The best password manager is not necessarily the one with the longest feature list. It is the one that helps its users create unique credentials, protects the stored vault appropriately and remains usable enough that people do not work around it.
That is why this is not a “top ten” ranking. Products, prices and security records change. A durable choice begins with questions that can be asked of any service.
What problem is being solved?

Most people have more accounts than passwords they can reasonably remember. Reusing one memorable password turns a breach at a minor website into a route towards email, shopping or financial accounts. Small organisations add shared logins, leavers, emergency access and the need to know who can see what.
A password manager stores credentials in an encrypted vault and can generate long, unique passwords. It may also fill credentials into the correct website, reducing the temptation to reuse or simplify them.
Start with the threat model

Decide whether the manager is for one person, a family or an organisation. Consider the devices and browsers used, the sensitivity of the accounts, whether credentials need to be shared and what happens if a device is lost.
For a small business, ask who administers the service, how access is removed when someone leaves, whether activity can be audited and how recovery works. For a household, usability across phones and computers may matter more than central administration.
Encryption and architecture
Read the provider’s security documentation. Look for a design in which the provider cannot casually read vault contents, strong published cryptography, protection for data in storage and transit, and some form of independent security assessment.
Marketing expressions such as “military-grade” are less useful than a clear explanation of what is encrypted, where keys are derived and what data remains visible. Titles, website addresses or account metadata can themselves be sensitive.
Open source is not an automatic guarantee, and closed source is not automatic evidence of weakness. The useful question is whether the design can be scrutinised and whether the provider responds transparently to findings.
The master password and multi-factor authentication
The master password protects an unusually valuable account. Make it long, unique and memorable enough to enter reliably. Do not reuse it anywhere else. Store a recovery copy securely if the chosen system’s recovery model makes that appropriate.
Enable multi-factor authentication. A passkey or security key can provide stronger phishing resistance than a one-time code, although account recovery must be planned. The vault should not become inaccessible to the business because one phone was lost or one employee left unexpectedly.
Recovery is part of security
Ask what happens when the master password is forgotten. Some “zero knowledge” systems cannot recover the vault without an emergency kit, recovery key or trusted administrator. That may be a sound security property, but only if users understand it.
For organisations, test the leaver and emergency-access process before it is needed. For families, decide whether a trusted person should be able to recover essential credentials after illness or death. Convenience without governance creates a different risk.
Autofill and phishing
A good manager fills a password only on the matching domain, which can help expose a convincing fake login page. Users should still check the address and treat unexpected login prompts with suspicion.
Do not copy passwords through insecure channels when a controlled sharing feature exists. Where a business genuinely needs shared credentials, use named access, least privilege and revocation rather than a spreadsheet or message thread.
Passkeys and the changing login landscape
Passkeys can replace passwords for supported services and are designed to resist phishing. Check whether the manager can store and synchronise them across the devices you actually use, and whether they can be exported if you change provider.
Interoperability is improving but is not complete. A password manager remains useful during the transition because most people will have a mixture of passwords, passkeys, recovery codes and secure notes.
Questions to ask before subscribing
- Does it work reliably on every required device and browser?
- What is encrypted, and has the design been independently assessed?
- Does it support strong multi-factor authentication and passkeys?
- How do recovery and emergency access work?
- Can an organisation add, remove and audit users?
- Can vault data be exported in a usable format?
- Where is data stored, and what contractual terms apply?
- How does the provider disclose and respond to security incidents?
- What happens when the subscription ends?
- Can the least technical user operate it without creating unsafe workarounds?
Trial the shortlisted product with low-risk accounts. Test import, autofill, a new device, offline access, recovery documentation and export. A manager that people dislike using will slowly become an incomplete manager.
A sensible baseline
Use unique generated passwords; protect the vault with a unique master password and multi-factor authentication; keep devices updated; store recovery material securely; and periodically remove old access.
A password manager concentrates risk, which deserves care. It also replaces widespread, repeated risk with something that can be governed. For most people and small organisations, that is a worthwhile exchange when the product is selected and operated thoughtfully.
Further reading on The Perry
- Before you paste it into AI: a data-safety checklist for UK small businesses
- Working from home when self-employed: simplified expenses or actual costs?
- Making Tax Digital for Income Tax in 2026: a practical first-year checklist
Browse this section
Move naturally through the Journal articles or jump back to the section overview.
Previous in Journal
You are at the start of this section.
Next in Journal
Before you paste it into AI: a data-safety checklist for UK small businesses
Sources and further reading
- NCSC: Managing your passwords
- NCSC: Updating your approach to password policy
- NCSC: Securing your users’ accounts
- NCSC: Cyber Security Small Business Guide
Source check: 23 August 2026. This article does not endorse a particular product.
Featured image credit: Photo by FlyD on Unsplash.


Leave a Reply