Why passwords matter more than you think
Most small business owners I talk to have a password system. It's usually the same password, with maybe a number on the end for different sites. AmazonPassword1. SagePassword1. BarclaysPassword1. They know it's not ideal, but it's manageable, and who's going to target a small building firm or a family-run cafe anyway?
The answer: nobody targets you specifically. They don't have to. The attack that catches people like Dave is called credential stuffing. It works like this: a big website gets hacked — LinkedIn, Dropbox, Adobe, take your pick — and millions of email-and-password combinations leak onto the dark web. Criminals then run automated scripts that try those same email-and-password pairs on hundreds of other sites: Gmail, online banking, Amazon, accounting software, domain registrars. They're not targeting you. They're targeting everyone who reused a password across multiple sites. If your email address and password from a 2019 data breach match your current Gmail login, they're in — and from there they can reset the password on everything else, because your email is the key to your entire digital life.
There's a common refrain I hear: "I've got nothing worth stealing." It's not true. Your email account alone is worth plenty — it's the gateway to resetting passwords on every other service you use. Your domain registrar account, where someone could redirect your website to a scam page. Your accounting software, with bank details, client addresses, and VAT records. Your social media business page, where a hijacker could post anything under your business name. Even a seemingly unimportant supplier login can be used to send fake invoices to your accounts team.
The fix isn't to become a security expert. It's to stop trying to remember passwords altogether.
How a password manager actually works
A password manager is an encrypted digital vault. You create one strong master password — the only one you'll ever need to remember — and the password manager remembers everything else. When you sign up for a new website, it generates a long, random password like Xk9#mP2v$Lq7@wR4 and saves it. When you return to that site, it fills in your login automatically. You never type the password. You never even see it unless you choose to.
Under the hood, everything in your vault is encrypted with military-grade encryption (AES-256, the same standard banks use). Even if someone stole Bitwarden's servers, all they'd get is scrambled data they can't read without your master password — and Bitwarden never sees your master password. The encryption and decryption happen on your device, not on their servers. This matters because it means there's nothing for a hacker to steal from the company itself.
You install the password manager on your phone (for apps and mobile browsing), as a browser extension on your computer (for websites), and optionally as a desktop app. All three sync automatically. Add a password on your phone, it's instantly available on your laptop. The browser extension is the clever bit — it detects when you're on a login page and offers to fill in your details. One click and you're in. No typing, no remembering, no sticky notes on the monitor.
Which password manager to pick
There are dozens of options. For a small business, three are worth looking at:
Bitwarden — free, open source, and what I recommend
Bitwarden is free for individuals and has a free plan for teams of up to two people. The code is open source, meaning security researchers can — and do — inspect it for flaws. It works on every platform: iPhone, Android, Windows, Mac, Linux, and every major browser. The free plan covers unlimited passwords, unlimited devices, and a basic password generator. The premium plan is $10 per year (yes, per year) and adds emergency access, advanced two-factor options, and security reports. For a small business with a team, the Families or Teams plans start at $3–4 per user per month and add shared Collections, so you can share the office Wi-Fi password or the supplier login with your staff without them seeing the actual password.
1Password — prettier, paid, and excellent
1Password is the premium option. The interface is polished, the onboarding is smooth, and it has a feature called Watchtower that alerts you when a website you use has been breached. It costs about $3–5 per user per month, with a 14-day free trial. It's a great product, and I use it personally — but for a small business watching costs, Bitwarden's free plan does 95% of the same thing.
Apple Keychain — built in, but limited for business
If your business is all-in on Apple devices — iPhones, Macs, iPads — the built-in Passwords app and iCloud Keychain are surprisingly capable. They generate strong passwords, autofill across Safari and apps, and sync through iCloud. The catch: they only work properly in Apple's ecosystem. If anyone on your team uses an Android phone or a Windows laptop, they're locked out. There's no shared vault for teams, and no way to share a password with a colleague without texting it to them. For a solo Apple user, it's fine. For a business with mixed devices, it's a non-starter.
Setting it up for your business — step by step
This is the part that puts people off, but I promise it's straightforward. Here's exactly what to do:
Step 1: Install Bitwarden everywhere
Go to bitwarden.com on your computer. Click "Get Started" and create a free account. Download the browser extension for Chrome, Edge, or Firefox — whichever you use. Go to your phone's app store, search "Bitwarden," and install the app. Log in once on each device with your master email and master password. That's the setup. It takes about ten minutes.
Step 2: Create your master password
This is the one password you need to remember, so make it count. The best method is a passphrase: four or five random words strung together, like correct-horse-battery-staple. It's long enough to be secure (cracking it would take centuries with current technology) and weird enough to remember. Add a number and a capital letter somewhere if the site requires it: Correct-Horse-Battery-Staple-42. Write this password down once — on paper, not in a file on your computer — and store it somewhere physically secure: a safe, a locked drawer, or a sealed envelope with a trusted family member. If you forget this password, you lose access to everything. That's by design — it means nobody else can get in either.
Step 3: Add your first few passwords
Start with the accounts that would hurt most if they were compromised: your email, your online banking, your accounting software, your domain registrar. For each one, log in as normal, and Bitwarden's browser extension will ask if you want to save the password. Say yes. For a stronger approach, use Bitwarden's password generator to create a new random password, update the account with it, and let Bitwarden save the new one. Do this for your top five accounts and you're already safer than 90% of small businesses.
