As 2026 approaches, credential-based attacks are accelerating faster than ever. AI-generated passwords, massive breach datasets, and automated credential-stuffing tools are redefining how attackers operate and exposing the limits of traditional password policies. Complexity and rotation rules alone can no longer keep pace with the speed at which credentials are stolen, reused, and evolved through AI. Attackers now generate near-infinite password variants, while many organizations still rely on outdated controls that were never designed for this level of automation.
Today, organizations must adopt real-time password protection that aligns with modern regulatory expectations and provides security teams with the visibility they need to act before attackers do.
Osman Celik, Research Analyst at KuppingerCole, will examine the password protection trends defining 2026: AI-accelerated password attacks, the velocity of breaches, and the regulatory direction from NIST, NCSC, and NIS2. He will explain why static password policies are no longer sufficient and offer concrete recommendations for organizations preparing for the next phase of compliance and credential protection.
Darren James, Senior Product Manager at Specops Software, will demonstrate how password protection and modern password policy enforcement can stop AI-generated and compromised credentials in real time. He will showcase Specops capabilities for aligning with security standards and reducing risk without adding user friction.
Hi, everyone. My name is Osman Celik. I'm a research analyst at KuppingerCole.
Today, I'm joined by Darren James. He's a senior product manager at SpecOps. And together, we are going to cover this topic today in our webinar, Your 2026 Password Wake-Up Call, Breaches, AI, and What Comes Next.
Hi, Darren. How are you doing?
Hi, Osman. It's a pleasure to be here.
Very well, thank you. Likewise. So before we begin, let me remind some housekeeping rules before our webinar. So for those of you who are not familiar with our Livestorm panel, you are centrally muted, so you don't have to click on any button to mute yourself or try to talk because we won't hear you. And we are going to run a couple of polls during the webinar, and you can always send us your questions using the menu on the right-hand side.
There, you'll see the polls, questions, and the chat button. You can use all of them to answer the poll questions and also send your other questions, the ones that we can discuss at the end of the webinar. And for those of you who are not with us live today, we are recording the webinar, so the recording of the webinar and also the presentations from both of us will be available in the couple of days after the web reveal webinar day. All right. So without further ado, I explained the agenda of today. I will briefly cover the password security market and trends.
And in that part, I will also discuss how the solution works briefly, the main required capabilities for a password security software, and the challenges that, the most important challenges that customers face today. And after that, I will hand it over to Darren, and he is going to tell us what SpecOps offers. And also he is, most interestingly, maybe he is going to show us a live demo of their product. And if time allows, we will try to answer your questions today.
And yeah, this is basically the agenda of today. Before we begin, let's start with our first question.
As I said, you can use the right-hand menu to answer our poll questions. The first question, which region are you participating to this webinar from? You'll see the options there. Please answer correctly. You will see that this is kind of relevant to the regulations we are going to discuss in our, I think I will cover it, and I am sure Darren will cover it too briefly. So maybe you will see some relevant content and insights for your region. All right. Let's begin with some threat landscape highlights, because I think this is very important to understand what is changing in 2025 to 2026.
And to be honest, I went through a couple of searches, and the most relevant one I found was from CrowdStrike. I don't know. And I just wanted to briefly use this graphic to make you understand that you are, whatever the region you are, you're always targeted by cybercriminals.
Of course, if you're in North America or in APAC or EMEA region, you're more targeted by the cybercriminals. But if you look at the table, you'll see that if you're from technology or consulting services or services or manufacturing or retail or financial services, you are more targeted. Why? Because you work with customer data in most cases, and that involves passwords, credentials, and also the other sensitive data. And I found some other supporting numbers.
They are all from 2025, by the way, just to make you understand that what is the situation now and then what it has to do with the password. So IBM says that on average, the cost of a data bridge has reached $4.44 million. That's a lot of money. And out of all the cyber attacks or cyber incidents, let's say, 22% of them are relevant, related to stolen or compromised credentials. So they are highly relevant to your weak passwords. And out of these attacks, 80 to 90% of these breaches involve a compromised password.
So I think that this kind of gives us a clear idea of why we are talking about how you need to come up with a password hygiene, and also how to increase your cybersecurity posture using the insights or the instructions we provide you today, and also the tools that might be helping you with it. All right, so let's first begin with some definition, also the basic insights for those of you who doesn't know what the market is. So we talk about today password security software market.
And what password security software is basically doing is you need a solution to strengthen your enterprise password practices. You need to enforce some password security policies. And you need to detect and block some of the passwords that are using in your organizations.
And also, you will probably go through some auditing processes. And then these solutions help you comply with these regulations, and also help you go through the auditing processes. And no matter what environment you use, on-premises or cloud, they can be deployed anywhere. I'm talking about most solutions here. And let's do some vocabulary checks here for those of you who doesn't know. So you need to understand what the password policy enforcement is. You need to be familiar with the passphrases. This is something different than passwords, right?
So they are easier to remember, but there are sequences of words that are different in form than the passwords. And then you also need to be aware of your password lifecycle management. You need to understand if you have integrations to the Azure or Active Directory environment. And if you have a self-service for password resets, if you already deployed the MFA, multi-factor authentication, to provide more than two authentication factors to your access controls.
