On almost every first visit to a new client we find them: the Excel list with every login, the notebook in the drawer or the sticky note on the edge of the monitor. Nobody does this out of carelessness. An office of ten people quickly ends up with two hundred logins, and they have to be written down somewhere.
The real problem isn’t the note itself but what follows from it. Because nobody can remember two hundred passwords, the same one gets used everywhere. If it’s stolen from a web shop, attackers automatically try it on email, the VPN and online banking.
What a password manager actually does
A password manager is an encrypted vault for login details. You remember one long master password. The program generates all the others, long and random, and fills them in automatically when you sign in.
For a business, three features matter most:
- Shared vaults. The team password for the supplier’s web shop lives in a shared folder. New staff get access, and people who leave lose it with one click.
- Warnings. Good tools flag passwords that are weak, reused or show up in a known data breach.
- Audit trail. You can see who opened which entry and when.
Cloud or self-hosted?
The well-known providers store the vaults encrypted in their cloud. That works well and is secure, as long as the master password is strong and sign-in is protected with a second factor. If you’d rather keep your data in-house, a solution like Vaultwarden can run on your own server or in a Swiss data centre. The apps and browser extensions are the same; only the storage location changes.
For most SMEs, where the vault lives matters less than whether everyone is actually using one.
Getting the rollout right
Password managers rarely fail because of the technology. They fail because of habits. This order has worked well for us:
- Start with management and the people who handle the most logins.
- Move the shared accounts first. The benefit is immediate because nobody has to ask around anymore.
- Give the team a half-hour introduction, ideally on their own screens.
- Only delete the old Excel list once everything has been moved. Then actually delete it.
- After a few weeks, go through the warnings and replace weak or reused passwords.
One important point: the master password and recovery code don’t belong in the vault. A printed emergency sheet in the office safe is, for once, exactly the right place.
What it costs
Business plans from the major providers usually cost a few francs per person per month. A self-hosted solution has no licence fee but needs some effort for operation and backup. Compared with the damage of a hijacked mailbox, both are small amounts.
How we help
We choose the right password manager with you, set up the vaults, move your existing logins and show your team how to work with it. Together with multi-factor authentication, this closes the most common gap of all. More under IT security.
Frequently asked questions
Isn’t it risky to keep all passwords in one place?
The vault is encrypted so that not even the provider can read it. The risk is much lower than with reused passwords, provided the master password is strong and protected by a second factor.
Isn’t the browser’s password storage enough?
For private use, maybe. In a business it lacks shared folders, central management and a clean way to revoke access when someone leaves.
What happens if someone forgets their master password?
With business solutions, an administrator can restore access if this was set up in advance. That’s why recovery is part of the rollout.
Can we host Vaultwarden ourselves?
Yes. It runs lightly in a container but needs regular updates and a backup. We’re happy to take care of that for you.

