The limit of character substitution
A recent security case involving a Chief Information Security Officer (CISO) has highlighted that traditional methods of creating passwords are often insufficient. Many users believe that replacing letters with symbols or numbers—such as using a zero instead of the letter 'o'—makes a password difficult to crack. In technical terms, this is known as leetspeak.
Automated tools used by attackers are now programmed to account for these common substitutions. A password that follows a predictable pattern, even with symbols, can be cracked quickly by modern hardware. For a business, relying on these methods creates a false sense of security.
The importance of software patching
The report also notes that strong credentials cannot protect a system if the underlying software contains unpatched vulnerabilities. In this specific instance, an attacker gained access not just through a password, but by exploiting a known flaw in the software that had not been updated.
Patching is the process where software providers release updates to fix security holes. When a business neglects to install these updates, they leave a door open for attackers, regardless of how complex their passwords may be. Security is a multi-layered process that requires both user diligence and technical maintenance.
Recommendations for UK businesses
Businesses should consider moving toward passphrases rather than single words with substitutions. A passphrase is a string of several random words, which is longer and harder for computers to predict but often easier for humans to remember.
Additionally, multi-factor authentication (MFA) should be applied to all business accounts. MFA requires a second form of verification, such as a code sent to a mobile device, which prevents access even if a password is stolen. Finally, ensuring that all office hardware and software are set to update automatically will reduce the risk of falling victim to known security flaws.