And also, what is password auditing and compliance? Because then you need to, at the end of the day, comply with the regulations and also your auditing processes. So we were talking about the password security software market. But when we think about the solutions, what could be the core capabilities for such software, right? So we can begin with the policy enforcement. And then these are related to the length or complexity or the reuse prevention of the passwords. And then we can talk about how these solutions ban or deny this password, the deny listed passwords.
So they can sort of give you an idea which ones are common, which ones are weak, which ones are reused, and which ones are easy to predict. So the solution needs to give you feedback. And in case if you're using a password already, and then the solution should already warn you if this is compromised in the dark deep web environment or in the surface web. So we know that this password is already breached or not. So that we get the idea if we should change it right now. And then if maybe you should inform for those who are using this compromised password within our organization.
And then the other one, then we need to tell people that real-time, that your password is not strong enough. And then for that, the solution provides real-time feedback. And then during the creation, also when you want to change it. And on top of that, you need to also have a solution that is helping you with the creation, rotation, and expiration, and the reset processes when it comes to the lifecycle management of passwords.
And you need to have a centralized auditing and reporting for the password events, and then the policy adherence, and also for some templates for the regulatory compliance, and also the other industry-related standards like NIST or BSI. We will cover them later on, and you will understand the details of it. And then the solution should also offer you some role or group-based policies. For example, different rules for admins or users, and then determines which users are at high risk, etc.
And then lastly, you need to make sure that you have the logging, you have the logs present, and also the SIEM integration for monitoring them better. And here is not limited to only SIEM integrations, to be honest, but you can think of other cyber security tools that are providing real-time monitoring. And speaking of those integrations, maybe we can start already talking about what could be innovative in the market, and we can already say that not only SIEM, but ITDR and XDR solutions might be also helpful to you.
But this is, again, not a market standard, but this is something I see innovative in the market. But not only that, but you also need to have continuous credential monitoring in the dark deep web, the websites, and also some AI or ML-based password risk scoring to also detect the anomalies, and then also what is relevant to your organization. These risk scoring help you prioritize the risks arising from your credentials and passwords. And then some automated remediation works are also very helpful. They help you force reset and also target.
They also warn you about the targeted campaigns and then the users that are at risk. So basically, this is kind of working in conjunction with cyber threat intelligence. And if your solution allows integration to those or already providing this threat intel by itself, then you are aware of most of the threats before your company are targeted by the cyber criminals. And lastly, also the solutions around there, some of them have already passed the strategy.
I'm sure Darren will also share their strategy on this because that is something that we need to consider today, no matter how much we use the passwords in our daily life, in our daily and also in our enterprises. So we should look for always solutions that are supporting password risk strategies from today on.
So here, I actually wanted to briefly show you. Again, this is a brief comparison. If I wanted to show what has changed over time, then this webinar would be only about that. So even one hour wouldn't be enough. But I wanted to give a clear overview of the changing regulatory environment here. Quickly going to the next slide, so you are aware which regulations and standards we are talking here today. So in the second slide, I will see PCI DSS, SEBI from India and ANSI from France.
But beginning with the first part of the list, so we have BSI from Germany, NCSC from UK, and NIST that is, I think, relevant to all of us from US. And here, we talk specifically about SB863B.
So here, you can see that in most of the regulations, they are emphasizing longer and more high-quality passwords, right? They require also some sort of better user experience. In the past, we were changing all the passwords for no reason. And it was regular, it was good maybe, but it was a pain for customers, for users. And then they were not giving any reason to this.
For BSI, for example, we are supposed to change this password only when there's a suspicion or indication of compromise. And now, for example, for NCSC, the recommended organizations do not force regular password expiry. But what we do is, we do promote blocking weak and common passwords and then encourage long passphrases nowadays. And then I think that we should all be more familiar with the passphrases. I'm sure Darren will share his insights and then what specs are in this field as well. And as you see, NIST is also aligning with the rest.
And I want to think that you should be aware that when you look at these regulations, they are actually kind of updating and going in the same direction. Because even though they do not officially cooperate with each other, in most cases, they are kind of following each other to make sure that we have a standardized password management. Throughout the regions, because at the end of the day, organizations collaborate with each other and they do business with each other. So if something is changing in Germany, that's not limited to Germany.
We see the same changes of BSI for the ANSI, which we'll cover in the next slide. So it applies to most regions, I would say. But here today, I covered Europe, North America, and India for the time management also for the sake of the length of the webinar. But I also wanted to include PCI DSS here because most of the time we deal with customer data and the payment information. So when it comes to sensitive data, I would prefer to have a solution complying with the latest version 4.0 of PCI DSS, right?
So if you are dealing with password and the credentials of your customers, then you have to comply with PCI DSS. And here you see, I thought that PCI DSS should be a universal regulation. It's not limited to the United States. But you see the changes here. The minimum password length was seven characters. Now it's increased to 12.
But yeah, I mean, these are slight changes. But these are because of the attacks and also the brute force attacks and also the AI tools that the cybercriminals are now utilizing. The number, even one character, really decreases the chance of being hijacked drastically. Because the ratios of being hijacked is drastically changing even with one character. And now we are now supposed to implement MFA for all the accesses into cardholder data environment for PCI DSS.
