About Partners Contact Client Portal
LinkedIn Twitter
Services Industries Insights & Events Careers & Culture

Services

RubinBrown specializes in providing a comprehensive range of services to meet business and personal needs. Whether you require expert tax, strategic business consulting, audit services or more, RubinBrown's team of experienced professionals are here to support you.

View All Our Services
Assurance Services
Benefit Plan Audit Services Public Company Services SOC Examinations, IT Audit, & Third-Party Risk
Consulting Services
Business Process Improvement Services Business Restructuring & Bankruptcy Services Cyber Security Services Environmental, Social and Governance Services ERP & Enterprise Software Advisory Fraud & Forensics SOC Examinations, IT Audit, & Third-Party Risk Information Technology Services Litigation Services Mergers & Acquisitions Services Risk & Internal Audit Services Valuation Services
Entrepreneurial Services
Outsourced Accounting & Advisory Services
Tax Services
Federal Tax Services Private Client Services Credits & Incentives Services State & Local Tax Services
RubinBrown Advisors RubinBrown Corporate Finance

Industries

At RubinBrown, we bring experience across a range of industries. Our experience enables our professionals to offer tailored solutions catering to the intricacies of each sector. Our professionals have years of focused engagement and skills, allowing them to navigate industry-specific challenges to benefit our clients.

View All Our Industries
Colleges & Universities Construction Gaming Healthcare Law Firms Life Sciences & Technology Manufacturing & Distribution Not-For-Profit Private Equity Public Sector Real Estate Transportation & Dealerships

Insights & Events

At RubinBrown, we provide valuable insights detailing emerging trends and industry-specific information. Our events, hosted virtually and in-person, keep you informed and connected to the topics and industries that matter most to you and your organization.

View All Insights & Events
Jun 11

RubinBrown’s Leveraging Technology for Business Success

Learn More & Register
Jun 17

RubinBrown’s Rural Health Webinar Series

Learn More & Register

RubinBrown Sports Betting Index: March 2025 Analysis

Learn More

Tax Bill Watch 2025: Budget Resolution Compromise

Learn More

Careers & Culture

At RubinBrown, we are inspired team members, working as one firm, living our core values, and Being Our Best for Others while delivering totally satisfied clients. We invite you to learn more about the Firm's culture, the Be Your Best for Others mentality, and explore the available opportunities at RubinBrown.

Discover Our Culture
Baker Tilly International Campus Recruiting Diversity & Inclusion Experienced Recruiting RubinBrown Charitable Foundation Join The Team
Back to Insights

Focus on Cyber Security: Password Manager Security

Contact Us

Focus on Cyber Security: Password Manager Security

Contact Us

Password managers are great tools for using unique passwords for each web site, securing confidential information, and securely sharing information. Credential theft is used extensively by criminals for ransomware attacks and committing fraud – so using unique passwords is a critical security control. However, it also represents a single point of failure, if it is compromised every password protected in it is also compromised. Many tools exist with different features, capabilities, and costs. We encourage every organization to review the available tools and select a standard tool that fits.

What do you do when your password manager company is compromised? The recent announcement by LastPass  that a backup of the encrypted customer vault was copied from their systems is a reminder we all need to stay vigilant. The announcement indicates the sensitive data (e.g., username, password, and secure notes) are encrypted with 256-bit AES and can only be decrypted by a specific user’s master password. The risk is that a brute-force (guessing every possible combination) attack could give the criminal access to usernames and passwords. Overall, the risk is pretty low as long as the master passphrase is longer than 12 characters and (ideally) has some complexity. But, there is still a risk, so we recommend a few key actions to protect yourself and the organization.

So what needs to be done now? Any time a Password Manager is compromised (others have been breached and more will be breached over time) we recommend the following actions:

  • Change the master passphrase – make it at least 15 characters long, easy to remember, and significantly different from the previous passphrase. Some additional guidance on passphrases: nothing personal (relatives, school, work, pets, etc.), do not use historically significant, pop culture, song lyrics, or sports related. Hackers load their software with all this information and use it in the brute force attacks. Mix in some complexity if you can, but make sure it is easy for you to remember.
  • Change sensitive accounts passwords – change the passwords for all accounts with sensitive data such as banking, investments, healthcare, credit tracking, cell phone, or related accounts. The good news is that using a password manager makes this part a bit easier.
  • Multi-factor authentication – as you change passwords for sensitive data accounts, it is also an excellent time to enable multi-factor authentication wherever possible (including the Password Manager).

Switching Password Manager software is always an option, but the three steps above are still recommended as you set up your new software. Do not reuse any passwords or passphrases from the old solution, only new, unique, and 15+ characters long passwords. Remaining vigilant, using layers of security, and maintaining security awareness are critical to staying safe in our increasingly digital world.

As always, if you need information or assistance with cyber security, please feel free to contact our RubinBrown Cyber Security team at any time.


 

Published: 1/19/2023

Readers should not act upon information presented without individual professional consultation.

Any federal tax advice contained in this communication (including any attachments): (i) is intended for your use only; (ii) is based on the accuracy and completeness of the facts you have provided us; and (iii) may not be relied upon to avoid penalties.

 

Contact Us:

Talk to Our Experts

Robert Rudloff, CISSP, CISA, QSA, CMMC RPA Partner rob.rudloff@rubinbrown.com 303-952-1220

Be Your Best for Others at RubinBrown

At RubinBrown, our firm fosters a culture built upon five vision points, and are guided by our philosophy of Being Our Best for Others. Discover how you can be your best at RubinBrown today by visiting our Careers & Culture Overview for available opportunities and more.

Discover Our Culture

Join Our Mailing List

RubinBrown periodically sends breaking regulatory updates, technical summaries, industry-specific information and event (in-person and virtual) invitations through electronic newsletters.

Sign Up for Our Communications
1-800-678-3134 Certified Public Accountants & Business Consultants

Ranked a Top 50 Accounting Firm by Inside Public Accounting

Firm News Disclaimers Privacy Policy Client Payment © 2025 RubinBrown LLP
RubinBrown Executive Recruiting RubinBrown Advisors RubinBrown Corporate Finance