Cybersecurity
Guide

Choosing a Password Manager for Your SMB

Employees reusing passwords across personal and work accounts is the failure mode the NCSC specifically warns about. This guide covers what a password manager protects against, cloud vs. offline and browser-built-in vs. stand-alone, and how a rollout actually works once a whole team shares the tool.

Sep 18, 2026
8 min read
Choosing a Password Manager for Your SMB

Every employee in a Dutch SME now juggles logins for email, a CRM, accounting software, a handful of SaaS tools and probably a personal Gmail or Instagram account on the same laptop. The NCSC — the Nationaal Cyber Security Centrum, the Dutch national cybersecurity centre — points out a specific failure mode this creates: an employee reuses the same password for a personal account and a work account, that personal account gets caught in an unrelated data breach somewhere else, and the leaked password becomes a way in to the employer's systems even though the employer never did anything wrong. Accounts secured by a password alone are also more vulnerable to phishing than accounts with an extra authentication step. A password manager does not fix either problem by itself, but it removes the reason employees reuse passwords in the first place: nobody has to remember forty unique ones. This guide covers what a password manager actually protects against, the choices you have to make before rolling one out to a team, and what changes once several people share the tool rather than one person using it privately.

What a Password Manager Actually Solves — and Doesn't

A password manager is a tool that stores your login details behind a single master password or passphrase, so that's the only one you have to remember yourself. Beyond storage, it generates strong, unique passwords — long strings mixing upper- and lowercase letters, digits and punctuation — and because those passwords autofill only on the website they were saved for, the same autofill also works as a phishing check: a manager will not offer to fill your credentials on a look-alike domain the way muscle memory might.

That convenience concentrates risk in one place. The NCSC is direct about this trade-off: if an attacker gets into the password manager itself, they get every stored password at once. That is precisely why the master password matters more than any individual password it protects — the NCSC recommends at least 12 characters combining letters, punctuation and digits, and notes that a passphrase is often both easier to remember and more secure than a short complex string. A longer passphrase using only lowercase letters, at minimum around 16 characters, is safer than a short one packed with symbols. A handful of vendors now also offer "deterministic" managers that never store a vault at all — instead they recalculate each password from the master password and the site name every time, which removes the single point of failure but also removes the convenience of a shared vault, so it is a genuine trade-off rather than a strictly better option.

Losing the master password is its own risk to plan for. Recovery usually means proving you are the account owner, through identity verification or a backup recovery address, and some providers cannot restore access at all if that fails. Before you pick a manager for the business, check what its recovery process actually requires, not just whether one exists.

Cloud-Based or Offline: The First Real Choice

Most password managers keep your vault in the cloud, meaning you log in once and it works across your phone, browser and laptop wherever you are. If you'd rather control and secure the vault yourself, on your own server or device, an offline manager stores it locally instead, and you can only reach your passwords from the device that holds it. For a team spread across devices and, increasingly, home offices, a cloud vault is usually the practical default; an offline vault suits a single specialist workstation or a business that has a specific reason to keep credentials off a third party's infrastructure entirely.

Browser Built-In or a Separate App

Every major browser now offers to save your passwords itself and fill them back in automatically. It is convenient and needs no separate master password, but it comes with a real gap for a business: passwords saved in one browser do not reliably follow you to a different browser or a different operating system, so a Windows laptop, an iPad and an Android phone each build up their own inconsistent set unless everyone standardises on the same browser everywhere, which most SMEs cannot enforce. A stand-alone manager, installed separately from any browser, keeps the vault accessible regardless of device or browser choice, and typically adds features a browser's built-in store does not: warnings about weak or reused passwords, alerts when a saved site turns out to have been breached, and support for multi-factor authentication at login. That gap between the two is the practical argument for a dedicated tool once more than one or two people are involved.

What Changes at Business Scale

A personal vault and a business rollout are different problems. Most managers add a shared vault alongside each person's private one: anyone with access to that shared vault can see every password stored in it, which is useful for a shared device login or a tool the whole team touches, but exactly how sharing, revoking and auditing that access works varies by product, so it is worth testing with a real shared login before committing rather than assuming it works the way the last tool you used did. Free tiers are often a perfectly adequate starting point — check what the free version's business model actually is before relying on it — while paid tiers typically add extras like storing payment details or checking whether your saved passwords have shown up in a known breach, though which features sit behind a paywall differs by vendor, so verify what you're paying for against your team's actual needs rather than the marketing page.

