Does a small business need a password manager? Yes, and here's how to start

Bizer · 2026-10-01

Verizon's 2025 Data Breach Investigations Report found that the abuse of stolen or guessed credentials was the most common way attackers first got into the organizations it studied, at 22 percent of breaches. Not clever hacking. Logging in.

CISA, the federal cybersecurity agency, puts the advice for small businesses plainly: require strong passwords and a company-wide password manager, and add phishing-resistant multifactor authentication on top. If more than one person in your business shares a login, you need one.

What a password manager actually fixes

The problem in most small businesses is not weak passwords. It is shared ones. The Facebook page login on a sticky note. The supplier portal password everyone knows. The bank login the bookkeeper and the owner both use, set in 2019 and never changed because changing it means telling three people.

A password manager stores each login once, fills it in for the people allowed to use it, and lets you generate long random passwords nobody has to remember. When someone leaves, you remove their access in one place and change the shared logins they could see. That last step is the one that matters most and that almost nobody does without a tool.

What do the current rules say about passwords?

The guidance changed, and it got simpler. NIST's updated digital identity guidelines, published in August 2025 as SP 800-63B-4, say:

  • Length beats complexity. At least 15 characters for a password used on its own.
  • No forced mixtures. Stop requiring a capital, a number and a symbol.
  • No scheduled changes. Change a password when there is evidence it was compromised, not every 90 days.

CISA goes further for its own advice and suggests at least 16 characters. A password manager makes all of this painless, because the manager generates and remembers them for you.

How to choose one

Several well-known products sell business plans, including 1Password, Bitwarden, Dashlane, Keeper and Zoho Vault, the last of which this page used to review. Apple and Google build password managers into their phones and browsers, and those are fine for one person. For a team, choose a product with a business plan, because you want four features the free personal tools lack:

  1. Shared vaults you can grant by role, so the front desk sees the booking system and not the bank.
  2. Admin recovery, so a locked-out employee does not lock the business out.
  3. Offboarding, so removing a person is one action.
  4. Published security audits from an independent firm.

The fourth one is there for a reason. In December 2022, LastPass disclosed that an attacker had stolen backups of customer vault data. The vaults were encrypted, which is the design working, but customers with weak master passwords were exposed. The lesson is not to avoid password managers. It is to pick a vendor that publishes its audits, and to make the master password long.

Prices change and vary by team size, so compare them on each vendor's own page.

Set it up in one afternoon

  1. Start with yourself. Put your own accounts in first, in this order: email, bank, domain and website, payroll, tax accounts. Email comes first because it resets everything else.
  2. Turn on multifactor authentication for every account that offers it, starting with the same list. An authenticator app or a security key beats a text message code.
  3. Print the emergency recovery kit the product gives you and keep it somewhere physical and safe. Tell one trusted person where.
  4. Create shared vaults by role, then invite staff and move the shared logins in.
  5. Change every shared password as you move it. You do not know where the old ones have been.

The FTC's cybersecurity guidance for small business and the short lesson on locking down your accounts cover the steps around this.

What it costs you

A monthly fee per user. An afternoon of setup, and a week of staff grumbling. And one real risk: the manager becomes the single most important password you own. If you lose the master password and the recovery kit together, you have a very bad day. That is why the kit matters.

We still think the trade is easy. The alternative is a business whose logins are spread across notebooks, browsers and memories, with no way to take them back when someone leaves.

What is uncertain

Passkeys, the sign-in method that replaces a password with a key stored on your phone or computer, are spreading across major services. How fast smaller vendors and supplier portals adopt them is unclear as of October 2026. The major password managers already store passkeys as well as passwords, so starting now does not lock you into the old way.

Bizer
Loading…