Tim Syratt
Creating, storing, and managing multiple passwords can be tedious, which is where password managers help.
Password managers have become an essential tool for organisations to increase the security of their digital assets. They provide an excellent, affordable solution and help organisations secure their digital assets, monitor for data breaches and vulnerable passwords, ensure a strong 'password recipe' is used, and reduce password duplication.
However, like any other software, password managers are not immune to failures or security breaches. In the event of a data or security breach, an attacker may gain access to a vast amount of sensitive information, including passwords, personal information, and confidential business data.
A password manager database breach could result in severe consequences for an organisation, including financial losses, reputational damage, and a loss of customer trust.
To prevent such incidents, organisations must adopt a multi-layered security approach and ensure a recovery plan is regularly tested and updated as the IT landscape evolves.
Password manager software should be regularly updated, using two-factor authentication and monitoring their online accounts for compromised logins.
Furthermore, organisations should choose a password manager that includes advanced toolsets such as regular reporting, threat-based firewalling, multi-factor authentication, provisioning automation and activity logging for audit at the very least.
You should always carefully examine which components of your vault data is encrypted and which may not be.
For example, are the notes fields encrypted in addition to the login and password fields?
Password managers are a valuable tool for organisations to increase their online security, but it's essential to be aware of their risks. By being proactive and implementing the necessary security measures, organisations can minimise the risk of a breach and protect their valuable assets.
Weighing the benefits of using a password manager against the potential risks is essential, and deciding if it is the right choice for your organisation. In most cases, using a password manager will decrease the risk to an organisation; however, poor vendor selection may increase risk rather than reduce it.
© 2023 Vertrauen Advisory Pty Ltd. All Rights Reserved.