Password Security for a Small Business Without an IT Department

The fix for the most common way small businesses get breached costs $4 per user per month and takes an afternoon. Stolen credentials are still the number-one way breaches begin, involved in 22% of confirmed breaches in Verizon's 2025 report. Not a zero-day. Not a hoodie at a dark terminal. Someone typing a username and password into a normal login page, and the site letting them in.
Start with the vault, not the passwords
This is the single move. Not longer passwords. Not a locked spreadsheet. One business password manager, every login in it, nobody reusing anything. You pick the team plan, add everyone on day one, and set up shared vaults for the logins people share: the bank, the registrar, the Google account, the social media accounts.
Bitwarden Teams runs $4 per user per month, and there is a free tier to start on. 1Password Teams costs a bit more and is smoother for non-technical people. The tool does not matter nearly as much as the policy: if a login is not in the vault, it does not exist.
Two details people skip. First, whoever owns the business also owns the admin account on the password manager. Second, the recovery codes for every important account go into the vault the day you set them up. A password manager without its own master password and recovery kit written down somewhere safe is a locked box with the key inside.
Then the five logins everyone shares
Almost every small business has the same five shared logins: the bank, the domain registrar, the website host, the Google or Microsoft account, and the social media accounts. These are the ones where people text passwords to each other or all memorize the same one. Move all five into a shared vault on day one, and rotate every password as you move it. Assume the old ones have been seen by everyone who ever worked there.
Say yes to passkeys
Passkeys are the thing that finally kills the password for good: your phone or computer signs you in with your fingerprint or face instead of a password. They cannot be phished, because there is nothing to type into a fake login page. Passkey adoption jumped 400% in 2024, and one in five Dashlane users already has at least one saved — the sites you use daily are starting to offer them.
The practical move: every time a service offers "sign in with a passkey," say yes. Do it for Google, Microsoft, and Apple first, because those are the keys to the rest of the accounts. Passkeys live alongside the password manager, not instead of it. The manager holds the oddballs; the passkey handles the big ones.
Two-factor on the accounts that matter
A password manager plus a passkey still leaves you exposed on the accounts that only have a password. Turn on two-factor authentication for email, the bank, the domain registrar, the website host, and anything that touches customer data. Use an authenticator app, not text messages — SIM swapping makes SMS the weak option, and the authenticator app is no harder to use.
For the two or three accounts that could actually end the business if they were stolen — email and the bank — consider a physical security key. About $25, plugs into a USB port, and phishing attacks simply bounce off it.
Do the setup together, once
This is the part that gets skipped without an IT department. Sit down with everyone, phones in hand, and walk through the setup together. The two complaints you will hear are "it takes too long" and "I will get locked out." Both die in the first week of use: the authenticator prompts are faster than remembering a password, and the recovery codes in the vault cover the lost-phone scenario.
Then make it policy, not a request. One holdout with "Summer2021!" on the shared accounts is the same as having no policy. Only about a third of American adults use a password manager — your team's habits are average, and average is what the attackers count on.
The offboarding list
When someone leaves, you need to know exactly which logins they had. Without a password manager, that list does not exist, and former employees keep old passwords working for months. With one, you revoke their vault access and rotate the shared passwords they used. Ten minutes, and the account is actually closed.