By NHI Mgmt Group Editorial TeamBased on Netwrix: “The left back everyone underestimates” (June 29, 2026)

TL;DR: Weak, reused, and already-stolen passwords still let attackers in because many password policies only enforce basic complexity rules, according to Netwrix. Blocking weak credentials at creation time shifts control left, reducing a predictable entry path that reactive tools only see after compromise.


At a glance

What this is: This article argues that weak password policies leave a predictable credential stuffing path open, and that blocking poor passwords at creation time is more effective than reacting after compromise.

Why it matters: It matters because IAM teams still rely on policies that permit reused or leaked passwords, which means the first line of defence against account takeover is often still failing at issuance.


Context

Credential stuffing succeeds when attackers reuse valid usernames and password combinations that people have already chosen elsewhere or that have been exposed in prior breaches. The control gap is not exotic exploitation but predictable credential acceptance, especially when policy focuses on complexity rather than actual reuse and exposure risk.

For identity teams, the problem sits squarely in human IAM and access governance. If a password can still be created, reused, or kept after it appears in breach data, the environment remains open to low-cost, high-volume account takeover attempts across hybrid login paths.


Key questions

Q: What should security teams do first when default passwords are still present on privileged accounts and edge devices?

A: Security teams should identify every default credential, especially on internet-facing devices and administrative root accounts, then replace them with unique passwords and enforce banned-password controls. That first step reduces the easiest path attackers use to gain privileged access. From there, teams should add monitoring, rotation, and privileged access management so credentials are not static or broadly reusable.

Q: Why do password reuse and credential stuffing remain so effective?

A: They remain effective because many users still reuse passwords and many environments still accept credentials without enough contextual risk checks. Attackers can test stolen credentials at scale, often quietly enough to avoid detection. The more identities that share a secret pattern, the more one breach can become many account takeovers.

Q: What are the signs that a password policy is failing in practice?

A: Common warning signs include frequent help desk resets, users making only tiny changes to old passwords, repeated complaints about rejected passwords, and visible workarounds such as password reuse or note-taking. If employees routinely bypass controls to save time, the policy is creating friction without improving protection and should be redesigned around usability and actual risk.

Q: How should organisations govern password risk across hybrid workforces?

A: Start with the accounts that create the highest exposure, especially third parties and remote personnel, then enforce reuse checks, stronger authentication, and tighter reset controls. Password governance works when it is tied to risk, visibility, and user experience. If teams only publish policy, the weakest users will still work around it.


Technical breakdown

Why complexity-only password policy fails

Complexity rules measure shape, not risk. A password can satisfy length, symbol, and case requirements while still being trivially guessable, previously leaked, or recycled from another service. That is why credential stuffing remains effective: attackers are not cracking passwords, they are trying known-good combinations at scale. In modern identity environments, the decisive question is whether the policy blocks low-entropy, reused, and compromised credentials before they become valid authentication material.

Practical implication: move from complexity checks alone to password screening against known-bad and reused credentials at creation time.

Why reactive controls miss the earliest identity exposure

Endpoint and identity monitoring can detect suspicious activity after an account is already in play, but that is downstream of the real failure. Once a weak or leaked password is accepted, the account becomes a legitimate identity path that attackers can use without malware or privilege escalation. The security problem is therefore upstream: preventing the credential from being usable in the first place. That changes password governance from detection support to access control.

Practical implication: treat password rejection logic as a preventive identity control, not as a hygiene feature.

How weak passwords create repeatable account takeover risk

Credential stuffing depends on repetition. The attacker does not need a custom exploit when users keep choosing the same style of predictable passwords or reusing credentials that were exposed elsewhere. That creates a stable entry pattern across offices, homes, mobile devices, and cloud-connected systems because the weakness travels with the identity, not the network. The result is a consistent account takeover avenue that survives perimeter changes and device controls.

Practical implication: harden password acceptance rules across all authentication entry points, including hybrid and remote access paths.


Threat narrative

Attacker objective: The attacker aims to take over valid user accounts by reusing weak or stolen credentials, then use that access to enter the environment.

