drj logo

"*" indicates required fields

Name*
Zip Code*
Please enter a number from 0 to 100.
Strength indicator
I agree to the Terms of Service and Privacy Policy*
Yes, of course I want to receive emails from DRJ!
This field is for validation purposes and should be left unchanged.

Already have an account? Log in

drj logo

Welcome to DRJ

Already registered user? Please login here

Login Form

Register
Forgot password? Click here to reset

Create new account
(it's completely free). Subscribe

x
DRJ Fall 2025 Dallas Show
Skip to content
Disaster Recovery Journal
  • EN ESPAÑOL
  • SIGN IN
  • SUBSCRIBE
  • THE JOURNAL
    • Why Subscribe to DRJ
    • Digital Edition
    • Article Submission
    • DRJ Annual Resource Directories
    • Article Archives
    • Career Spotlight
  • EVENTS
    • DRJ Fall 2025
    • DRJ Spring 2025
    • DRJ Scholarship
    • Other Industry Events
    • Schedule & Archive
    • Send Your Feedback
  • WEBINARS
    • Upcoming Webinars
    • On Demand
  • MENTOR PROGRAM
  • DRJ ACADEMY
    • DRJ Academy
    • Beginner’s Guide to BC
  • RESOURCES
    • New to Business Continuity?
    • White Papers
    • DR Rules and Regs
    • Planning Groups
    • Business Resilience Decoded
    • DRJ Glossary of Business Continuity Terms
    • Careers
  • ABOUT
    • Advertise with DRJ
    • DEI
    • Board and Committees
      • Executive Council Members
      • Editorial Advisory Board
      • Career Development Committee
      • Glossary Committee
      • Rules and Regulations Committee
  • Podcast

Cybersecurity experts share their advice on keeping your passwords safe from the Dark Web this World Password Day

by Jon Seals | May 4, 2022 | | 0 comments

Some of the most notorious data breaches of the modern era, including the Colonial Pipeline, were a result of a stolen password or credentials. This year’s World Password Day serves as a reminder of the importance of continuously implementing proper security practices. Several cybersecurity experts have provided valuable insights at what you can do to avoid having your passwords being one of the 15 billion available on the Dark Web. 

Patrick Beggs, CISO, ConnectWise

“In the early days of the world wide web, you were probably able to get away with a password as simple as ‘12345’. Times have changed since then, but humans remain predictable. Research has found that women typically include personal names in their passwords while men often use their hobbies. And experienced hackers also know the common vowels, numbers, and symbols that often appear in passwords. 

Cybersecurity breaches are at an all-time high, but there are three simple things we can all do to protect ourselves. First, prioritize length over complexity, because we aren’t very good at remembering complex passwords, and longer ones are more secure. Second, only use platforms with multi-factor authentication — a password alone is not enough to protect you. And finally, never reuse. Most breaches happen when a password from one platform is used with another system that shares the same password. 

If you follow these three simple steps, your passwords should be strong enough to stop a determined hacker from causing damage.”

Tyler Farrar, CISO, Exabeam

“Colonial Pipeline, SolarWinds, Twitch. All of these organizations have one thing in common: they suffered data breaches as a result of stolen passwords and credentials. Credential theft has become one of the most common and effective methods cyber threat actors use to infiltrate organizations of all sizes and access sensitive data. 

We strongly support efforts, like World Password Day, that raise public awareness and can help to combat this pervasive issue. We advocate for the best practices that ensure cyber hygiene and protect personal and professional passwords and credentials to prevent credential-based attacks from continuing.

Credential-driven attacks are largely exacerbated by a ‘set it and forget it’ approach to credential management, but organizations must build a security stack that is consistently monitoring for potential compromise. Organizations across industries can invest in data-driven behavioral analytics solutions to help detect malicious activity. These analytics tools can immediately flag when a legitimate user account is exhibiting anomalous behavior indicative of credential theft, providing greater insights to SOC analysts about both the compromised and the malicious user, which results in a faster response time.”

Neil Jones, director of cybersecurity evangelism, Egnyte

“For as long as I can remember, easily-guessed passwords such as 123456, qwerty, and password have dominated the global listing of most commonly-used passwords. Unfortunately, weak passwords can become a literal playground for cyber-attackers, particularly when they gain access to your organization’s remote access solution and can view corporate users’ ID details. 

Similarly, not a day goes by where I don’t hear another customer in a public setting like a pharmacy or a supermarket vocally share his/her email address and/or personal or business phone number, to obtain affinity club credit for a transaction or to earn a discount. That private contact information – combined with weak password administration – can represent a data breach just waiting to happen.

