Password managers are the highest-return security purchase a small business can make, and the reason is not the passwords themselves.
Credential-based attacks — phishing, reused passwords, credentials from a breach somewhere else — account for a large share of small business compromises. Antivirus does not stop those. A password manager plus enforced multi-factor authentication does, and costs less than almost anything else on your software bill.
What Business Plans Add
Personal licences on business machines are the common mistake, and the gap is not features.
Central administration. You can see who has access to what, enforce policy, and revoke someone in seconds rather than hoping they forget.
Shared vaults. Credentials for the company Twitter account, the domain registrar and the hosting panel live somewhere defined, not in a WhatsApp message from 2023.
Offboarding. When someone leaves, you remove their access and the shared credentials stay. Without this, offboarding means changing every shared password by hand, which nobody does.
Recovery. An administrator can recover an account when someone forgets their master password. Personal plans generally cannot.
That last one matters more than people expect. Zero-knowledge encryption means nobody can help you — business plans solve this with administrator recovery keys.
The Twelve
1. Bitwarden
The default recommendation. Open source, independently audited with published results, and priced well below most competitors for teams. Self-hosting is available if you want your vault on your own infrastructure.
The free tier is genuinely usable for individuals, which makes it easy to trial personally before rolling out.
Suits: most small businesses. Give up: some interface polish. Functional rather than delightful.
2. 1Password
The most polished, and architecturally the strongest. Its Secret Key — a 128-bit key generated on your device and never sent to the server — means a breach of 1Password’s servers does not expose vaults to offline brute-forcing.
App quality genuinely matters here: a password manager only works if people use it, and 1Password is the one non-technical staff adopt without complaint.
Suits: teams where adoption is the risk, developer teams (the CLI and SSH tooling are best in class). Give up: no free tier, no self-hosting.
3. Keeper
Strongest on compliance — detailed audit reporting, granular admin controls and extensive certifications.
Suits: regulated industries, or businesses answering security questionnaires. Watch: add-ons priced separately.
4. Dashlane
Polished, with dark web monitoring and a VPN on some plans.
Watch: Dashlane discontinued standalone desktop apps in favour of a browser-based experience, which some users dislike.
5. NordPass
From the Nord family, using XChaCha20 encryption. Straightforward and competitively priced, especially if you already buy NordVPN or NordLayer.
6. Proton Pass
Swiss jurisdiction, part of the Proton suite, with hide-my-email aliases that genuinely reduce spam and limit breach exposure.
Suits: businesses already on Proton, or where jurisdiction matters.
7. Vaultwarden
A lightweight community-built server implementing the Bitwarden API, self-hosted. Free, and you use the official Bitwarden clients against it.
Suits: technical teams wanting full control at no licence cost. Watch: you own backups, updates and uptime — and losing the server without a backup means losing every vault.
8. Psono
Open source, self-hostable, designed for teams with granular sharing.
9. Passbolt
Open source and self-hostable, built specifically for teams rather than adapted from a consumer product.
10. Zoho Vault
Good value, particularly within the Zoho ecosystem, with admin controls and shared folders.
11. Enpass
One-time purchase option, storing your vault in your own cloud storage rather than the vendor’s.
Suits: businesses that object to subscriptions specifically.
12. Your browser’s built-in manager
Named honestly. Chrome, Safari, Firefox and Edge all store passwords, sync across devices and generate strong ones.
Better than reusing passwords, and unsuitable for a business — no shared vaults, no admin visibility, no offboarding, and everything tied to a personal browser profile. Use it as a stepping stone, not a destination.
How They Compare
| Product | Free tier | Self-host | Open source | Best for |
|---|---|---|---|---|
| Bitwarden | Yes, generous | Yes | Yes | Most small businesses |
| 1Password | No | No | No | Adoption, developers |
| Keeper | Limited | No | No | Compliance, audit |
| Dashlane | Limited | No | No | Polish, monitoring |
| NordPass | Yes, limited | No | Partially | Nord ecosystem, value |
| Proton Pass | Yes | No | Yes | Proton users, aliasing |
| Vaultwarden | Self-host free | Yes | Yes | Technical teams |
| Psono | Self-host free | Yes | Yes | Team sharing, control |
| Passbolt | Self-host free | Yes | Yes | Team-first design |
| Zoho Vault | Limited | No | No | Zoho users |
| Enpass | Limited | Your cloud | No | Avoiding subscriptions |
Pricing is per user per month for hosted options and changes regularly. Verify current business tier pricing directly.
