Are credentials circulating through your company by email, in Excel spreadsheets, or on sticky notes? Are shared accounts protected with strong, unique passwords – and in an emergency, does anyone know who has access to what? This practical guide shows how companies define password policies in line with BSI and NIST, assign responsibilities, grant access rights cleanly, and document changes traceably – step by step, from taking stock to offboarding.
Careless handling of passwords
Around one third of internet users in Germany use the same password for several services (Bitkom, January 30, 2025) – and precisely such passwords are how most successful attacks happen, from brute-force attempts to credential stuffing. Why a single leaked password turns into a chain reaction is shown in our article Identical passwords. This guide covers the organizational side: how to set up and enforce the handling of passwords in your company properly.
Important and current: Since 2025, the BSI has advised against changing passwords regularly as a purely precautionary measure. Instead: strong, unique passwords, where possible two-factor authentication (2FA) or passkeys, plus risk-based changes (e.g. on suspected compromise).
Setting up a company password policy: BSI, NIST, 2FA, and passkeys
Many companies lack binding password policies or fail to enforce them. Passwords are shared by email or messenger, and lists sit unencrypted on file shares. This is exactly where centralized, well-designed password management comes in:
- Strong, unique passwords for all accounts – without a memory burden for users.
- Central policies on length, structure, checks against blocklists (e.g. compromised passwords), and 2FA requirements.
- Transparent responsibilities and audit trails for traceability.
- Immediate revocation of access rights when roles change or employees leave.
Password Depot helps you enforce a high security standard – for example, through password quality analysis and warnings about weak entries.
How to manage passwords properly in your company
The process at a glance – the detailed steps follow below:
- Take stock of passwords and shared accounts
- Define responsibilities and points of contact
- Set a password policy in line with BSI/NIST (length, uniqueness, blocklists, MFA)
- Build a permission and role model – down to database, folder, and entry level
- Define a sharing process for shared credentials
- Regulate onboarding and offboarding (granting and revoking permissions, password rotation)
- Anchor event-based password changes instead of calendar rotation
- Review audit logs regularly and trace incidents
Companies that take password security seriously put the following items on their to-do list:
Raise employee awareness:
Explain clearly why unique and long passwords, 2FA, and passkeys massively increase data security. Training, short guides, and internal FAQs help.
Assign points of contact:
Designate a responsible function (e.g. IT security/IT operations) for questions about password protection, policies, and incident handling.
Define policies for secure passwords:
Follow established guidelines (e.g. NIST SP 800-63B & BSI recommendations). Focus on length and uniqueness instead of purely formal complexity rules. Our tips for creating secure passwords show what this looks like in practice – and how Password Depot checks and enforces it.
Modernize password change rules:
No more rigid rotation intervals. Change passwords based on specific events (e.g. after incidents, when roles change, or when systems change) and force changes only when there are indicators of compromise. This is also what the BSI and the NIST guidelines recommend.
Increase productivity – security without friction:
Avoid manual group emails and paper chaos. Equip your team with easy-to-use tools that generate secure passwords, fill them in automatically, and control sharing based on rules – keeping the focus on work, not on password management.
Enforcing password rules with centralized password management
Policies only work if a tool enforces them. The Password Depot Enterprise Server anchors the practice described here centrally: encrypted team databases on your own server, server-side password policies, role-based access, and audit-ready logs. When someone leaves the company, administrators block access centrally and rotate affected passwords traceably. Which requirements such a solution must meet in detail – from roles to AD integration to data sovereignty – is described in our overview Business password manager.
Controlling access rights with granularity

In addition to strong encryption, a fine-grained permissions and sharing model provides security. Define for each user which databases, folders and entries are visible, which changes are permitted, whether exports are allowed and which actions are logged. Assign permissions quickly and transparently to departments and groups. Dedicated roles (Audit Reader, Security Officer, Backup Operator) are available for separation of duties, and every action is recorded in a tamper-evident audit trail – the article Enterprise Server & ISO 27001 shows how this supports ISO 27001 controls.
The technical basis: encryption in line with BSI recommendations
Password Depot encrypts data at the highest level (AES-256); new local databases use the authenticated AES-GCM mode. Communication between clients and server takes place via TLS (optionally with certificate validation/client certificates). This means you follow established cryptographic recommendations from the BSI; see TR-02102 (TLS, algorithms & key lengths).
Externally verified: in the 10-day penetration test by SySS GmbH (12/2025), no critical or high-severity vulnerabilities were identified. How to assess the security of password managers in general – from encryption to residual risks – is explained in our article How secure are password managers?.
Conclusion: With our server, you manage passwords, documents, identities, and other secrets centrally, securely, and traceably – and save time. No more paper chaos, insecure text files, and email ping-pong.
See for yourself
Watch a short video to see what Password Depot Enterprise Server can do for your business: Protect your company’s passwords with Password Depot Enterprise Server
Would you like to see Password Depot Enterprise Server in a personal webinar? Pick your preferred slot here. Alternatively, arrange an appointment by email or by phone. You can find information on licensing here.
Frequently asked questions about password practice in companies
What belongs in a company password policy?
Minimum length and uniqueness instead of formal complexity requirements, a ban on reuse, checks of new and existing passwords against compromised-password lists, MFA requirements for admin, remote, and cloud access, event-based change rules, and clear procedures for shared accounts, onboarding, and offboarding.
What does the BSI recommend on regular password changes?
Since 2025, the BSI has advised against routine password changes without cause. Instead: strong, unique passwords or passphrases, two-factor authentication or passkeys where possible – and a change only on suspicion or proof of compromise.
What does NIST recommend on password length and complexity?
NIST SP 800-63B focuses on length and uniqueness instead of forced special-character rules, recommends checks against lists of compromised passwords, and requires that pasting from password managers remains allowed – the guideline rejects rigid rotation intervals without cause.
When should passwords be changed in a company?
Based on events: after security incidents or suspected compromise, after phishing cases, when roles change, and whenever employees with access to shared accounts leave the company – not on a fixed calendar.
How do you control access rights for shared passwords?
Via groups and roles in centralized password management: permissions are granted per database, folder, and entry (read, edit, export), assignment happens via group membership instead of passing passwords around, and every access is logged.
How does offboarding work with shared credentials?
Block the departing person’s access centrally, use the central overview to determine which databases and entries are affected, rotate the affected passwords, and document the process in the log. Without central management, this step is practically impossible to do reliably.
Discover Enterprise Server
Find out how Password Depot supports your company with secure password management.
Go to Enterprise Server