Commit to ending universally shared default passwords, which continue to feature in attacks every year, and decide which password rules the product enforces, such as a minimum length and refusing passwords known to have been breached.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.