And yes, you see that for the India and also for the France, we also have covered a bit. But as I said, for France, ANSI is really similar to BSI. So if you're curious, please ask me more questions. But I'm not going to bother you with the rest of the slides. So for the time management, I will skip to the next slide. But please raise your questions if you have any questions regarding the regulatory environment. I have some experience in this, and I can also answer your questions. So this was the first challenge, right? The changing regulations.
So the second one is the sophisticated attack vectors. So we believe that, I think that everyone agrees with, that the traditional defenses are no longer sufficient against AI-powered attacks. And then the new cyber attack techniques that the cybercriminals are utilizing now.
But they, because they, for example, get better success rates with the brute force and the password spraying with the help of AI-powered tools. And some machine learning tools generate more realistic password guesses based on the personal data. And this large breach data sets used for automated testing against the login forms. So these are all part of the utilization of AI by cybercriminals.
I mean, we should not be thinking that this is the one only one in it, because we can also use AI to counter attack them. And I think that we should look for solutions that can mitigate risk arising from AI-powered tools and also can also utilize AI against them. But why do they matter to us? Because attackers no longer rely on random guessing, and they leverage patterns. And then they also see the patterns, because they are also monitoring what you do. And these stolen password data sets are a good guidance for them. And then these lists are constantly expanding.
And then, I mean, you don't really have to do much. Just go to dark deep web, and then you will see. You will have an access to it. Even the data sets from countries are being shared in those environments, containing millions of people's data. And lastly, password reuse creates cross-service compromise risk. And the second point I wanted to cover here is the Active Directory, because it's the primary target of cybercriminals in most cases.
So you need to understand that if you have a password management solution, password security software that is connected to your Active Directory, that is going to help you, actually. Because then you will have a better control of your Active or Azure directories. And for me, the key takeaway would be more than identity attacks succeed, not because attackers are clever, but because passwords remain weak, reused, or compromised. And to understand this, I can actually give some insights here. Past hash attacks exploit hash credentials inside the Windows environments.
Again, we were talking about Active Directory here. Kerberoasting and SRAP roasting rely on weak or crackable passwords. So these are the reasons for us. Credential harvesting via LSA, SS, and memory scrapping. Privileged accounts often protected by outdated password practices. And it's not only limited to that, but it also extends to password hygiene gaps. Weak users' passwords become entry points for lateral movement. Compromised, non-privileged accounts escalate to domain admins. And attack success often depends on predictable password selection.
So if you are using Active Directories, please take a look at, please be aware that your password security software supports the Active Directories that you're using or Azure. The challenge number three is, I think, very easy to guess. I'm sure all of us are aware of this, but I think this is one of the most difficult ones to overcome because humans are still the weakest link in this trend landscape, let's say. And for me, when I look at the people, they don't remember the secure password. They just want to remember the convenient ones. So that's why it all begins.
And they don't know that the attackers know more about themselves and then their habits than they realize. For example, they already know your dog's name, your maiden name, or your favorite club, football club, or the child's name, or the birthday. And the most password patterns you use, the alternations and also the variations you do because they know which email and which password you're using. And then it's just really up to a couple of variations that they need to try, slight variations. And then they will have access to your accounts already.
And because people all the time use the same passwords everywhere, and then they, again, they use the same variations, slight variations in every different platform. And they always think that I will fix it later. But this is actually the reason why the humans are still the weakest link. But to overcome this, what do we have to do is, especially in our corporate lives, then we have to provide some employee training methods. And these ones should be coming in different variations.
Like we can talk about the micro learning models, like, you know, short, focused, five to 10 minutes, not boring security habits that our employees can actually execute in their daily life in their organizational workflows. And also, we need to have some understanding of phishing. And then how can we actually overcome it by the simulations, so we can actually come up with some realistic practices. And then at the end, we are not causing any breach, but we are actually able to train our employees against those phishing attacks.
Some password security workshops we can maybe cover here, some practical sessions on passphrases, password managers, and MFA. So they will understand the basic introductory concepts for password management, like I did earlier in my slides. So if you already have some vocabulary and also familiarity with the basics, then you will already understand the rest.
But yeah, you have to begin with some sort of initial information. Just-in-time education prompts that could be coming in, small reminders that appear during the password changes, maybe not once per year. And also scenario-based learning, what would you do if this or that happens, like, and then the simulations that match, that could match the real attacker tactics. So this could be nice.
And also, lastly, you should gamify this learning objectives and also the steps, because then people like to achieve something, like you can give them badges or points, you can give some recognition, and then this will increase the engagement and also the participation rates. And this training should focus on how attackers target passwords, why password reuse is dangerous, and how breach passwords are exploited. And also it should provide practical password hygiene habits, like I discussed earlier, but they should not be boring and must be easily conducted every day.
All right, so this was the last part of my section. But before moving to Darren's section, I would like to ask my second question to you today. What is your biggest challenge in password management today? Regulations, advanced attacks, human factor, password policy enforcement, or other? Please indicate if you think that another thing is the most important or the biggest challenge of your password management today. I give you five seconds here, and I hand it over to Darren.
