The Same Old Passwords Create The Same Old Risk: How Should Employers Respond?

A recent analysis of password data by NordPass highlighted that many users continue to rely on extremely weak and predictable passwords, even on business-related systems.

In the United States, commonly used passwords included basic words such as "admin" and "password," along with simple numeric sequences like "123456," all of which can be hacked quickly using automated tools.

The study grouped passwords by country and industry, finding similar patterns of short length, dictionary words, and keyboard patterns across multiple sectors. The report emphasized that these reused and easily guessed passwords leave accounts vulnerable to brute force attacks, credential stuffing, and other common techniques used by attackers to compromise systems.

Security experts cited recommended longer passphrases, unique passwords per account, and wider use of password managers and emerging passkey technology to improve overall security hygiene.

Source: https://www.techradar.com/pro/security/the-worlds-most-popular-passwords-are-pretty-unsurprising-surely-we-can-do-better

Commentary

Despite years of breaches and security guidance, workplace participants are still using poor security hygiene.

Obviously, weak passwords create low-cost entry points for attackers, which places systems at risk.

Security hygiene is as much about culture and convenience as it is about technology. Employees tend to pick passwords they can remember under pressure, reuse them across systems, and resist change if policies feel confusing or punitive.

When organizations simply issue a complex policy and walk away, users quietly work around it. A more effective approach recognizes that people will take the easiest available option, so leadership and IT must make the secure choice the easy choice.

Practical steps for improving password hygiene include using strong passwords:

  •   12-16 characters long
  •   A mix of uppercase and lowercase letters, numbers, and special characters in no sequence/pattern
  •   Are unique to every account
  •   Are complex and random
  •   Are never reused
  •   Are never recycled in whole or part
  •   Are never shared
  •   Are never disclosed in communications
  •   Are never left unsecure
  •   Are never a manufacturer/developer default password in whole or part
  •   Are never used after notice of a security breach/warning
  •   Are never used again after voluntary disclosure for repairs/troubleshooting
  •   Are backed up by multi-factor authentication
  •   Are created by a trusted and vetted password manager

Strong, unique passwords should not consist of, or contain:

  •   A single word (e.g., "password")
  •   Dictionary words (e.g., "aardvark")
  •   Default passwords from manufacturer/developer
  •   Common words/phrases/slang (e.g., "bro", "bet")
  •   Personal identifiers (e.g., social security numbers, addresses)
  •   Online identifiers (e.g., gamertags, aliases, nicknames)
  •   Family names
  •   Pet names
  •   Birthdays
  •   Common special character substitution (e.g., "p@ssword")
  •   Simple patterns/sequences/repetition (e.g., "qwerty" or "12345")
  •   Predictable patterns/sequences (e.g., "abcd1234")
  •   Incremental patterns/sequences (e.g., work1 to work2)

The final takeaway is that password risk is not a purely technical issue; it reflects daily habits across the workforce. As a result, employers and IT teams must continue with strong policies, user friendly tools, and ongoing education to lower their risk.

Finally, your opinion is important to us. Please complete the opinion survey:

What's New

The Same Old Passwords Create The Same Old Risk: How Should Employers Respond?

A global password study found that simple, predictable passwords like "admin" and "password" remain among the most commonly used credentials worldwide, despite years of warnings from security professionals. We comment.

Cybersquatting: How Fake Domains Pose A Threat To All Organizations

Security researchers have identified large?scale malicious cybersquatting campaigns. We comment on how cybersquatting works in practice, what the loss trends show, and the helpful prevention steps employers should take.

A Fake Windows Update Is Causing Real Life Damage: Prevention Steps

Security researchers report that attackers are cloning popular adult websites and displaying a realistic full screen Windows Update screen that tricks users into installing info stealing malware. We comment.

Latest Numbers

  • Unemployment Rate
    4.3% in Jan 2026
  • Payroll Employment
    +130,000(p) in Jan 2026
  • Average Hourly Earnings
    +$0.15(p) in Jan 2026
  • Employment Cost Index (ECI)
    +0.7% in 4th Qtr of 2025
  • Productivity
    +4.9% in 3rd Qtr of 2025

Source: Department of Labor