Building a business case for password managers

Davey Winder ponders the best way for SMBs (and larger firms) to tackle the thorny issue of password security

Passwords have always been at the heart of data security policies, and often data security breach reporting as well. Be it the password re-use question, the too simple to crack versus too complex to remember debate, or, as I touched upon recently, whether passwords are old tech that should be sent to the security scrap heap.

The unravelling Heartbleed saga has brought the password problem to the fore once more for both enterprise users and consumers.

Wearing my small business security consultant hat, one of the arguments I often find myself on the receiving end of is that I shouldn't be recommending the use of password managers as a solution.

"They are OK for the consumer who has no business critical data to protect, but even then the adoption case is a marginal one in terms of the security they offer," I am repeatedly told by people who usually fall into one of two categories.

Advertisement - Article continues below
Advertisement - Article continues below

The first are security consultants who deal exclusively with the medium-to-large' bit of the SMB sector. No consultant in their right mind would recommend consumer-grade password manager software to this level of enterprise application. Just because they are not an acceptable fit with the bigger players, does not mean that the smallest enterprises cannot benefit from using them nor that they are inherently insecure.

This brings me to the second category: the password naysayers who want to sell you on some other method of authentication and access control. This second group will often use the 'all your eggs belong to us' argument. In that, putting all your passwords in one place creates a very attractive target for hackers.

I agree. If there was a compromise, it would be disastrous. Just like it would be if that small business was re-using passwords across services and one of them suffered a breach. Just like if the passwords being used were not strong enough to resist attempts to crack them. Just like so many data breach scenarios involve passwords.

Would I rather see every enterprise adopt tokenisation, multi-factor authentication method? Of course I would, but that ain't going to happen at the bottom of the enterprise sizing graph where money, time and technical knowledge are all too often in short supply.  

Featured Resources

Digitally perfecting the supply chain

How new technologies are being leveraged to transform the manufacturing supply chain

Download now

Three keys to maximise application migration and modernisation success

Harness the benefits that modernised applications can offer

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

The 3 approaches of Breach and Attack Simulation technologies

A guide to the nuances of BAS, helping you stay one step ahead of cyber criminals

Download now

Most Popular

operating systems

17 Windows 10 problems - and how to fix them

13 Jan 2020

Windows 10 and the tools for agile working

20 Jan 2020
Microsoft Windows

What to do if you're still running Windows 7

14 Jan 2020
web browser

What is HTTP error 503 and how do you fix it?

7 Jan 2020