Reported, not repackaged

Nine Staff, Forty Logins, One Insurance Questionnaire. What the Good Version of a Password Rollout Does Differently

title:Nine Staff, Forty Logins, One Insurance Questionnaire. What the Good Version of a Password Rollout Does Differentlyauthor:Beatrix Stapletonpublished:2025-09-17section:Innovationwords:1,010read:4 min
A small office desk with an open drawer showing a handwritten note taped inside, a laptop displaying a login screen, and a printed insurance questionnaire be...
A small office desk with an open drawer showing a handwritten note taped inside, a laptop displaying a login screen, and a printed insurance questionnaire be...

A composite small-office password rollout, examined week by week, and the handful of decisions that separate a policy people follow from one they route around.

The trigger is almost never a breach. In small offices it is usually a renewal questionnaire from the cyber liability carrier, a client's vendor security form, or a bank that has started asking how administrative accounts are protected. Somebody has to answer, in writing, on a deadline. What happens next is where a password program either becomes something staff use without thinking about it or becomes something they work around by Thursday.

What follows is a composite, assembled from the shape these projects take in offices of eight to fifteen people: a property management firm, nine staff, roughly forty accounts spread across a bank portal, a payments processor, two state filing systems, a leasing platform, email, and a maintenance dispatch tool. Two versions of the same project. Same budget bracket, same software category, very different week-to-week reality six months later.

The week the questionnaire arrived

The carrier's form asked three things that matter: whether multifactor authentication was enabled on email and remote access, whether administrative accounts were separate from daily-use accounts, and whether credentials were shared between employees. The office manager, who is the person actually holding this problem, could answer honestly on none of them. Email had MFA for two of nine people. The bank portal had one login that four people used. The maintenance dispatch tool had a password taped inside a desk drawer because the vendor's system allowed only one seat on the plan they bought in 2019.

That drawer is the whole story. It was not laziness. It was a licensing constraint that nobody had revisited, and every password policy written on top of it was going to be a policy with a hole in it.

What barely adequate looked like on an ordinary Tuesday

The first version of the rollout did what most first versions do. A password manager was purchased, seats were assigned, everyone was told to move their logins in, and a one-page policy was circulated requiring long passphrases and MFA. The questionnaire got answered. The renewal went through.

By month three, the Tuesday reality looked like this. Two staff had installed the browser extension and never used it, because their most-used system was a desktop application the extension did not fill. The shared bank login was now stored in the manager's personal vault rather than in a shared folder, so when she was out, someone texted her for it. Nobody had told the manager that a departing leasing agent's accounts were still active, because offboarding was a payroll process and nothing connected payroll to the vault. The drawer password was still in the drawer.

Nothing had failed. That is the point. A barely adequate program produces no visible incidents and no useful protection. It fails on the day it is tested, and until then it looks identical to a good one on paper.

The three decisions that made the second version hold

The second version, run the following year with a fractional IT contractor rather than internally, changed three things. None of them was the software.

It inventoried before it enrolled. Every account got a line: what it is, who needs it, whether it supports MFA, whether it supports named users or only a single seat. Forty-one accounts. Six of them could not support individual logins at the current license tier. Those six were the actual project. Four were upgraded, one was replaced, and one genuinely had no option, so it got a dedicated shared entry with an access log and a quarterly review rather than a pretense that sharing had been eliminated.

It attached credential changes to events, not to the calendar. Nobody rotates passwords every ninety days anymore in a well-run shop, and the guidance that once required it has been formally reconsidered by the National Institute of Standards and Technology, which is responsible for the federal digital identity guidelines that most private-sector policies are copied from. What replaced the calendar is a trigger list: a departure, a suspected exposure, a breach notice naming a service the office uses. That is a shorter list of events, and each one has a named owner.

It made offboarding one checklist held by one person. The vault was the record of what an employee could reach, so revoking access became a single pass down a list rather than an archaeology project. The first time it ran, on a scheduled resignation, it took under an hour.

The week-to-week test

Judge a password program by the friction it creates in a normal week, not by the policy document.

Ordinary eventBarely adequateGood
New hire needs access on day oneManager forwards passwords by email or textVault group assignment, no credential ever spoken aloud
Employee leaves on a FridayNobody is certain what they could reachOne checklist, all accounts, done that day
Manager is out and a wire needs approvingSomeone texts her for the shared loginSecond named user already has it
Breach notice names a vendorUncertain whether anyone used itVault search answers in a minute
System refuses MFAQuiet exception nobody wrote downLogged exception with a review date

Who else is in the room

Three people shape this outcome and none of them writes the policy. The carrier's underwriter decides which controls get asked about, and therefore which get funded. The software vendor's license tier decides whether individual accounts are even possible, which is why the sales rep's answer about seat counts is a security question. And the office manager decides, every week, whether the approved route is faster than the workaround. If it is not, the workaround wins, and no amount of training reverses that.

Cost separated the two versions by very little. Per-user password management sits in the range of a paid streaming subscription, and the license upgrades were annual line items an office of that size absorbs. The real spend was a few hours of somebody's attention on the inventory, front-loaded, once.

The office that did the inventory answered its next questionnaire from a spreadsheet instead of from memory, and answered it in an afternoon.