In commemoration of World Password Day, here are practical tips to protect your company’s mission-critical data: 

  • Institute Multi-Factor Authentication (MFA) – One of the most effective ways to prevent unauthorized access is by requiring additional validation of login credentials during a user’s authentication process. This can be as straightforward as a user providing his/her password, then entering an accompanying numeric code from an SMS text.  
  • Educate your employees on password safety – Educate your users that frequently-guessed passwords such as 123456, password, and their favorite pets’ names can put your company’s data and their personal reputations at risk. Reinforce that message, by reminding users that passwords should never be shared with anyone, including your IT team. 
  • Inform users about the dangers of social engineering and spear-phishing – Remind users that unanticipated email messages, texts, and phone calls can be attempts to capture their login and password credentials. When proper login credentials are entered, malware can be initiated that will place your organization at risk of an even wider and more destructive cyber-attack. 
  • Keep personal and business contact information separate – Remind your users that maintaining separate email accounts and contact details for affinity clubs and discount programs protects their personal privacy and your company’s valuable data. Users should never provide business login credentials (such as their email addresses) in public forums, particularly within earshot of others. 
  • Establish mandatory password rotations – Discourage the usage of system default passwords and easily-guessable employee credentials, by forcing employees to change their passwords on a routine basis. 
  • Update your account lockout requirements – Prevent brute force password attacks, by immediately disabling users’ access after multiple failed login attempts.”

Gunnar Peterson, CISO, Forter

“It is especially fitting that we collectively celebrate World Password Day in light of recent breaches this quarter that have resulted in terabytes of stolen proprietary data and untold financial cost. The day is a reminder that the simplest of defenses in our toolbelt, credential and identity management, can be the difference between a secure system or an unimaginable incident.

Most of the breaches we hear about in the news are a result of businesses relying on automated access control and realizing too late when a user has been hijacked. Once an account is compromised, identity-based fraud can be extremely difficult to detect considering the advanced tactics and randomness of different crime groups like LAPUS$ and Conti.

To succeed against dynamic cybercriminals and account takeover (ATO) attacks, organizations must build robust identity management systems and invest resources into building a learning system that evolves to identify anomalous user activity. These techniques can ebb and flow with the sophisticated threat landscape we’re witnessing today.”

Aaron Sandeen, CEO and co-founder, Cyber Security Works (CSW)

“World Password Day is a day set aside not just to promote better password use, but to draw attention to the numerous password-related assaults. Tackling every password-related attack would be difficult, but addressing the problem of Password Reset Poisoning plays an important role in increasing organizational knowledge about better password use and vulnerability management.

Every online application with a login gateway has password reset capabilities. When a user forgets his password, this reset password option is useful. However, in many organizations, password reset poisoning is an attack in which the attacker obtains a victim’s password reset token and is now able to reset the victim’s password. The problem occurs when the program uses the host header to create the password reset link and then adds the user-supplied host header to the password reset link. It is crucial for companies to inform themselves of this type of password attack to protect the privacy of their employees and the business as a whole. While addressing similar password-related attacks, more vulnerabilities can be addressed and give security teams peace of mind.”

Surya Varanasi, CTO of StorCentric: 

“Few would argue the fact that a strong password is an ideal first line of data protection defense. Without this basic security measure, you are leaving the door wide open to a multitude of cybercrime risks. Unfortunately, however, while highly sophisticated password tools are available, today’s cyber criminals also have extremely advanced password hacking technology at their fingertips. Which means, an increased risk of your passwords being leapfrogged, and your data being compromised.

The ideal cybercrime defense is a layered defense that starts with a powerful password and continues with Unbreakable Backup. As backup has become today’s cyber criminals’ first target via ransomware and other malware, an Unbreakable Backup solution can provide you with two of the most difficult hurdles for cyber criminals to overcome – immutable snapshots and object locking. Immutable snapshots are by default, write-once read-many (WORM) but now some vendors have added features like encryption where the encryption keys are in an entirely different location than the data backup copy(ies). And then to further fortify the backup and thwart would be criminals, with object locking layered on top of that, data cannot be deleted or overwritten for a fixed time period, or even indefinitely.”

JG Heithcock, GM of Retrospect, a StorCentric Company:

“Ransomware is a huge global threat to businesses around the world. Beyond the high-profile attacks, including Colonial Pipeline, JBS, Garmin, and Acer, many people now personally know a colleague whose business was attacked. In fact, a Coveware research study revealed that most corporate targets are small and medium businesses (SMBs), with 72% of targeted businesses having fewer than 1,000 employees, and 37% fewer than 100.

There are likely a few reasons for this continuing trend. Certainly, one is that today’s ransomware is attacking widely, rapidly, aggressively and randomly – especially with ransomware as a service (RaaS) becoming increasingly prevalent – looking for any possible weakness in defense. Another is that SMBs do not typically have the technology or manpower budget as their enterprise counterparts, leaving them more vulnerable targets.

It is therefore critical that in addition to powerful passwords, which anyone would agree is an indispensable first line of defense, there must be additional measures taken. The first is that all organizations regardless of size must be able to detect anomalies as early as possible to remediate affected resources. The next is SMBs and large enterprises alike need a backup target that allows them to lock backups for a designated time period. Many of the major cloud providers now support object locking, also referred to as Write-Once-Read-Many (WORM) storage or immutable storage. Users can mark objects as locked for a designated period of time, preventing them from being deleted or altered by any user – including internal bad actors.”

