Practical cyber security guidance

Passkeys and password managers for small businesses

Passwords remain common, but businesses can reduce password risk by using password managers, unique credentials and stronger authentication. Passkeys and FIDO2-based methods can further reduce exposure to phishing where services support them.

Frequently asked questions

6 practical answers.

### Should staff use a password manager?

A well-managed password manager can help staff create and store unique passwords rather than reusing memorable passwords across services. The password manager account itself should be strongly protected.

### What is a passkey?

A passkey uses public-key cryptography and a trusted device or security key instead of relying on a reusable password sent to a website. Correctly implemented passkeys are designed to resist common phishing techniques.

### Are passkeys the same as MFA?

A FIDO2 authentication can constitute MFA when local user verification such as a PIN or biometric is required as part of the sign-in.

### Should we change passwords regularly?

Avoid forcing arbitrary frequent password changes unless there is a specific reason or policy requirement. Focus on unique credentials, compromised-password response, strong authentication and secure account recovery.

### How should administrator passwords be handled?

Privileged accounts should be separate from routine user accounts where practical, use unique credentials, strong authentication and tightly controlled recovery methods.

### What if a service does not support passkeys?

Use the strongest supported MFA method, a unique password stored in an approved password manager and additional controls appropriate to the risk.

Related guidance

Keep improving the control set.