Every company has one. A "Passwords.xlsx" spreadsheet on the shared drive. A sticky note under the keyboard. A shared mailbox password known to half the office, and to two people who left the company long ago. Everyone knows it's not ideal. Few know exactly how not-ideal it is.
How passwords actually fall
Attackers rarely "guess" passwords by hand. They have better methods. Data breaches at major services have produced databases of billions of email-and-password combinations, and the first thing an attacker tries is your old password from some long-hacked service, on your business account. If you reuse passwords, somebody else's breach becomes your problem.
The second method is brute force: modern hardware tries billions of combinations per second. A short password with "tricks" like swapping letters for digits falls in seconds or hours. A long passphrase of several random words. In centuries. Length beats complexity, every time.
A password manager: one fix for the whole problem
A password manager solves the human side of the problem: nobody can remember fifty long, unique passwords, and nobody has to. The tool generates, stores and fills them in for you; you remember one strong master phrase.
For companies, business editions bring what a spreadsheet on a drive never will: sharing access without sharing the password itself, instantly revoking access when someone leaves, an audit trail of who accessed what, and alerts when a password shows up in a known breach. The monthly cost per user is less than a cup of coffee.
Three rules that change everything
First: every password unique. That turns a breach at one service into irrelevant news instead of an incident. Second: MFA on everything important, because even the best password can leak, and with MFA it's worthless on its own. Third: a tidy offboarding procedure, a list of accesses and their shutdown on the same day someone leaves, no exceptions.
And one common misconception to finish: forcing password changes every 30 days is no longer considered good practice. People respond by picking weaker passwords with a number bumped at the end. Better: a long, unique password changed when there's a reason: suspected compromise, not the calendar.