Beth Miller, Field CISO at Mimecast; Cynthia Lee, APAC Vice President at Delinea; , Tomer Bar, Associate VP of Security Research at Semperis; and Jon Fielding, Managing Director, EMEA, at Apricorn, have shared their insights on the evolving role of passwords and identity protection ahead of World Password Day. From the growing threat posed by AI-driven phishing campaigns and credential theft to the rise of zero standing privilege, Multi-Factor Authentication and hardware-based encryption, the experts outline why organisations must move beyond traditional password hygiene and adopt layered, behaviour-focused security strategies to defend against increasingly sophisticated cyberthreats.
Beth Miller, Field CISO, Mimecast
World Password Day is a useful moment, but the industry keeps having the wrong conversation. The question was never ‘are your passwords strong enough?’ It’s ‘why do attackers keep getting through even when they are?’
AI has changed the equation. The fake login pages I’m seeing now are indistinguishable from the real thing. The lures are contextually accurate, timed well, and crafted to exploit exactly the pressure employees are already under. Credential theft isn’t a technical failure — it’s a behavioural one, and we’ve been slow to treat it that way.
Our State of Human Risk data exposes a three-part problem. First, 91% of organisations acknowledge obstacles to employee compliance — they know their people are a risk factor. Second, 96% recognise their protection is incomplete — they know their defences have gaps. Third, nearly three-quarters are still running fragmented defences where people-focused and technology-focused controls never talk to each other. Attackers don’t exploit what organisations fail to see. They exploit what organisations see but fail to connect. That gap — between recognition and action — is where incidents happen.
Passwords aren’t going away, and proper password hygiene still matters. But hygiene alone isn’t a strategy. What organisations need is the combination: identity protection at the access layer, real-time detection at the technical layer, and behavioural instrumentation at the human layer. The third is the most underinvested. It is also exactly where attackers are focused.
Cynthia Lee, APAC Vice President at Delinea
World Password Day feels increasingly outdated. Passwords can no longer be relied on as a meaningful line of defence, as attackers routinely bypass them through social engineering and third-party apps.
To make matters worse, many organisations are deploying AI agents to improve productivity and granting them standing access to their core systems, which 72% of Australian leaders acknowledge is increasing their security risk. AI agents are susceptible to revealing passwords themselves or to being used as an entry point for attacks.
Organisations can build true resilience by rethinking access altogether. For example, they can adopt ephemeral permissions, which last just for a set period, or just-in-time (JIT) access management, to ensure privileges exist only when needed, and drastically reduce the window of opportunity for attackers. By creating strict role-based access controls, businesses can limit both movement and overall exposure.
Ultimately, organisations’ mindsets must shift toward a model of zero standing privilege where no user, device, or agent is inherently trusted, and every access request is continuously verified.
Tomer Bar, Semperis, Associate VP of Security Research, Semperis
We’ve been using passwords to prove who we are since the very first multi-user computers. Decades later, they’re still with us – and still causing trouble. Passwords have a terrible reputation, but that’s not really the password’s fault. It’s ours. Most of the risk comes from human limitations and predictable behaviour, not from the mathematics behind ‘guessing every possible combination’.
On World Password Day, let’s look at why ‘strong’ passwords can be weaker than you think, what advanced attackers do and how to choose passwords that are hard to crack.
When people create long passwords, they often choose memorable options like reused patterns, small variations of old passwords, predictable phrases, or popular lyrics, quotes and memes rather than random strings. Attackers take advantage of this by using large dictionaries built from leaked password databases and applying rule-based tweaks – such as adding the current year, swapping letters for symbols, or tacking on punctuation to guess these ‘memorable’ passwords efficiently.
They also build rainbow tables: precomputed tables of password hashes. Because most systems store only hashes, not raw passwords, a rainbow table allows an attacker to reverse a hash back to the original password, if that password is in the table. These tables can be downloaded from public sites.
Are passwords useful today? Yes, but they’re no longer enough on their own. Multi-factor authentication (MFA) should be enabled wherever possible because it makes stolen or guessed passwords far less valuable.
If you keep using passwords, the best practice is to stop letting humans design them. Use a password manager to generate and store long, truly random passwords (20+ characters) and never reuse them; turn on MFA wherever possible so stolen passwords are far less useful; and for the few passwords you must remember, use long, unique passphrases made of random words instead of lyrics, quotes or clever patterns. The goal isn’t perfect, it’s to make attacking you so difficult and unprofitable that attackers move on to easier targets.
Jon Fielding, Managing Director, EMEA, Apricorn
Weak password practices remain one of the easiest ways for attackers to gain access, yet many organisations still fail to enforce strong password policies, leaving a basic gap in their defences.
Where policies are in place, the focus should be on strength rather than frequent changes, and while password managers have helped tackle reuse by generating unique credentials, they also need to be secured properly with a strong master password and multi-factor authentication.
Crucially, organisations must ensure this is overseen on all devices, and removable media remains a major blind spot. USB drives and external hard disks often fall outside standard controls. Encrypting them with access only available with a password that can be configured in line with corporate policy ensures sensitive data remains secure if devices are lost or stolen.
The shift now is towards always-on, hardware-based encryption combined with tighter device control policies, ensuring that sensitive data remains protected even if devices are lost, stolen or connected to untrusted systems. In fact, our 2025 survey indicated a growing maturity in the adoption of encryption, with 94% of organisations now having a defined data encryption strategy or policy for removable media, which works in tandem with password protection.
While alternatives such as biometrics and passkeys gain ground, passwords will continue to play a key role, strengthened by measures like multi-factor authentication and zero trust.
Jon Abbott, CEO and Co-founder, ThreatAware
As most people are aware, passwords remain the first line of defence for the majority of services and applications. A weak password, whether short enough to crack via brute force or simply easy to guess, leaves the door wide open. However, what people still regularly overlook is the risk of reusing the same password across multiple systems, even a complex one.
All too often, someone will have a single master password that is genuinely strong, but they use it everywhere, from their banking system to a low-security site like a tennis club portal. The problem is, if that tennis club portal is breached and its password database is stolen and cracked, attackers can try that password against every major platform automatically.
They have your email address and a possible password, so the code simply tests common services such as Microsoft 365, Google, and others, and reports back when a combination works. It will also try common variations, appending an exclamation mark or the digit 1, since so many people make exactly those tweaks when resetting a password.
The best approach is to use passwordless authentication where possible, or a password safe. This is where you remember one strong master password, and the manager generates a unique, complex password for every app and site.
While your password should be the first line of defence, it should never be the only one. MFA or SSO must be enabled on every account where it is available. If a critical system does not offer MFA, you need to find a different provider as the risk is simply too high.
Ultimately, good cyber hygiene goes beyond passwords. It requires stronger visibility across your environment, tighter control over devices and layered security that protects data wherever it resides.
Jon Kane, Senior Director, Europe & META Channel at Forcepoint
When I first started in cyber, I worked with someone who had ‘Tipp-Exed’ their passcode onto the back of their two-factor authentication device! This certainly wasn’t acceptable then but shows that security is not just about the tech; its policy and education too. The rise of social engineering threats and phishing scams – which rely on human error – are forcing users to rethink their passwords and broader security strategy.
This World Password Day, organisations need to rethink the ways they secure their networks, not just technology but also how it is used. Recent guidance from the NCSC recommends moving from passwords to passkeys and other biometric identity methods – a reflection of the changing nature of our identity security landscape.


