{"id":787,"date":"2016-02-02T02:30:04","date_gmt":"2016-02-02T06:30:04","guid":{"rendered":"https:\/\/solutionsreview.com\/identity-management\/?p=787"},"modified":"2016-02-02T15:39:11","modified_gmt":"2016-02-02T19:39:11","slug":"forrester-passwords-are-here-to-stay-heres-how-to-deal-with-it","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/identity-management\/forrester-passwords-are-here-to-stay-heres-how-to-deal-with-it\/","title":{"rendered":"Forrester: Passwords are Here to Stay, Here&#8217;s How to Deal With It"},"content":{"rendered":"<p style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/identity-management\/benchmark-your-employee-password-policies-and-practices\/\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-793 size-full\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/11\/Deal-with-it.jpg\" alt=\"\" width=\"385\" height=\"206\" srcset=\"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/11\/Deal-with-it.jpg 385w, https:\/\/solutionsreview.com\/identity-management\/files\/2015\/11\/Deal-with-it-300x161.jpg 300w, https:\/\/solutionsreview.com\/identity-management\/files\/2015\/11\/Deal-with-it-151x81.jpg 151w, https:\/\/solutionsreview.com\/identity-management\/files\/2015\/11\/Deal-with-it-336x180.jpg 336w\" sizes=\"(max-width: 385px) 100vw, 385px\" \/><\/a>Passwords, with all of their issues and rumored replacements, are here to stay\u2014at least for the time being\u2014according to a new research report from Forrester.<\/p>\n<p style=\"text-align: justify\">In 2015, passwords remain \u201cthe most common form of user authentication for apps and systems,\u201d according to the Cambridge, MA-based tech research and analysis firm. The truth is that until we can find an adequate replacement for the ubiquitous username-password combination, Security and Risk (S&amp;R) professionals have no choice to coexist with passwords while their organizations assess alternatives.<\/p>\n<p style=\"text-align: justify\">But that doesn\u2019t mean we have to take the lost productivity and frustration commonly associated with lost or reset passwords lying down, according to Forrester\u2019s <a href=\"https:\/\/solutionsreview.com\/identity-management\/benchmark-your-employee-password-policies-and-practices\/\" target=\"_blank\">new report<\/a>, <em>Benchmark Your Employee Password Policies and Practices<\/em>.<\/p>\n<p style=\"text-align: justify\">The report, based on a survey conducted by Forrester in 2015 to identify firms&#8217; &#8220;current password policies, usage, and challenges,&#8221; offers guidance and recommendations on password management that S&amp;R pros can use to manage the costs and risk associated with managing employee and customer identity. So what exactly did Forrester find in their survey of 70+ large organizations? Here a few key takeaways from the 18-page report (available <a href=\"https:\/\/solutionsreview.com\/identity-management\/benchmark-your-employee-password-policies-and-practices\/\" target=\"_blank\">here<\/a>)\u00a0you can use to benchmark your own password and identity management policies:<\/p>\n<p style=\"text-align: justify\"><strong>Password structures and Policies are Becoming Standardized<\/strong><\/p>\n<p style=\"text-align: justify\">As noted above, though the &#8220;kill the password&#8221; warcry is growing louder, passwords remain &#8220;a necessary evil,&#8221; as <a href=\"https:\/\/solutionsreview.com\/identity-management\/benchmark-your-employee-password-policies-and-practices\/\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-791 size-full\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/11\/Forrester_Ping_Figure1.jpg\" alt=\"Forrester_Ping_Figure1\" width=\"443\" height=\"281\" srcset=\"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/11\/Forrester_Ping_Figure1.jpg 443w, https:\/\/solutionsreview.com\/identity-management\/files\/2015\/11\/Forrester_Ping_Figure1-300x190.jpg 300w, https:\/\/solutionsreview.com\/identity-management\/files\/2015\/11\/Forrester_Ping_Figure1-426x270.jpg 426w, https:\/\/solutionsreview.com\/identity-management\/files\/2015\/11\/Forrester_Ping_Figure1-128x81.jpg 128w, https:\/\/solutionsreview.com\/identity-management\/files\/2015\/11\/Forrester_Ping_Figure1-284x180.jpg 284w\" sizes=\"(max-width: 443px) 100vw, 443px\" \/><\/a>Forrester puts it. But that doesn&#8217;t mean they need to be a messy ordeal. One of the primary findings revealed in Forrester&#8217;s survey data is that\u00a0a sizeable majority of firms have adopted consistent, organization-wide password policies based on password length, number of characters, and frequency of change.<\/p>\n<p style=\"text-align: justify\">According to Forrester&#8217;s research, 77% of firms require quarterly passwords changes for employees, and 81% of firms store employee password histories to prevent passwords from being reused, a recommended best practice.<\/p>\n<p style=\"text-align: justify\">Forrester recommends that security teams not following these protocols, and other best practices listed in <a href=\"https:\/\/solutionsreview.com\/identity-management\/benchmark-your-employee-password-policies-and-practices\/\" target=\"_blank\">the report<\/a> revisit thier current policy and consider strengthening it, especially for high-risk and privileged users.