Okay, so thanks, Osman. I think that gave us a really good insight into sort of where we are or where we have been and where we might want to go in the future. And I'm going to kind of drill down into a few of those topics in my presentation here. So we'll skip past this, you know, crafting a password policy for 2026 and beyond. That's important. When I first started at SpecOps 15 years ago, I was often asked, aren't passwords dying? And here we are, 15 years later, still talking about bad passwords.
So sadly, the answer is no. Passwords are still the prime way of authenticating people, whether we like it or not.
And so we, as cybersecurity professionals, need to find good ways of implementing strong passwords or passphrases, as Osman was talking about earlier. And, you know, again, to sort of double down on what Osman was saying, Active Directory is still being used by many organizations around the globe, and it's generally regarded as the source of truth when it comes to employees' passwords. The AD password policy hasn't changed in 25 years. So ever since the dawn of Active Directory in Windows 2000, it's the same now as it was then.
Originally, you needed an entirely new domain if you wanted a different password policy. So applying the right password to the right people is important.
Back then, you didn't have a choice. Everybody got the same. Doesn't matter if you're an admin or a regular user or a service account, everybody got the same password policy. Microsoft did add fine-grained password policies back in 2008 to try and address that somewhat. But to be honest with you, it fell really short of the requirements because it gave you no other extra choices. It was still complexity on or off, length, and that was it. And when we think about complexity, complexity essentially means three out of the five character types and mustn't contain a username.
So password1 with a capital P is a perfectly good Microsoft complex password. And of course, when it expires, password2 with a capital P is fine as well. The AD password is often synced to cloud-based services. So whether it's Entra or Google or Okta or you name your IDP, it's normally the AD password that ends up on those cloud-facing systems. So these days, you don't have that security perimeter, which is your office. Lots of people work from home. Lots of people log into the cloud. Lots of people are still using those same terrible passwords.
And of course, we should switch on MFA wherever we can, but sometimes that isn't possible. And sometimes, even if it is possible, we often don't see it. People still fall back to using passwords.
And also, even if we're looking at passwordless solutions, what's the recovery process for a passwordless solution? It's normally still a password. And then if we look at cloud solutions in general, native Entra hasn't improved this at all. So it's still the same complexity rules. There's one policy per tenant, and the character set is limited to US keyboard characters only. So in a way, it's kind of worse than certainly for us Europeans and maybe people who work in Israel or China where we've got other characters that we could have used in the past.
If we move to a native Entra, we lose those choices. We've only got US English alphabet characters and special characters to use, no Unicode characters anymore. And there is also a feature called Entra ID password protection, but it doesn't actually block real breach passwords, just variants of Microsoft's weak words. And in fact, we did a study recently that found that only one in 10 passwords from a public breach that was disclosed months ago was actually breached by Entra password protection. So it isn't a replacement for certainly what SpecOps offers today. So what do we do instead?
How do we make these things better? Well, just as Osman was saying, there's been a bunch of guidance that's been updated over the past few years.
In fact, NCSC started talking about this all the way back in 2016. NIST caught up last year in 2024 around switching their guidance from short, complex to long and more simple passphrases. But it's essentially it boils down to these five points here. So remove complexity and instead increase length. Remove expiry, which lots of people jumped on, particularly during COVID. But if you're going to remove expiry, then make sure you block the use of known breached passwords. And then help the user. It's not their fault. We have to give them some guidance.
So yeah, all familiar points with Osman's slideshow. So what was the old?
Well, really, as I said, those first two points are related. So we need to remove complexity. But if we do that, we need to make sure that if we're only still limiting it to eight or even 12 characters, you're going to be in trouble because those sorts of passwords, particularly in an Active Directory environment, may still be floating around as LM patches. So we've got to replace complexity and replace it with length rather than complexity. What's wrong with this old way?
Well, short, complex passwords are difficult for humans to remember and difficult for us to type. And the use of complexity also forces our brains introducing predictable patterns. So if we think about our passwords, maybe not that all of the audience have today, but maybe if we could think about our family or colleagues that aren't into cybersecurity quite so much, I'd probably guess that the first character of their password is probably an uppercase character. The second character is probably a lowercase vowel, certainly in UK English where I'm from.
And the rest of the characters are probably all lowercase. And of course, we need the third character on the end. So guess what? It's going to be a number, right? And if I've just described your password to you, yeah, you probably ought to change it. And of course, if we're feeling super secure, we might want to add a special character. But guess what that's going to be? It's probably going to be an exclamation mark, and it's probably going to be at the very end of the password because we can hit shift and one with one hand.
And also, you know, these passwords that our users generally create will be the absolute minimum. So password one with a capital P is nine characters. Password 12 is 10 characters or password 12 is 10 characters. And password 123 is 11 characters. So you can guess what their 12 character password is going to be, right? Password 1234. And so I know this, you guys know this, but also all the bad guys know these patterns as well and these behaviors as well. So this isn't a technical problem. This is a human problem that we have to solve.
And all these short passwords and keyboard walks make it really, really easy to guess the passwords or crack them or shoulder surf them. And passphrases ultimately solve these problems, but passphrases haven't really been defined.
