When It Comes to Password Hygiene, Users Say One Thing, But Do Another

Stu Sjouwerman | Oct 8, 2021

Poor Password HygieneWith credentials being at the forefront of most cyberattacks, the need for strong, unique passwords is at an all-time high. But new data shows users know what to do, but don’t do it.

We’ve seen how the majority of phishing attacks target credentials, so it becomes increasingly important for those stolen credentials to only provide access to a singular platform/application/etc. But, that only works IF (and it’s a pretty big if!) users utilize unique usernames and passwords for each and every system.

According to LastPass’ Psychology of Passwords report, users are a bit apathetic to the cause of securing the organization with proper password hygiene:

  • 51% of users rely on their memory to keep track of passwords, despite 79% agreeing that compromised passwords are concerning
  • 65% always or mostly still use the same password or a variation, despite 92% admitting that they know using the same password or a variation is a risk

Now add in working remotely – something I’ve written about a number of times as not helping the organization’s security stance – and LastPass shows users aren’t looking out for their organization:

  • 47% have not changed their online security habits since working remotely
  • 46% have not strengthened their passwords while working remotely
  • 44% have shared sensitive information and passwords for professional accounts while working remotely

In short, users are not concerned (or are made to be concerned) with password security. Security Awareness Training assists with not just educating users on scams, phishing attacks, social engineering tactics, and the like, but also teaches users why they need to be vigilant, use good password hygiene, and participate in the organization security.

This password problem can only be addressed through educating the user; Security Awareness Training is the key.

Are your user’s passwords ... P@ssw0rd?

Identify which users are using easily guessable or brute-forceable credentials before cybercriminals do. 

Get Your Weak Password Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.