Last week three different clients asked me a version of the same question. One was sat in our office sorting out a new starter laptop. One emailed at half ten on a Sunday night. The third asked me on the phone while I was driving back from a job in Cannock. All three sentences started the same way.
“Is it OK if I just let Chrome save my passwords?”
I get why people ask. It is, on the face of it, free, instant, and already there. Click “save”, forget about it, log in automatically next time. No new app to learn, no extra subscription, no faff. For a personal Netflix login, fine. For your work passwords, no.
This article is the honest answer I gave all three of them, plus the reason we move every client onto Keeper as part of our managed IT and cyber security rollout.
Key takeaways
- Browser-saved passwords are fine for personal use, not business. Anyone who picks up an unlocked laptop sees every password in plain text.
- Chrome syncs across personal and work profiles. When a staff member leaves, your business passwords go with them.
- There’s no safe way to share a Chrome-saved password. Which is how they end up in Teams chats and WhatsApp threads.
- We roll Keeper out for every client at £5 per user per month. One master vault, proper sharing, an admin console you can actually use.
The short answer
For your personal passwords, browser-saved is acceptable as long as your laptop is locked and your Google or Microsoft 365 account has multi-factor authentication on it.
For your business passwords, no. Browser-saved passwords are too soft a target, share too easily by accident, and break the moment a member of staff leaves. A proper password manager fixes all three.
Why people do it anyway
Worth saying upfront, this isn’t laziness, it’s the path of least resistance. Chrome and Edge actively offer to save the password every single time you log into something. Most business owners I work with have hundreds of saved passwords in Chrome that they didn’t even consciously add. The browser nudged, they clicked yes, the password got saved, life moved on.
The problem isn’t that your team is careless. The problem is that browsers are designed to be helpful, and “helpful” in the password world means “everywhere, all the time, with not enough friction.”
The worse option: no password manager at all
Browser-saved is one end of the scale. The other end is the “I just remember them all” school. We see it more often than you’d think, including in businesses that have otherwise sensible IT. The honest position is that no password manager, browser or otherwise, is the worst of the three options, and it’s the one most likely to be quietly costing you already.
What it actually looks like in practice:
- The same password on everything. The bank login, the M365 login, the CRM, the LinkedIn account. So when any one of those services has a breach, every other login is exposed in the same evening.
- Password plus a number. The classic “CompanyName2024”, then “CompanyName2025” when forced to change. Attackers know this pattern and try it first.
- Written down somewhere. The notepad in the desk drawer, the Post-it on the monitor, the back of the diary, the Notes app on the phone. Cleaners, contractors and visitors all see those.
- The spreadsheet. “Passwords.xlsx” sat on the desktop or worse, on a shared OneDrive folder. Every member of staff who has ever needed a login can find it.
- Asking IT to reset every time. The compromise position where staff don’t store the password anywhere, they just trigger a reset link weekly. It works, but it wastes their time, your IT budget, and trains your team to ignore reset emails, which is exactly the email pattern phishing relies on.
The bit that catches business owners out is the assumption that “in my head” is the safest place. It isn’t. Humans can’t remember more than four or five long, unique, random passwords, so the brain compromises. It picks something short, something memorable, something reused. That’s the security trade-off most people never realise they’ve made.
If this is closer to how your business handles passwords today than the Chrome-saved scenario, the gap to fix is bigger but the fix is still the same: one tool, one master password, proper sharing, proper recovery. Below is how we do it.
Three real things that go wrong
I’ll skip the abstract security theory and tell you what I see breaking in real businesses.
1. The whole vault opens if anyone gets onto the laptop
If someone gets your unlocked laptop, even just for ten minutes at a coffee shop, every password in Chrome is visible in plain text. Settings, autofill, passwords. Three clicks. They can see your bank login, your Microsoft 365 admin, your CRM. No “master password” prompt, no second factor. Just the same Windows login you’ve already opened.
This isn’t theoretical. It’s the same reason laptop theft in business is so expensive, the device matters less than the access that sits behind it.
2. Sync chaos when work and personal Google accounts mix
Most people are signed into Chrome with both a personal and a work Google account. Chrome syncs passwords across whichever profile they’re using at the time. So work passwords end up sitting in their personal Chrome profile on the home PC the kids use, and personal passwords end up syncing onto the work laptop.
When that staff member leaves, your work passwords go with them. They don’t even need to do it on purpose. They just need to log into their personal Chrome on a different device.
