Admin passwords are the achilles heel of security

IT admins are good at establishing and enforcing password security policies, but not so great at following those policies

Passwords are the predominant means of securing sensitive data, and that is why there are established best practices defining password policies. Sadly, though -- the most critical data is often less secure because Admin passwords function outside of those policies and are rarely changed or updated.

Everyone knows that passwords need to be hard to guess or crack, and should never be shared with others. Granted, not many people follow that guidance -- which explains the results from a recent Webroot survey that found four in ten respondents have shared a password with another person in the past year, almost half don't use special characters to create more complex passwords, and 20 percent use easily guessed information like birth dates or a pet's name.

That is where IT admins and information security professionals come in to establish and enforce security policies. Password policies can ensure that users choose more complex passwords, don't reuse the same passwords over and over, and that passwords are changed on a regular basis to minimize the potential for exposure or compromise. The problem is that nobody is establishing and enforcing those same policies on the IT admins that made them.

The administrative passwords that restrict access to servers, protect the most sensitive company data, and guard critical processes and database transactions are often virtually carved in stone. The password are hard-coded into scripts and macros, making any change a potential nightmare that might require manually modifying the same password information across multiple systems, and possibly bring business to a grinding halt if not executed properly.

Be that as it may, the passwords have to be changed. Any password left static long enough is increasingly prone to inadvertent exposure, guessing, or cracking. IT staff with privileged access come and go, taking that sensitive knowledge with them as well.

There are free tools available that can help IT admins tackle the daunting task. Bulk Password Reset from Netwrix, Reset Local Password Pro, and a host of other freeware and shareware tools exist that can change the admin password en masse on remote systems.

It admins should exercise extreme caution, though, when using such tools. Again, those passwords may be tangled in a complex Web of scripts and custom applications, and if the update is not reflected in those various locations it could have catastrophic results.

The admin password should be updated regularly, but make sure you make the change off-hours -- like late at night, or over a weekend or holiday break. Once the password change(s) are implemented, thoroughly test any dependent business processes to make sure everything is still functioning properly.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags softwaredata protectionnetwork securityapplicationsfirewalls

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Tony Bradley

PC World (US online)
Show Comments

Father’s Day Gift Guide

Brand Post

Bitdefender 2019

Bitdefender solutions stop attacks before they even begin! Get cybersecurity that 500 MILLION users already have and trust.

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Laura Johnston

MSI GS65 Stealth Thin

If you can afford the price tag, it is well worth the money. It out performs any other laptop I have tried for gaming, and the transportable design and incredible display also make it ideal for work.

Andrew Teoh

Brother MFC-L9570CDW Multifunction Printer

Touch screen visibility and operation was great and easy to navigate. Each menu and sub-menu was in an understandable order and category

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Featured Content

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?