Managed security
Password Management
Stop reusing the good one.
Managed password management gives every person a private encrypted vault and every team a proper way to share the credentials they genuinely have to share, then removes the spreadsheet, the sticky note and the one good password used in nine places. happier IT deploys it, does the work that gets people actually using it, and monitors for credentials of yours that surface in somebody else’s breach.
Who it's for
This is a habit problem wearing a software costume.
The technology has been solved for years. What has not been solved is getting a busy team to change how they do something forty times a day.
There is a shared spreadsheet. Or a document, or a group chat, or one person who knows all the logins. Every organization has a version of this, and it exists because sharing credentials is a genuine daily need with no obvious sanctioned answer.
Someone left and you changed eleven passwords by hand. Slowly, over two days, hoping nobody had missed any. With shared vaults, removing one person’s access takes a minute and does not require anybody to remember what they had.
You bought a vault and half the company never opened it. The licence renews annually and adoption stopped at the rollout email. Adoption is the actual product here, and it is the part almost nobody sells you.
The same password protects the bank and a forum from 2014. Not carelessness, a reasonable human response to being asked to invent and remember sixty distinct strings. The fix is to stop asking people to remember them.
Second control, not first
If MFA, multi-factor authentication, a second check such as a prompt on a phone before a login is accepted, is not yet on every account, spend the money and the attention there first.
MFA makes a stolen password insufficient on its own. A password manager makes each password unique, which limits how far one leak travels. Both are worth having, in that order. See identity and access management.
What's included
What we set up, and what we do to make it stick.
Five of the eight items below are about deployment and adoption. That ratio is deliberate, because it reflects where this succeeds or fails.
-
A private vault for every person
Encrypted, personal, and usable without asking permission. It works on their phone and in the browser they already use, because a tool that is slower than the old habit will lose to the old habit every time.
-
Shared vaults, organised by team
The credentials that genuinely must be shared, the supplier portal, the social account, the shared inbox, held in vaults granted by role rather than by person. Access can be granted and removed in a minute, without anyone changing a password.
-
Administrator and service credentials handled separately
The highest-value credentials come out of documents and spreadsheets into a controlled vault with access logging, so it is possible to answer who retrieved what and when. This is usually the most valuable single move in the project.
-
Joiner and leaver process wired in
Vault access granted as part of onboarding and removed as part of offboarding, tied to the same checklist as the rest of it. This is the mechanism that means a departure never again means an afternoon of manual password changes.
-
Breach monitoring on the credentials in the vault
When a credential of yours turns up in a third-party breach, it is flagged with a defined action rather than a notification. The wider service, covering domains and executives as well, is dark web monitoring, and it lives under cybersecurity.
-
A recovery process that exists before it is needed
A forgotten master password is the moment a rollout either survives or collapses. Recovery is configured, documented and tested during deployment, and each person is walked through it before they need it.
-
The rollout and training that makes it stick
Short sessions by team rather than one all-staff email, help importing the passwords already saved in browsers, and a person to ask during the awkward first fortnight. This is the difference between a licence and a change in behaviour.
-
An adoption number, reported honestly
How many people are actually using it, how many credentials are stored, how many are still duplicated across sites. Reported monthly, including when the number is disappointing, because a vault at 40% adoption is a problem to solve rather than a box to tick.
How it works
Configure, migrate, then make it the default.
The migration is the awkward stage and it is short. What matters is what happens in the fortnight afterwards.
-
Configure and set the policy
Platform selected and set up, vault structure designed around your actual teams rather than your organization chart, recovery configured and tested, and a written policy short enough that people will read it.
-
Migrate the spreadsheet
Existing shared credentials imported into the right vaults, browser-saved passwords imported for each person, and then the old spreadsheet is deleted rather than left as a comfortable backup. Anything with signs of exposure gets changed during the move.
-
Make it the easy path
Short team sessions, browser and phone apps set up on every device, and someone available for the first two weeks. Then adoption is measured monthly, and where a team is not using it we ask why rather than sending another reminder.
What it costs
Per user, per month, with the rollout quoted once.
