Save Money And Time By Giving Up On Outdated Password Concepts
If you don’t use sufficiently complex password, you don’t appropriately use Multi-Factor Authentication (“MFA”), you use the same password in multiple places, or you have any indication at all that your password has been disclosed, the rest of this article isn’t for you. Change your password, implement MFA, then come back and read the rest.
Recently we helped a large enterprise customer retire the requirement for typical users to change passwords on a 90-day cycle. The effort wasn’t as trivial as it sounds, but the result has been more than worth the effort.
If you do the same you may enjoy some great returns.
The idea of keeping password expirations very long or doing away with them all together isn’t anything new. However, to most security professionals it is still challenging a deeply held belief. Our biggest challenge was helping the CISO sell this idea to the business units and compliance.
Below is some ammunition and references you can use in your discussions. As always, Bridge is here to help you in this conversation and effort.
At this point I should note, if you have compliance requirements for password changes you will need to deal with these very carefully. Alongside our customer, we sometimes need to meet with a certifying body to provide mathematical, logical, and industry practice arguments to get this approved as a [compensating] control.
The grid below illustrates the time it would take given relatively ideal conditions to traverse half the space of a given password complexity.
You can change the “Guesses per Second” to see what it does to the timeline.
Our Formula is: (((Combinations ^ Length)/Attempts per second) *.5) / Seconds in a Year
About
BSA is a cybersecurity firm founded in 2019, with a decentralized global presence, led by experienced partners. Offering risk mitigation solutions such as emerging technologies, staffing and advisory services, vulnerability assessments and accredited security solutions to meet compliance standards and drive revenue for clients.
Company
Network and Resource
Contact Info
Phone: +1 908 440 7926
Email: info@bridgesecurtiyadvisors.com
Address: 591 Cone Hill Rd, Richmond, MA 01254
Let's Connect
Copyright © BridgeSecurityAdvisors 2023. All rights reserved.