Password Strength Audit

How strong are your organization’s passwords really β€” against the lists and rigs attackers actually use? A measured answer, not a policy document.

Why this matters: Password β€œstrength” policy usually means complexity rules from 2003 β€” while attackers crack with GPU farms and massive real-password lists. We documented how breached passwords flow into combo lists on this site; this audit measures your organization against those actual techniques and tells you where you really stand.

What we cover

  • Offline strength measurement of your password set (hashed, controlled)
  • Testing against modern cracking wordlists and rules
  • Weak, reused, and predictable-pattern detection
  • Policy review: what your rules actually achieve vs. NIST guidance
  • MFA coverage map: which accounts have a second factor
  • Prioritized fixes: resets, lockouts, and policy updates

How we test

1Scope & safety

We agree how hashes are handled β€” controlled environment, no plaintext retention, defined window.

2Measure

Your password set tested the way real attackers test it: wordlists, rules, and realistic hardware assumptions.

3Analyze

Patterns, reuse, and policy failures identified β€” the story behind the numbers.

4Fix

Targeted reset lists, policy modernization, and MFA gap closure.

What you get

  • Measured strength results, not guesses
  • Lists of weak and reused credentials for reset
  • Modernized password policy aligned to NIST
  • MFA coverage recommendations

The engagement at a glance

πŸ“ž Free scoping call

A short conversation about your environment. You receive a written scope, timeline, and fixed quote β€” no obligation.

✍️ Signed authorization

Testing begins only with your written permission and agreed rules of engagement. Always.

⏱️ Time-boxed delivery

A calendar agreed before we start, with an agreed communication plan while testing runs.

πŸ” Retest included

A verification pass over everything you fix β€” included in the price, not an add-on.

See the full engagement process β†’ and how pricing is scoped in our public pricing guide.

Related research from Hmmnm

Common questions

Do you ever see our passwords?

The preferred method works on password hashes in a controlled environment β€” plaintext never leaves your control, and nothing is retained after the audit.

We enforce complexity rules β€” isn’t that enough?

Complexity rules often produce predictable patterns (Summer2026!) that crack in minutes. Measurement beats policy.

How often should this run?

Annually, and after any significant breach affecting your users.

Authorization first, always. Testing happens only with your written permission and agreed rules of engagement β€” the same ethics that govern responsible disclosure on this site.

Want this assessed for your environment?

A short scoping conversation is enough to get a fixed quote. No obligation β€” a researcher replies.

Start the conversation β†’