Step 4: Set up Collections for sharing
If you have staff, you'll want to share some passwords — the office Wi-Fi, the shared supplier login, the social media accounts. In Bitwarden, you create a Collection (a folder of shared items), put the relevant passwords in it, and invite your staff member by email. They get access to log into those services without ever seeing the actual password. When someone leaves, you remove them from the Collection and they lose access instantly. No password changes needed, no awkward conversations, no risk of a former employee logging into your Instagram at 2 a.m.
Step 5: Turn on two-factor authentication
Two-factor authentication (2FA) means you need two things to log in: something you know (your master password) and something you have (a code from your phone). Even if someone somehow got your master password, they couldn't log into your Bitwarden vault without your phone. Bitwarden supports several 2FA methods — the simplest is an authenticator app like Google Authenticator or Authy. Install one, scan the QR code Bitwarden shows you, and you're protected. This step takes two minutes and it's the single biggest security upgrade you can make.
What to store in your password manager
Once you've added your obvious logins, here's what else belongs in your vault — things most people don't think to store until they need them urgently and can't find them:
- Bank and card details. Online banking logins, card numbers, sort codes, and account numbers. If your wallet gets stolen, you can pull up your card details to cancel them without hunting through paperwork.
- Email accounts. Your primary email is the most important login you own — it's the key to resetting everything else. Protect it accordingly.
- Social media business pages. Facebook, Instagram, LinkedIn, TikTok — any platform where your business has a presence. A hijacked business page is a reputational nightmare.
- Supplier and trade portals. Builders' merchants, wholesaler logins, trade discount sites. These often get set up once and forgotten until the password-reset panic.
- Domain registrar and hosting. If someone gets into your domain registrar account, they can redirect your website, intercept your email, and hold your domain to ransom. This login deserves a strong, unique password more than most.
- Accounting and payroll software. QuickBooks, Xero, Sage, FreeAgent, BrightPay — full of financial data, employee details, and HMRC credentials.
- Software licence keys. Microsoft Office, Adobe Creative Cloud, antivirus subscriptions, specialist trade software. Bitwarden has a "Secure Note" type specifically for storing licence keys and serial numbers.
- Wi-Fi passwords. The office network, the guest network, the router admin page. Share these through a Collection so new staff can connect on day one without you reading a password over the phone.
- Secure notes. Insurance policy numbers, key safe codes, alarm codes, server IP addresses, the phone number for your alarm monitoring company. Anything you'd be scrambling to find during an emergency.
- Client and project access. If clients give you logins to their systems — their WordPress site, their domain registrar, their social media — store them securely. Losing a client's credentials because they were in a spreadsheet on a laptop that died is an awkward conversation.
The master password — your one vulnerability
Your master password is the key to your entire digital life. If someone gets it, they get everything. If you forget it, you lose everything. That's the trade-off, and it's a fair one — but only if you handle it carefully.
Making it strong and memorable
We covered the passphrase method above: four or five random, unrelated words. The classic example from the webcomic xkcd is correct horse battery staple — easy to remember, hard for a computer to guess. The key is randomness. "Ilovemykids" isn't safe because it's a common phrase. "CorrectHorseBatteryStaple" is safe because those four words have no logical connection. Your brain remembers a strange image of a horse powering a battery-powered stapler more easily than it remembers Tr0ub4dor&3. Lean into that.
For a business, you can add a business-related twist: Vengera-Correct-Horse-Battery-2026!. The company name frames it, the words are the core, and the year and symbol satisfy any complexity requirements. Write this down on paper exactly once and store it physically. Never in a Notes app. Never in an email to yourself. Never in a Word document called "passwords.docx."
What happens if you forget it
Nothing. That's the point. Bitwarden cannot reset your master password because they don't know it. Your vault is encrypted with it, and without it the data is mathematically unrecoverable. This sounds terrifying, but it's why password managers work — there's no back door for a hacker to exploit, because there's no back door at all.
If you do forget, and you've set up emergency access (a premium feature that lets a trusted person request access to your vault after a waiting period you define), you can recover. If you haven't, and you've lost your paper backup, your vault is gone. This is why the paper backup in a safe or with a trusted family member matters. A sealed envelope in a fireproof safe. A safety deposit box if you're particularly cautious. The physical world is harder to hack than the digital one — use it.
Sharing with your team — without sharing your master password
Your master password is yours alone. Nobody else in the business needs it, and nobody should have it. Bitwarden's sharing works through Collections, not by sharing your login. Each staff member gets their own Bitwarden account with their own master password. You invite them to specific Collections — "Office Wi-Fi," "Social Media," "Supplier Logins" — and they see only what you choose to share. When they leave, one click revokes access. Their master password is their problem; your vault stays separate and secure.
How much time this actually saves
People resist password managers because they think it'll slow them down. The opposite happens. Every time you'd normally type a password — and retype it because you got it wrong, then click "forgot password," then wait for a reset email, then create a new password you'll forget next week — Bitwarden fills it in with one click. Over a working week, the minutes add up. More importantly, you stop dreading the "reset password" dance on sites you visit once a quarter.
From a security perspective, you go from one reused password to unique, unguessable passwords on every account. A data breach at some random forum you signed up for in 2018 no longer compromises your email, your bank, and your business. Each account is an island. That's the real value — not the convenience, but the peace of mind that one leak doesn't chain-react through your entire business.