Is the smoke beginning to clear for password security?

Issue 3 2022 Access Control & Identity Management, Security Services & Risk Management


Steven Hope.

It seems that not a day goes by without the publication of a new survey revealing that people are using so-called weak passwords. As the CEO of a company that develops password security management, passwordless and other authentication solutions aimed at protecting organisations from being compromised, I read these reports with mixed feelings.

On the one hand it is important to hammer home the message that password security needs to be taken seriously. Yet with every new statistic being similar to the last, I wonder whether we are making any progress. Like any story that hits the headlines, we initially sit up and take notice, but the longer it goes on, the more desensitised we become to it.

Let’s be honest, everyone knows that 12345 is a bad password. So, if you are using it to access one, or likely more accounts, you are doing so knowingly. That means you are either unaware of or ambivalent to the repercussions that can befall you as an individual or your organisation. Similarly, those of us working in the IT and security profession have known for many years about the pitfalls of poor password security, yet still it is the cause of the vast majority of data breaches.

So, if the awareness is not being accompanied by action we are at an impasse.

However, recently while watching the world go by in the sunshine outside in a pub garden, I was given a sense of optimism from an unexpected place. I suddenly noticed how no one was smoking cigarettes. As a non-smoker I would rather have sat inside than inhale the smoke of people who had been banished to the garden, but apart from a few people vaping, the air was fresh.

My point is that everyone who smoked knew it was bad for them (and those around them), but they did it anyway. The price of tobacco was steadily increased, bans on where they could light up were introduced, even horrific images of the damage it does to your body were added to packets, but still people chose to smoke. It was the introduction of vaping and e-cigarettes that changed the game completely. Smokers could continue to behave in a very similar way, but the risks to them and those around them were reduced. Vape shops quickly appeared and the price of maintaining their habit was competitive, making the swap easy.

This is where we need to get to with passwords. We need to clear the smoke (pardon the pun) and create a clear and simple path for people to follow. Technology vendors (Authlogics included) have brought to market a plethora of different products and solutions all trying to solve the same problem in a different way – use a password manager, ditch passwords, use multifactor authentication, introduce biometrics – the list goes on. These solutions will solve the problem but the message to the world is unclear and confusing, with every vendor arguing about the best approach.

Passwordless may be the next big leap, but just like those addicted to nicotine, very few will leap from 20 a day to quitting. Having tried to convince the market to jump to passwordless (albeit with some success, but not quite global domination), I am convinced that the right approach for the mass corporate market is password security management. This approach enables people to continue to behave in a similar way, continuing to use passwords, but within an ecosystem that ensures they are being used in accordance with best practice. For some organisations this may be enough, for others it may provide them with the roadmap they need to take the next step to improve how information and systems are accessed in a secure and compliant way.

The password problem is the result of bad habits, and they can be hard to break. But ask anyone that has done it and they will not tire of telling you the benefits. We can make progress and the survey results will improve, but it is going to take time, effort, and education.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Keenfinity creates two security businesses
News & Events Access Control & Identity Management Perimeter Security, Alarms & Intruder Detection
The Keenfinity Group, today announced the creation of two dedicated businesses from its former Intrusion & Access portfolio. Radionix will focus exclusively on intrusion alarm systems, while MiCOS will become a dedicated access control company.

Read more...
Security has an identity problem
Access Control & Identity Management Information Security
Cybersecurity discussions have mainly focused on defence, including stronger firewalls, tighter network controls, and better endpoint security. However, in today's world, those traditional defences have become less relevant.

Read more...
Connecting access control, logistics and asset tracking
Access Control & Identity Management Asset Management Logistics (Industry)
Physical barriers matter, but a site is not secure just because the gate is strong or the container is locked. True security requires verifying every movement, tracing handovers, making exceptions visible, and allowing intervention before minor issues become major losses.

Read more...
AI assistants learn bad workplace habits
AI & Data Analytics Security Services & Risk Management
An employee under pressure at a logistics firm finds a productivity-boosting shortcut. Instead of manually parsing a 40-page supplier contract, they paste the confidential PDF into a public generative AI tool for a quick summary.

Read more...
Gallagher Security assists St Vincent School for the Deaf
Gallagher News & Events Access Control & Identity Management
At a time when vehicle purchase and running costs are higher than ever, St. Vincent School for the Deaf will have a more reliable vehicle thanks to a recent donation from Gallagher Security.

Read more...
Shadow AI: The next evolution of Shadow IT
AI & Data Analytics Security Services & Risk Management
Today, as AI gains traction in all aspects of life and business, African organisations face a new challenge, known as ‘Shadow AI’, where employees at all levels make use of AI without considering the potential impact.

Read more...
Solo replaces legacy access control
Paxton Access Control & Identity Management
Paxton’s new Solo system is giving student accommodation providers a simpler way to manage access at scale. This case study examines how a phone-based, cloud-hosted security system modernised access for 500 students without requiring network infrastructure.

Read more...
Readers support employee badge in Apple Wallet
Gallagher Access Control & Identity Management Products & Solutions
rf IDEAS, a global manufacturer of RFID credential readers, today announced that its WAVE ID readers support Gallagher Employee Badge in Apple Wallet, expanding the range of credential technologies supported across its reader platform.

Read more...
Free live travel risk map covering multiple countries
News & Events Security Services & Risk Management
Most widely cited travel risk maps are published once a year as static documents, but risk conditions do not follow a publishing calendar. The Sicuro map draws on official travel advisories from the ...

Read more...
The line between locking residents out and restricting their access
News & Events Security Services & Risk Management Residential Estate (Industry)
A June 2026 High Court judgment has clarified one of the most contested issues in modern estate governance: when an HOA's digital access restrictions amount to unlawful self-help or spoliation, and when they do not.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.