Passkeys Change the Picture
Worth understanding, because it affects what you should buy now.
Passkeys replace passwords with cryptographic key pairs — nothing shared, nothing to phish, nothing to reuse. Adoption is growing steadily across major services.
Two implications:
Choose a manager that stores passkeys. All the major products now do. Keeping passkeys in a cross-platform vault avoids being locked into one device ecosystem, which is what happens if you let Apple or Google hold them exclusively.
Passwords are not going away soon. Plenty of business software, banking portals and legacy systems will require passwords for years. You need both.
Rolling It Out Without It Failing
Most small business rollouts fail on adoption, not technology.
- Set up shared vaults first, before inviting anyone. Decide what goes where — company accounts, department-specific credentials, per-person vaults.
- Enforce multi-factor on the manager itself. The vault is now your highest-value target.
- Import from browsers. Every manager imports from Chrome, Safari and Firefox. Do this in the onboarding session so people start with their existing logins already there.
- Run the breach report. Every product flags reused, weak and breached credentials. Fix the top twenty in week one — this is where the actual security improvement happens.
- Add it to offboarding. Write “revoke password manager access, rotate shared credentials they knew” into your leaver checklist.
- Do not mandate it without training. Fifteen minutes live prevents months of people keeping a spreadsheet alongside.
Common Mistakes to Avoid
- Personal licences on business machines. No admin visibility, no shared vaults, no offboarding — and terms often prohibit business use.
- Not enforcing MFA on the vault. It is now the single most valuable credential you hold.
- Sharing credentials outside the manager. If the culture is to paste passwords into chat, the software changes nothing.
- Skipping the breach report. The highest-value thing the software does, and routinely ignored.
- Self-hosting without backups. Vaultwarden or Passbolt means losing the server can mean losing every vault.
- No offboarding process. Removing someone’s access without rotating shared credentials they knew is incomplete.
- Storing the recovery kit inside the vault. People genuinely do this. Store it physically.
- Choosing on price alone. The annual difference is small next to one credential-based compromise.
FAQs
What is the best password manager for a small business?
Bitwarden for most — open source, audited, well priced for teams, with self-hosting available. 1Password if adoption is your risk or you have developers. Keeper if you have compliance obligations.
Is a free password manager safe for business?
Bitwarden’s free tier is genuinely secure but lacks the business features — shared vaults, admin controls, offboarding — that are the reason to buy. Use free personally, pay for the team.
Can I just use my browser’s password manager?
Better than reusing passwords, and unsuitable for a business. No shared vaults, no admin visibility, no offboarding, and credentials tied to personal browser profiles you do not control.
What happens if someone forgets their master password?
On business plans, an administrator can usually recover the account through a recovery key. On personal plans with zero-knowledge encryption, generally nothing can be done. This is a real reason to use business plans.
Should we self-host?
Only with someone who will own backups, updates and uptime. Vaultwarden and Passbolt remove licence costs and hand you responsibility for the most sensitive data in the company. Losing the server without a backup loses every vault.
Do password managers support passkeys?
The major products now store and use passkeys. Keeping them in a cross-platform vault rather than a single device ecosystem is worth doing deliberately.
Key Takeaways
- Central admin, shared vaults and offboarding are what business plans buy — not features.
- Bitwarden for most small businesses; 1Password where adoption is the risk.
- Enforce MFA on the vault itself; it is now your highest-value credential.
- Run the breach report in week one — that is where the security gain actually is.
- Add credential rotation to your offboarding checklist, not just access removal.
Where to Start
Try Bitwarden’s free tier yourself this week and import your browser passwords. Run the breach report. If what you see concerns you — and it usually does — roll it out to the team with shared vaults set up in advance.
For detail, see our 1Password review, LastPass vs 1Password, and 1Password alternatives.
