Cybersecurity

Password managers for small teams: what actually works

Password managers for small teams: one vault, shared safely, instead of reused and scattered logins

Somewhere in your business there's a spreadsheet, a sticky note under a keyboard, or a browser's saved-password list with half your logins on it. Most small teams end up there. Almost none of them meant to. It happens one shared account at a time, until nobody remembers who's got access to what, or which of three slightly different passwords actually works on the accounting software.

A proper password manager fixes the reuse problem, the sharing-over-WhatsApp problem, and the “does Dave still have access after leaving in March” problem, in one move. Here's what it actually gets you, what to look for in a team plan, and how to roll it out without half the office ignoring it by Friday.

Why "we just remember them" stops working

It works fine right up until it doesn't. Someone reuses their email password on the accounting portal because it's one less thing to remember. A phishing email catches them on a Tuesday, and now the same reused password unlocks two systems instead of one. This is how a single mistake turns into a much bigger problem: the same password, written the same way, sitting behind three different logins.

Browser autofill isn't much better once more than one person's involved. It doesn't share a login securely between colleagues, so people copy passwords into email threads or group chats instead, where they sit indefinitely, readable by anyone with access to that inbox. There's no record of who can see what, no way to force a stronger password, and if a laptop gets compromised, whatever's saved in that browser profile is there in plain text for the taking.

What a password manager actually does

At the core, it's a single encrypted vault that holds every login, unlocked by one master password (or a passkey, increasingly). From there it generates long random passwords you'd never remember on your own, autofills them on the right site, and syncs across your phone, laptop and browser. Most of the well-known ones also store two-factor authentication codes and flag passwords that are weak, reused, or have turned up in a known data breach.

The part that matters most for a team isn't any of that, though. It's secure sharing: giving a colleague access to the printer admin panel or the shared social media account without ever telling them the actual password, and being able to revoke it the moment they don't need it any more. Nobody has to remember, write down, or forward anything.

Personal plan vs a proper team plan

A personal or family-tier plan gets one household a shared vault and not much administration on top. A business plan adds the layer that makes it work for a company: an admin console showing exactly who has access to which shared vault, the ability to add or remove someone in seconds, enforced two-factor authentication on the vault itself, and usually an audit log of who accessed what and when. If it's genuinely just you and one other person, a family-tier plan can be enough. Past three or four people, the admin console stops being a nice-to-have.

The well-known options, honestly compared

Bitwarden is open source, which means its code has been publicly reviewed rather than taken on trust, and it has a genuinely usable free individual tier alongside an affordable business plan. There's also a self-hosting option if you'd rather run the vault on your own server, which suits a technically minded team but isn't something most small businesses need to bother with.

1Password has some of the most polished apps of the bunch and a feature called Watchtower that automatically flags reused, weak, or breached passwords across your whole vault. There's no permanent free tier, only a trial, but the business console is well built and Travel Mode lets you temporarily hide sensitive vaults when crossing a border.

Dashlane and NordPass both bundle extras into some plans, a VPN in Dashlane's case, dark web monitoring in both. Keeper leans toward larger organisations and holds FedRAMP authorisation, which mostly matters if you're selling into US government contracts and need to prove it.

Prices and what's included in each tier change often enough that quoting a figure here would be out of date within months, so check the current plans directly on each vendor's site before committing. Any of these five beats a shared spreadsheet.

Rolling it out without a mutiny

Pick one plan and one person to champion it, rather than letting three different tools appear across the office. Set aside an actual session, an hour is usually enough for a small team, to migrate the passwords currently scattered across browsers and notebooks into the vault properly, rather than leaving it as a someday task nobody starts.

The master password matters more than any other setting in the whole system, because it's the one thing that isn't stored anywhere and can't be reset by the vendor. A long passphrase, four or five unrelated words strung together, beats a short complex-looking password that's actually easier to guess than it looks. And don't write it on a sticky note by the monitor. That's the exact habit the whole exercise is meant to fix.

Turn on two-factor authentication for the vault itself before anything else. It's now the single most valuable target in your business, holding every other password behind one lock, so it deserves a second lock, not just a password.

What happens when someone leaves

Without a proper admin console, this is a Friday afternoon nobody planned for: working out from memory which of a dozen shared logins the leaver could see, then changing every one by hand, hoping nothing gets missed. With one, it's removing the person from the console, then rotating anything genuinely sensitive they had access to. Minutes, not hours, and nothing left to memory.

Where this fits with compliance

UK GDPR expects "appropriate technical measures" to protect personal data, and unique, machine-generated passwords instead of reused ones are a reasonable, defensible part of meeting that. We should say plainly here: Alpha IT does not hold Cyber Essentials or Cyber Essentials Plus certification ourselves. Our security page is a self-assessment against recognised good practice, not a certification claim, and we've never suggested otherwise. If Cyber Essentials is a requirement for a specific tender or client contract, an accredited certification body is who to speak to about exactly what they'll accept. Our plain-English guide to the five controls is a reasonable starting point if you haven't looked at what's actually required yet.

