The human element is often referred to as the weakest link in a secure system. Despite this, regular initiatives to shore up password strength are unlikely to be wasted time. Even a low privileged employees account is a great place to learn more about a company and launch a plausible social engineering attack. Even authenticated staff-only apps are rarely tested as well as the public ones. An attack will likely involve one of a few known tools. If one of those tools, out-the-box, employs a strategy that cracks a password hash then it’s unequivocally weak.”]
Source: https://nakedsecurity.sophos.com/2012/08/17/practical-it-passwords-101-for-businesses/

