Skip links

Insight Article: Password Spraying


The Shift Towards Passwordless Authentication

Much of the cyber security conversation today focuses on the future of identity. Passwordless authentication, biometrics, phishing-resistant MFA and Zero Trust architectures are all becoming increasingly common in security strategies and technology roadmaps. The direction of travel is clear and the role of the traditional password is gradually reducing. However, there is a difference between where organisations want to be and where they are today.

Many businesses, including those in the hospitality sector, still rely heavily on passwords across legacy applications, third-party platforms, service accounts and everyday user access. While the long-term objective may be passwordless authentication, passwords remain deeply embedded in most environments. As a result, attackers continue to target one of the oldest and most familiar weaknesses in cyber security: poor password security.


Why Password Spraying Remains Effective

One of the most common examples is password spraying.

Unlike traditional attacks that repeatedly target a single account, password spraying involves attempting a small number of commonly used passwords across many accounts. By spreading login attempts across multiple users, attackers can often avoid account lockout thresholds while increasing their chances of finding valid credentials.

The technique itself is relatively straightforward. What is more concerning is that it remains effective despite years of investment in security technologies, identity platforms and user awareness programmes. Password spraying succeeds because it exploits a reality that many organisations still face today: passwords are rarely as strong, unique or well-managed as security policies assume.


The Gap Between Strategy and Reality

Password spraying highlights a broader challenge for organisations. Cyber security strategies often focus on reducing risk in the future, but attackers exploit the risks that exist today. While discussions around passwordless authentication are important, many businesses still need practical ways to protect environments where passwords remain unavoidable.

The question therefore isn’t simply whether an organisation plans to become passwordless. It’s whether it has adequately managed password-related risk in the meantime.


What Organisations Should Be Focusing On Today

Strong password policies, multi-factor authentication, monitoring for unusual login activity and controls that prevent the use of weak or compromised passwords are not particularly new concepts. However, they remain some of the most effective ways to reduce the likelihood of a successful identity-based attack.

As identity remains central to modern cyber security, organisations should view password security as an operational priority today rather than a problem that will eventually disappear tomorrow.


A Useful Reminder

The cyber security industry understandably spends a lot of time discussing emerging threats. However, attacks such as password spraying serve as a reminder that some of the most common attack techniques continue to rely on weaknesses that have existed for years.

For organisations still relying on passwords across parts of their environment, reducing the risk can start with a few practical steps:

  • Enforcing strong password policies
  • Blocking commonly used and compromised passwords
  • Enabling multi-factor authentication
  • Monitoring for unusual authentication activity
  • Regularly reviewing dormant or unused accounts.

While many organisations are working towards passwordless authentication, passwords remain a key part of most environments today. Managing password-related risk therefore remains an important part of any cyber security strategy. Sometimes the most important cyber security question is not what’s coming next. It’s whether we’ve properly addressed the risks we already know about.