You know, so the NCSC has been preaching about three random words for many years, but we still see a lot of our customers thinking about what three words, you know, using the map to think about three words, but they're not three memorable words. And we often see people thinking about lines from songs or film titles, that sort of thing.
Again, if you look at my LinkedIn profile, you'll know that I'm a Star Wars fan. So do you think may the force be with you would be a good passphrase for me? It's only a phrase, it's not a good passphrase. So I really like the UK government's three random words, but even with that, you have to make sure that they aren't the same words or they're not something obvious, like A-A-A-A-A space B-B-B-B-B space C-C-C-C-C, right? We've got to have some control even when it comes to passphrases.
And then again, let's not forget, passphrases are still vulnerable if you get phished or keylogged, and especially if you tend to reuse passwords. So we'll talk a little bit more about that later. What about expiring?
Well, yeah, that's removing expiry and blocking breach passwords. These both go in hand in hand. Traditionally, we used to expire passwords every 30, 60, 90 days. But what this led to was that our beloved users would just change the number at the end. So password one, password two, so it didn't actually improve security. So the official guidance today is you should remove password expiry, but you might find that some of the guidance particularly from some of the other regulatory bodies out there still recommends that you have an expiry for some users.
So whether it's PCI and you've not got MFA enabled on all accounts for whatever reason, you still need to expire every 90 days. You might also find some admin passwords are still required to have expiring in mind. So be mindful to apply the right password policy to the right type of user. That's something that's really, really important. Don't have a one size fits all. And a lot of our customers, as I mentioned earlier, particularly after COVID, switched never expire on because of all of the problems of expiring passwords and people working from home and cash credentials.
And the problem with that is that they didn't read the small print because the small print says, you should still force a change if you know or suspect a password has become breached. But how do you know? That's the problem. So when they set it, that's great. Wasn't breached password. But if they've reused it or it's subsequently become breached, how do you know? How often do you scan it again? Very few solutions, certainly nothing in Active Directory, nothing in Entra will tell you if a password becomes breached.
So you need to look for a tool that can continuously check against the constantly updated database and then initiate a remediation of some kind. So whether that's sending an email or a text message or enforcing the user to change their password, or even generating just the report so that you can manually go and follow up with your users. These are all important things to keep in mind. And there's another thing to consider as well. All of our users might not be the best typists in the world.
You know, I often think of my late father and every time he has to type in a password, he was literally, you know, smashing the keyboard with his fingers. And if I asked him to type in a 20 character passphrase, there is very little chance that he'd ever get to successfully enter that. But what you can do with, certainly with our solution, is use something called length-based password aging.
So this allows the user to choose between a short complex password and a longer passphrase, and then reward them with a longer or maybe even a never expiring password, providing it never becomes breached, of course. So, yeah, use Xpari as a reward. Let's touch a little bit on AI.
So sure, you know, there are various tools that Osmond talked about that we can use AI for spotting trends in vast amounts of data and automate responses to enforce systems to be patched or prompt again for MFA in a true zero trust enabled network. But we can also use AI for pretty simple things as well.
So, for instance, if you're coming up with some dictionary words that belong to your company, that can be quite hard for you to figure out what all of those words are. So why don't you use your AI of choice to generate a list of words that relate to your company? So this could be the company name, it could be products and services you provide, it could be your office locations, it could be the departments that you have, a whole heap of them.
The AI would have already scraped all the websites that mention your company and the things that you do and it can provide a 1,000 word list, a 2,000 word list, a 10,000 word list that relates to your company. You don't have to worry about blocking things like password or let me in or admin because our solution would block those sorts of words anyway. But if you can generate a list, and again, each of these words themselves, you don't have to put the variants in because again, our solution can block all of the variants of those exact same words for you as well.
So they will never exist in your environment. And I touched on this a couple of slides ago, but what happens if your amazing passphrase gets phished or reused and then becomes leaked? How do you know?
Well, you could turn to various scripts or tools that will essentially crack your user's passwords or run them against rainbow tables and then you can see how easy they are to crack or if they've all may have already been bridged. But many of these DIY tools can leave live credentials exposed.
So yes, you're running them in your environment, but it's a bit of a gray area. You're cracking people's actual real passwords. Do you really want to do that? What happens to that desktop that you've run this tool on of a file that you generated? How risky is that exposed file?
So really, when you're running those tools, you should be very, very careful if you go down that route. Alternatively, and I'm going to show you in a few moments, a tool called SpecOps Password Auditor and that you can run a scan against the pretty up-to-date one billion breach hash database. Try saying that with your mouth full. And we update that every couple of months and it can provide a full health check around your password landscape in your environment and even produce detailed easy report and easy to read reports.
So you can hand those off to any decision makers that might need to make a choice on a third party solution. But we'll take a closer look at that later when I jump into the demo. And then the final item on that list was supporting the user, helping the user. Entering and changing passwords are probably two things that are right at the bottom of the list of fun things to do with your computer. Everybody hates doing it. So it's not their fault that they chose weak passwords. It's our responsibility to try and help the user as much as possible.
