Why Businesses Still Get Password Management Wrong | TNW Deals
Latest
Deep tech • Sustainability • Ecosystems • Data and security • Fintech and ecommerce • Future of work
May 25, 2026 – 8:37 am
(Image by: Canva)
A password manager feels like a solved problem. Pick one, store your credentials, move on. Yet breach after breach tells a different story: compromised passwords remain the single most common entry point for attackers, responsible for over 80% of hacking-related breaches according to Verizon’s annual data breach report. The issue is rarely that people choose weak passwords. It’s that the systems around those passwords are fundamentally broken in most organisations.
This article contains affiliate links. If you make a purchase through these links, we may earn a commission at no extra cost to you.
The Gap Between Personal and Enterprise Password Management
For individuals, the calculus is simple:
- A good password manager generates unique credentials for every account.
- It fills them automatically.
- It encrypts the vault with a master password only you know.
The market has plenty of decent options for this use case. But when you move beyond a single user, the complexity multiplies. Teams need to share credentials without exposing them in plaintext. Departing employees must have their access revoked instantly across every system. Compliance frameworks like SOC 2, HIPAA, and PCI DSS demand audit trails showing who accessed what, when, and from where. And increasingly, organizations need to manage not just passwords but SSH keys, API tokens, database credentials, and privileged session access.
TNW City Coworking Space – Where Your Best Work Happens
Book a tour now
Why Credential Governance Matters More Than Credential Storage
Consider a typical mid-sized company:
- Marketing has a shared Google Ads login saved in a spreadsheet.
- The development team stores database connection strings in environment variables and CI/CD pipeline configs.
- IT rotates admin passwords quarterly but tracks them in a separate vault that nobody else can access.
- Customer support shares a CRM login through Slack messages.
Each of these is a credential management failure waiting to become a breach—not because the passwords themselves are weak, but because there’s no centralized system governing how they are created, stored, shared, and retired.
Enterprises That Handle This Well
Enterprises that handle this well tend to use privileged access management (PAM) platforms, but traditional PAM tools carry their own baggage: six-figure implementation costs, months-long deployments, and interfaces that security teams tolerate rather than enjoy.
A Different Approach to the Problem
Keeper Security has been working on this problem from a slightly different angle. Instead of building a traditional PAM platform and bolting on a password manager, Keeper started with consumer-grade password management and expanded upwards into enterprise credential governance, privileged access management, and secrets management. The result is a platform that…