Your company passwords are in a spreadsheet, aren't they
There's a file. It lives on the shared drive, or on the office manager's desktop, or in an email thread titled "logins" that everyone forwards around. It's usually named "passwords." Sometimes "passwords_final." I have seen one called "passwords_FINAL_use_this_one." It has every login the business runs on, in one place, and anybody who can open it owns the company.
Almost every small business I look at has this file. It's not a sign anyone's careless. It's just what happens when a business grows faster than anyone's job description, and somebody sensible decided the logins shouldn't live in five different heads. The instinct was right. The spreadsheet is the part that aged badly.
Why it's riskier than it feels
A spreadsheet of passwords has two problems, and they're both quiet.
The first is that it has no gate. Every login sits behind one file that opens with a double-click. The bank, the payroll system, the domain, the email, the point-of-sale. One file, one click, everything. There's no "this person can see the vendor logins but not the bank," because a spreadsheet doesn't do that. It's all or nothing, and it's usually all.
The second is that it keeps no record. When someone opens it, nothing is logged. When someone copies it to a thumb drive, or emails it home "just to have it," nothing is logged. You will never know it happened. The whole security of the thing rests on everyone who has ever had the file being trustworthy forever, including the people who don't work for you anymore.
"But it's password-protected"
A lot of people lock the file with a password and feel better. I understand why. The trouble is that the password on an Excel file protects the file, not the business. Once it's open on a screen, it's a plain list again, and anyone standing there can read it, screenshot it, or send it on. The lock only matters if the file is stolen closed, and that's not how this usually goes wrong.
How it usually goes wrong is far more ordinary. A laptop gets a bad email attachment, and the attacker finds a file named "passwords" sitting right there. An employee leaves on bad terms with a copy in their personal email. The file quietly syncs to someone's personal cloud account and stays there after they're gone. None of those are dramatic. All of them hand over everything at once.
The part that makes it worse
The spreadsheet almost always comes with a second habit: the same password, or a close cousin of it, used in a lot of places. "Business2024!" becomes "Business2025!" and gets typed into the bank, the email, and the shipping account. So the spreadsheet isn't just a list of keys. It's a list that shows a thief the pattern, and the pattern opens the doors that aren't even on the list.
That's the real exposure. Not one account. The shape of how you think about passwords, written down for anyone who finds it.
What to use instead
The fix is a real password manager. It's the same idea as the spreadsheet - one place for all the logins - but it closes the two gaps. Think of it as the difference between a drawer with a sign that says "keys" and an actual key cabinet where each key is on its own hook and you can see who took what.
- Per-person access. The bookkeeper sees the accounts she needs. The new hire sees three things, not thirty. You decide, and you can change it in a minute.
- A record of who used what. So "who has the bank login" is a question with an answer, not a shrug.
- One click to cut someone off. When an employee leaves, you revoke their access and you're done. You don't change forty passwords and hope you got them all, because you never do.
- It fills logins for people, which quietly ends the reused-password habit, because nobody has to remember them anymore.
There are good ones built for small teams, and they cost a few dollars per person a month. It is one of the rare security fixes that's cheaper and easier than what it replaces. The spreadsheet was never free either. It just billed you later.
How to check where you stand
Open your shared drive and search the file names for "password," "logins," and "credentials." Check the obvious desktops too. If something turns up, that's your finding, and the next question is who has ever had a copy of it.
While you're there, ask yourself a plainer one: if your most capable employee quit this afternoon and wasn't feeling generous, how many passwords would you be changing tonight? If the answer is "I'm not sure," that's the same finding from a different angle.
Not sure who can reach what? The free Systems Checkup is a 20-minute look at your accounts, your logins, your email and your backups, with a one-page report you keep. If what we find points to deeper cleanup, the Systems & Operations Audit is the full investigation.
Book your free Systems CheckupCommon questions
Is it safe to keep business passwords in an Excel spreadsheet?
No. A spreadsheet gives every login to anyone who can open the file, keeps no record of who opened or copied it, and can't limit one person to only the accounts they need. For a business, those are the gaps that matter.
Is a password-protected Excel file good enough?
The password protects the file when it's closed and stolen, which is rarely how this goes wrong. Once the file is open on a screen it's a plain list again, and it does nothing about reused passwords or a copy walking out the door.
What should a small business use instead?
A team password manager. It stores the logins in one place like the spreadsheet did, but adds per-person access, a record of who used what, and one-click removal when someone leaves. Good ones cost a few dollars per person a month.
What happens to our passwords when an employee leaves?
With a spreadsheet, nothing automatic - they may still have a copy, so the only safe move is changing everything they could have seen. With a password manager, you revoke their access in one step and the logins they used are closed to them immediately.
← More articles