<\/p>\n<p style=\"text-align: justify\"><strong>Password Troubles Continue to Cost Organizations Productivity<\/strong><\/p>\n<p style=\"text-align: justify\">Despite the growing number of organizations following best practices and protocol for password monitoring and management, many organizations are still dealing with the headaches, lost productivity, and financial cost associated with forgotten, reset, or locked passwords. Forrester&#8217;s survey data shows that \u00a0the cost and frequency of passwords issues are not decreasing,<\/p>\n<p style=\"text-align: justify\">As an example, Forrester examines a large US-based public university, with over 300,000 total users (including students, faculty, and administrators). Forrester found that in 2014, that university&#8217;s users completed an average of nearly 8,000 password resets per month\u00a0and that nearly 50% of users requesting a password reset could not complete that action via self-service. That meant the IT help desk had to field an average of 890 calls per month just to reset passwords\u2014 that&#8217;s a lot of productivity lost waiting for IT to provision or change user access. To combat this loss, Forrester recommends several best practices, including the use of automatically provisioning Identity and Access Management (IAM) solutions.<\/p>\n<p style=\"text-align: justify\"><strong>Cloud Security Concerns are Not Influencing Security Policy as Much as We Thought<\/strong><\/p>\n<p style=\"text-align: justify\">Even as enterprise adoption of public cloud services hits\u00a0<a href=\"https:\/\/solutionsreview.com\/cloud-platforms\/the-international-state-of-the-cloud-in-2015\/\" target=\"_blank\">record numbers<\/a>, security concerns often remain <a href=\"https:\/\/solutionsreview.com\/cloud-platforms\/enterprise-adoption-of-office-365-saas-is-high-but-security-concerns-linger\/\" target=\"_blank\">the<\/a> <a href=\"https:\/\/solutionsreview.com\/cloud-platforms\/how-secure-is-your-iaas-compare-the-top-5-csps-security\/\" target=\"_blank\">most<\/a>\u00a0<a href=\"https:\/\/solutionsreview.com\/cloud-platforms\/3-best-practices-for-evaluating-cloud-security\/\" target=\"_blank\">common<\/a> excuse for avoiding the use of public cloud services, but Forresters research shows that, while CISOs may have no trouble voicing their concerns over cloud security, they aren&#8217;t exactly acting on them.<\/p>\n<p style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/identity-management\/benchmark-your-employee-password-policies-and-practices\/\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-792 size-full aligncenter\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/11\/Forrester_Ping_Figure2.jpg\" alt=\"Forrester_Ping_Figure2\" width=\"548\" height=\"253\" srcset=\"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/11\/Forrester_Ping_Figure2.jpg 548w, https:\/\/solutionsreview.com\/identity-management\/files\/2015\/11\/Forrester_Ping_Figure2-300x139.jpg 300w, https:\/\/solutionsreview.com\/identity-management\/files\/2015\/11\/Forrester_Ping_Figure2-175x81.jpg 175w, https:\/\/solutionsreview.com\/identity-management\/files\/2015\/11\/Forrester_Ping_Figure2-390x180.jpg 390w\" sizes=\"(max-width: 548px) 100vw, 548px\" \/><\/a><\/p>\n<p style=\"text-align: justify\">S&amp;R pros understand the cloud security risks, says Forrester, but they aren&#8217;t strengthening password requirements for SaaS and other cloud apps. According to the report, the majority of firms surveyed apply the same old password policies and protections they use for on-premise apps to cloud apps. This may be done to create a consistent and easy employee experience, but using the same policy for both on-prem and cloud apps can greatly increase risk, warns Forrester.<\/p>\n<p style=\"text-align: justify\">Interested parties can download Forrester&#8217;s report in full. Inside, you&#8217;ll get a full breakdown of these issues, as well as best practices for resolving them, and Forrester&#8217;s take on:<\/p>\n<ul style=\"text-align: justify\">\n<li>The State Of Employee Passwords: Trends Good, Bad and Ugly<\/li>\n<li>How IAM Can Help Ease the Password Burden<\/li>\n<li>How to Tackle Password Challenges and Plan For The Future<\/li>\n<\/ul>\n<p style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/identity-management\/benchmark-your-employee-password-policies-and-practices\/\" target=\"_blank\">Get the full report.<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Passwords, with all of their issues and rumored replacements, are here to stay\u2014at least for the time being\u2014according to a new research report from Forrester. In 2015, passwords remain \u201cthe most common form of user authentication for apps and systems,\u201d according to the Cambridge, MA-based tech research and analysis firm. The truth is that until [&hellip;]<\/p>\n","protected":false},"author":24,"featured_media":793,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5,1,185],"tags":[125,152,91,63,127],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Forrester: Passwords are Here to Stay, Here&#039;s How to Deal With It<\/title>\n<meta name=\"description\" content=\"Passwords are here to stay\u2014for the time being at least. Forrester breaks down the best practices driving todays password policies.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/identity-management\/forrester-passwords-are-here-to-stay-heres-how-to-deal-with-it\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jeff Edwards\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/forrester-passwords-are-here-to-stay-heres-how-to-deal-with-it\/\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/forrester-passwords-are-here-to-stay-heres-how-to-deal-with-it\/\",\"name\":\"Forrester: Passwords are Here to Stay, Here's How to Deal With It\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/forrester-passwords-are-here-to-stay-heres-how-to-deal-with-it\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/forrester-passwords-are-here-to-stay-heres-how-to-deal-with-it\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/11\/Deal-with-it.jpg\",\"datePublished\":\"2016-02-02T06:30:04+00:00\",\"dateModified\":\"2016-02-02T19:39:11+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6\"},\"description\":\"Passwords are here to stay\u2014for the time being at least. Forrester breaks down the best practices driving todays password policies.