On 29 April 2025, teissTalk host Thom Langford was joined by Shannon Muller, Cyber security Specialist, Microsoft; Jay Vinda, Cyber Risk Engineering and Emerging Solutions Lead, Mosaic Insurance; and Darren James, Senior Product Manager, Specops.
With the addition of some 85 million compromised passwords to the Specops breached password protection service on March 18, detected through a combination of honeypots and threat intelligence sources, the time to start taking password security seriously has long since passed. Specops has revealed that the top ten passwords observed in RDP port brute force attacks are: 123456, 1234, Password1,12345, P@ssw0rd, password, Password123, Welcome1, 12345678 and Aa123456. Hackers often target RDP passwords to get access to remote and hybrid workers. If an RDP port is exposed, then it is fair game for the brute-force password hackers.
Changing criteria for creating passwords is the easy part, enforcing and monitoring good practice is much harder. Users’ password fatigue is also working against compliance with password creation rules. There is also mistrust about password managers, as, if the password manager provider is breached, all the user’s passwords will get stolen at the same time. A good strategy for companies to get employees involved is incentivising them to think of company data as if it was their own. Bigger corporations tend to offer better tools for password management, such as SSOs (single sign-in passwords) or corporate password managers. However, a company’s security can’t exclusively rely on user passwords if it is multi-layered. The problem should be addresses on a network level, too by forcing every device on the network to prove that it’s a corporate managed device. All corporate sub-systems must be protected by at least two factors to make the whole network safe.
Security will improve considerably when all websites have required MFA from their customers, sometimes even at the expense of the user experience. Although security that doesn’t impact customer experience comes at a cost, it can also be seen as a business opportunity and highlighted as a selling point. When passwords have become too hard to crack, criminals will probably target the service desk by, for example, requesting password changes as seen in the case of Scattered Spiders. Although passkeys may be the next step, there is a long way to go before they become widespread. At the moment, they can’t be used across different devices or device brands.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543