The habit that turns one leak into every account
Reusing one password is a rational habit. You have a business to run and a dozen or more accounts to look after, and nobody can memorise a different long password for each of them. So one password gets used everywhere, and it works, sometimes for years. The trouble starts the day one of those accounts leaks. The password that opens that account also opens every other account using it, and a password that has leaked once keeps working until you change it everywhere. That is how one leaked account becomes all of them.
The old advice made the habit worse, and the government's own security centre says so. The National Cyber Security Centre has written that memorising lots of complex passwords is nearly impossible, which is what pushed people into reusing them in the first place, and that "Security that's not usable doesn't work". For passwords a person chooses themselves it recommends a minimum length and steering clear of anything guessable. It also says the random passwords a password manager generates are stronger still, and that hardly anybody uses one. This piece is about closing that gap without buying anything you do not need.
The order of the jobs matters more than either one, and it is the part the results pages get wrong. Search for this topic and you find page after page selling a manager built for a team, licences, admin consoles and shared vaults. The NCSC's own list runs the other way round: two-step verification comes "first, and most important", avoiding password reuse comes next, and a password manager comes after that so every account can finally have one of its own. The vault is the third job, not the first.
Two-factor authentication comes first
Two-factor authentication means a password on its own no longer opens the account. Logging in from a new device asks for a second thing too, usually a short code on your phone; you will see it called two-factor authentication, 2FA or two-step verification depending on the service. A criminal who has bought your password from a leaked list is still stuck, because they do not have your phone. That is why the NCSC puts the second step ahead of the vault: it protects the accounts you have tonight, with the passwords they already have, and it costs nothing.
Start with your email account, and the reason is blunt: whoever controls your mailbox can press the reset button on nearly everything else. The password resets for your bank, your bookkeeping and your supplier accounts all arrive at the same address. It is also the account most worth owning outright rather than borrowing from a broadband bundle, which business email address: free or your own domain explains in detail.
Most firms have not done even this. The Cyber Security Breaches Survey, the government's annual count, found 47% of UK businesses used some form of two-factor authentication, up from 40% the year before; among micro businesses, those with one to nine employees, the figure was 43%, up from 35%. Too small to be hacked? works through the rest of that survey, and the short version of this number is that the free, minutes-long job is the one most firms your size skip. The small business website security checklist gives it a single paragraph under item five; this section is that paragraph with the details filled in.
The free manager already in your pocket
A password manager is a simpler thing than the sales pages make it look. It is a locked list. You remember one master password, the manager remembers the rest, and because nothing ever needs typing from memory again, every account can finally have a different one. The administration layered on top is for teams; a firm of one needs the list and the lock.
You may already own one. Every mainstream browser will save passwords, fill them in and keep them in step across your own devices, and the NCSC says that is a legitimate way to do it: "It's safe for you to do this on your own devices and it's the easiest way to remember your passwords." For a one-person firm working from its own phone and laptop, that sentence is the whole case. The vault is free, it exists already, and turning it on is a settings toggle rather than a purchase.
It quietly helps against fake login pages too. A browser only fills a saved password into the site it was saved for; in the NCSC's words, "the password will only autofill on the correct website". A lookalike page built to harvest your bank login gets nothing, because the address is wrong and the browser knows it. Typing passwords from memory, or keeping them in a notes app, gives that protection up.
One rule comes with the browser vault, and the NCSC states it just as plainly: never save passwords in the browser on a shared or public device. The safety in the advice hangs on the devices being yours. And where a site offers a passkey instead of a password, take it: "The NCSC recommends making passkeys your first choice of login and using them wherever they are offered." A passkey is a way of logging in that lives on your own device instead of in a password, so there is nothing to remember and nothing for a leaked password list to contain.
When a paid manager earns its keep
The honest cut-off is sharing. The moment somebody else needs the same logins, a family member who does the books or a first employee, a browser each stops working, because the passwords stop belonging to one person. A paid password manager is built for exactly that: logins shared properly rather than emailed around, and a leaver's access switched off in one action instead of an afternoon of changing everything. Until that day arrives, paying for one buys little the browser has not already given you.
