Passwords Are Still Your Biggest Vulnerability
According to Verizon's annual Data Breach Investigations Report, stolen or weak credentials are involved in over 80% of hacking-related breaches. Not unpatched software. Not sophisticated zero-day exploits. Passwords.
The reason is straightforward: most people — and most businesses — have terrible password habits. They reuse the same passwords across multiple accounts, use predictable patterns ("Summer2024!"), or share login details with colleagues via email or sticky notes. Cybercriminals know this, and they exploit it systematically.
When one of those reused passwords turns up in a data breach — and breaches happen constantly — attackers use automated tools to try that same password against banking platforms, Microsoft 365 accounts, payroll systems, and anything else they can reach. This technique, called credential stuffing, is behind a huge proportion of business account compromises in Australia.
For a business, that means a single compromised password — from any breach, anywhere — could give an attacker access to your email, your file storage, your accounting system, and more. One breach becomes many.
What is a Password Manager?
A password manager is a secure application that stores all your login credentials in an encrypted vault. Instead of trying to remember (or reuse) passwords, you remember one strong master password. The manager handles everything else — generating unique, complex passwords for each account, storing them securely, and filling them in automatically when you need to log in.
Think of it like a digital safe-deposit box. Your passwords are locked inside with strong encryption. The manager holds the key, you hold the combination, and nobody — not even the password manager provider — can see what's inside without both.
For businesses, the value goes further. Team-focused password managers let you securely share credentials for shared accounts (like a social media login or a billing portal), manage access when staff change roles, and immediately revoke access when someone leaves — without needing to change every password manually.
The Real Cost of Poor Password Hygiene
Beyond the technical risk, poor password hygiene creates real, measurable business costs that most owners underestimate until it's too late.
Account compromise and data breaches
A single compromised Microsoft 365 account gives an attacker access to your emails, SharePoint files, Teams conversations, and potentially your clients' data. The ACSC reports the average cost of a cyber incident for an Australian SMB exceeds $49,000 — and that's before considering regulatory exposure under the Notifiable Data Breaches scheme.
Business email compromise (BEC)
Once inside your email account, attackers can impersonate you to redirect payments, request wire transfers, or deceive clients. BEC is one of the costliest cybercrime types in Australia — and it almost always starts with a compromised credential.
Offboarding gaps
When staff leave, do you know every system they had access to? Shared passwords that were never changed, or personal accounts used for business systems, are a common security gap. A password manager with centralised admin gives you a complete picture — and instant revocation.
Productivity lost to password resets
Forrester Research estimates that password resets cost an average of $70 per incident in IT support time. For a 10-person business with frequent resets, that adds up fast. A password manager virtually eliminates forgotten-password support requests.
Comparing the Main Options: 1Password, Bitwarden, and LastPass
Three names dominate the business password manager market. Here's how they compare for Melbourne SMBs.
1Password is the gold standard for business password management. Its Teams and Business plans include polished admin controls, detailed audit logs, guest access for external contractors, and integrations with single sign-on (SSO) solutions. The interface is intuitive enough that staff adoption is rarely a struggle — which matters more than people expect.
- Excellent team management and vault sharing
- Travel Mode for crossing borders securely
- Watchtower alerts for compromised or weak passwords
- Strong MFA support including hardware keys
- Integrates with Microsoft Entra ID (Azure AD) and Okta
Bitwarden is open-source, independently audited, and significantly cheaper than 1Password — making it a strong choice for cost-conscious businesses. It has all the core features you need: secure vault sharing, admin console, MFA support, and browser extensions for every major browser. Self-hosting is possible for businesses with specific data sovereignty requirements.
- Open-source and independently audited
- Most affordable business pricing
- Self-hosting option available
- Strong MFA support
- Slightly less polished UI than 1Password
LastPass was once the market leader, but suffered a significant breach in late 2022 in which encrypted password vaults were stolen. While LastPass maintains that properly secured vaults remain protected, the incident damaged trust significantly — and many businesses have since migrated to alternatives. If you already use LastPass and have strong master passwords and MFA enabled, the risk is manageable. For new deployments, we recommend 1Password or Bitwarden.
- Familiar interface and wide user base
- Good admin features on business plans
- 2022 breach involved theft of encrypted vaults
- Trust has been a concern since the incident
What Good Password Hygiene Actually Looks Like
A password manager is a tool, not a complete strategy. Here's what genuinely good password hygiene looks like when it's working correctly in a business context.
The Essential Eight includes "Multi-Factor Authentication" as a required control and recommends strong credential management practices throughout. A business-grade password manager directly supports Essential Eight compliance. Read our Essential Eight guide →
Rolling It Out: How to Get Your Team Using a Password Manager
The biggest challenge with password managers isn't choosing one — it's getting your team to actually use it. Here's a practical approach that works for most Melbourne SMBs.
- Start with leadership. If the business owner and senior staff aren't using it, no one else will. Adoption follows from the top.
- Run a short onboarding session. Most staff take 20–30 minutes to go from zero to fully set up. A group walkthrough — even over Teams — removes the friction that kills adoption.
- Migrate one department at a time. Don't try to move everything at once. Start with the team that has the highest security exposure (finance, legal, or whoever handles client data).
- Create shared vaults for shared accounts. Map out which accounts are shared across the team and migrate them into the vault with appropriate access controls. This immediately demonstrates the tool's value.
- Set a deadline for the old way. If people know they can still email passwords around, they will. Set a clear date after which shared credentials must live in the vault.
- Pair it with an MFA rollout. Password managers and MFA solve complementary problems — rolling them out together is more effective than doing them separately.
For businesses on a managed IT support plan, Melbit Services handles the full rollout — from choosing the right platform to configuring admin controls, migrating existing credentials, and training your team. Most deployments are complete within a week.
Frequently Asked Questions
What is a password manager?
A password manager is a secure application that stores all your login credentials in an encrypted vault. Instead of remembering dozens of passwords, you remember one strong master password. The manager generates, stores, and auto-fills strong unique passwords for every site and app you use.
Is it safe to use a password manager?
Yes — reputable password managers use strong encryption (AES-256) and zero-knowledge architecture, meaning even the provider cannot see your passwords. They are significantly safer than reusing passwords, writing them down, or storing them in a spreadsheet. Business-grade options like 1Password and Bitwarden also support MFA for the vault itself.
What's the difference between 1Password, Bitwarden, and LastPass?
All three are well-known options. 1Password is widely regarded as the gold standard for business use — polished, feature-rich, and with excellent team management tools. Bitwarden is open-source and the most cost-effective, making it a great choice for budget-conscious businesses. LastPass is well-known but suffered a significant breach in 2022, which has led many businesses to move to alternatives. For new deployments, Melbits generally recommends 1Password or Bitwarden.
Do password managers work with multi-factor authentication?
Yes, and you should use both together. A password manager ensures every account has a unique, strong password. MFA adds a second verification layer so that even if a password is somehow compromised, an attacker still cannot log in without the second factor. Used together, they address the two most common causes of account compromise.
What happens if I forget my master password?
Business plans include account recovery options — an IT administrator can recover team members' accounts without knowing their master password. Personal recovery options vary by provider but typically involve a recovery kit or emergency contact. This is one reason business plans are strongly preferred over personal accounts for work use.