Support is worth a specific check before you decide: most paid providers offer some level of help, but that help usually cannot get you back into the vault if you forget the master password, because the provider never has access to it either. That is a deliberate design choice, not a support gap, and it means the master password has to be written down somewhere secure rather than trusted entirely to memory.

Rolling It Out Without Losing Anyone

A rollout works best as a short pilot with one team before it becomes company policy: pick a group that already juggles several shared logins, get them through the setup and master-password choice, and use what breaks or confuses them to write the instructions everyone else gets. Provisioning and offboarding both need an explicit step from day one — add the shared vault to a new starter's checklist alongside their email account, and remove their access to it the same day their employment ends, not as an afterthought during a wider offboarding review. On the master password itself, the passphrase approach the NCSC recommends works well for training a team that has never had to memorise anything more complex than a birthday: a short made-up sentence with a capital letter, a number and a bit of punctuation mixed in is both easier to teach and harder to guess than a string of substituted characters.

None of this replaces two-factor authentication on the accounts that matter most. A password manager can generate and store the codes for a second login step, which is convenient, but the NCSC is explicit that having that extra layer never justifies a weak master password — the two protect different things. Email accounts and anything with administrative access to cloud services or your network deserve their own MFA on top of whatever the password manager does.

If a Password Turns Up in a Leak

If you suspect a password has been exposed, whether from a phishing attempt or a breach at a service you use, you can check it yourself: the Dutch police run Check je Hack, and HaveIBeenPwned indexes a large set of known breached credentials. If a password does turn up, change it immediately and enable two-factor authentication if you have not already, especially for email and any account with business-critical access. When choosing a replacement password, avoid predictable sequences like appending a number that increases each time you're forced to change it, and never reuse a password you have set for anything else.

FAQ

Is a free password manager good enough for a small business? Often, yes, as a starting point — the NCSC notes a free tier can suit your needs perfectly well, though it is worth checking what the provider's business model actually is before relying on it long-term. Paid tiers typically add extras like breach checking or payment-detail storage, and which of those sit behind the paywall differs by vendor.

What is the difference between a browser's built-in password manager and a separate app? A browser-based manager is convenient and needs no extra master password, but it does not reliably sync passwords between different browsers or operating systems. A stand-alone app works across any browser or device and usually adds features like weak-password warnings and breach alerts that a browser's built-in store does not.

What happens if I lose the master password? Recovery depends on the provider, and usually means proving you are the account owner through identity verification or a backup email address. Some providers cannot restore access at all if that fails, which is why the master password needs to be written down and stored securely rather than left to memory alone.

Does everyone on the team need to use the same password manager? Not strictly, but a shared vault only works if everyone who needs access uses the tool it belongs to, and how sharing and revoking access works differs between products. Standardising on one manager for shared and business logins, even if some people keep a personal vault elsewhere, makes provisioning and offboarding far simpler to manage.

Is a password manager legally required under the AVG or NIS2? No. Neither law names a password manager as a specifically required tool, and this article doesn't rely on either to make the case for using one. The practical reason to use one is reducing password reuse, not a compliance checkbox.

Rolling out a password manager well is less about picking a product and more about the process around it: provisioning, offboarding, master-password training, and deciding what still needs its own MFA on top. Our Cybersecurity & Identity service builds exactly that process for teams that would rather not work it out by trial and error, and our Managed IT Support team can run the pilot, the training and the day-to-day requests — like a locked-out new starter — once it's live.

Cybersecurity
Password Security
Identity Management
SMB

Related Articles

Cybersecurity

AI-Powered Cybersecurity: How Machine Learning Is Transforming Threat Detection

Cyberattacks are growing in volume and sophistication. AI-powered security tools are shifting the balance back to defenders. This article examines how Dutch organisations are using ML-driven SIEM, EDR, and threat intelligence to stay ahead.

Read More
Cybersecurity

NIS2 for SMBs: What the Law Means and What You Must Arrange

The Dutch Cyberbeveiligingswet (NIS2) lands in 2026 and brings duty of care, a 24-hour reporting duty and personal director liability. Here is who is in scope, what you must arrange, and a practical step-by-step plan for SMBs.

Read More
Cybersecurity

Preventing Ransomware in the SMB: 8 Measures That Actually Work

SMBs are now the primary target for ransomware precisely because attackers assume their defences are weak. The good news: a handful of well-implemented measures stop the vast majority of attacks. Here are the 8 that deliver the most protection per euro.

Read More

Need Help with Your IT Infrastructure?

Let's discuss how we can help transform your IT operations with modern solutions.