3. You can’t share a password safely
Try this. You want to give one colleague access to the shared LinkedIn account, the company Twitter, and the Canva workspace. With Chrome saved passwords, your options are:
- Tell them the password in a Teams message (now it’s permanent and searchable)
- Email it (worse)
- Text it (worse still)
- WhatsApp it (worst, because it leaves your network entirely)
You can’t share a saved Chrome password to another Chrome installation without basically giving them your whole Google account. There’s no concept of “share this one password with this one person, revoke when they leave.” Which is how passwords end up in WhatsApp threads, which is how they end up screenshotted, which is how they end up on a competitor’s whiteboard.
What we do instead
We roll out Keeper for every client. It’s a proper business password manager, used by everyone from solo business owners up to enterprise IT teams, and it does the three things Chrome can’t.
One master password, encrypted vault. Every password lives inside a vault that only opens with a master password plus a second factor. If someone steals the laptop, the vault stays shut. Even Keeper themselves can’t open it, the encryption is end-to-end.
Proper sharing. You can share an individual login with one colleague for as long as they need it, then revoke. They never see the actual password. They just see “log me into this.” When they leave, you revoke their account and every shared password is gone with them.
An admin console you can actually use. As the business owner, you can see which staff have weak passwords, which ones are reused across sites, and which logins haven’t been opened in six months. You can force everyone onto MFA. You can recover a vault if someone gets hit by a bus. None of that exists in Chrome.
It also has a free family plan thrown in for every business user, which staff actually like because it solves the home-PC password chaos at the same time.
How we set it up
When we roll Keeper out for a new client, the whole thing takes about half a day across the business.
- Set up the Keeper tenant under your domain, link it to your Microsoft Entra ID directory so logins are automatic
- Import every existing password from Chrome and Edge across every staff member’s laptop (Keeper has a one-click importer)
- Strip the passwords out of Chrome and Edge once the import is verified, so there’s no double-storage
- Set the company policy, minimum length, MFA required, no reuse, and let Keeper auto-flag the gaps
- Train the team in a 30-minute Teams call so they know how to add new logins, share, and use the autofill
After that it’s invisible. Staff barely notice the change apart from “this is actually easier than the browser thing was.”
What it costs
Keeper is £5 per user per month. For a 25-person business that works out at £125 a month, or £1,500 a year. It’s not the place to penny-pinch. The first time a member of staff leaves and you don’t have to change 40 passwords overnight pays for the next year on its own.
What to do this week
If you’ve read all of this and you’re nodding along, three things worth doing in the next seven days, even before you decide what password manager to use.
- In Chrome, go to Settings → Autofill → Password Manager, see how many passwords are saved. Most people are surprised by the number.
- Turn on multi-factor authentication on the Microsoft or Google account that Chrome is syncing to. This won’t fix the underlying problem but it raises the floor.
- Stop letting Chrome save new business passwords from today. When the popup appears, click “Never.” This stops the bleed while you sort the rest out.
Want us to roll Keeper out for your team?
Book a 30-minute natter with Andy
For UK small businesses with up to 100 staff. No slides, no pitch, just a proper conversation about where you are now and what a sensible first move would be.
Pick a time →Frequently asked questions
Is it ever safe to let Chrome save passwords?
For personal logins like Netflix or your local council parking app, yes, if your Google account has MFA on it and your device is locked. For anything connected to your business, no.
Why Keeper specifically rather than 1Password or Bitwarden?
All three are good products. We picked Keeper because the admin console for a small business owner is the cleanest of the three, the Microsoft 365 integration is the most reliable, and the included family plan makes adoption easier across a team. If you already have 1Password or Bitwarden working well, we’re happy to support those too.
What happens if I forget the master password?
Keeper has account recovery options including a recovery phrase and admin-assisted recovery for business accounts. We set this up properly during rollout so a forgotten master password is annoying, not catastrophic.
Can the IT team see my personal passwords?
No. Keeper’s encryption is zero-knowledge, which means even your IT admins can’t see the contents of your vault. They can see policy compliance and force resets, but they can’t read your passwords.
Will it work with our existing Microsoft 365 setup?
Yes. Keeper integrates with Microsoft Entra ID (formerly Azure AD) so staff sign in with their normal work account. SSO and conditional access both work.
What about saving passwords on phones?
Keeper has iOS and Android apps that autofill into any app or browser. Once it’s set up, the experience on a phone is actually better than on a desktop.
– Andy Price, Founder & MD, Initial IT · 01543 524 594 · hello@initialit.co.uk
