Business security

Password security for small businesses: choosing a password manager

Use strong, unique passwords without relying on memory, choose a manager your team can use and plan account recovery before it becomes urgent.

Person using a smartphone with a laptop and smartwatch nearby

Business accounts need strong protection, but the process has to work for the people using them. Remembering a different password for every service is a poor foundation for that process. A suitable password manager can help staff use unique credentials without relying on memory. Choosing the tool is only part of the work: you also need to protect access to it, decide how team accounts are handled and prepare a recovery route.

Reduce reuse without making everyday work harder

The problem with a reused password extends beyond the account where it is first exposed. If an attacker obtains it, they can try the same password elsewhere. The NCSC recommends unique passwords and two step verification to help protect accounts if a password is compromised. Two step verification adds another check when you sign in, so the password is not the only protection. NCSC password guidance

A password manager stores credentials in a vault and can generate new passwords. Staff can then use a different one for each service without memorising the whole collection. That is a practical reason to adopt a manager, but not a reason to ignore its own security. The NCSC notes that password managers can have vulnerabilities and that usability matters when deciding which one will work for an organisation. NCSC password manager buying guide

Begin by listing the business accounts that need attention. Identify who uses each service, whether individual staff access is available and who is responsible for it. Keep this account inventory separate from the passwords themselves. Its purpose is to help plan ownership and rollout, not create another unprotected list of credentials.

Involve the people who will use the manager. Ask which devices they work on and where they currently get stuck with logins. A short introduction using safe test entries can reveal questions about finding an account, saving a new password or recognising the correct service. Give staff a clear place to ask for help, rather than expecting an installation alone to settle the working process.

Ad: Rogue Sparrow Digital is a Proton Partner and receives a commission for paid subscriptions purchased through the link in this section.

Where Proton Pass fits

We recommend considering Proton Pass (Ad) for its documented protection of stored credentials, open source applications and published security audit information. Proton describes encryption that protects the contents of the password vault. These are useful properties to assess, but they do not mean that every part of a business’s account security is handled automatically. Proton Pass security

The recommendation should fit the way you work. For a team, compare the current business plans with your requirements for sharing, administration and visibility. Features differ between plans. Establish which controls you need before choosing a subscription, rather than assuming the features available to an individual account cover the organisation’s responsibilities. Proton Pass for Business

We suggest a small, controlled pilot before a wider rollout. Use appropriate test entries to check the tasks staff will need to perform and confirm which devices and browsers are involved. Ask the person administering the trial to demonstrate the relevant access controls. Record any limitations that matter to the business and resolve them before relying on the arrangement for essential accounts.

Prefer individual staff accounts on the services you use where they are available. Where a shared credential is genuinely necessary, decide who needs it and how changes to access will be handled. Ask how the chosen arrangement deals with someone changing role or leaving. Consider whether a shared password itself needs changing; removing a person’s access to a vault should not be treated as proof that every account they previously knew is secured. The NCSC’s buying guide also addresses the limits and management of shared credentials.

Plan for being locked out

Before relying on the manager, ask how you would recover if the password was forgotten or the usual device was unavailable. Make sure the required recovery material can be reached securely without opening the vault you are trying to recover. Record who is authorised to help with business accounts.

Protect the manager and understand recovery

Use a long, unique passphrase for the password manager account and enable two step verification. Follow the provider’s guidance for protecting the devices and applications you use with it. A vault is only one part of the account access process, so keep responsibility for the surrounding devices and access arrangements clear.

Proton makes an important distinction between resetting an account password and recovering encrypted data. A reset lets you choose a new password; data recovery restores access to existing encrypted contents. Its recovery phrase can cover both functions, while other recovery methods may cover only one. A recovery email or phone number alone should not be mistaken for a complete plan to recover the vault contents. Proton account recovery guidance

Set up the appropriate recovery methods before they are needed and follow Proton’s current instructions for the account type involved. Keep recovery material secure and accessible outside the vault. Review what would happen if the second verification method was also unavailable. Use the account settings and provider guidance to check the recovery setup without disrupting working access.

After setup, work through the accounts that matter most and replace reused passwords. Make sure each change is saved correctly and that the authorised user can sign in before moving on. Treat the rollout as a piece of business administration with an owner, rather than a one time installation left for everyone to interpret differently.

Return to the arrangement when people, devices or important services change. Review who has access and whether the manager still suits the work. The useful outcome is a process staff can follow consistently, with clear ownership and a recovery plan that has been considered before access is lost.

Explore managed support and continuous improvement.

See the thinking in practice.

Explore the business needs and delivery behind our client projects.

Explore Project Lab

Share this article

Start a useful conversation.

Ask Rogue Sparrow Digital about choosing and setting up business password management, including team access and recovery planning.

Contact us