Weak Passwords Are No Longer Just an IT Problem

By Chardé Janse van Vuuren
Image

Passwords are often treated as a small operational inconvenience. Something for IT to manage, users to remember and helpdesks to reset. But in many organisations, weak password hygiene is no longer just a technical problem. It has become a business-control weakness.

This matters because a password is rarely just a password. It is often the first layer of access to finance systems, payroll platforms, customer relationship management tools, supplier information, cloud environments, email accounts and sensitive business records. When that access is poorly managed, the risk can extend far beyond one compromised login.

For many SMEs and mid-market organisations, this risk is especially relevant. These businesses are digitising quickly. They use cloud platforms, remote working tools, shared drives, collaboration apps, finance systems and customer databases. But their access controls, user reviews and authentication processes do not always mature at the same pace.

This creates a gap between digital adoption and cyber governance.

In practice, password weaknesses often appear in very ordinary ways. Employees reuse passwords across systems. Teams share generic logins. Old user accounts remain active after people leave. Password reset processes are not properly controlled. Access rights are not reviewed regularly. Legacy systems do not support modern authentication. And in many cases, businesses still believe they are too small to be targeted.

That assumption is dangerous.

Cybercriminals do not only target large organisations with sophisticated attacks. They also look for easy access points. A small business with weak controls, reused passwords and limited monitoring may be an attractive target because it is easier to compromise. The organisation may also form part of a broader supply chain, creating risk for clients, suppliers and partners.

Recent data shows why this issue deserves attention. Kaspersky reported that password-stealer attacks in South Africa grew by 116% in 2025 compared with the previous year, while Microsoft’s 2025 Digital Defense Report found that 97% of identity attacks were password spray attacks. In June 2026, Have I Been Pwned added a stealer-logs dataset comprising 56 million unique email addresses and 124 million unique passwords to its searchable breach database, while MyBroadband reported that South Africans were warned after a 24-billion-record credential exposure involving usernames, emails, plaintext passwords and login URLs.

The lesson is clear: credentials remain valuable, and attackers continue to exploit weak, reused or exposed passwords.

However, the answer is not simply to make passwords longer, force constant resets or overwhelm employees with security prompts. This can create another problem: cybersecurity fatigue.

When users are bombarded with password changes, repeated multi-factor authentication prompts, awareness messages and warnings without proper context, security starts to feel like noise. Employees may approve prompts without checking them properly, delay updates, reuse easier passwords or find shortcuts simply to get through their day.

That does not mean users do not care. It often means the organisation has made secure behaviour too difficult, too repetitive or too disruptive.

This is where the conversation needs to shift. Password hygiene should not be viewed only as an IT policy. It should be treated as part of business risk management and internal control.

From a business perspective, the key questions are practical. Who has access to critical systems? Is that access appropriate for their role? Are accounts removed when people leave or change positions? Are shared accounts being used? Are high-risk users protected with stronger authentication? Are password reset and recovery processes properly controlled? Are legacy systems creating avoidable exposure?

Two-factor authentication remains one of the most effective controls available, but it must be implemented properly. If a password is stolen or guessed, an additional authentication factor can prevent unauthorised access. Yet not all forms of multi-factor authentication provide the same level of protection. SMS-based one-time pins can be vulnerable to SIM-swopping and social engineering, while excessive push notifications can lead users to approve requests without thinking.

A strong MFA process can also be undermined by weak recovery controls. If an attacker can bypass authentication through a poorly managed password reset or unsecured recovery email account, the business may still be exposed.

Passkeys are an important step forward. They reduce reliance on traditional passwords and are designed to be more resistant to phishing, credential theft and password reuse. The FIDO Alliance estimates that 5 billion passkeys are now in active use globally, with 68% of organisations deploying, piloting or rolling them out for employee authentication.

But passkeys are not a complete solution on their own.

Many SMEs and mid-market organisations still rely on legacy systems that do not support modern authentication. Businesses also need to manage practical issues such as users changing devices, losing access, working across personal and company-owned devices, and ensuring recovery processes do not become the next weak point.

Even in a passwordless environment, governance still matters. Businesses still need role-based access, regular user access reviews, proper offboarding, controlled recovery processes, incident response planning and user awareness.

The real goal is not password perfection. It is control.

For SMEs and mid-market organisations, the starting point does not have to be complex. Identify critical systems. Remove shared accounts where possible. Enforce unique passwords and use password managers. Apply stronger authentication to finance, payroll, email, administrator and cloud accounts. Review user access regularly. Disable dormant accounts. Strengthen recovery processes. Train users to recognise suspicious authentication activity. And where legacy systems create risk, build a practical roadmap to modernise them.

Password hygiene becomes a business risk when weak access controls are allowed to sit unnoticed inside everyday operations.

The organisations that manage this well will not be the ones that add the most friction. They will be the ones that understand where the real risks sit, apply stronger controls where they matter most, and make secure behaviour realistic for the people who use the systems every day.




Image

Sign up for HLB insights newsletters