And you can see on the right here a couple of the UIs that we have available for our customers. So the one to the left or the black background one you can see here is something that we can interface with the password change process on a Windows device. And so it's a dynamic feedback. So as the user types in their new password or passphrase, you can see at the top there they can choose. It will display with a nice green tick as they meet each one of those rules.
And again, the nice green bar at the bottom there will tell them if they can keep it for a year or just 30 days or maybe never expire. So again, the user gets to see live feedback about what they're doing right. And more importantly, they do what they're doing wrong. And then to the far right, you can see a web interface which shows you exactly the same thing, but now in a web browser. So it doesn't matter if you're not using a Windows device. Maybe you're using a mobile device or a MacBook or a Linux box.
You can get that exact same feedback during a reset process or a password change process, but in a web interface instead. And again, this is all dynamic. And this time you can see it on the password tab.
And sadly, this guy's used a breach password. So again, no need to call the service desk. You can see exactly what you've done wrong.
So yeah, don't use a breach password in this particular instance. So in summary, it only takes one breach password to put your entire infrastructure at risk. Current password policy arguably has never been good enough, and especially not in 2026 with the upcoming threat of AI being used for bad as well as good... being used by the bad guys as well as good guys. And so you mustn't take this one size fits all approach. Make sure you apply the right policy to the right user. Try and choose passphrases. Get your users to adopt them if that fits your regulatory requirements.
Always continuously scan for breach passwords and help your users as much as you can. They are your human firewall. So it's really important that you have happy users. So let's see how we can solve this problem. So I'm going to show you in a few moments password policy, which will show you how you can create a 21st or 2026 and beyond password policy that's absolutely fit for purpose today, both within your own Active Directory and hybrid environments. So you can have a strong, robust password policy for your admins, your users and your service accounts.
I'm not going to go through those lists there because I want to talk about it a bit more when we jump into the demo. But the other thing I'm going to show you is Password Auditor. So Password Auditor is a free tool you can download from us today. You can run it and within minutes you'll get your results. There's a nice pretty infographic you can see whizzing across the screen there. So I talked about it a little bit earlier.
And again, I'm going to jump into the demo now. Let's not take too much time on this slide. So here we are. I've switched to my demo environment. This is running on a Windows 11 device. I'm logged in as a domain admin at the moment. I can also run Password Auditor as a regular user as well. It can be run with an internet connected machine, but it can also be run offline. So you don't have to trust me when I say it doesn't phone home to us.
You could restore a domain controller in an isolated environment, take the Password Auditor and the database to that isolated environment and run it there as well if you want to. We can scan multiple directories, entire ADs. We can scan individual OUs if we want to as well. We can also include disabled accounts.
Remember, enabled users. Obviously, our live users today, but disabled accounts are literally one click away from being an enabled user again, so a threat again. So if that is a concern of yours, if you have to keep disabled accounts in your active directory for a long, long time, you can still scan against those guys. And of course, we can anonymize the data. Very often when people run Password Auditor, there can be some quite embarrassing results in there. So maybe the CEO of the company, maybe even your own colleagues may show up in some of these reports.
So it's good to run it with the details to begin with. Yeah, I can see some laughing faces coming up there, but believe me, it does happen. But maybe when you hand off to your stakeholders, it might be wise to anonymize it. But that's all possible. So you just see the numbers. So let's click Start. So first thing it prompts us to do is to download the database. So right now, you can see that I'm on version 41 of the database. As I mentioned earlier, we keep this regularly up to date. And this database is made up of all of the most popular breaches that have happened in the last few months.
It takes feeds from public breaches. It takes the feeds from our threat intelligence platform. It also takes these from our Honeypot network. So our Honeypot is made up of fake servers, basically. They're scattered all around the internet. They change on a regular basis. And we know that there is no legitimate reason why anybody would type a username or password into those Honeypot websites or servers. And so we know that if one is entered, it's probably for a bad purpose, an illegitimate purpose. I can download the latest version, which we released in mid-November.
There'll be another release over two months, another release in January. So you've got the very, very fresh data in there. And it's around 1.1 billion password hashes in this database at the moment. It's about 7.5 gig, 7.8 gig, something like that. So make sure you've got enough disk space on the machine that you're running this from. And then we're going to click Start Scanning. So what this is doing now is it's extracting the user's current password hash from Active Directory and comparing it with those 1 billion password hashes in the database.
What it's not doing is it's not cracking anybody's password. So we're not leaving any sensitive data around the system that we're running on. So that's really important. The other thing that it's not doing is it's not sending any information back to us. As I said earlier, you can run this in a completely isolated environment, but it doesn't, even if you don't, it doesn't send any of your result data back to us. So let's click Show Result. So we can see a number of reports here. We've got some gold reports up here and we've got blue reports, the rest of them down here.
Now, the gold reports require domain admin access. So who's got a blank password? Who's got a breach password? Who's got an identical password? That all requires the extraction of a password hash. You need to be a domain admin to get that data. But any regular user can get any of these read, any of these blue reports. So I can say, who's got an admin account? Who's got an admin account that isn't using it? How many of my users haven't logged in for 90 days? And I can click on all of these reports and I can adjust the day since log on.
