The conversation usually starts the same way. I ask where the business keeps its credentials. And there is a pause.
After the pause comes one of three answers. A shared spreadsheet on the company drive. A note inside someone’s phone. Or some version of “I think so-and-so has all of that.” There are times that I do see applications similar to 1Password mentioned. That is amazing to hear and the best answer.
Each of these is describing the same underlying situation. The passwords for the business are living somewhere informal, somewhere that was never designed for this purpose, and somewhere that gives the company no real control over who has access to what.
What a Spreadsheet Cannot Do
A spreadsheet is a grid of cells. It can hold information. What it cannot do is anything that a password management system actually needs to do.
It cannot tell you who accessed a credential last Tuesday. It cannot alert you when a password appears in a public breach. It cannot revoke access when someone leaves the company.
It also cannot prevent someone from emailing a copy to themselves before they hand in their laptop. Once a spreadsheet is downloaded, copied, or forwarded, the information in it belongs to whoever has it. There is no way to know how many copies exist, where they are, or who still has access.
For a business with 8 employees and 15 systems, the typical credential count runs well above 100 individual logins. Each one of those, sitting in an uncontrolled spreadsheet, is a potential entry point for someone who should no longer have access.
The Off-Boarding Problem
Every business has a moment where someone leaves. Sometimes it is planned and amicable. Sometimes it is not.
In either case, the question that has to be answered immediately is: what did this person have access to, and has that access been revoked?
With a properly managed credential system, that question has an answer. You can see every system the person was provisioned for, revoke their access individually, and have confidence that their entry points are closed.
With a shared spreadsheet, you are doing something different. You are trying to remember every account that person might have touched, manually changing passwords for each one, and hoping you did not miss anything. The process is manual, error-prone, and almost never complete.
The accounts that get missed are the ones that become problems. Not right away, and maybe never, but the exposure is real and it persists for as long as the old credentials work.
The Personal Phone Problem
The phone version of this is even more exposed than the spreadsheet version.
When credentials live in someone’s personal notes app, on their personal device, the business does not own that information. It cannot remotely wipe the information if the phone is lost or stolen. It cannot access the credentials if the person is suddenly unavailable.
Businesses often realize this problem acutely during an emergency. A key team member is out sick. Or has left without proper notice. The credentials for a critical system that only they managed are on a device the company has no access to. Whoever is trying to run the business is now locked out of something they should have been able to reach all along.
What a Data Breach Looks Like From the Password Side
The most common method of unauthorized access is not a technical exploit. An attacker obtains credentials, either by guessing a weak password, purchasing credentials from a previous breach, or collecting them through a phishing attack. Then they log in. There is nothing dramatic about it. The entry point is a username and password that was too easy or too reused.
Someone gets access to the email account. They do not immediately do something obvious. They read. They watch. They look for patterns: payroll information, client lists, banking instructions, wire transfer requests. Weeks or months later, when they have enough context, they act.
A business storing credentials in a spreadsheet has no meaningful way to detect this kind of access. The spreadsheet does not log who opened it. It does not alert anyone when a credential inside it appears in a public breach database. It just sits there, a static document, while access accumulates.
The Actual Alternative
A password manager built for business is a secure vault that the company controls, with individual access provisioned per employee, an audit trail of who accessed what and when, and the ability to revoke access instantly when someone leaves.
Employees get access to only what they need. When they need a credential, they retrieve it from the vault. When they leave, the vault removes them. The credential itself never has to leave the managed system.
Setup takes hours, not weeks. The ongoing management is minimal. The audit trail it creates becomes useful almost immediately, both for security purposes and for the ordinary operations of figuring out who set up which account and what the login is.
One Credential Away From a Serious Problem
The spreadsheet feels safe because nothing has gone wrong yet. That is the entire argument for it, and it has nothing to do with security. It has everything to do with luck.
For a business that runs on client trust, financial accounts, and sensitive data, the credential situation is worth addressing before there is a reason to address it under pressure.
The businesses that end up in a breach investigation always had a version of the same conversation afterward: we knew we should have tightened this up. We just never got around to it.
Idea 6 of 16 | Source: Gino Wickman + Chris Henke
Unmanaged Devices Are Not an IT Problem. They Are a Business Risk.
Short Version — Social Post (100–200 words)
A Mac that nobody enrolled in device management is a gap in the security perimeter of the business — an entry point with no visibility, no policy enforcement, and no way to act on it remotely if something goes wrong.
Unmanaged means no visibility into whether the operating system is current. No ability to push a security policy. No way to remotely wipe the device if it is lost or stolen. No audit trail of what software is installed or running.
For a team of 15 people, two or three devices outside of management are entry points into the business that nobody is watching, with no policy enforcement and no ability to respond remotely if one of those devices is compromised or goes missing.
The device each person uses every day to access email, client files, financial records, and communication tools is either inside the managed perimeter or it is not. There is no partial version of this.

