Your auditor will ask about passwords.

Cyber Essentials and ISO 27001 both expect you to show how credentials are created, stored, shared and revoked. A spreadsheet, a shared inbox and a good memory won't pass.

One Managed Service

Addooco Secure gives you the password manager, the rollout and the evidence as one managed service - from £3.50 per user, per month.

Start With A Free Review

Thirty minutes with our Secure team to find the gaps before your assessor does.

Book a free review

12+


Characters

Cyber Essentials minimum for passwords without MFA.

MFA


Everywhere

Required on all cloud services and administrative accounts, without exception.

5.17


ISO 27001 Annex A

The control covering authentication information - allocation, storage and secure handling.

Why It Matters

Most breaches don't start with a hacker. They start with a habit.

Reused passwords, credentials pasted into chat, one login shared by five people, a leaver who never really left. None of it is malicious. All of it is exactly what an assessor - or an attacker - looks for first.

One Password, Every Door.


When a staff member reuses a work password on a personal site, any breach of that site becomes a breach of yours. A manager makes every password unique without anyone having to remember one.

Sharing You Can Revoke.


Shared accounts are a business reality. Shared vaults make them governable: access by role, removed in one click when someone changes job or leaves.

Evidence On Demand.


Policy enforced in the tool, reports showing weak and reused credentials, an audit trail of access. That's your Cyber Essentials answer, and your insurer's too.

"We don't have a password problem" usually means "we've never looked". The first review almost always finds a live login belonging to someone who left last year.

Addooco Tech Team

What We Provide

Addooco Secure Password Manager.

You don't need another product to administer — you need the outcome. We provide enterprise-grade vaults licensed per user, deployed, migrated and supported by our Secure team, with the compliance evidence produced for you every quarter.

One managed service. One monthly invoice. From £3.50 per user, per month.

Included

Licences & Vault Build.


Per-user licensing, company and team vaults structured around how you actually work, MFA enforced from day one.

Included

Migration Done For You.


We import what's in the spreadsheets and inboxes, rotate the credentials that matter, and delete the old copies.

Included

Adoption & Support.


Short live sessions per team, joiner and leaver handling folded into our service desk, and a named UK Tech Team on the end of the phone.

Included

Quarterly Evidence Pack.


Policy compliance, weak and breached credential reports, access by role - filed ready for your assessor, insurer or client questionnaire.

Already running a password manager? We'll take it on and fix the adoption gap rather than replace it.

The 5-Step Review

Five steps to a company-wide password strategy.

This is the process our Secure team runs with clients. You can run it yourself — or we'll run it with you and hand you the evidence pack at the end.

01 - Discover What Exists

List every system that holds a login: line-of-business apps, cloud services, banking, social, domain registrars, routers, CCTV, the accounts nobody owns. Include personal-looking logins used for work.

Output: a single credential inventory with a named owner per system.

02 - Score The Risk

For each system, mark four things: is the password unique, is it shared, is MFA on, and who could still get in who shouldn't. Anything that is shared, reused and MFA-free is where you start.

Output: a ranked risk list your board can read in one page.

03 - Write The Policy First

Decide the rules before you pick a tool: minimum length, where MFA is mandatory, what may never be shared, how contractors get access, what happens on day one of a leaver's notice. Keep it to a page people will actually read.

Output: a one-page password and authentication policy, signed off.

04 - Roll Out, Don't Announce

Deploy the manager team by team, structure vaults to match how people work, enforce MFA, then rotate every credential that mattered in step two. Adoption is the whole game - a tool nobody uses is worse than no tool, because you'll believe you're covered.

Output: every business credential in a managed vault, old copies deleted.

05 - Prove It, Then Keep Proving It

Export the reports that show policy compliance, weak-password counts and access by role. Book a quarterly review and tie it to your joiner & leaver process so it never drifts back.

Output: an evidence pack for Cyber Essentials, ISO 27001, insurers and clients.

Checklist

Ten minutes, ten questions.

Answer these honestly. If you can't answer three or more with a confident yes, your credentials are a live risk - and a likely finding at your next assessment.

01

Can you produce a list of every system your business logs into?

02

Is every one of those passwords unique to that system?

03

Is MFA switched on for every cloud service and every admin account?

04

Are shared logins held in a managed vault rather than a spreadsheet, inbox or chat thread?

05

When someone leaves, is their access removed the same day - everywhere?

06

Do you know which of your credentials have appeared in a known breach?

07

Does anyone hold a business password only in their head, or only on their own device?

08

Do you have a written password policy staff have actually seen this year?

09

Could you evidence all of the above to an assessor this week?

10

If your finance system was accessed tonight, would you know by morning?

Next Step

Free password strategy review.

Thirty minutes with our Secure team, at no cost. Tell us how your team shares access today and we'll tell you where the gaps are, what your assessor will flag, and exactly what it costs for Addooco to run your password manager end to end.

What You Get On The Call

A plain-English read on your current exposure.

The gaps a Cyber Essentials assessor would flag first.

A fixed monthly price for the managed service, sized to your headcount.

The one-page policy template to start from.

Company No: 06687050
VAT No: 940180645
©2025 Addooco IT Limited

Addooco IT Limited
Dundee House, Millennium Way
Chesterfield, Derbyshire, S41 8ND

Addooco IT Limited
Dundee House, Millennium Way
Chesterfield, Derbyshire, S41 8ND

Call: +44 3333 447887
Privacy Policy | Terms

Addooco IT Limited
Dundee House, Millennium Way
Chesterfield, Derbyshire, S41 8ND

Call: +44 1246 887887
Privacy Policy | Terms

Privacy Preference Center