Security Policies and the eventual demise of the password.
Summary
It came to my attention that there are still a lot of people still following best practices from a decade ago… For the longest time now, the primary method of securing most systems has been the use of a simple Username, and a Password. It is just 2 short pieces of information that can be gleaned in a myriad of ways, from brute force attacks, key loggers, social-engineering, Phishing attempts, Shoulder surfing data breaches…. This is where a subsequent proof of identity and intent to log in is provided via a second path, common examples are security keys – small USB “dongles that need to be inserted to your computer, codes sent to mobile phones via text, codes generated by a mobile app, or notifications reacted to on your phone. One of these is Data Loss prevention – a system available from Microsoft 365 to prevent sensitive information being shared outside your network, but we are progressing beyond the real intent of this article, for now let’s get to the right password policy in place, and MFA on every system that supports it, and we are onto a good start. We are always happy to help and even without detailed knowledge of all your systems we can point you in the right direction with advice to make improvements.