The mistakes we see most often

A master password taped to the monitor, which defeats the entire point in about four seconds. Personal and business vaults mixed into one account, so a leaver walks out the door still able to see company logins from their phone. No two-factor authentication on the vault itself, turning one strong system into a single point of failure. And one shared login used by an entire team instead of individual named access, which is exactly the setup a password manager is meant to replace, not recreate inside itself.

Where Alpha IT comes in

This is exactly the kind of gap our health check tends to turn up: shared logins nobody's tracking, a leaver from months ago who technically still has access, or a master password that's one sticky note away from being useless. We'll help pick a plan that fits your team and budget, migrate what's scattered across browsers and notebooks, and set the admin console up properly so joiners and leavers stop being a fire drill. If credential theft leading to something worse is the scenario you're actually worried about, our first-hour ransomware guide covers what happens if a stolen password is how someone got in, and our guide to stopping email spoofing covers the other common way credentials get phished in the first place.

The short version

A password manager isn't a luxury tool for people who are paranoid about security. It's the fix for a problem every small team already has: passwords reused because remembering a unique one for every account is genuinely hard, shared logins nobody's tracking, and access that should have been revoked months ago. Pick one of the well-known names, turn on two-factor authentication for the vault itself, and set aside an hour to actually move everything in. That hour is the whole project.

Frequently asked questions

What's actually wrong with letting everyone save passwords in Chrome?+

Nothing catastrophic happens the first day. The problem shows up later. Browser-saved passwords don't get shared securely between colleagues, so people end up messaging plaintext logins over WhatsApp or email instead. There's no way to see who has access to what, no forced password strength, and if someone's laptop is compromised, whatever's saved in that browser profile is sitting right there in plain text. It works fine for a personal Netflix login. It's the wrong tool for a shared business account.

Do we need a paid business plan, or can everyone just get a free personal account?+

You can limp along on personal accounts, but you'll feel the gap fast. A business or team plan adds an admin console, so you can see who has access to which shared logins, add or remove people in seconds, and enforce a minimum password strength across the whole team. None of that exists on a personal account. If it's just you and one other person, a shared family-tier plan might genuinely be enough. Past three or four people, the admin layer earns its keep.

What happens to shared logins when someone leaves the company?+

This is the exact scenario a business plan is built for. Without one, someone leaving means manually working out which of your dozen shared accounts they had access to, then changing every single password by hand, and hoping you didn't miss one. With an admin console, you remove the person, then rotate anything sensitive they could see. It's a five-minute job instead of a Friday afternoon you didn't plan for.

Do we still need two-factor authentication if we're using a password manager?+

Yes, on two different things. Turn on two-factor authentication for the password manager account itself, ideally with an authenticator app rather than SMS, because that vault is now the single most valuable target in your business. Then keep two-factor turned on for email, banking and anything else that offers it, exactly as before. A password manager stores your second factor codes for convenience. It doesn't replace having one.

Which password manager should we actually use?+

That depends on your budget and how much admin control you want, and pricing changes often enough that we won't quote you a number here, so check current plans on each vendor's own site before deciding. Bitwarden is open source with a genuinely usable free tier and an affordable step up to business. 1Password has polished apps and a Watchtower feature that flags reused or breached passwords automatically. Dashlane and NordPass bundle a VPN or dark web monitoring into some plans. Keeper leans enterprise and holds FedRAMP authorisation, which mostly matters if you're selling into US government contracts. Any of the well-known names beats a spreadsheet.

Does using a password manager help with Cyber Essentials or GDPR?+

It genuinely helps with the access control side of both. GDPR expects “appropriate technical measures” to protect personal data, and unique, generated passwords instead of reused ones are a reasonable part of that. We should be upfront, though: Alpha IT doesn't hold Cyber Essentials or Cyber Essentials Plus certification ourselves. If you need it for a specific tender or client requirement, an accredited certification body is who to speak to about exactly what they'll accept, not us.

What if someone forgets the master password?+

This is the one real weakness of the whole approach, and it's worth planning for before it happens rather than after. Most reputable password managers can't reset a forgotten master password themselves, by design, because they don't store it. Business plans usually include an admin recovery option, so it's worth confirming that's switched on before you need it, and agreeing as a team where the master password itself gets written down as a backup, somewhere that isn't a sticky note on the monitor.

Can Alpha IT set this up for us?+

Yes. We'll help you pick a plan that fits your team size and budget, migrate what's currently scattered across browsers and spreadsheets, and set up the admin console properly so leavers and joiners are a two-minute job. It's the kind of thing our health check flags anyway, so if you're not sure where your business currently stands on this, that's a reasonable place to start.

Call usFree consultation