The licence is a small number. The rollout is where a password manager either becomes how your organization works or becomes an annual renewal nobody questions.
Platform we deploy and manage: Keeper or Passportal, depending on what the rest of your stack looks like.
We would rather charge for it honestly than pretend a rollout is free and then not do it.
For happier IT managed IT If you already own a password manager and simply want the adoption work done, we will quote that alone.
What we will not ask you to do
We will not set passwords to expire every 90 days. Forced routine rotation produces predictable variations, the same word with a rising number, which is measurably worse than one long password nobody has reason to change.
Current guidance from NIST, the US standards body most frameworks follow, is long unique passphrases, no scheduled expiry, and a change only when there is reason to believe one is exposed. That is the policy we will write with you.
Why us for this
Anyone can sell you the licence.
The password manager market is mature and the products are good. Buying one is easy, and quite a lot of organizations already have, sitting at partial adoption, with the shared spreadsheet still open in a tab because it is faster for the four logins people need most.
So the work happier IT actually does here is adoption: designing vaults around how your teams really operate, running short sessions by team rather than sending an announcement, importing what people already have so day one is easier than day zero, and being reachable during the fortnight where a small annoyance decides whether somebody sticks with it.
Then the monitoring, which is where our security operations centre in Canada comes in. A flagged credential is checked against what is actually valid in your directory today before anybody is asked to do anything, because most exposed credentials are already dead and confirming that quickly is a genuine part of the service. Staffed hours: 24/7, with the Surrey office on Monday to Friday, 8:00 am to 5:00 pm Pacific.
Go deeper
- Identity and access management MFA and access, which come first.
- Dark web monitoring The wider credential-exposure service.
- What is MFA? The control that does the most here.
Questions
What people ask before they sign anything.
What is a password manager and is it safe?
A password manager is an encrypted vault that generates, stores and fills in a different password for every site, so nobody has to remember or reuse any of them. It is safe in the way that matters: the alternative is reuse, and reuse means one leak from an unrelated website becomes a problem at work. Reputable products encrypt everything on your device before it is stored, so the provider cannot read your vault even if their systems were reached.
Isn’t storing every password in one place risky?
It is a fair question and the honest answer is that it concentrates risk in exchange for removing a larger one. Today, one password is probably reused across many sites, so a single breach anywhere exposes several accounts. A vault replaces that with one strong passphrase and a second factor protecting a store the provider itself cannot read. The trade is a good one, and it improves further with MFA on the vault, which we configure as standard.
Do we still need MFA if we use a password manager?
Yes, and if you have to choose, MFA first. MFA, multi-factor authentication, means a stolen password is not enough on its own, which addresses the most common way accounts are reached. A password manager means each password is unique, which limits how far a single leak travels. They solve different halves and the combination is what you want. See identity and access management.
What happens if someone forgets their master password?
They use the recovery method configured during deployment, which is why we configure and test it before anybody depends on it. Depending on the platform this is an administrator-assisted recovery, a recovery key, or a trusted-device approval. It is worth knowing that some products deliberately have no back door, which is a security feature and a support problem, we set expectations about that during the rollout rather than at the moment somebody is locked out.
Should passwords expire every 90 days?
No, not on a schedule. Forced routine rotation makes people choose predictable variations, the same word with an incrementing number, which is easier to guess than one strong passphrase left alone. Current NIST guidance, which most frameworks now follow, is long unique passphrases with no scheduled expiry, changed when there is evidence of exposure. If an auditor is asking you for 90-day rotation, that guidance is worth showing them.
How do we share a login that genuinely cannot be split?
Put it in a shared vault granted by role, so access can be removed without changing the password and you can see who retrieved it. That is the honest answer for a supplier portal or a social account that offers no separate user accounts. Where the service does support individual accounts, use them instead, shared credentials should be the documented exception rather than the everyday habit, and part of the rollout is finding out which is which.
What does password management cost?
Inside happier IT’s managed IT agreement it is not a separate line. If you already own a password manager and want the adoption work done, we will quote that on its own.
Related
Where to go next.
Want to know what this would look like for you?
A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.