Cyber Security

IT Security Chief Spends Fifth Consecutive Hour Explaining Why ‘Password123!’ Isn’t Actually Fine

Martin Fletcher has been sitting in Meeting Room 3B since half past nine this morning, attempting to convey to the accounts payable team that their current approach to password security might charitably be described as a catastrophic liability, though he has begun using gentler terms as the day has worn on.

The Director of IT Security at Hargreaves Industrial Solutions spent the first ninety minutes working through a presentation titled ‘Basic Password Hygiene: A Gentle Reminder’. He is now, according to colleagues who passed the room at lunchtime, simply sitting with his head in his hands whilst Janet Moorhouse from Purchasing explains why she needs to keep her password as ‘Fluffy2019’ because that was the year she got her rabbit and she has already memorised it.

Fletcher, who holds a master’s degree in cybersecurity and once advised the Home Office on ransomware protocols, has reportedly tried seventeen different approaches to explaining the concept of password complexity. These have included metaphors involving house locks, bank vaults, and at one point a somewhat strained comparison to leaving your car unlocked in Moss Side with the keys on the dashboard and a sign saying ‘please steal this’.

“I showed them the list of the world’s most commonly used passwords. I explained that ‘qwerty’ appears on literally every hacker’s dictionary. David from Finance asked if ‘qwerty123’ would be better because it has numbers in it.”

The meeting, originally scheduled for thirty minutes, entered its fifth hour shortly after Fletcher attempted to introduce the topic of multi-factor authentication. This prompted Steven Walsh, a procurement officer with eighteen years at the company, to ask whether that was ‘the thing where you get a text’ and if so, whether it was really necessary because his phone is quite old and sometimes takes a while to receive messages.

Sources within the building report that Fletcher has now moved past the anger stage and into what witnesses describe as a sort of hollow acceptance. He was last seen drawing a diagram on the whiteboard that appeared to illustrate the various entry points a malicious actor might exploit, whilst Sharon Bennett nodded politely and asked whether this would take much longer because she had a parcel being delivered at four.

“We had mandatory security training last month. Multiple choice, online, twenty minutes. Apparently one hundred per cent of people passed it. I’ve just watched a man write his password on a Post-it note and stick it to his monitor whilst maintaining eye contact with me.”

The session eventually concluded at twenty past three when Fletcher agreed to a compromise position whereby staff would add a single capital letter and an exclamation mark to their existing passwords. He was seen returning to his office carrying a box of compliance documentation and the remainder of a meal deal he had not had time to eat.

The company’s last security audit, completed in January, recommended immediate action on password policy. Fletcher has scheduled follow-up sessions for next month, though he has reportedly already started updating his CV.

Leave a comment

Your email address will not be published. Required fields are marked *