Password Advice

Robust password policies are vital to help organisations remain secure and protect against a range of attacks such as unauthorised access or hacking.

Almost all password policies consist of regular password changes, which tend to be long and also as random as possible. We suggest to both our employees and customers that employing a strong password, with a mix of capitalised letters, numbers and special characters is the most effective way of reducing the chance of being compromised by unauthorised access. However, we don’t force regular password changes for several reasons.

The National Cyber Security Centre (NCSC) believe that it’s more of a security risk to actively force users to change their passwords. They summarise it perfectly, “It’s one of those counter-intuitive security scenarios; the more often users are forced to change passwords, the greater the overall vulnerability to attack”.

This is mainly due to fact that most replacement passwords tend to be slightly different variations of previous ones. Users that are required to change their passwords on a regular basis are likely to choose weaker and weaker passwords each time to remember the most recent one. This behaviour can be exploited easily, for example if an attacker gets hold of a previous password, they’re likely to figure out the new one if it’s similar.

Another downside of frequent password changes is that it’s more likely that the new password will have to be written down to remember and left in vulnerable locations. Not to mention there’s an increased chance that a user might forget their password altogether.

At Pentagull we use system monitoring tools on ESB which provide useful information, such as the users last successful login and the most recent date that their password was changed. With this information we can inform users if we believe their account has been compromised, or simply ask the question to ensure it was them.

For more information click the following link to understand what the NCSC say regarding frequent password changes.

Other news stories

Nscswarning
Strengthening our cyber resilience with NCSC Early Warning

We have signed up to the National Cyber Security Centre’s free Early Warning service to help identify potential cyber threats sooner and strengthen our overall security position.

North Yorks Permit Go Live
North Yorkshire County Council Go-Live with our HWRC Permit system

Here at Pentagull, we’ve had an action-packed first half of the year and as promised, have plenty more go-lives to shout about!

Hertfordshire Epass Go Live (1)
We are thrilled to announce yet another go-live, with plenty more upcoming!

It’s been as busy as ever at Pentagull this year and we are thrilled to announce yet another go-live, with plenty more upcoming! Hertfordshire County Council, an existing customer with our Weighbridge & Asbestos Bookings, have recently gone live with our HWRC Permit system with DVLA.

Oxfordshire Go Live
Yet another local authority go-live with our HWRC Booking & Permit System

Oxfordshire County Council are the latest local authority to go-live with our HWRC Booking and Permit System, taking a significant step forward in managing site access and improving operational efficiency.

Designer (1)
Our Commitment to Security

At Pentagull, security isn’t just a box we tick — it’s a responsibility we carry on behalf of every council, team, and organisation that trusts our software to support their essential services. As our platforms continue to evolve, so does our commitment to keeping them safe, resilient, and transparent.

Busy Worker (1)
Pentagull chosen to deliver Hampshire’s new digital HWRC booking and permit system

We’re delighted to share that Hampshire County Council has chosen Pentagull to deliver its new Household Waste Recycling Centre (HWRC) booking and permit system — one of the largest HWRC networks in the country.