Intelligent CISO Issue 36 | Page 50

Changing your password every two to three months is a really effective way to deter cyberattacks .
FEATURE

Changing your password every two to three months is a really effective way to deter cyberattacks .

organisations leave themselves at risk of cyberattacks due to their lack of having ( or enforcing ) password rotation policies .
Of the companies and organisations that do have password rotation policies in place , 39 % of employees confess that they didn ’ t know these policies actually existed .
A staggering 56 % of education workers who did know about their company ’ s password protection policies revealed they do not adhere to them by regularly changing their password , and of those who do adhere , 27 % confessed to simply using the same passwords on rotation .
For the companies and organisations without password rotation policies , only 5 % of staff regularly rotate or change their passwords . The main reasons education workers cited for not changing their passwords were : they are worried they will forget their password ( 47 %), regularly changing passwords is annoying ( 36 %), and they don ’ t see the point ( 29 %).
Surprisingly , the research also found that entry-level staff in this industry were most likely to be guilty of not following password rotation policies ( 44 %).
David Janssen , Security Researcher and Founder at VPNOverview . com , said : “ Password rotation policies safeguard both businesses and employees alike by protecting their work , especially when working in an industry that frequently deals with sensitive information like education .
“ Changing your password every two to three months is a really effective way to deter cyberattacks , and although some may find it frustrating , it could save a lot of heartache down the line .
“ It ’ s shocking to see how many people who work in education don ’ t realise what the point in regularly changing their password is and it ’ s clear from our research these organisations and employees alike need to be educated on the importance of implementing policies such as these .” u
50 www . intelligentciso . com