Cybersecurity Security Tools Small Business

Why your business should use a password manager

Small-business owner reviewing a password manager with an IT adviser.

Weak or reused passwords can put your business accounts at risk. Staff usually want to keep accounts secure. The problem is having too many logins and no reliable way to manage them.

A password manager designed for businesses gives your team one controlled place for passwords, recovery codes and other sensitive login details. It makes it easier to stop storing passwords in spreadsheets or notes and reusing the same password across accounts.

What a password manager changes

Each account can have its own long, random password. Staff do not need to memorise every password, and your business does not need to send credentials through email or chat.

Give staff their own logins wherever the service allows it. Where a shared login is unavoidable, share it through the password manager.

A password manager can also make staff changes easier. You can remove a person’s access to the password manager centrally. You still need to disable their business accounts and change any shared passwords they knew or could have saved.

Illustration of a password manager vault controlling access to separate business accounts

Where small businesses get caught out

  • Shared passwords. Everyone may end up using the owner’s password when the service does not support separate logins.
  • Old access. Former staff, contractors and old devices can retain access long after the work is finished.
  • Recovery details. The business may depend on one person’s phone, email address or authenticator app to recover an important account.
  • Browser-only storage. A password saved in one person’s browser is difficult to manage when that person is unavailable.

What if the password manager is hacked?

A password manager reduces risk, but it does not remove it. Choose a provider with strong account protection, turn on multi-factor authentication and keep the recovery process under business control.

Do not approve a login just because the password manager offers to fill it in. If the website address looks unfamiliar or the request arrives through an unexpected message, stop and check it first. Autofill cannot tell you whether a convincing phishing site is legitimate.

How to choose one

Choose based on how your team works, as well as price.

  • Look for individual staff accounts and check which actions the activity log records, such as viewing, sharing or changing passwords.
  • Require multi-factor authentication for the password-manager account itself.
  • Check how the business would regain access if the person who manages the password manager were unavailable.
  • Choose controls that let you give each person or team access only to the passwords they need.
  • Confirm how the provider handles exports, backups and account recovery before you commit.

A sensible first week

  1. List the business accounts that matter most, including Microsoft 365, banking, accounting, cloud storage, domain management and social media.
  2. Set up individual staff accounts and protect the administrator account with multi-factor authentication.
  3. Move the highest-risk accounts first. Replace passwords that have been shared or reused.
  4. Remove old users and review external access.
  5. Keep the password manager’s recovery instructions and emergency credentials in a secure place that authorised people can access even if they are locked out of the vault.
  6. After importing passwords from browsers or another vault, remove exported files and check that old copies are no longer sitting in downloads, email or shared folders.

What an IT provider should help with

A business password manager should be owned by the business, not tied to one employee’s personal email or phone. Your IT provider should be able to help set up named administrators, access groups, offboarding steps and a tested emergency-access process.

That also makes migration safer. Importing browser passwords or exporting vault data can create extra copies. Plan the move, protect the exported data and remove temporary copies when the migration is complete.

Ask JCPIT to review your highest-risk accounts and set up a business-owned password vault. We can start by looking at how your team currently stores and shares access, then recommend a practical next step.

Sources and further reading

Jake
Jake
JCPIT Support — Keeping IT Simple.
← Previous Article
Business continuity plan for a small business: what to include
Next Article →
Microsoft 365 shared mailboxes: the setup checks small businesses miss