Eye-Opening Password Predictions: Remote Work Will Increase Risk for Data Breaches

Stu Sjouwerman | Dec 21, 2020

Password PredictionsPonemon's State of Password and Authentication Security Behaviors Report analyzes password and security behaviors over time with similar trends. We wanted to deep dive into the reports of years past and give some predictions as we move closer to 2021.

We'll start with 2019 - according to the report, extremely poor password management habits by those in IT were making a hacker’s job much easier. One of the most surprising stats from that report 51% of IT admins reuse the same password across an average of five business and/or personal accounts

Now onto 2020 - based on the updated report, there were several findings, including two-thirds of IT organizations use older best practices such as requiring periodic password changes (67%), a recommendation Microsoft has officially killed. It also revealed that 20% of users don’t take any steps to secure passwords.

What similarities can we find year over year? For starters, re-use of the same passwords across multiple accounts is still happening a lot. Password policies are also not being updated, with organizations still sticking to the old-school approach. This lack of best practices has also shown an increase in data breach attacks year over year. 

The only wrench in the 2020 report was the COVID-19 pandemic, causing millions of companies to move to a remote workforce. With 2021 still moving in that direction, there are some causes for concern what next year's report will look like. We have some predictions: 

  • Increase in attacks on multiple accounts - according a recent report from Security Magazine, 53% of people admit to reusing the same password for multiple accounts. Now that users are working remote, it's a larger attack surface for the bad guys to go after.
  • Passwords re-use will continue - without any strict password policies, users will continue to go on a downward spiral of reusing the same passwords on multiple accounts

As we continue to work in a remote environment, user education is of high importance. New-school security awareness training can keep your users informed about good password hygiene and avoid potential data breaches. 

Are your user’s passwords ... P@ssw0rd?

Identify which users are using easily guessable or brute-forceable credentials before cybercriminals do. 

Get Your Weak Password Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.