Validate Your Defences

Can we crack your passwords?

You set the rules. We test if they hold.

It's 2026, and passwords are still your front line of defence. Despite the rise of password-less technologies and strong authentication alternatives, the reality is simple: most medium and large organisations still rely heavily on passwords.

The attackers know it.

A common response we hear is: "Our policy requires 15 characters or more, surely that's enough?" Fifteen is a reasonable floor, and it matters most on the accounts that can do the most damage. But a policy sets the requirement for new passwords, not for the ones already in use, and that is where the gap lives. What follows is what the measurement found, not what the policy says.

The hidden gaps in password policies

One of the most overlooked realities of password policies is when they take effect. Updating a policy does not instantly secure your organisation:

  • New requirements often apply only to a subset of users
  • Existing passwords remain valid until they expire or are forcefully changed
  • Accounts created before a policy change may never become compliant

The result? A large portion of your environment may be operating with legacy, weak or non-compliant passwords, completely unnoticed.

Weak passwords are still everywhere

Despite years of awareness campaigns, we continue to see patterns like:

  • Seasonal passwords, for example SummerSummer2026
  • Company names or brand terms
  • "Password-plus-number" variations
  • Passwords reused across multiple accounts

These are exactly the patterns attackers exploit, and the exploits remain alarmingly effective.

Real security requires real testing

At PB Security, we don't guess. We test.

We operate purpose-built, customised password-cracking hardware designed for speed. This allows organisations to analyse password resilience under realistic conditions, not theoretical assumptions. The goal isn't to embarrass users. It's to give leadership clear, defensible insight into risk.

What one engagement looked like

These are the headline figures from a recent analysis. The organisation is not named, and the point of the numbers is not that this environment was unusual. It wasn't.

Measure Result
Passwords analysed 9,257
Passwords recovered 6,230
Share recovered 67.3%
Users sharing a password 10.6%
Weak passwords 21.5%
Found in a known data breach 18.9%

The five most common passwords were Company1234, Summer2025, qwert@12345, Start2015 and Password12345. The five weak words that appeared most often were Summer, Password, Start, Winter and admin.

The five issues we flagged most often were: found in a breach, company name or a variant of it, repeated or sequential characters, keyboard walks, and passwords containing the user's own name.

Note what is absent from that list. Nothing exotic, nothing that required a novel technique. Two thirds of an organisation's passwords came back on patterns that have been documented for twenty years.

What our password analysis delivers

A clear, actionable overview, including:

  • Non-compliant passwords, measured against your own policy
  • The most commonly used and shared passwords across the organisation
  • The percentage of passwords successfully cracked
  • Identification of weak passwords: dictionary-based terms, seasonal and predictable patterns, company-specific words, and passwords found in known breach datasets

The result enables informed decisions about policy enforcement, user awareness and authentication strategy, based on facts rather than assumptions.

Where weak passwords lead

The five actions we recommend most often after an analysis are, in order:

  • Force a change on the weak passwords
  • Increase password length in your policy, to 15 characters or more
  • Implement a banned password list
  • Prevent password reuse
  • Implement SSO and MFA wherever it is possible

Additional measures may be relevant. That is a question of assessing the risk, which is what the analysis is for. Our password guidance goes through what we recommend in more detail, including the numbers we suggest for regular users, admins and service accounts.

What to do with this

The numbers above came from one organisation, and they are ordinary. If your policy has changed in the last few years, the useful question is not what it requires today. It is how many accounts predate it, and nobody can answer that from the policy document.

You set the rules. We test if they hold.

← All articles

If you need help, we're here.

Tell us where you are, and we'll help you find the right first step.

Talk to us