I can export these to CSV files if I wanna analyze them in Excel or whatever your favorite spreadsheets software is. But the big one that everybody's interested in is breach passwords. So who today currently has a breach password in my network? And I can see their usernames. I can see whether they're enabled or not. I can see their email addresses, where they are in AD, last time they logged in, the last time they changed their passwords, if their passwords are due to expire or whatever. And of course, I could ring.
I don't know if we've got any diehard fans on the call today, but I've got John McClane and Hans Gruber here. It is a Christmas movie, by the way, as we're in December.
But, you know, I could ring John up and say, could you change your password? But as I haven't got any rules in place to stop John from making a bad choice, he could say, sure, yeah, I'm gonna change it to, from password one to password two. And that would be perfectly acceptable. So this doesn't solve your problem. How do we solve the problem? That's the key question. So we'll just look at that in a couple of minutes. One final thing I wanted to show you before we move on to how we solve it. Are we affected by regulatory compliance? So most of us are, right? So are we affected by NIST or PCI?
We can see whether our password policies are NIST compliant, PCI compliant, NCSC. There's a whole bunch of different ones here. Green ticks means we're fully compliant. Yellow dots means we're partially compliant. And red squares, yeah, we better fix that one.
All right, so lots of really great info in here. And the final thing I wanted to show you, rather than you guys having to explain what all of these reports are to your boss or your team, wouldn't it be nice if we could just click a button and it create a nice score at the top and then explain exactly why each of these reports is a risk and how you can fix them, right? So this essentially writes your business case for you. I have a lot of people that often say to me, yeah, I haven't got a problem. I'm using another solution or my answer to that is just run this tool.
You don't get many free lunches in cybersecurity. This is a real genuine free lunch, right? Run the tool, then tell me you don't have a problem. And I'll be very happy for you if you have very few brief passwords. But typically, when people run this, they see that if they've got anything less than 30% of their users in this list, they're doing fabulously well.
So yeah, if you want to take me up on that challenge, please do. So how do we fix all this stuff? So that would be password policy.
So again, it's about having the right password applying to the right people. So we can have as many password policies as you wish. And within these policies, these are user-based group policies, by the way. So if you've got an admin OU, you can link an admin policy to the admin OU. Every user object in that admin OU will be affected by the policy. You've got the service account OU. Every service account will have that. We'll have to comply with that policy. But within here, we can choose whether we want passwords or passphrases.
We can set that length-based password aging that I was talking about earlier. So reward users for setting longer passwords. We've got the ability to continuously scan against not just that 1.1 billion word password, but also against their online database, which is constantly updated and contains over 4.5 billion passwords. And we add hundreds of thousands of bridge passwords to that online database every week.
So yeah, that amazing passphrase that you set last week, last year, last month, and it now turns up on our database. Well, now you can do something about it. You can generate a report. You can email users. You can text users. You can force them to change it or a whole different combination of whatever you want to do. And then finally, passphrases. So we mentioned earlier, yeah, it's important to come up with a passphrase policy that suits your requirements. So not just 20 characters in length or lowercase, but make sure that you're doing things like three random words or three or more words.
Make sure they can't repeat the same word. Make sure they can't use consecutive identical characters. And certainly, if we want to block certain words, absolutely, we need to do that as well. And then finally, as we mentioned earlier, help the user. So we've all seen this interface before. Wouldn't it be nice if a little panel slid in from the left-hand side so that as we started typing in our new passphrase, all the nasty red dots turned to nice green ticks? This is a game changer for your users.
It will help your service desk no end and it will help you switch from short complex to long passphrases, potentially overnight if you want to. So that's it for the demo. I think we've got a few minutes left for questions.
Hopefully, we've got a couple. But thanks for the demo. I think it was very informative and also maybe clarified a couple of points from your presentation. But my first question would be that we only covered two solutions from SpecOps today, right? That's correct.
Exactly, yeah. We didn't really have a lot of time to drill into it. But we have lots and lots of solutions out there that really support the entire password ecosystem. So it doesn't matter if you just want to improve your password policy. Absolutely, the two solutions that we just looked at, they're amazing. But what impact is that going to have on our service desk? Do we need to self-service password reset solution?
We looked at all the scattered spider attacks earlier, or we saw all the scattered spider attacks earlier this year with big impacts on the likes of Marks & Spencer in the UK and then wider across the world when we saw some copycat attacks. So we have a secure service desk product that allows your service desk to verify users at the other end of the phone. And of course, passwords are great, but it's even better to have a second layer.
So yes, SpecOps Secure Access, especially with our SpecOps ID mobile app, provide an amazing second factor that leverages biometrics on your mobile device, as well as a strong password factor. So yeah, lots and lots of nice solutions. And the SpecOps solution portfolio is not limited to only these two because I recently worked on your solution, as you know, and we will release our executive view either today or tomorrow, I don't know, but very soon.
And then for those of you who are interested in the SpecOps product portfolio, you can go and read that executive view and then you will see the coverage of SpecOps, that it's not only limited to auditing and then the policy enforcement of your passwords, but also it's going beyond there. But before I discuss the questions from our audience, I would like to have my last poll question very quickly. Where do you see the biggest need for improvement in your password security today? Stronger authentication, better visibility and reporting, improved user experience or other?
