Password Advice

Robust password policies are vital to help organisations remain secure and protect against a range of attacks such as unauthorised access or hacking.

Almost all password policies consist of regular password changes, which tend to be long and also as random as possible. We suggest to both our employees and customers that employing a strong password, with a mix of capitalised letters, numbers and special characters is the most effective way of reducing the chance of being compromised by unauthorised access. However, we don’t force regular password changes for several reasons.

The National Cyber Security Centre (NCSC) believe that it’s more of a security risk to actively force users to change their passwords. They summarise it perfectly, “It’s one of those counter-intuitive security scenarios; the more often users are forced to change passwords, the greater the overall vulnerability to attack”.

This is mainly due to fact that most replacement passwords tend to be slightly different variations of previous ones. Users that are required to change their passwords on a regular basis are likely to choose weaker and weaker passwords each time to remember the most recent one. This behaviour can be exploited easily, for example if an attacker gets hold of a previous password, they’re likely to figure out the new one if it’s similar.

Another downside of frequent password changes is that it’s more likely that the new password will have to be written down to remember and left in vulnerable locations. Not to mention there’s an increased chance that a user might forget their password altogether.

At Pentagull we use system monitoring tools on ESB which provide useful information, such as the users last successful login and the most recent date that their password was changed. With this information we can inform users if we believe their account has been compromised, or simply ask the question to ensure it was them.

For more information click the following link to understand what the NCSC say regarding frequent password changes.

Other news stories

Its that time of year where we like to give a gift!
Its that time of year where we like to give a gift!

This year, we have chosen to participate in Dunelm Mills' Delivering Joy Campaign again; find out more, including how to join in.

G-Cloud 14 Award
We are officially in G-Cloud 14

We are pleased to announce that we have been named as a supplier for the Crown Commercial Service’s (CCS) G-Cloud 14.

OUR ADVICE ON PASSWORDS
OUR ADVICE ON PASSWORDS

Strong password policies are essential for keeping organisations secure against various threats, including unauthorised access and hacking. However, we do not enforce regular password changes for multiple reasons.

Garden waste gets a new string to its bow
Garden waste gets a new string to its bow

We have added a new payment option to our garden waste service!

MANCHESTER TO BLACKPOOL CHARITY BIKE RIDE 2024
MANCHESTER TO BLACKPOOL CHARITY BIKE RIDE 2024

It’s approaching that time of year again! On 14th July, cyclists will be gathering at Salford Quays for one of the biggest fundraising cycle events in the UK to raise vital funds for The Christie Charity.

Stirling Council Go-live with our HWRC Booking system
Stirling Council Go-live with our HWRC Booking system

We have yet another go-live to shout about! Here at Pentagull we are very pleased to announce that Stirling Council are the latest to benefit from our industry-leading HWRC booking system.