Somewhere in your business there is a spreadsheet called Passwords, or a notebook, or a Word file on the shared drive, and everyone knows about it, including, potentially, anyone who ever compromises a single account with access to it. Shared credentials in plain text are how most SMEs actually manage passwords, and it persists not because anyone thinks it is good but because it is convenient and nothing bad has happened yet. This page is about the tool that replaces it, what separates the business-grade options, and the rollout that gets a whole team using it without a revolt.
Why the spreadsheet has to go
The case is not theoretical hygiene; it is four concrete failure modes:
- One breach opens everything. A plain-text password file is a skeleton key: any compromise that reaches it (a phished mailbox it was emailed through, a stolen laptop, one bad browser extension) hands over every system at once, including the ones that matter.
- It fails your audits. Cyber Essentials requires credible password management, insurers ask how credentials are stored, and “a spreadsheet” is the wrong answer on both forms in ways that cost real money.
- It guarantees weak, reused passwords. Humans who must remember or retype passwords make them short and reuse them; every credential-stuffing attack on the internet is built on this. A manager generating 20-character random strings removes the human from the loop that keeps failing.
- Leavers keep the keys. When someone leaves, the spreadsheet’s passwords leave with them, and nobody changes them all. The offboarding problem is unsolvable at spreadsheet scale and trivial with per-user vault access you simply revoke.
What a business password manager actually does
The personal apps store your passwords; the business tiers add the parts an organisation needs: individual vaults per member of staff, shared collections for the credentials teams genuinely co-use (the company social accounts, the courier portal), role-based access so people see only what their job needs, an admin console with enrolment, revocation and password-health reporting, and audit trails of who accessed what. Staff get browser and phone apps that fill logins automatically, which is the feature that makes adoption stick: the secure path becomes the lazy path, which is the only kind of security policy that survives contact with a busy office.
Choosing one: the criteria that matter
The leading business products (Bitwarden, 1Password, Keeper and peers) are all competent, and UK pricing clusters in the £2 to £8 per user per month band, so selection is less about a winner and more about fit:
- Zero-knowledge architecture as a hard requirement: the vendor cannot read your vault, so a vendor-side breach yields ciphertext rather than credentials. All serious contenders offer this; anything that cannot say it clearly is disqualified.
- SSO and directory integration. Tying enrolment to Microsoft 365 accounts means joiners get vaults automatically and leavers lose access the moment their account is disabled: the feature that makes the leaver problem actually solved rather than policy-solved.
- Sharing granularity. Collections per team, per client, per system, with viewer-versus-editor rights. Businesses that manage credentials for customers (agencies, bookkeepers) should weight this heavily.
- Recovery design. What happens when someone forgets their master password, and who in the business can recover a vault under what controls? The answers differ meaningfully between products and matter more than most feature-list items.
- Track record, honestly read. The industry’s most instructive event was a major vendor’s 2022 breach, in which stolen encrypted vaults put customers’ weak master passwords under offline attack. The lessons are portable to any product: the vendor’s transparency record matters, and the master password (the one password each person still memorises) must be long, unique, and backed by MFA on the vault itself.
Password managers in browsers (Chrome and Edge remembering logins) are better than reuse but lack the admin console, sharing controls, audit trail and offboarding story, which is precisely the gap between personal and business tooling.
The rollout that sticks
Deployments fail socially rather than technically, same as MFA rollouts, and the same medicine works:
- Seed the shared collections first. Migrate the spreadsheet’s contents into properly structured shared folders before inviting anyone, so day one delivers instant value: everything you used to hunt for, now searchable and autofilling.
- Enrol in waves with a ten-minute induction each: install the extension and app, set a strong master password (a three-or-four-word passphrase, written nowhere), turn on MFA, find your team’s collections.
- Let autofill do the persuasion. The first week of not typing passwords converts most sceptics; the health dashboard (which flags weak and reused passwords for gradual cleanup) gives the project its follow-through phase.
- Retire the spreadsheet ceremonially. Delete it, empty the bin, and state plainly that it is gone. A migrated-but-surviving spreadsheet quietly undoes the entire project.
- Write the two policies that matter: every work credential lives in the manager, and every shared credential lives in a collection rather than a chat message. Enforcement is mostly cultural, helped by the audit trail.
For a typical SME this is a fortnight of elapsed time and single-digit hours of actual work, most of it the initial migration.
Frequently asked questions
Are password managers safe for businesses?
Zero-knowledge products storing encrypted vaults the vendor cannot read are, by a wide margin, safer than any alternative actually used in offices: the realistic comparison is not against perfection but against spreadsheets, reuse and browser-only storage, all of which lose. The vault’s own protection (a strong master passphrase plus MFA) is where the residual risk concentrates.
What if someone forgets their master password?
Business tiers include admin-controlled recovery designed for exactly this, with the design varying by product; it is a first-rank selection criterion. What no product offers is vendor-side recovery of a zero-knowledge vault, which is the architecture working as intended.
What does a business password manager cost?
Commonly £2 to £8 per user per month depending on product and tier. For context against the wider IT budget, a 10-person business is spending a few hundred pounds a year to close the credential layer entirely.
Is the built-in browser password manager enough?
For a sole trader, arguably. For a team: no admin console, no structured sharing, no audit trail, and no clean way to revoke a leaver’s access to shared credentials. The business features are the point, not a luxury.
Do password managers satisfy Cyber Essentials?
They are the practical route to the scheme’s password requirements (unique, strong credentials with sensible management), and a deployed manager with MFA is an answer assessors and insurers both recognise. The certification also examines the accounts and devices around it, per the full checklist.
Which password manager should we pick?
Any of the major business products, chosen on directory integration, recovery design and sharing fit rather than feature-count. We deploy and manage them as part of client security stacks and will recommend against our own convenience if your stack fits another product better.
Get the spreadsheet retired this month
The free IT health check includes the credential layer: where your passwords actually live today, what an audit or insurer would make of it, and a sized rollout plan for the fix, product recommendation included. Get in touch and make the Passwords file a story you used to tell.