logo

Finding: Weak Password Policy

ID: a44c016e-5828-5245-9132-163ff38cd644

STIX ID: report--a44c016e-5828-5245-9132-163ff38cd644

Feed Name: Black Hills Infosec Blog

Date Published: 2018-05-24

Date Updated: 2026-04-27

Author: BHIS

...
...

This guidance explains risks from weak passwords—both easily guessed and easily cracked—and recommends shifting to long passphrases (minimum ~15 characters, multiple dictionary words, allowing title case and digit substitution), reducing opportunities for hash collection, and deploying mitigations such as MFA, Credential Guard, admin-only admin workstations, and password managers to limit credential theft and lateral compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.