TL;DR: Weak, default, and stolen passwords still underpin most successful breaches, and SMBs are especially exposed because poor password hygiene, shared credentials, and limited visibility turn basic identity controls into a high-impact attack surface, according to Devolutions. Password management is no longer an IT housekeeping task; it is a board-level risk control for human IAM and privileged access.
NHIMG editorial — based on content published by Devolutions: SMBs becoming ground zero for cyber crime and password management solutions
By the numbers:
- 61% of SMBs polled reported a cyberattack, up from 55% a year earlier, according to Ponemon Institute research.
- 54% of SMBs reported a data breach, with employee negligence cited as the top root cause, according to Ponemon Institute research.
- 52% of SMBs reported a ransomware attack, and stolen or compromised passwords were a leading enabler, according to Ponemon Institute research.
Questions worth separating out
Q: What breaks when SMB password management is treated as an IT-only task?
A: When password management stays in IT alone, exceptions multiply, shared credentials persist, and risk decisions never reach the people who own business processes.
Q: Why do weak passwords keep causing breaches even when users are trained?
A: Training does not change the underlying constraint that people are asked to invent and remember complex secrets under cognitive load.
Q: How should organisations handle shared credentials with third parties?
A: Shared credentials should be eliminated wherever possible and replaced with individually attributable access, delegated roles, or vault-mediated sharing with logging and expiry.
Practitioner guidance
- Enforce unique, machine-generated passwords everywhere Replace reusable and human-chosen passwords with generated credentials for employee, admin, and shared systems.
- Centralise credential storage in a zero-knowledge vault Move shared passwords, encrypted files, and privileged credentials into a vault that enforces access policy without exposing secrets to administrators or the vendor.
- Inventory password sharing across teams and third parties Map where credentials are shared, copied, or handed off informally, then tie those cases to owner approval, audit logging, and revocation paths.
What's in the full article
Devolutions' full article covers the operational detail this post intentionally leaves for the source:
- The article expands on the password hygiene failures that make SMBs easy targets, including common patterns of reuse and sharing.
- It outlines how comprehensive password management changes visibility, vaulting, and policy enforcement for employees and administrators.
- It discusses how password management can tie into privileged accounts, encrypted storage, and cross-team sharing workflows.
- It also explains why leadership ownership matters for making password governance part of organisational risk management.
👉 Read Devolutions' analysis of SMB password risk and credential governance →
SMB password management gaps: what identity teams need to fix?
Explore further
Password sprawl is an identity control failure, not a user habit problem. SMBs often frame password weakness as employee negligence, but the real issue is governance failure around credential policy, reuse detection, and privileged access oversight. When passwords are easy to share, write down, or recycle across systems, the organisation has not defined a durable identity boundary. The implication is that password management has to be treated as part of IAM and PAM governance, not as a training memo.
A few things that frame the scale:
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, according to The State of Non-Human Identity Security.
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, which shows how quickly identity blind spots extend beyond employee accounts.
A question worth separating out:
Q: When does password management need PAM and audit controls?
A: It needs PAM and audit controls when credentials can open privileged systems, administrative consoles, or customer-facing infrastructure. At that point, password hygiene is no longer a user convenience issue. It becomes a high-risk access control problem that requires approval, logging, review, and rapid revocation.
👉 Read our full editorial: SMB password management gaps still drive most breach paths