\",\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/forrester-passwords-are-here-to-stay-heres-how-to-deal-with-it\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/identity-management\/forrester-passwords-are-here-to-stay-heres-how-to-deal-with-it\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/forrester-passwords-are-here-to-stay-heres-how-to-deal-with-it\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/11\/Deal-with-it.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/11\/Deal-with-it.jpg\",\"width\":385,\"height\":206},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/forrester-passwords-are-here-to-stay-heres-how-to-deal-with-it\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/identity-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Forrester: Passwords are Here to Stay, Here&#8217;s How to Deal With It\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/\",\"name\":\"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services\",\"description\":\"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6\",\"name\":\"Jeff Edwards\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g\",\"caption\":\"Jeff Edwards\"},\"description\":\"Jeff Edwards is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in Journalism from the University of Massachusetts Amherst, and previously worked as a reporter covering Boston City Hall.\",\"sameAs\":[\"https:\/\/solutionsreview.com\",\"https:\/\/x.com\/InfoSec_Review\"],\"url\":\"https:\/\/solutionsreview.com\/identity-management\/author\/jedwards\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Forrester: Passwords are Here to Stay, Here's How to Deal With It","description":"Passwords are here to stay\u2014for the time being at least. Forrester breaks down the best practices driving todays password policies.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/identity-management\/forrester-passwords-are-here-to-stay-heres-how-to-deal-with-it\/","twitter_misc":{"Written by":"Jeff Edwards","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/identity-management\/forrester-passwords-are-here-to-stay-heres-how-to-deal-with-it\/","url":"https:\/\/solutionsreview.com\/identity-management\/forrester-passwords-are-here-to-stay-heres-how-to-deal-with-it\/","name":"Forrester: Passwords are Here to Stay, Here's How to Deal With It","isPartOf":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/identity-management\/forrester-passwords-are-here-to-stay-heres-how-to-deal-with-it\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/identity-management\/forrester-passwords-are-here-to-stay-heres-how-to-deal-with-it\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/11\/Deal-with-it.jpg","datePublished":"2016-02-02T06:30:04+00:00","dateModified":"2016-02-02T19:39:11+00:00","author":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6"},"description":"Passwords are here to stay\u2014for the time being at least. Forrester breaks down the best practices driving todays password policies.","breadcrumb":{"@id":"https:\/\/solutionsreview.com\/identity-management\/forrester-passwords-are-here-to-stay-heres-how-to-deal-with-it\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/identity-management\/forrester-passwords-are-here-to-stay-heres-how-to-deal-with-it\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/forrester-passwords-are-here-to-stay-heres-how-to-deal-with-it\/#primaryimage","url":"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/11\/Deal-with-it.jpg","contentUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/11\/Deal-with-it.jpg","width":385,"height":206},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/identity-management\/forrester-passwords-are-here-to-stay-heres-how-to-deal-with-it\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/identity-management\/"},{"@type":"ListItem","position":2,"name":"Forrester: Passwords are Here to Stay, Here&#8217;s How to Deal With It"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/identity-management\/#website","url":"https:\/\/solutionsreview.com\/identity-management\/","name":"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services","description":"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6","name":"Jeff Edwards","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g","caption":"Jeff Edwards"},"description":"Jeff Edwards is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in Journalism from the University of Massachusetts Amherst, and previously worked as a reporter covering Boston City Hall.","sameAs":["https:\/\/solutionsreview.com","https:\/\/x.com\/InfoSec_Review"],"url":"https:\/\/solutionsreview.com\/identity-management\/author\/jedwards\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/787"}],"collection":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/users\/24"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/comments?post=787"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/787\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media\/793"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media?parent=787"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/categories?post=787"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/tags?post=787"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}