A good password manager generates a unique, complex password for every account, stores it in a vault only you can decrypt, and makes those credentials easy for your team to use and share safely. For a business, the ones worth paying for add zero-knowledge encryption, separate team vaults, admin reporting and access controls. Here is why that matters, and which one we recommend.
The average person now has 156 online accounts
The average person currently has around 156 online accounts, and that number keeps climbing. Most people handle that load one of two ways: the same password everywhere, or small variations on a single password; swapping a number, adding an exclamation mark at the end. Both fail for the same reason, and it has a name…
What is credential stuffing?
Credential stuffing happens when an attacker breaches a website. Usually a smaller, less secure one and walks away with a list of email addresses and passwords. They then feed that list into automated tools that try the same combination against hundreds of other services: your email, your banking, your social accounts, your accounting software, your Microsoft 365 tenant.
The breach that exposes you is rarely the one that matters. A forum you signed up to in 2014 can hand an attacker the keys to your business email today.
There are three reliable defences against it:
- A unique, complex password on every service
- Two-factor authentication (2FA)
- Passkeys
The first is where a password manager earns its place.

What is a good password manager? Five things to look for
Any password manager will store passwords. What separates a good one from a merely convenient one is how it protects the vault, and how well it holds up once more than one person is using it.
1. Zero-knowledge encryption
Your vault should be encrypted on your device, with a key the provider never holds. If the provider itself is breached, attackers should walk away with nothing but unreadable data.
2. Strong generation and autofill
A good manager fills the “create a password” box automatically with a brand-new complex password and saves it before you have finished signing up. If it takes effort, staff will not use it and a tool nobody uses protects nobody.
3. Separate vaults and controlled sharing
Your HR team should see the HR vault and nothing else. Directors see everything. Every user gets a personal vault. Sharing a login with a colleague should never mean pasting it into a chat message or an email.
4. Admin visibility and reporting
You need to see reused passwords, weak master passwords, credentials caught up in known breaches, and who has access to what; before an auditor or an attacker tells you.
5. Access controls
Business-grade tools let you restrict sign-ins by IP address or location, so a company vault cannot be opened from outside your office, or from outside Australia.
Browser password managers vs dedicated online safety software
Google Password Manager and Apple iCloud Keychain together account for more than half of all password manager use, largely because Chrome dominates the browser market and Keychain ships on every Apple device. They are genuinely better than reusing one password, and we would far rather a client used Chrome’s manager than nothing at all.
But they are consumer tools. They are tied to a single browser or ecosystem, they offer almost nothing in the way of team structure, and they give a business owner no visibility at all. The moment credentials are shared between staff, or between someone’s personal life and the business, you need dedicated online safety software built for teams, not a browser feature.

Which password manager does Nexlo recommend?
We use and recommend 1Password, both internally and for our clients. The reason comes down to one design decision.
In 2022, LastPass suffered a breach in which attackers obtained encrypted customer vaults from its cloud storage. The encryption itself held, but it meant that any customer with a weak master password was, in principle, one offline brute-force attempt away from having every credential exposed.
1Password protects against precisely that scenario with a Secret Key: a long, randomly generated key created on your device when you set up your account. 1Password never sees it and cannot recover it. Opening your vault requires both your master password and the Secret Key, so even a stolen vault file is useless to an attacker, and even a weak master password does not sink you.
For teams, 1Password delivers the vault separation, reporting and sign-in restrictions described above, plus the ability to grant and revoke staff access in seconds as people join and leave.
Two-factor authentication and passkeys
Two-factor authentication
Microsoft’s analysis of account compromises found that 99.9% of them involved accounts without multi-factor authentication enabled. 2FA adds a second check on top of your password: something you know (the password) and something you have (your device).
Use an authenticator app such as Microsoft Authenticator or Google Authenticator. Avoid SMS and email codes wherever you can, both are the most easily intercepted, whether through SIM swapping or a mailbox that has already been compromised.
Passkeys
Passkeys are the newest and, technically, the strongest option, which is why Amazon, Google, Apple and Microsoft have all been pushing them so hard.
When you create a passkey, your device generates a pair of keys. The public key goes to the website; the private key never leaves your device and is unlocked by your fingerprint, face or PIN. To sign in, the website sends a challenge, your device signs it with the private key, and the website verifies that signature against the public key it holds. No shared password ever sits on the server, so a breach of that website gives an attacker nothing to steal.
Passkeys are also phishing-resistant by design, because each one is bound to the exact domain that created it. If your passkey was made on amazon.com and you click a phishing link through to amazonn.com, the passkey simply will not activate. No amount of convincing branding changes that.
The trade-off is recovery: getting back into an account secured by a passkey can be harder than a standard password reset, which is worth planning for before rolling them out across a team.

Passwords are one layer, cloud email security is the other.
Password hygiene solves half the problem. The other half arrives in the inbox.
Over 90% of successful cyberattacks start with a phishing email, and the goal of most of them is credential theft: a convincing fake login page that harvests whatever your staff member types in. A password manager helps here, because it will not autofill on a lookalike domain, but it is not a filter.
This is why cloud email security services for small business belong alongside a password manager rather than instead of one. Cloud email security sits in front of Microsoft 365 or Google Workspace and blocks phishing, spoofing, impersonation and malicious attachments before they reach anyone. Combined with 2FA and a managed password policy, that gives you a layered defence: stop the message, stop the reuse, stop the login.
The password policy every small business should have
In the small business market, we consistently see the line between personal and business credentials blurred; owners who started the company years ago still sharing logins across both. It is a genuine exposure, and most IT providers have very little visibility into how a business adopts new software in the first place.
We think every small business should be running:
- No repeated passwords across services
- Passkeys wherever the service supports them
- 2FA on every account that offers it, via an authenticator app rather than SMS
- A company-wide password audit at least annually
- A managed password manager, with vaults and access reviewed as staff change
- Cloud email security in front of Microsoft 365 or Google Workspace
Get a free password and security audit from Nexlo
Not sure where your business currently stands? Nexlo will run a free password and account security audit for you. We review how credentials are stored and shared today, check your accounts against known breach data, identify where 2FA and passkeys should be switched on, and assess whether your email is properly protected.
You get back a plain-English report with a prioritised recommendation: which password manager suits your team, what it will cost, and what we would fix first. No jargon, no obligation. Nexlo is a Central Coast managed IT provider working with businesses across the Central Coast, Sydney, Newcastle and regional NSW, and we are always one call away. Get in touch to book your audit.