Choosing one does not require reading comparisons, because the NCSC publishes a buyers' guide and its criteria take a minute to read. The passwords stored in the manager should be encrypted. The key that unlocks them should be held by you alone, not by the company selling it, so nobody at the vendor can read what is inside. Multi-factor authentication belongs on any manager that syncs through the cloud. Autofill should only ever offer a password to the site it was saved for, never the whole list to whatever page asks. And the vendor should have a record of fixing security problems promptly when they turn up. Any manager that clears those five bars is a reasonable choice, and the choice between them matters far less than switching one on.
The objection worth answering is the one most owners raise first: is it not dangerous to keep everything in one basket? The NCSC's answer is direct: "we believe that the benefits outweigh the risks, and password managers will improve your security overall". The arithmetic behind it is the one from the top of this piece. Reusing one password everywhere means a single leak opens every account. A vault means a leak opens one account, and the one strong password guarding the rest is yours to make memorable, which is the recipe in the next section.
Two practical points come with the master password. Losing it means losing the vault, so it needs to be memorable rather than merely clever. And the manager's own account gets two-factor authentication like every other account, so a stolen master password on its own opens nothing; the NCSC makes the same point on the page above.
The twenty-minute setup, in order

Mailbox first. Turn two-factor authentication on for your email account, tonight if you can, because that one resets everything else. Registrar second: that is the company your web address is registered with, and whoever holds that login decides what happens to it when something goes wrong, so it gets its own unique password and a second step like any other account. Who owns your domain name covers checking that the account is really yours rather than your last web designer's, which is worth confirming rather than assuming.
Bank third, then anything else holding customer details. After those three, work down the rest as you meet them: over the next fortnight, every time you log in to something, switch its second step on where it is offered and let the browser save a fresh password while you are there. Nothing on the list needs a weekend, and the first three jobs take about twenty minutes between them.
For the one password you do have to invent, the master password, the NCSC's recipe is three random words. Three random words are long enough and strong enough, and nothing personal goes in: birthdays, pets and teams are all findable on social media. Do not bother swapping letters for numbers, a zero for an o and the rest, because criminals know every one of those tricks and the swaps add nothing. And if the fear is forgetting it, the NCSC is comfortable with passwords written down, provided the paper is kept somewhere safe. The vault's recovery codes belong on the same paper, in the same drawer.
The half the check can see
Everything this piece has covered sits inside your business, where no outside scan can see it. The free security check grades the other half: it reads your domain's public records and grades SPF and DMARC, the records that decide whether somebody can send email as your business, along with whether your site loads over HTTPS. It is passive, it takes seconds, and there is no sign-up.
Neither half catches what the other misses. A clean grade on the records does not put a second step on your mailbox, and a second step on the mailbox does nothing about a forged invoice. The check confirms the outside half in seconds; the passwords and the second steps are the inside half, and they are the part only you can do.
The questions that come up
Is it safe to keep all your passwords in one place? The NCSC's position is that the benefits outweigh the risks and a password manager improves your security overall. The honest comparison is with the habit most owners have now, one password reused everywhere, which is the same single basket with no lock on it.
Are passwords saved in the browser safe, or should I pay for an app? On your own devices the browser's saving is safe, and it is the NCSC's endorsed starting point. Paying earns its keep once logins are shared with staff or family, because shared vaults and tidy offboarding are what the paid products are actually for.
Do I need a password manager if I am a one-person business? You need unique passwords and two-factor authentication, and on your own devices the browser supplies both for nothing. Add a paid manager when a second person needs the same logins, not before.
What is two-factor authentication, in plain English? A second check when you log in, usually a short code on your phone, so a stolen password on its own no longer opens the account. The government's survey found only 47% of UK businesses use any form of it, which is why the twenty minutes it takes buys more than almost anything else on the list.
What happens if I forget my master password? The vault stays shut, which is why the recovery codes it offers at setup go on paper and into a drawer rather than into the vault itself. The NCSC is content with passwords written down when the paper is kept safe, and recovery codes are exactly that case.
What makes a strong password these days? Length and nothing guessable. Three random words beat a short password full of symbol swaps, because the words make it long and criminals already know the swaps. Better still, let the browser or a manager generate one: random passwords are the strongest kind, and the only kind you never have to remember.
The check grades the outside half in seconds. The passwords and the second steps are the twenty minutes that only you can spend.