Related Content

  1. Disaster Recovery Journal
    Celebrate World Password Day By Protecting Yourself From Cybercriminals
  2. Integration of Cybersecurity into Physical Security Realm
  3. eDiscovery and Cybersecurity: Protecting Sensitive Data Throughout Legal Proceedings

Recent Posts

Introducing Kusari Inspector: Empowering Developers with Real-Time Software Security Insights in Every Pull Request

June 17, 2025

HackerOne Launches Technology Alliance Program to Advance AI-Powered Security Ecosystem and Customer Innovation

June 16, 2025

Cayosoft Awarded Multi-Year Contract with Internal Revenue Service to Manage Microsoft Identity Environment

June 16, 2025

Volvo Penta and Central Power Expand Industrial Power Support Across the Midwest

June 16, 2025

Cyolo Unveils Major New Capabilities, Expanding Secure Remote Access Coverage for OT and Cyber-Physical Systems

June 16, 2025

Qualys Expands Public Sector Footprint with Opening of Washington, D.C. Office

June 11, 2025

Archives

  • June 2025 (32)
  • May 2025 (59)
  • April 2025 (91)
  • March 2025 (57)
  • February 2025 (47)
  • January 2025 (73)
  • December 2024 (82)
  • November 2024 (41)
  • October 2024 (87)
  • September 2024 (61)
  • August 2024 (65)
  • July 2024 (48)
  • June 2024 (55)
  • May 2024 (70)
  • April 2024 (79)
  • March 2024 (65)
  • February 2024 (73)
  • January 2024 (66)
  • December 2023 (49)
  • November 2023 (80)
  • October 2023 (67)
  • September 2023 (53)
  • August 2023 (72)
  • July 2023 (45)
  • June 2023 (61)
  • May 2023 (50)
  • April 2023 (60)
  • March 2023 (69)
  • February 2023 (54)
  • January 2023 (71)
  • December 2022 (54)
  • November 2022 (59)
  • October 2022 (66)
  • September 2022 (72)
  • August 2022 (65)
  • July 2022 (66)
  • June 2022 (53)
  • May 2022 (55)
  • April 2022 (60)
  • March 2022 (65)
  • February 2022 (50)
  • January 2022 (46)
  • December 2021 (39)
  • November 2021 (38)
  • October 2021 (39)
  • September 2021 (50)
  • August 2021 (77)
  • July 2021 (63)
  • June 2021 (42)
  • May 2021 (43)
  • April 2021 (50)
  • March 2021 (60)
  • February 2021 (16)
  • January 2021 (554)
  • December 2020 (30)
  • November 2020 (35)
  • October 2020 (48)
  • September 2020 (57)
  • August 2020 (52)
  • July 2020 (40)
  • June 2020 (72)
  • May 2020 (46)
  • April 2020 (59)
  • March 2020 (46)
  • February 2020 (28)
  • January 2020 (36)
  • December 2019 (22)
  • November 2019 (11)
  • October 2019 (36)
  • September 2019 (44)
  • August 2019 (77)
  • July 2019 (117)
  • June 2019 (106)
  • May 2019 (49)
  • April 2019 (47)
  • March 2019 (24)
  • February 2019 (37)
  • January 2019 (12)
  • ARTICLES & NEWS

    • Business Continuity
    • Disaster Recovery
    • Crisis Management & Communications
    • Risk Management
    • Article Archives
    • Industry News

    THE JOURNAL

    • Digital Edition
    • Advertising & Media Kit
    • Submit an Article
    • Career Spotlight

    RESOURCES

    • White Papers
    • Rules & Regulations
    • FAQs
    • Glossary of Terms
    • Industry Groups
    • Business & Resource Directory
    • Business Resilience Decoded
    • Careers

    EVENTS

    • Fall 2025
    • Spring 2025

    WEBINARS

    • Watch Now
    • Upcoming

    CONTACT

    • Article Submission
    • Media Kit
    • Contact Us

    ABOUT DRJ

    Disaster Recovery Journal is the industry’s largest resource for business continuity, disaster recovery, crisis management, and risk management, reaching a global network of more than 138,000 professionals. Offering weekly webinars, the latest industry news, rules and regulations, podcasts, the industry’s only official mentoring program, a quarterly magazine, and two annual live conferences, DRJ is leading the way to keep professionals up-to-date and connected in an ever-changing world.

    LEARN MORE

    LINKEDIN AND TWITTER

    Disaster Recovery Journal is the leading publication/event covering business continuity/disaster recovery.

    Follow us for daily updates

    LinkedIn

    @drjournal

    Newsletter

    The Journal, right in your inbox.

    Be informed and stay connected by getting the latest in news, events, webinars and whitepapers on Business Continuity and Disaster Recovery.

    Subscribe Now
    Copyright 2025 Disaster Recovery Journal
    • Terms of Use
    • Privacy Policy
    OSZAR »