Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operations //

Identity & Access Management

11/8/2019
09:00 AM
50%
50%

6 Small-Business Password Managers

The right password manager can help bring enterprise-class security to small businesses. Here are a half-dozen candidates to strengthen your access management.
Previous
1 of 7
Next

Good passwords are messy. They're long, chaotic, and very difficult to memorize. That's what makes them so strong. To keep them good and useful, though, requires a tool — a password manager.

The idea at the core of most password managers is simple: A database that matches user names and passwords to login pages is stored under the protection of a single strong password. When a login page is encountered, the password manager springs into action, filling in the necessary fields when unlocked with the master password.

With a password manager, the security best practice of a different strong password for every account can be followed, and changing those passwords on a regular basis becomes much less traumatic.

Any password manager worthy of consideration will perform this basic task well, though differences exist in how it is performed, how credentials are protected, and how the tool integrates with other security, directory, and network management components. These differences are especially critical for small businesses. Since smaller companies tend to have smaller budgets for IT staff, the need is high for a password manager that has features to fill in the blanks left by other products, is easy to integrate into existing infrastructure, and protects passwords for users who might have access to significant caches of critical data.

What products fit the bill? Dark Reading scoured the Internet for user comments, professional opinions, and published reviews of password managers of use to small business IT. We found half a dozen candidates that span a wide range of capabilities and prices.

As you click through the list, you'll notice there are no free or open source options. That's because all of the options in those categories are most suited to individual consumers, are quite complex to integrate into business infrastructures, or both.

We'd also like to know: Which password manager do you use for your small business? Do you worry about integration, or do see password management as a purely end-point issue suitable for a free-for-all solution? Let us know in the Comments section, below.

(Image: beebright VIA Adobe Stock)

 

Curtis Franklin Jr. is Senior Editor at Dark Reading. In this role he focuses on product and technology coverage for the publication. In addition he works on audio and video programming for Dark Reading and contributes to activities at Interop ITX, Black Hat, INsecurity, and ... View Full Bio

Previous
1 of 7
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
debrajohansen
100%
0%
debrajohansen,
User Rank: Apprentice
11/10/2019 | 9:26:55 AM
thanks
thanks
Navigating Security in the Cloud
Diya Jolly, Chief Product Officer, Okta,  12/4/2019
SOC 2s & Third-Party Assessments: How to Prevent Them from Being Used in a Data Breach Lawsuit
Beth Burgin Waller, Chair, Cybersecurity & Data Privacy Practice , Woods Rogers PLC,  12/5/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "This is the last time we hire Game of Thrones Security"
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-17185
PUBLISHED: 2019-12-09
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2019-12424
PUBLISHED: 2019-12-09
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2019-18380
PUBLISHED: 2019-12-09
Symantec Industrial Control System Protection (ICSP), versions 6.x.x, may be susceptible to an unauthorized access issue that could potentially allow a threat actor to create or modify application user accounts without proper authentication.
CVE-2019-19687
PUBLISHED: 2019-12-09
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Users with a role on a project are able to view any other users' credentials, whic...
CVE-2019-19682
PUBLISHED: 2019-12-09
nopCommerce through 4.20 allows XSS in the SaveStoreMappings of the components \Presentation\Nop.Web\Areas\Admin\Controllers\NewsController.cs and \Presentation\Nop.Web\Areas\Admin\Controllers\BlogController.cs via Body or Full to Admin/News/NewsItemEdit/[id] Admin/Blog/BlogPostEdit/[id]. NOTE: the ...