Password management for UK businesses: beyond the spreadsheet
Why shared passwords are still the most common breach route, and how to roll out a password manager and passkeys properly.
By the Telappliant team

Stolen and reused credentials remain the most common way UK businesses get breached. A password manager is not a nice-to-have piece of housekeeping; it is one of the highest-return security controls available to a small team.
Why the current approach fails
- The same password reused across work and personal services
- Shared logins for finance, social media and supplier portals in a spreadsheet
- Credentials pasted into chat threads and never rotated after someone leaves
- Browser-stored passwords syncing to unmanaged personal devices
- Forced 90-day rotation producing predictable, weaker passwords
What a business password manager changes
Every account gets a unique, long, generated password nobody needs to remember. Shared credentials live in role-based vaults rather than a spreadsheet, so access is granted and revoked centrally. Offboarding becomes a single action instead of an archaeology exercise, and you gain a defensible audit trail.
Passkeys and phishing-resistant MFA
Passkeys remove the password from the equation for supported services and cannot be phished the way a code can. Adoption is uneven, so plan for a mixed estate: passkeys where they are supported, app-based MFA with number matching elsewhere, and SMS only as a last resort.
Rolling it out so people actually use it
- Deploy to a pilot group and fix the awkward applications first
- Import shared credentials into role-based vaults before asking users to switch
- Enforce MFA on the password manager itself, without exception
- Rotate every shared credential during the migration, especially the old ones
- Train on browser and mobile use, because that is where adoption is won or lost
- Monitor the built-in breach and reuse reports monthly and act on them
How this maps to Cyber Essentials
Cyber Essentials expects unique credentials, MFA on cloud services, prompt removal of leavers and a defensible password policy. A password manager, combined with the leaver process it enables, is the simplest way to evidence all of those without inventing paperwork.