Please indicate if you're selecting other and then if time allows, I will share the poll results as well. So here, I think we have some time left for our Q&A session and maybe we can begin with the first question there and if that's all right for you.
Yeah, it looks like Alfred has been very engaged. So Alfred says, in remote working scenarios, we were advised to set never expire on passwords to reduce reset calls.
Yeah, I can believe that. What's your advice in this scenario?
So yes, as I was saying earlier, never expire is really important and it does bring you in line with what NIST and NCSC and all of the other regulatory bodies are changing their advice to. But there is a caveat. You need to have continuous scanning enabled because if you don't have that, then that amazing password or passphrase that you set many, many moons ago could become breached and then could become a risk.
Now, with regards to remote working scenarios, you then have the problems of things like cache credentials. So if you've sent all your users home in COVID, for instance, they're sat at home, they're working from home, they're logging into Microsoft 365 or Google Suite and they're doing their work, then their password expires, then you've got a problem, right? So how do you deal with that? How do they update their password that is then synced to Entra or synced to Google?
Well, in that case, you need to have a self-service system that not only updates the password in Active Directory, but also then gets immediately synced to all of those other cloud-based services, but most importantly, can write back to your locally cached credential on your laptop. Now, some organizations are very lucky and they have always-on VPN solutions, but many don't. And that is a big sticking point, again, for lots and lots of solutions that you see out there, self-service reset solutions.
They go, great, yeah, you can update it in Active Directory, but it doesn't help you very much because your locally cached password on your remote user's laptop still doesn't know anything about the update. So you have to drag your laptop into the office, dock it, log in, and then go back home again, which doesn't really help anybody. So U-Reset, a self-service password reset solution, has the ability to update the cached credential on your Windows device without you having an always-on VPN.
It's an amazing solution that certainly helps lots and lots of our customers throughout the COVID period. So that's my advice, Alfred. Make sure you've got a great self-service password reset solution that can actually support your remote workers. Don't just buy a self-service and keep your fingers crossed. All right. I think that was a very detailed answer, but I think that Alfred has one more question. Do I need to worry about breach passwords if I have MFA enabled? This is a very interesting question.
Yeah, it is. So my answer to that, I often get asked this question as well. MFA is really important. You need to have it switched on. There's no doubt about that. But you need to think to yourself, where is MFA enabled? Lots of organizations use cloud-based services, and if you've got cloud-based MFA, that's amazing. Well done. Awesome. But what about those legacy apps, those really critical line-of-business apps that have lived for years and years and years, rely on your Active Directory password, and there is no way you can replace them with a cloud app immediately?
Or all of those other scenarios where someone loses their phone, so they don't have MFA anymore. How do they reset their MFA to set up on the new device? What's the fallback? And often the fallback is a password.
So sadly, again, although the passwords might be hidden behind Windows Hello for Business or MFA or passwordless solution, the password is only hidden. It's not gone. And sometimes it's still needed. And that could be the hole in your armor that someone wants to exploit. So passwords are still important. You still need to make sure you haven't got breached ones.
Yeah, I think that the MFA is a helpful mechanism. It actually decreases the chances of getting hijacked. But attackers are still using the methods like credential stuffing or they hijack your sessions. And I think that they could still utilize techniques that could bypass the MFAs. And then AI could be behind this still. So the compromised passwords still, for me, remain a major risk. So regardless, maybe MFA enabled like this.
Well, I mean, you bring up another really good point there with session hijack and cookie theft and all of those sorts of things. So you might be very interested to hear that, well, if you check out SpecOps announcements today, you might see that we've recently announced a new acquisition, which can help our customers out with cookie theft and device pinning and device posture. So I can't talk to them too more because I don't know how public it is yet.
But yeah, it seems to be resolved as well. Perfect. Any final words? I think that we are right on time. Maybe you can share your final thoughts and then we can try to wrap up from here.
Well, like I say, for me, make sure that you have a great password policy in place. Sadly, the tools that you've shipped with Entra and Active Directory aren't up to scratch and they unlikely never will be. It's not a focus really for Microsoft. But if you're interested in learning more, our door is always open. You can speak to me directly as a senior product manager.
But also, we've got some great technicians that have worked through lots and lots of industries throughout the world, two and a half thousand customers at the moment and counting. So always feel free to get in touch and we'd be happy to talk through your own individual scenario as well. Perfect. And for me, my last words will be, if there's one takeaway for me, I think that will be, sorry, the passwords are still at the center of the emerging attacks, the modern attacks, I would say. And strengthening the password policies and also using the right tools doesn't have to hurt the user experience.
I think that when I look at the regulations, they are also following this pattern because most of the time, the users are so reluctant to manage their passwords properly due to the hassle they are going through. So the tools should help with the user experience as well. So I think that will be my take. And we are happy to discuss any other questions or if you have any questions related to the next steps with Darren, please feel free to ask us, reach out to us after this session.
Yeah, I think with that, thank you again. And thank you again for spending our time today. And I'll see you in our next webinar. Cheers.
Thanks, everyone.
See All Locations
See All Locations