  1. Entry occurs when attackers test weak, reused, or leaked credentials against identity systems using credential stuffing.
  2. Credential access succeeds because the password is already valid, so no malware or exploit is needed to authenticate.
  3. Impact follows when the attacker gains legitimate access to user accounts and can operate inside the environment as the real user.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Weak-password acceptance is a governance failure, not a user-behaviour footnote. Complexity checks alone assume that users will choose unique, non-leaked passwords if rules are sufficiently strict. That assumption fails in practice because attackers target the gap between policy compliance and actual credential quality. The implication is that password governance has to be measured by what it blocks, not by how many rules it publishes.

Credential stuffing is a predictable access-path problem, not an advanced intrusion problem. If reused or compromised passwords remain valid, attackers can scale account takeover without malware, privilege escalation, or sophisticated tradecraft. That makes password screening part of the identity attack surface, not just an authentication convenience. Practitioners should treat every permitted weak password as an open route into the environment.

Identity security must shift left to credential issuance. Reactive tools can observe compromise, but they cannot make an already-usable password safe after the fact. The stronger control point is when the password is created or changed, because that is when weak, leaked, and commonly used values can still be rejected. For IAM programmes, the control question is whether the credential ever becomes usable.

Hybrid access expands the blast radius of weak password policy. Once a reused password works, it does not matter whether the user signs in from an office, a home network, or a cloud-connected device. The identity becomes the pivot, and the same weakness can be exercised repeatedly across the estate. Teams should therefore evaluate password policy as a cross-environment access control, not a local login setting.

What this signals

Credential stuffing is fundamentally an identity issuance problem. When password policy still permits reused or leaked values, the control failure happens before the attack ever reaches detection tooling. The practical shift is to treat password acceptance as a hard security gate, not a convenience check.

Weak password governance creates a reusable attack path across every access channel. Once the same credential works in the directory, it can be exercised through SSO, cloud apps, and remote login paths without changing the attack method. IAM teams should therefore review password controls as part of the broader access architecture, not in isolation.


For practitioners

  • Enforce password screening at creation time Reject weak, reused, leaked, and commonly used passwords before they become valid credentials in the directory or SSO layer.
  • Tune policies beyond complexity rules Replace policy language that only checks length and character variety with controls that block known-bad password patterns and exposed values.
  • Align password controls with credential stuffing risk Review where users authenticate and make sure the same password restrictions apply consistently across remote, hybrid, and cloud-connected entry points.
  • Reduce account takeover opportunity windows Use account monitoring and reset workflows to remove weak credentials quickly when exposure is detected, then validate that the original password cannot be reused.

Key takeaways

  • Weak password policy leaves a predictable account-takeover path open, and credential stuffing succeeds precisely because valid but poor credentials are still accepted.
  • The article’s core evidence is operational rather than statistical: users keep choosing weak or reused passwords, and reactive controls only see the problem after access is already granted.
  • Blocking weak credentials at the point of creation is the control that changes the outcome, because it prevents reusable passwords from entering the environment at all.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationWeak password acceptance directly enables insecure authentication and credential stuffing.
Recommendation — Block weak and reused passwords before they become valid authentication material.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementPassword policy and lifecycle controls sit inside authenticator management.
Recommendation — Apply IA-5 to reject weak credentials and govern password lifecycle consistently.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsPermitting weak credentials undermines access control at the authentication boundary.
Recommendation — Use PR.AA-05 to tighten authentication acceptance criteria across access paths.
CIS Controls v8CIS-5 — Account ManagementAccount management controls must prevent predictable credentials from remaining usable.
Recommendation — Use CIS-5 to manage account credential quality and reduce takeover exposure.

Key terms

  • Credential Stuffing: Credential stuffing is an attack that uses stolen username and password pairs from previous breaches to try logging into other services. It works because many people reuse credentials, and because the login attempt uses valid information, it can look ordinary until the surrounding behavior gives it away.
  • Master Password Policy: A set of organisation-defined rules for the primary password that unlocks a password manager account. It typically governs length and complexity so weak or easily guessed passwords are not accepted. The policy supports consistent enforcement and makes credential hygiene part of central access governance.
  • Password Screening: Password screening is the process of checking a proposed password against lists of known breached or commonly used passwords before allowing it to be set. The goal is to stop users from choosing credentials that attackers already possess or can easily guess. It is most effective when combined with length, uniqueness, and MFA.
  • Account Takeover: Account takeover is unauthorized use of a legitimate account after an attacker obtains valid access through stolen credentials, tokens, or trusted integrations. The key security problem is that the resulting activity often looks normal to logs and controls, which makes containment and attribution harder than in a forced-entry breach.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 1, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org