Cybersecurity Glossary
Brute Force Attack
Guessing a password by trying enormous numbers of combinations until one works.
What Brute Force Attack means
A brute force attack works through possible passwords systematically, or through a dictionary of likely ones. Speed depends on where the attacker is guessing: an online login page is slow and noisy, while an offline attack against a stolen password database can test billions of candidates per second.
Why Brute Force Attack matters for small businesses and nonprofits
Login pages that do not limit attempts, and remote access services exposed to the internet, are attacked constantly. Length beats complexity, which is why a long passphrase outperforms a short password full of symbols.
What to do about Brute Force Attack
- Limit failed login attempts and lock or delay accounts after repeated failures
- Require long passphrases rather than complex short passwords
- Never expose remote desktop directly to the internet
Not sure where you stand on this?
We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.