Devices can no longer be supplied with easily guessed, universal passwords such as “admin”, “password” or “12345”. Manufacturers must also provide a way for security vulnerabilities to be reported and publish information about how long their products will receive security updates.
These measures address a problem that should never have been allowed to become normal: internet-connected technology being shipped with credentials that are widely known, easily discovered or identical across thousands of devices.
But the new rules also raise an uncomfortable question for businesses.
If manufacturers are now legally prohibited from supplying new connected devices with basic default passwords, how can an organisation justify continuing to operate existing systems using exactly the same insecure practices?
Regulation Is Raising the Baseline
The Product Security and Telecommunications Infrastructure regime represents an important shift in accountability.
Historically, responsibility for securing a device was often pushed towards the customer. A manufacturer might ship a product with a standard administrator account and assume that the user would change it during installation.
In reality, many default passwords were never changed. Some devices were difficult to configure, some were installed without proper technical oversight, and others simply remained forgotten on corporate networks for years.
The new regulations begin to address that problem at source. Manufacturers must ensure that passwords are either unique to each product or capable of being defined by the user.
That is positive progress. However, the legislation primarily concerns the security of consumer-connectable products being placed on the UK market. It does not automatically remediate the equipment, applications and accounts already operating inside businesses.
That remains the organisation’s responsibility.
The Legacy Password Problem
Most businesses have accumulated technology over many years.
Network devices, printers, CCTV systems, building-management platforms, backup appliances, cloud services, databases, websites and line-of-business applications may all have been introduced at different times by different teams and suppliers.
Some will be actively managed. Others may still be operating with:
- Factory-default administrator credentials
- Simple passwords shared between employees
- The same password reused across multiple systems
- Credentials stored in spreadsheets, documents or email
- Accounts belonging to former employees or suppliers
- Passwords known by several people but owned by nobody
- Service accounts that have not been reviewed for years
These practices are not merely untidy administration. They create direct routes into an organisation.
A compromised password can give an attacker an initial foothold. Password reuse can then allow one compromised credential to unlock several systems. Shared accounts reduce accountability because activity cannot be reliably attributed to an individual. Forgotten privileged accounts can provide extensive access without attracting attention.
The introduction of minimum product-security requirements makes these weaknesses harder to excuse. The direction of travel is clear: predictable, shared and unmanaged credentials are no longer compatible with a credible cybersecurity strategy.
“Change the Default Password” Is Not a Complete Strategy
Replacing “admin” with a slightly less obvious password is an improvement, but it is not effective password management.
Businesses need to know:
- What systems and accounts exist
- Who owns each account
- Which accounts have privileged access
- Where credentials are stored
- Whether passwords are unique
- Whether former staff and suppliers retain access
- How credentials are transferred when responsibilities change
- How access will be recovered during an emergency
- Whether suspicious access can be detected and investigated
Without that governance, password security depends on individual memory and goodwill.
People are also expected to manage an increasing number of accounts. When organisations provide no practical alternative, employees will naturally create workarounds: reusing passwords, selecting memorable credentials, saving them in unsecured documents or sharing them over messaging platforms.
The National Cyber Security Centre recognises this operational reality. Its guidance states that password managers can help employees use unique, harder-to-guess passwords while reducing their reliance on insecure workarounds. It also stresses that usability matters: a solution that employees find difficult will be bypassed, undermining both the investment and the security outcome.
Password Management Must Become a Business Capability
An effective business password-management solution provides more than an encrypted place to save credentials.
Implemented correctly, it can provide:
- Secure generation and storage of unique passwords
- Controlled sharing without revealing the underlying credential
- Separate personal and organisational vaults
- Central administration and policy enforcement
- Access removal when an employee leaves
- Audit records showing who accessed shared credentials
- Alerts relating to weak, reused or compromised passwords
- Emergency and recovery access
- Protection for privileged and service accounts
However, buying a password manager is the easy part.
The real work is identifying which credentials should be migrated, establishing ownership, agreeing policies, integrating the platform with existing identity services, defining joiner and leaver processes, training employees and dealing with exceptions.
Poorly implemented security technology simply creates another system that employees avoid.
The objective should not be to deploy a password-management product. It should be to establish a sustainable, controlled and measurable approach to credential security.
Passwords Should Be Part of a Wider Identity Strategy
Password management is important, but passwords should not carry the full weight of an organisation’s security.
Where systems support it, businesses should also introduce:
- Multi-factor authentication
- Single sign-on
- Role-based access controls
- Conditional-access policies
- Privileged-access management
- Device-compliance controls
- Passkeys and phishing-resistant authentication
- Monitoring for suspicious sign-in activity
- Regular access reviews
The NCSC advises organisations to implement multi-factor authentication for online services to reduce the risk of password guessing and theft. For access to sensitive data, it recommends mandating strong MFA for every user.
The right approach depends on the organisation, its systems and the sensitivity of the information involved. A legacy application may not support modern authentication. A third-party supplier may still require a shared credential. Operational equipment may be difficult to update without disrupting the business.
Those constraints do not make the risk disappear. They make it necessary to understand the exposure, introduce compensating controls and create a realistic remediation roadmap.
How {n}.bora Can Help
At {n}.bora, we help organisations move from informal password practices to a properly governed identity and access-management capability.
Our cybersecurity and technology services can help you:
- Discover legacy devices, applications and administrative accounts
- Identify unchanged default, shared and weak credentials
- Assess privileged access and account ownership
- Select and implement an appropriate business password manager
- Introduce multi-factor authentication and single sign-on
- Strengthen joiner, mover and leaver processes
- Secure cloud platforms, endpoints and network infrastructure
- Modernise legacy systems that cannot support current security controls
- Establish policies, operating procedures and audit evidence
- Train employees so that secure practices become part of everyday work
- Provide ongoing management, monitoring and technical support
We combine security expertise with practical implementation and change management. That matters because cybersecurity improvements only create value when they work within the reality of the business and are consistently adopted by its people.
The Technology Industry Is Removing the Excuses
The ban on weak default passwords is a welcome step towards making connected products secure by design.
Businesses should apply the same principle internally.
If an organisation still relies on “admin”, “password123”, shared spreadsheets or credentials known only by a former supplier, the problem is no longer a lack of awareness. It is an unmanaged business risk.
Are you confident that every device, application and privileged account in your organisation is properly secured?
Speak to {n}.bora about a cybersecurity and password-management review. We will help you identify your exposure, prioritise the risks and implement security controls that protect the business without creating unnecessary barriers for your people.