Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Giving CISOs The Tools To Measure, Improve Password Security.

by The Gurus
June 21, 2019
in Data Protection
Giving CISOs The Tools To Measure, Improve Password Security.
Share on FacebookShare on Twitter

By Gerald Beuchelt, CISO at LogMeIn

Despite the well-publicised growth in cyber-attacks every year, both in number and complexity, businesses are still struggling to implement effective security policies. It’s no secret that weak passwords are a leading security threat and bad password habits are far too common.

Yet businesses are struggling to quantify their own level of password risk, even those that use password managers. Why? They lack proof of their policies’ effectiveness. They’re missing visibility into their employees’ behaviours. And they can’t verify how they compare to others of similar size, industry or location, including competitors.

That is why we undertook an effort to analyse the password habits of employees at 43,000 organisations of all sizes and across industries that use the LastPass password manager. Not only does the report reveal real password behaviours in the workplace, but it offers the first true benchmark that CISOs and other IT professionals can use to see how they rank compared to other similar businesses and how to improve their password security.

Weak, reused, old and potentially compromised credentials open organisations up to innumerable risks that could be easily avoided. Our data shows that most businesses are performing middle of the road (an average of 52 out of 100) for password security, demonstrating the need for more effective policies and training to improve overall security. Password risk affects companies regardless of size, industry and location – but it’s something all organisations can work on for a more secure workplace.

The larger the company, the larger the risk

In a survey of 43,000 organisations, we found that the larger the company, the lower its security score on average. Organisations that use LastPass with 25 employees or fewer demonstrated the highest average security score of 50, but that score drops as the company size increases – up to a point. Organisations with more than 500 employees displayed stagnant scores, sharing similar challenges in improving password hygiene regardless of whether they had 1,000 employees or 10,000. These larger organisations make it more challenging for IT to hold all employees to password security standards, increasing opportunities for dangerous password behaviours.

Still, that doesn’t mean larger organisations are beyond help – some of the top performers overall were large businesses, showing that size is merely a factor that IT professionals should account for when implementing security policies. The larger the organisation, the more difficult it is to address certain challenges, from budgets to bureaucratic red tape. Smaller companies still face similar challenges, just on a smaller scale. Despite having fewer resources, it’s simpler to ensure near-perfect passwords and multifactor authentication for all employees when the employee base is smaller.

Password sharing provides the perfect example for a challenge that increases in scale with larger companies. On average, any given employee shares about six passwords with coworkers. Imagine the impact at a company with 100 employees. Now imagine the same for a company with more than 10,000 employees. Password sharing is frustrating for employees and IT administrators alike, with users resorting to using weak-but-memorable passwords that present potential backdoors into the business. As teams become more distributed and technology-dependent, the ability to protect, track and audit shared passwords is more complicated – and more necessary – than ever.

Security challenges span across industries and the globe

Technology and not-for-profit organisations achieved the highest security scores, with retail and insurance trailing behind. Given the need to comply with privacy and data laws and the tech-savviness of this industry, it’s no surprise that technology companies lead the way. Even so, other heavily-regulated industries such as banking, health, insurance and government – all frequently targeted by cybersecurity attackers – demonstrated lower security scores, revealing an opportunity for these industries to commit to more effective password security.

With a reputation for security and the adoption of standards like the General Data Protection Regulation (GDPR), companies in Germany ranked higher than the global average in terms of security score, closely followed by the Netherlands. The United Kingdom falls behind in sixth place, so even though the country has a number of strong top performers, we have a lot of work to do overall. In particular, the UK leads other European countries in multifactor authentication adoption but still ranks far lower than the United States. Ten percent of companies using multifactor authentication are in the UK, while about 63 percent are based in the U.S.. It’s evident that despite the growing usage of this technology overall, many countries are still slow to adopt this security trend.

Improving overall security is a work in progress, but no matter the size, industry or location, all organisations can take steps toward more efficient password management – and we’re already seeing a positive selection of companies doing something for passwords. We found that one year after implementing a password manager, most companies increased their security score by an average of nearly 15 points. For businesses looking into implementing a password manager or trying to measure their own password security for board reporting, this report should serve as a helpful benchmark, offering realistic goals and best practices.

As more and more companies implement BYOD policies, opening up networks to unsanctioned devices and apps, CISOs and other IT leaders need to change the way they think about password security. Visibility is key: You can’t measure security unless you have a system that provides insights into potential areas of risk. Implementing a password manager won’t just improve security, but increase productivity, brand perception and employee satisfaction as organisations are better equipped to safely navigate future challenges.

ShareTweet
Previous Post

Giving CISOs The Tools To Measure, Improve Password Security.

Next Post

New Start Date Announced for Pron Blcok As 15 July Following Delay.

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol