Rollouts
How to stop staff reusing passwords (without being the IT guy)
A one-week owner-manager plan: tool choice, shared logins first, MFA, and a two-line house rule.
If you run a business with 5 to 50 people, you already know the pattern. Someone picks one "strong enough" password in 2019, then uses it on Gmail, Xero, the shop's Shopify, and the shared supplier portal. When that password shows up in a breach dump months later, every one of those accounts is suddenly a candidate for takeover.
This is not about lazy staff. It is about human limits. People cannot invent and remember unique, long secrets for dozens of tools. Without a system, reuse is the rational shortcut.
For UK SMEs the damage is practical, not theoretical: locked Microsoft 365, fraudulent invoice redirects, customer data exposed, and days of recovery while you are still trying to serve clients. The National Cyber Security Centre (NCSC) has been clear for years that password managers beat complexity rules and forced monthly rotations. The goal of this guide is a rollout you can finish in a week without becoming the unofficial IT department.
What "stop reuse" actually means
Stopping reuse is not a poster in the kitchen or a stern email. It means three concrete outcomes:
1. Every person has a unique password for every work account they use. 2. Those passwords are generated and stored in a shared company vault, not in browsers, sticky notes, or personal memory. 3. Shared business logins (bank, Companies House, supplier portals) live in named vault items with clear owners, not in a WhatsApp thread.
If you only achieve those three, you have already cut the most common account-takeover path for small firms. Fancy policies can wait.
The one-week rollout (owner-manager version)
Day 1 — Decide the tool and who pays.
Pick one business password manager for the whole company. For most UK SMEs under 50 seats, the shortlist is 1Password Business or Bitwarden Teams/Enterprise (see our earlier comparisons). Pay on a company card. Do not let people buy personal plans and "share somehow". One bill, one admin, one vault structure.
Day 2 — Create the company account and invite everyone.
Turn on SSO later if you have Microsoft 365 Business Premium and want it. Day one is simpler: invite every mailbox that touches work systems. Set yourself (or one trusted ops person) as the only person who can delete the organisation. Store the emergency recovery kit offline, not in the vault it protects.
Day 3 — Migrate the dangerous shared logins first.
Before personal habits change, move the accounts that can bankrupt you: banking, HMRC / Agents, Companies House, domain registrar, hosting, Microsoft 365 global admin, Xero/FreeAgent, payment processors, and any supplier portal that can change bank details. Put each in the vault with a unique password rotated on the day you import it. Note the owner in the item notes.
Day 4 — Staff import and generate.
Ask everyone to install the desktop app and browser extension, then:
- Create a new unique password for their email (if not already on SSO).
- Create unique passwords for the five tools they use most.
- Delete saved passwords from Chrome/Edge for those work sites once the vault copy works.
Give them a 30-minute window and a written checklist. Do not run a two-hour seminar.
Day 5 — Kill the anti-patterns.
Ban shared Google/Microsoft personal accounts for company work. Ban password lists in Notion, Confluence, or Excel. Ban "reply all with the Wi-Fi password". Replace with vault items and, for Wi-Fi, a separate guest network password you can rotate.
Day 6 — Spot-check.
Pick five people at random. Confirm they can unlock the vault, open one shared item, and generate a new password. Fix blockers the same day (extension permissions, MFA on the vault itself, forgotten master passwords).
Day 7 — Write the two-line house rule.
Example: "All work passwords live in [Product]. Unique passwords only. Shared business logins only via vault items." Put it in the staff handbook and the onboarding checklist. That is your policy. You do not need a 12-page information security manual to start.
Make the password manager the path of least resistance
Reuse dies when the manager is faster than memory. That means:
- Browser extension autofill on by default for work profiles. • Mobile apps for people who approve invoices on phones. • Vaults or collections per team (Finance, Ops, Sales) so people are not drowning in irrelevant items. • A clear rule for leavers: revoke their seat the day they leave, rotate every shared item they could open.
If the tool feels heavier than "same password everywhere", people will quietly go back. Spend your energy on ease, not lectures.
MFA without the chaos
A password manager stops reuse. Multi-factor authentication (MFA) stops many stolen-password logins. For UK SMEs, prioritise MFA on:
- Microsoft 365 / Google Workspace • Banking and finance tools • The password manager itself • Domain and hosting panels
Prefer app-based or hardware keys over SMS where the product allows it. Store backup codes in the vault. Do not put MFA solely on one person's personal phone with no spare.
What to tell staff (short script)
You do not need a fear talk. Use something like this:
"We are moving all work logins into a company password manager so nobody has to invent or reuse passwords. It takes about 30 minutes. Unique passwords become automatic. Shared business accounts move out of chats and spreadsheets. If something feels blocked, message [name] the same day."
Offer a single help channel. Ambiguous "ask IT" with no IT person is how rollouts stall.
Common failure modes (and the fix)
1. Half the team never installs the extension. Fix: make day-4 a diary block, not optional homework. Check installs in the admin console.
2. Shared passwords stay in the old Excel sheet "just in case". Fix: after migration, delete or archive the sheet and say so in writing.
3. Owner keeps the only vault recovery kit in their laptop bag. Fix: duplicate recovery materials in a sealed envelope at home or with your accountant, with a dated note of where they are.
4. Contractors get full vault access forever. Fix: guest or limited collections, end dates, and a leaver checklist tied to their last invoice.
5. People still reuse for "unimportant" sites. Fix: remind them that the unimportant site is often where the password dump starts. The manager makes uniqueness free, so there is no unimportant exception.
When affiliate IDs are live, place CTAs here (no live tracking links yet):
Above each CTA, keep a one-line disclosure: "We may earn a commission if you buy through this link."
Quick checklist you can copy
- One company password manager, one admin, company billing □ Emergency recovery kit stored offline (two places) □ Banking, M365 admin, domain, finance tools rotated into the vault □ Every staff member invited with app + browser extension □ Top five personal work logins uniqued per person □ Shared Excel/Notion password lists deleted □ MFA on email suite, bank, vault, hosting □ Leaver process: revoke seat + rotate shared items □ Two-line house rule in handbook and onboarding
Written for UK SME owners. More guides · How we make money