Every business we walk into has one. Sometimes it is a spreadsheet called “Logins” in a shared folder. Sometimes it is a document in the office manager’s email drafts. Sometimes it is a sticky note under a keyboard, a hiding place about as clever as the mat by the front door.
Nobody set out to do this. It grew. One shared login became five, then thirty, then a hundred and twenty, and by the time anyone noticed it was load bearing. Here is the good news: you can move an entire small business onto a real password manager in about a week of light effort. Not a quarter. A week. This is the playbook.
Why The Spreadsheet Is Worse Than It Feels
The spreadsheet feels safe because it is yours and it is right there. But it fails in ways that stay invisible until they are not.
- One file, total exposure. Anything that gets into that file gets everything at once. There is no partial breach of a password spreadsheet.
- Copies multiply silently. Somebody emailed it to themselves to work from home. Somebody else has it on a personal laptop. You cannot count the copies, so you cannot secure them.
- It quietly encourages reuse. When a human has to type a password, that password gets short, memorable, and reused everywhere. That is not a discipline problem. It is what happens when the system depends on memory.
- No record of who saw what. When someone leaves, you have no idea which credentials they knew, so the honest answer is all of them. Nobody ever changes all of them.
- It goes stale immediately. Half the entries are wrong, so people keep private lists on the side. Now you have a spreadsheet plus a dozen shadow spreadsheets.
None of this is theoretical. Verizon’s 2025 Data Breach Investigations Report found the human element involved in roughly 60 percent of the breaches it analyzed, and reported ransomware present in 44 percent of breaches reviewed. Credentials are the front door. If your front door is a spreadsheet, the lock is decorative. We covered that wider shift in why cybersecurity is no longer optional for mid sized businesses.
What A Password Manager Changes Day To Day
People expect a password manager to be a chore. Once it is in place, most staff stop thinking about passwords entirely, which is the actual goal.
- Logging in gets faster. The extension fills the field. No hunting through a spreadsheet, no calling the office manager, no “try Summer2019 with an exclamation point.”
- Passwords stop being human sized. Because nobody types them, they can be long and random. The current revision of NIST Special Publication 800-63B, “Authentication and Lifecycle Management,” published in August 2025, states verifiers “SHALL require passwords that are used as a single-factor authentication mechanism to be a minimum of 15 characters in length.”
- Sharing becomes a permission, not a copy. You grant access to a vault entry and revoke it when someone changes roles. The credential never travels by email or chat.
- You get an inventory for the first time. A dashboard showing weak, reused, and known compromised passwords is often the most useful thing to come out of the whole exercise.
- Offboarding takes minutes. Remove the person from the vaults, rotate the few credentials they genuinely used, done.
Worth knowing: the same NIST publication says verifiers “SHALL allow the use of password managers and autofill functionality.” Password managers are not a workaround. They are the assumed baseline in current federal guidance.
The One Week Rollout Plan
Spread this across a normal working week.
- Day one, admin setup. Pick a business tier product, not the free personal one, because you need central administration and recovery. Connect it to your company sign in, turn on multi factor authentication, name two administrators rather than one, and document recovery somewhere that is not inside the tool you would be recovering.
- Day one, build vaults by team. Create shared vaults matching how your business is actually organized: Accounting, Operations, Sales, Marketing, plus a small locked one for administrative credentials. Not a vault per application, and not one giant company vault.
- Days two and three, import week. Bulk import the spreadsheet, then have each team spend thirty minutes claiming and correcting their own entries. Everyone installs the browser extension and phone app, and as people log in during normal work the vault fills itself.
- Day four, amnesty. Announce that nobody is in trouble for anything they put in the vault this week. A personal password on a company account, a vendor login, an account nobody knew existed: all of it comes in, no questions asked. Skip this and people hide things, and the hidden things are the dangerous ones.
- Day five, fix the worst offenders. Run the built in health report and rotate passwords flagged as compromised or reused on anything touching money, email, or customer data. You do not need to rotate everything.
- Week two, turn off the old way. Delete the spreadsheet, including the copies you can find, and say so plainly. Leaving it “just in case” guarantees half your team keeps using it.
The Objections You Will Hear
Have real answers ready. Dismissive ones create quiet non compliance.
- “All our passwords in one place is more dangerous.” They are already in one place, and that place has no encryption, no access log, and no way to revoke anything.
- “What if the vendor gets breached?” Fair question. Ask how the vault is encrypted and whether the vendor can read your data. Then compare that to your spreadsheet’s answer, which is that anyone who opens the file reads everything.
- “I will get locked out of everything.” The real fear, and it deserves a real plan. Set up recovery on day one, keep two administrators, and test recovery deliberately before you delete the spreadsheet.
- “We have to change passwords every ninety days anyway.” Not according to current guidance. NIST Special Publication 800-63B, in its August 2025 revision, states verifiers “SHALL NOT require subscribers to change passwords periodically,” while also stating verifiers “SHALL force a change if there is evidence that the authenticator has been compromised.” The same document says verifiers “SHALL NOT impose other composition rules (e.g., requiring mixtures of different character types) for passwords.” Long and unique beats short and shuffled every quarter.
The Accounts Nobody Remembers Owning
Every migration turns up the same archaeology. A domain registrar under a former employee’s personal email. A payment processor tied to a phone number nobody has. Six marketing tools somebody signed up for during a busy quarter, three still billing you.
Work it from the money and the mail. Pull twelve months of statements and list every recurring software charge, then check your email system’s connected applications. Sort what you find into keep, cancel, and cannot identify. For that last pile, start recovery now while you still have billing evidence. Then move ownership of anything critical to a role based company address rather than a person’s mailbox.
The Bottom Line
The spreadsheet of passwords is not a failure by your team. It is what happens when a business grows faster than its systems. It just cannot keep working, because the number of accounts keeps going up and so does the cost of one bad day.
A week of light effort gets you long unique passwords everywhere, sharing without copying, an actual inventory, and offboarding that takes minutes. Features and pricing shift, so confirm current capabilities with any vendor before you commit. Do the amnesty. Delete the old file. Then never think about it again.
If you would rather not run this yourself, we do these migrations for small and mid sized businesses across Denton County and North Texas, including the unglamorous part where we track down the accounts nobody remembers owning. Contact us today
Sources:
Comments are closed