Shared logins on sticky notes, a spreadsheet called passwords, and the same word reused everywhere — these are the security habits most small teams start with, and they quietly become one of the biggest risks in the business. A password manager fixes the whole category of problem at once, and setting one up for a team is genuinely a job you can finish in an afternoon.
Why the informal approach fails
The trouble isn't that your team is careless; it's that human memory and good security pull in opposite directions. Passwords strong enough to resist attack are impossible to remember, so people reuse a handful of easy ones across dozens of accounts. The moment one of those accounts is breached — and breached credential lists circulate constantly — attackers try the same email and password combination everywhere else. This is called credential stuffing, and it's automated, cheap and effective.
Shared accounts make it worse. When five people know the login for a critical system and one of them leaves, that credential walks out the door, and changing it means finding everyone who relied on it. A spreadsheet of passwords, meanwhile, is a single file that hands over your entire business to anyone who opens it. Reducing this kind of exposure is exactly the sort of thing the ASD's Essential Eight is built around, and password hygiene sits right at its foundation.
What a password manager actually does
A team password manager is an encrypted vault. Each person unlocks their vault with one strong master password (and, ideally, a second factor), and the tool generates, stores and fills long random passwords for every account so nobody has to remember or type them. For a business, the important features are the shared ones:
- Shared vaults or folders so a team can access a common set of logins without anyone knowing the underlying passwords.
- Role-based access so the right people see the right credentials and no more.
- Instant offboarding — revoke someone's access and they lose the lot in one action, rather than you hunting through systems.
- A password health report that flags weak, old or reused credentials so you can fix the worst ones first.
Choosing one
The market has several reputable, well-established options with business tiers, and for most SMEs the differences are smaller than the decision to adopt one at all. A few things are worth checking before you commit: that it supports the browsers and devices your team actually uses, that it offers business or team plans with the shared-vault and admin controls above, that it enforces two-factor authentication, and that the vendor has a clear, credible security posture and a good track record. Australian data-residency preferences may narrow the field for some businesses.
Rolling it out without the pain
Adoption is where these projects usually stumble, so make it easy:
- Pick the tool, set up the organisation account, and configure your shared vaults first — don't ask the team to think about structure.
- Install the browser extensions and get each person to set a strong master password and turn on two-factor authentication on their own vault.
- Import existing passwords, then use the health report to systematically replace the weak and reused ones with generated passwords, starting with your most critical systems.
- Retire the spreadsheet and the sticky notes deliberately — once the vault holds everything, delete the old copies so people can't fall back on them.
Spend ten minutes showing people how autofill works. Once they experience never typing a password again, the convenience does the change-management for you.
Two habits that multiply the benefit
A password manager is most of the battle, but two companion habits close the biggest remaining gaps. First, turn on multi-factor authentication everywhere it's offered, especially on email, banking, accounting and admin accounts — even a stolen password is far less useful when a second factor is required. Second, protect the master password itself: it's the one key to everything, so it must be strong, unique and never reused, and losing it should trigger your recovery process, not a panic.
Getting off shared logins and reused passwords is one of the highest-return security moves a small business can make, and it's neither expensive nor technical. If you're thinking about broader IT and security foundations, our operations hub covers where this fits alongside the rest. This is general information rather than specific security advice — for a full assessment against a framework like the Essential Eight, a qualified IT security provider can tailor it to your environment.
About the author
Andrew Northcott
Founder & Chairman, Valont
Andrew is the founder and chairman of Valont and the parent group Wattlestone. He has spent two decades building and running Australian SMEs, and writes about the realities of ownership — cash, people, systems, and the decisions that compound.
LinkedIn →