Admin passwords are the achilles heel of security

IT admins are good at establishing and enforcing password security policies, but not so great at following those policies

Passwords are the predominant means of securing sensitive data, and that is why there are established best practices defining password policies. Sadly, though -- the most critical data is often less secure because Admin passwords function outside of those policies and are rarely changed or updated.

Everyone knows that passwords need to be hard to guess or crack, and should never be shared with others. Granted, not many people follow that guidance -- which explains the results from a recent Webroot survey that found four in ten respondents have shared a password with another person in the past year, almost half don't use special characters to create more complex passwords, and 20 percent use easily guessed information like birth dates or a pet's name.

That is where IT admins and information security professionals come in to establish and enforce security policies. Password policies can ensure that users choose more complex passwords, don't reuse the same passwords over and over, and that passwords are changed on a regular basis to minimize the potential for exposure or compromise. The problem is that nobody is establishing and enforcing those same policies on the IT admins that made them.

The administrative passwords that restrict access to servers, protect the most sensitive company data, and guard critical processes and database transactions are often virtually carved in stone. The password are hard-coded into scripts and macros, making any change a potential nightmare that might require manually modifying the same password information across multiple systems, and possibly bring business to a grinding halt if not executed properly.

Be that as it may, the passwords have to be changed. Any password left static long enough is increasingly prone to inadvertent exposure, guessing, or cracking. IT staff with privileged access come and go, taking that sensitive knowledge with them as well.

There are free tools available that can help IT admins tackle the daunting task. Bulk Password Reset from Netwrix, Reset Local Password Pro, and a host of other freeware and shareware tools exist that can change the admin password en masse on remote systems.

It admins should exercise extreme caution, though, when using such tools. Again, those passwords may be tangled in a complex Web of scripts and custom applications, and if the update is not reflected in those various locations it could have catastrophic results.

The admin password should be updated regularly, but make sure you make the change off-hours -- like late at night, or over a weekend or holiday break. Once the password change(s) are implemented, thoroughly test any dependent business processes to make sure everything is still functioning properly.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags network securityfirewallsapplicationssecuritysoftwaredata protection

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Tony Bradley

PC World (US online)
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?