Somewhere in your business there is a spreadsheet called Passwords, or a notebook, or a Word file on the shared drive, and everyone knows about it, including, potentially, anyone who ever compromises a single account with access to it. Shared credentials in plain text are how most SMEs actually manage passwords, and it persists not because anyone thinks it is good but because it is convenient and nothing bad has happened yet. This page is about the tool that replaces it, what separates the business-grade options, and the rollout that gets a whole team using it without a revolt.

Why the spreadsheet has to go

The case is not theoretical hygiene; it is four concrete failure modes:

What a business password manager actually does

The personal apps store your passwords; the business tiers add the parts an organisation needs: individual vaults per member of staff, shared collections for the credentials teams genuinely co-use (the company social accounts, the courier portal), role-based access so people see only what their job needs, an admin console with enrolment, revocation and password-health reporting, and audit trails of who accessed what. Staff get browser and phone apps that fill logins automatically, which is the feature that makes adoption stick: the secure path becomes the lazy path, which is the only kind of security policy that survives contact with a busy office.

Choosing one: the criteria that matter

The leading business products (Bitwarden, 1Password, Keeper and peers) are all competent, and UK pricing clusters in the £2 to £8 per user per month band, so selection is less about a winner and more about fit:

Password managers in browsers (Chrome and Edge remembering logins) are better than reuse but lack the admin console, sharing controls, audit trail and offboarding story, which is precisely the gap between personal and business tooling.

The rollout that sticks

Deployments fail socially rather than technically, same as MFA rollouts, and the same medicine works:

  1. Seed the shared collections first. Migrate the spreadsheet’s contents into properly structured shared folders before inviting anyone, so day one delivers instant value: everything you used to hunt for, now searchable and autofilling.
  2. Enrol in waves with a ten-minute induction each: install the extension and app, set a strong master password (a three-or-four-word passphrase, written nowhere), turn on MFA, find your team’s collections.
  3. Let autofill do the persuasion. The first week of not typing passwords converts most sceptics; the health dashboard (which flags weak and reused passwords for gradual cleanup) gives the project its follow-through phase.
  4. Retire the spreadsheet ceremonially. Delete it, empty the bin, and state plainly that it is gone. A migrated-but-surviving spreadsheet quietly undoes the entire project.
  5. Write the two policies that matter: every work credential lives in the manager, and every shared credential lives in a collection rather than a chat message. Enforcement is mostly cultural, helped by the audit trail.

For a typical SME this is a fortnight of elapsed time and single-digit hours of actual work, most of it the initial migration.

Frequently asked questions

Are password managers safe for businesses?

Zero-knowledge products storing encrypted vaults the vendor cannot read are, by a wide margin, safer than any alternative actually used in offices: the realistic comparison is not against perfection but against spreadsheets, reuse and browser-only storage, all of which lose. The vault’s own protection (a strong master passphrase plus MFA) is where the residual risk concentrates.

What if someone forgets their master password?

Business tiers include admin-controlled recovery designed for exactly this, with the design varying by product; it is a first-rank selection criterion. What no product offers is vendor-side recovery of a zero-knowledge vault, which is the architecture working as intended.

What does a business password manager cost?

Commonly £2 to £8 per user per month depending on product and tier. For context against the wider IT budget, a 10-person business is spending a few hundred pounds a year to close the credential layer entirely.

Is the built-in browser password manager enough?

For a sole trader, arguably. For a team: no admin console, no structured sharing, no audit trail, and no clean way to revoke a leaver’s access to shared credentials. The business features are the point, not a luxury.

Do password managers satisfy Cyber Essentials?

They are the practical route to the scheme’s password requirements (unique, strong credentials with sensible management), and a deployed manager with MFA is an answer assessors and insurers both recognise. The certification also examines the accounts and devices around it, per the full checklist.

Which password manager should we pick?

Any of the major business products, chosen on directory integration, recovery design and sharing fit rather than feature-count. We deploy and manage them as part of client security stacks and will recommend against our own convenience if your stack fits another product better.

Get the spreadsheet retired this month

The free IT health check includes the credential layer: where your passwords actually live today, what an audit or insurer would make of it, and a sized rollout plan for the fix, product recommendation included. Get in touch and make the Passwords file a story you used to tell.