https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
    • Diversity, Equity & Inclusion
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
    • MSP 501 Information Center
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
    • Diversity, Equity & Inclusion
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
    • MSP 501 Information Center
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

MSSP Insider


Shutterstock

Password

How Reusing Passwords Is Hurting Your Business

  • Written by Michael Greene
  • December 27, 2019
Companies need to secure employee accounts from the start and have an ongoing ability to check password security.
Enzoic's Mike Greene

Michael Greene

Security hygiene is an increasingly important factor in today’s heightened threat environment when companies are vetting technology providers, MSPs and others in the channel. These groups are investing significant sums of money to strengthen security to protect their data and their clients, yet there is a critical area that is often overlooked: password reuse and the sharing of passwords between personal and work accounts.

The average person knows better than to reuse passwords across multiple work and personal related sites, but the human desire for convenience and efficiency will trump this knowledge every time. For example, 91% of respondents in a LogMeIn survey claim to understand the risks of reusing passwords across multiple accounts, but 59% admitted to doing it anyway. What’s more, 62% of employees are reusing the same password for both work and personal accounts.

You can learn more about the threats posed by reusing passwords in this gallery from Channel Partners.

There is a staggering amount of breach data on the internet and Dark Web and with attacks occurring on a continuous basis, this treasure trove for hackers is only growing. I recently spoke with a company that discovered that 4% of its uncompromised credentials become compromised within one month and this happened month over month. All a cybercriminal needs to do is obtain an exposed credential from one breach and use those same credentials to access other sites and systems. With the rampant practice of password reuse, it won’t be long before the hacker is able to access sensitive accounts and information.

For channel partners, this practice represents a serious security vulnerability. MSPs have emerged as a top target for hackers, with the U.S. Department of Homeland Security’s Computer Emergency Readiness Team (US-CERT), issuing an alert warning companies of advanced persistent threat activity. In addition to the typical headaches associated with data breaches — financial repercussions, brand impact, loss of sensitive data — MSPs and other groups in the channel face the added pressure of fallout from the client and vendor community. For many, this pressure will be too much to withstand — one study found that 60% of small businesses fold within six months of experiencing a breach.

What Can Channel Companies Do?

Organizations have historically addressed compromised passwords by implementing mandatory password resets every 42 to 90 days following the recommendations of traditional guidelines. However, times have changed as both the National Institute of Standards and Technology (NIST) and Microsoft have recently come out against password expiration for a number of reasons:

  • Security: Employees typically choose a simple password or a pattern that can be easily guessed when forced to change passwords frequently.
  • Costs: Mandatory password resets can drive up help desk costs, with Forrester estimating it costs $70 of help desk labor for a single password reset.
  • Productivity: In addition to the financial element, password resets divert both IT and end-user resources away from more strategic initiatives — companies lose upwards of $420 in productivity annually per employee due to password challenges. This is a painful factor for many MSPs.

With awareness growing of these and other issues associated with expiring passwords, organizations must now focus on securing employee accounts from the start. Many companies in the channel have high employee turnover, and it’s important to be conscious of poor password practices that might follow your new hire from their prior position. Researchers from Virginia Tech University found that more than 70% of users employed a compromised password for other accounts up to a year after it was initially leaked, with 40% reusing passwords which were leaked over three years ago. This underscores that companies must expect poor password hygiene from their users and revise password policies accordingly.

NIST recommends that companies now verify …

  • Page 1
  • Page 2
Tags: MSPs MSSP Insider Network Security Training and Policies

Most Recent


  • Making Waves
    7 Channel People Making Waves This Week at Datto, New Relic, Kyndryl, More
    Our No.1 story was a video segment highlighting IBM.
  • Fireworks
    Cybersecurity Experts: July 4th Weekend Ripe for Ransomware, Other Attacks
    Russia definitely has motivation to exploit the July 4th holiday in some way.
  • Software patch
    Tetra Defense: Unpatched Systems Behind Costliest Cyberattacks in Q1
    Log4J/Log4Shell is still being actively exploited.
  • data center storage
    Veeam Co-Founders Launch Startup Object First with S3-Compatible Storage
    The storage appliance will be built with commodity servers and JBOD storage using Veeam’s Smart Object API.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • Security Vulnerability
    Older Fortinet Vulnerabilities Lead to Attack on Local Government Office
  • Threats
    Cybersecurity and Threat Protection: MSSPs, Get Your Advice Here
  • DevSecOps
    ServiceNow, Microsoft Set to Deliver Broad SecOps Integration
  • Dunce Cap Businessman
    Tired of MSSPs ‘Failing,’ Nuspire Debuts Platform to Combat Cyberattacks

Upcoming Events

View all

MSP Summit

September 13, 2022 - September 16, 2022

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Galleries

View all

Channel People on the Move: AT&T, HPE, Google Cloud, Comcast, More

July 5, 2022

Missed June’s Cloud News? AWS, VMware, HPE, Google Cloud Made Headlines

July 5, 2022

Public Cloud Momentum Pacing Past Forecasts, With AWS, Azure in Lead

July 4, 2022

Industry Perspectives

View all

The Role of Mentors and Sponsors in Advancing Your Tech Career

July 5, 2022

How to Make Embracing Change Part of Your Company Culture

July 1, 2022

How to Differentiate to Leverage 5G’s Revenue Opportunity

June 28, 2022

Webinars

View all

VEP Platform for Delivery of uCPE, SD-WAN and SASE

June 29, 2022

The Digital Worker: How to Empower Customers with a Flexible, Scalable VDI Solution to Enable Remote Work

June 30, 2022

Growing Partner Revenue and Customer Satisfaction with Power Management Services

June 23, 2022

White Papers

View all

Work Goes Remote – (and Other Top ITOps Trends)

May 25, 2022

The New Bottom Line: How MSPs Can Meet the Healthcare Crisis While Evolving Their Businesses

April 19, 2022

How to build a Security Operations Center (on a budget)

April 4, 2022

Channel Futures TV

View all

Vonage a ‘Single Communications Stack Provider’ for Partners, Customers

IBM, Partners and the $1 Trillion Hybrid Cloud Opportunity

June 26, 2022

Agents Share ‘Secrets,’ Industry Opportunity

May 11, 2022

AT&T, Microsoft, Cisco, ThreatLocker on Unlocking Partner Potential

May 6, 2022

Twitter

ChannelFutures

Distributor @Infinigate to acquire @nuviasgroup to create "pan-European #cybersecurity powerhouse."… twitter.com/i/web/status/1…

July 5, 2022
ChannelFutures

[email protected], @AWSCloud, @VMware, @Azure, @HPE, more, all made big waves in June with respective #cloud news.… twitter.com/i/web/status/1…

July 5, 2022
ChannelFutures

Happy Independence Day 🎇 to our U.S. colleagues, from the #ChannelFutures and #ChannelPartners team to yours! We ho… twitter.com/i/web/status/1…

July 4, 2022
ChannelFutures

#Publiccloud demand is going nowhere. We dive into stats. @AWSCloud @Azure @IDC @Gartner_inc @SRG_Research #cloud… twitter.com/i/web/status/1…

July 4, 2022
ChannelFutures

Partners can bring more value to #customerrelationships with the #customerexperience, says @SAPPartners4U.… twitter.com/i/web/status/1…

July 4, 2022
ChannelFutures

Channel people making waves this week include: @jpdepa3rd, @RiyaShanmugam, @sandyhogan dlvr.it/STCM6S https://t.co/oVB86ztTtP

July 1, 2022
ChannelFutures

#Cybersecurity experts say July 4th weekend ripe for #ransomware, other attacks. @blumirasec @Netenrich @Vectra_AI… twitter.com/i/web/status/1…

July 1, 2022
ChannelFutures

New @PureStorage #ITchannel leader details jump from Veritas. dlvr.it/STBsLB https://t.co/BFSmZ5ubff

July 1, 2022

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2022 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X