May 24, 2012

Password Apathy

Few employees -- even IT employees -- are vigilant about using adequate passwords.    

Despite almost constant reports of data breaches and hacking incidents, many organizations are still not taking even the most basic measures to protect their organization's data. In fact, the password practices in some companies may actually be putting them at greater risk. According to a password security report by Lieberman Software, 48% of the more than 300 IT professionals surveyed have worked for organizations that have experienced a data breach.

But even with such first-hand experience, 42% said that two or more IT staff actually share passwords to access systems or applications in their organizations, 48% allow passwords to privileged accounts (those that contain high-level permission to access files, install programs, and change configuration settings) to remain unchanged for 90 days or more, and 25% admitted that their privileged account passwords were less complex than normal user logins.

Such practices make it easier for hackers -- and employees -- to gain access to sensitive data. For instance, 26% said that at least one IT staff member in their organization has abused privileged logins to access unauthorized information. This absence of fundamental data protection measures may point to a developing sense of apathy regarding data security, even among those who are tasked with maintaining it.      

Risk Management Magazine and Risk Management Monitor. Copyright 2012 Risk and Insurance Management Society, Inc. All rights reserved.

About the Author

Editor in Chief

Morgan O’Rourke is the director of publications for the Risk and Insurance Management Society, Inc. (RIMS) and the editor in chief of Risk Management magazine and the Risk Management Monitor blog.

212-655-5922

Boost: AJAX core statistics

Legal Disclaimer

You are responsible for reading, understanding and agreeing to the National Law Review's (NLR’s) and the National Law Forum LLC's  Terms of Use and Privacy Policy before using the National Law Review website. The National Law Review is a free to use, no-log in database of legal and business articles. The content and links on www.NatLawReview.com are intended for general information purposes only. Any legal analysis, legislative updates or other content and links should not be construed as legal or professional advice or a substitute for such advice. No attorney-client or confidential relationship is formed by the transmission of information between you and the National Law Review website or any of the law firms, attorneys or other professionals or organizations who include content on the National Law Review website. If you require legal or professional advice, kindly contact an attorney or other suitable professional advisor.  

Some states have laws and ethical rules regarding solicitation and advertisement practices by attorneys and/or other professionals. NLR does not accept advertising from attorneys or law firms. The National Law Review is not a law firm nor is www.NatLawReview.com  intended to be an advertisement or a referral service for attorneys and/or other professionals. The NLR does not wish, nor does it intend, to solicit the business of anyone or to refer anyone to an attorney or other professional.  NLR does not answer legal questions nor will we refer you to an attorney or other professional if you request such information from us. 

Under certain state laws the following statements may be required on this website and we have included them in order to be in full compliance with these rules. The choice of a lawyer or other professional is an important decision and should not be based solely upon advertisements. Attorney Advertising Notice: Prior results do not guarantee a similar outcome. Statement in compliance with Texas Rules of Professional Conduct. Unless otherwise noted, attorneys are not certified by the Texas Board of Legal Specialization, nor can NLR attest to the accuracy of any notation of Legal Specialization or other Professional Credentials.