All news
Security
1 October 2026

Password complexity and software patching requirements for business security

Recent security incidents demonstrate that substituting characters in passwords does not prevent automated attacks. Maintaining up-to-date software remains as important as credential management for protecting business data.

What this means for your business

Small businesses should review their password policies to move away from simple character substitution toward longer passphrases or multi-factor authentication. IT administrators must also ensure that all hardware and software receive security updates as soon as they are available to prevent known exploits.

The limit of character substitution

A recent security case involving a Chief Information Security Officer (CISO) has highlighted that traditional methods of creating passwords are often insufficient. Many users believe that replacing letters with symbols or numbers—such as using a zero instead of the letter 'o'—makes a password difficult to crack. In technical terms, this is known as leetspeak.

Automated tools used by attackers are now programmed to account for these common substitutions. A password that follows a predictable pattern, even with symbols, can be cracked quickly by modern hardware. For a business, relying on these methods creates a false sense of security.

The importance of software patching

The report also notes that strong credentials cannot protect a system if the underlying software contains unpatched vulnerabilities. In this specific instance, an attacker gained access not just through a password, but by exploiting a known flaw in the software that had not been updated.

Patching is the process where software providers release updates to fix security holes. When a business neglects to install these updates, they leave a door open for attackers, regardless of how complex their passwords may be. Security is a multi-layered process that requires both user diligence and technical maintenance.

Recommendations for UK businesses

Businesses should consider moving toward passphrases rather than single words with substitutions. A passphrase is a string of several random words, which is longer and harder for computers to predict but often easier for humans to remember.

Additionally, multi-factor authentication (MFA) should be applied to all business accounts. MFA requires a second form of verification, such as a code sent to a mobile device, which prevents access even if a password is stolen. Finally, ensuring that all office hardware and software are set to update automatically will reduce the risk of falling victim to known security flaws.

Worried this could affect you?

Cyber Essentials is the quickest way for a small business to close the gaps attackers use most.

See Cyber Essentials

Not sure how exposed you are?

Twenty minutes on a call is usually enough to tell you.