TMCnews Featured Article
Top Five Most Common Enterprise Password Management Mistakes that Administrators Make
By Jamie Epstein, TMCnet Web Editor
Enterprises must ensure that their IT security is at the highest level possible, at all times. Privileged passwords are an organization’s most vulnerable items and enterprise password management software has proven to protect these passwords effectively. However, even with this software in place, administrators continue to make common information security mistakes over and over. Here are some of the most frequent mistakes:
1) Allowing weak passwords. Kevin Beaver, a reporter for an enterprise desktop website said, “From operating system logins and file encryption to Web accounts and beyond, weak passwords are arguably the most nonsensical, yet simplest security flaws to fix. Come up with a password policy, apply it across the board, periodically check for weaknesses, and be done with this issue once and for all.”
2) Security policies can sometimes be trusted too much. Although a large amount of security policies and enterprise password management solutions are needed, many managers think that just because the rules have been set, everyone has been informed about them. All employees must be made aware of these rules eliminating the “I didn’t know” excuse forever.
3) Connecting to unknown and (sometimes unsecured) WiFi (News
- Alert) HotSpots. Many people will try and connect to any WiFi spot that allows for internet access. But a majority of people don’t think about the fact that if the wireless network they are utilizing is unsecure, their passwords and login credentials will no longer be safeguarded and they could cause a potential breach in security.
4) Not performing vulnerability scans or audits on a regular basis. “Many admins simply don’t acknowledge what’s really at risk with their systems. Therefore, when performing security assessments, they tend not to dig deep enough, often enough. Exacerbating this problem is the underlying assumption that compliant equals secure. But it never has, and it never will,” Beaver stated. In addition, passwords should be changed on a continuous basis to avoid potential fraud.
5) Not balancing enterprise password management security with ease of use. One of the main purposes of enterprise password management is to maintain a high level of security. According to Beaver, “That is balanced with usability so that it doesn’t get in the way of day-to-day business. Yet, either by design or the law of unintended consequences, security controls often get in the way of users, who then find ways around it. Writing passwords on sticky notes is just the beginning. Long after these security weaknesses become well-known, they often continue to be ignored, so it’s important to address them before you have to.”
Jamie Epstein is a TMCnet Web Editor. Previously she interned at News 12 Long Island as a reporter's assistant. After working as an administrative assistant for a year, she joined TMC (News - Alert) as a Web editor for TMCnet. Jamie grew up on the North Shore of Long Island and holds a bachelor's degree in mass communication with a concentration in broadcasting from Five Towns College. To read more of her articles, please visit her columnist page.
Edited by Rich Steeves


