
19.08.2026
Password security is one of the fundamentals of IT security – and yet it is frequently underestimated. People still use simple passwords like „123456“, personal information or the same login credentials for multiple services. For attackers, precisely this can become the decisive gateway.
Timur Yilmaz, Service Owner for Security Validation at accompio, regularly experiences in practice how insecure passwords endanger companies. During security audits and password checks, passwords are deliberately tested for security – with results that are sometimes sobering. In the expert interview, he explains how attackers obtain passwords, which mistakes are particularly common, and how secure passwords can actually be implemented in everyday life.
What actually makes a secure password? Which tools can help you with password creation and management? And what are the consequences of weak or recurring passwords at an enterprise level? Timur Yilmaz provides all the answers in the full video interview.
„SummerPlant2025!“ or „123456“ – passwords of this kind are still regularly encountered by security experts. Passwords with a personal reference, such as family names, pets, dates of birth or well-known places, are also problematic.
Timur Yilmaz knows these patterns from his daily work. As a Service Owner for Security Validation, he accompanies Security checks and security audits for clients. This also includes password checks, which test how secure the passwords used within the company actually are.
The result highlights a fundamental problem: no matter how extensive technical security measures may be, if access credentials are easy to guess or have already been compromised elsewhere, a significant vulnerability arises.
Passwords can fall into the hands of attackers in various ways. A particularly common scenario is phishing: for example, users receive an email with a link that leads to a fake login page. If the password is entered there, attackers can intercept the login details.
Another danger is data leaks. If an online service is compromised, stored access credentials or password data can fall into the hands of attackers. This information can then be cross-referenced with other known access credentials.
This is precisely where password reuse shows its danger: a password compromised on a private service can become a risk to corporate system access if the same password is used there as well.
When it comes to what makes a secure password, Timur Yilmaz focuses primarily on one factor: the length.
The longer a password is, the better. Instead of short, complex-looking character strings, long passphrases can therefore also be used. They have another advantage: long passwords are often easier to remember if they consist of several words.
At the same time, a password should not have any personal connection. Names, dates of birth, pets, favourite places or other information that can be found out about the person in question should not be part of a password.
„Anything with a personal connection should not be a password. I don't know my passwords. I know a single password – the one for my password manager.“
— Timur Yilmaz, Service Owner at accompio
So a good password is not necessarily the most complicated password. The crucial thing above all is that it long, unique and not derived from personal or easily predictable information is.
A Password manager solves one of the biggest practical problems in password security: nobody has to remember dozens of complex passwords anymore.
Instead, a strong master password is required. The remaining access credentials can be stored and managed within it. A password manager can also generate secure, random passwords that consist of many characters and have no personal connection.
Timur Yilmaz uses a password manager himself – both personally and in his business. As a result, he doesn't even know his individual passwords by heart. Instead, a separate, long password is used for every service.
Even a strong password should not be the only security measure. An important additional security layer is multi-factor authentication (MFA).
In this process, the login is not secured by the password alone. An additional factor must also be confirmed – for example via a smartphone, a code or a biometric method.
This significantly increases security. Even if an attacker knows a password or has managed to crack it, the password alone is not necessarily enough to gain access to a protected account.
Multi-factor authentication should therefore be an important component of a holistic identity and access security strategy for businesses.
Companies often try to enforce secure passwords through mandatory password policies. While requirements for upper and lower case letters, numbers and special characters can be useful, they do not automatically guarantee a secure password.
A real-world example illustrates the problem: a user can create a password such as „SommerPflanze2025!!“ and thereby formally meet various complexity requirements. Even so, the password remains predictable and therefore insecure.
This is why Timur Yilmaz trainings as a particularly important component of password security. Staff must understand how secure passwords are created, why password reuse is dangerous, and which behaviours attackers can exploit.
Password security is therefore not exclusively a technical task. It is also a matter of knowledge and behaviour.

accompio identifies vulnerabilities in your password and security structure before they can become gateways for real-world attacks.
The first step is to know the actual state. Password checks and security reviews can help to make vulnerabilities visible.
Building on this, companies should specifically raise awareness among their employees and provide them with concrete methods. These include in particular:
This is how an abstract password policy becomes a security concept that can also be implemented in everyday work.
Anyone wishing to improve their own password security can start with a few simple steps: Are passwords used multiple times? Do they contain personal information? Are important accounts additionally protected by multi-factor authentication? And is a password manager already being used?
The most important step is not to wait until a security incident occurs to take action. Password security should be an integral part of personal and corporate IT security.

Timur Yilmaz is an expert in password security and security solutions. He advises clients on securing their access and applications.
A secure password is above all long and individual. It should have no personal connection and not be used across multiple services. Long passphrases or randomly generated passwords are particularly suitable.
As a general rule, the longer a password, the better. In the interview, Timur Yilmaz therefore recommends passwords or passphrases that are as long as possible. When using a password manager, very long, randomly generated passwords can also be used.
Long passphrases can be a good way to create secure yet memorable login details. Length is particularly crucial. Furthermore, a passphrase should not consist of easily guessed personal information.
If a password is compromised in a data leak at one service, attackers can try using the same password on other services. If it is used both privately and for a corporate account, for instance, a private data leak can become a security risk for the company.
Password managers make it possible to use a unique and very long password for every service without users having to memorise all their access details. Instead, only one strong master password is required. The remaining passwords can be generated and stored by the password manager.
Yes. Multi-factor authentication provides an additional layer of protection. Even if an attacker knows the password, they need another factor, such as a smartphone, a code or biometric confirmation.
In addition to technical measures, companies should focus primarily on training. Password policies alone are not enough if employees use passwords that are formally complex yet easily predictable. Training should specifically teach how secure passwords are created and why password reuse is risky.

Arrange an initial consultation