Password Strength Audit
How strong are your organizationβs passwords really β against the lists and rigs attackers actually use? A measured answer, not a policy document.
What we cover
- Offline strength measurement of your password set (hashed, controlled)
- Testing against modern cracking wordlists and rules
- Weak, reused, and predictable-pattern detection
- Policy review: what your rules actually achieve vs. NIST guidance
- MFA coverage map: which accounts have a second factor
- Prioritized fixes: resets, lockouts, and policy updates
How we test
We agree how hashes are handled β controlled environment, no plaintext retention, defined window.
Your password set tested the way real attackers test it: wordlists, rules, and realistic hardware assumptions.
Patterns, reuse, and policy failures identified β the story behind the numbers.
Targeted reset lists, policy modernization, and MFA gap closure.
What you get
- Measured strength results, not guesses
- Lists of weak and reused credentials for reset
- Modernized password policy aligned to NIST
- MFA coverage recommendations
The engagement at a glance
A short conversation about your environment. You receive a written scope, timeline, and fixed quote β no obligation.
Testing begins only with your written permission and agreed rules of engagement. Always.
A calendar agreed before we start, with an agreed communication plan while testing runs.
A verification pass over everything you fix β included in the price, not an add-on.
See the full engagement process β and how pricing is scoped in our public pricing guide.
Related research from Hmmnm
Common questions
Do you ever see our passwords?
The preferred method works on password hashes in a controlled environment β plaintext never leaves your control, and nothing is retained after the audit.
We enforce complexity rules β isnβt that enough?
Complexity rules often produce predictable patterns (Summer2026!) that crack in minutes. Measurement beats policy.
How often should this run?
Annually, and after any significant breach affecting your users.
Want this assessed for your environment?
A short scoping conversation is enough to get a fixed quote. No obligation β a researcher replies.
Start the conversation β