered Spiders. Although passkeys may be the next step, there is a long way to go before they become widespread. At the moment, they can’t be used across different devices or device brands. 


The panel’s advice

  • Avoid traditional password patterns such as capital letter-word-numbers-special character. In the inventory of 85 million breached passwords, a high percentage follows this pattern.
  • Convenience is the enemy of security.
  • Passwords can’t be the only means of access control.
  • Microsoft blocked 7,000 password attacks per second in 2024.  

Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543