The Sticky Note Under the Keyboard Is a Security Policy
Every so often I sit down at a client's front-desk computer to fix something, lift the keyboard, and there it is: a sticky note with three passwords on it. Sometimes it's taped to the monitor. Sometimes it's a shared spreadsheet named passwords_FINAL_v2 that half the office can open. Nobody set out to build a bad security policy. But that sticky note is the policy, whether anyone wrote it down on purpose or not.
I'm not here to make you feel bad about it. I've seen this in law offices, HVAC shops, dental practices, and restaurants all over Texas, and the folks running them are smart, busy people. They just never had anyone explain the simple fix in plain English. So let me do that.
Why the passwords in your head are the real weak spot
Here's the thing most people get backwards. When they picture a "hack," they imagine some genius in a hoodie cracking a supercomputer. That almost never happens to a small business. What actually happens is boring: someone reuses the same password across six accounts, one of those websites gets breached, and now a stranger is quietly trying that same email-and-password combo everywhere else. Your bank. Your email. Your point-of-sale system.
The uncomfortable math is this. A person can maybe remember five or six real passwords. But a small business runs on twenty, thirty, sometimes fifty logins. So people cope the only way a human can — they reuse one password with a number on the end, or they write them down where they can see them. Both are completely understandable. Both are also exactly how businesses get burned.
The problem was never your memory. The problem is that we're asking a human brain to do a filing cabinet's job.
What a password manager actually does (no jargon)
A password manager is a locked vault for all your logins. You remember one strong master password — just one — and the vault remembers the rest. When you visit a site, it fills in the login for you. That's basically it.
But here's why it quietly changes everything:
- Every account gets its own long, random password. You never have to type or remember them, so there's no reason to reuse one. A breach at one vendor stops at that vendor.
- It works on your phone and your computer. No more "what was that login again?" texts flying around the office.
- You can share a password without showing it. This is the part that wins people over. You can give an employee access to the shared account without them ever seeing the actual characters — and when they leave, you pull the access back in one click. No more changing the Wi-Fi password because someone quit.
There are several good ones for small businesses. I won't turn this into an ad — the point is far less which brand you pick and far more that you pick one and actually use it. The best tool is the one your team will stick with.
How to roll it out without a mutiny
The fastest way to kill a good security habit is to dump it on your team all at once with a stern email. People are busy, and "new software" sounds like more work. So make it feel like less work, because honestly, it is.
Start with yourself for a week. Move your own logins in, get comfortable, and notice how nice it feels to stop typing passwords. Then bring in one or two people who touch the most accounts — usually whoever runs the front desk or the books. Let them feel the relief of autofill before you ask the whole team to switch. Once a couple of folks are saying "oh, this is actually easier," the rest follow without a fight.
And resist the urge to migrate all fifty logins in one sitting. Just add each password to the vault the next time you naturally log in to that thing. Within a month, you'll be done and you'll barely have noticed.
What to do this week
You don't need a big project. Pick a couple of these:
- Walk your own office and lift a few keyboards. Be honest about where passwords are living right now. You can't fix what you won't look at.
- Pick one password manager and set up your master password. Make it long — a short phrase you'll remember is better than a short jumble you won't.
- Move your five most important logins in first — email, banking, and whatever runs your money. Those are the ones worth protecting today.
- Turn on two-factor authentication on your email while you're in there. Your email is the master key to almost everything else; it deserves the extra lock.
- Delete the spreadsheet once its contents live safely in the vault. A tidy filing cabinet beats a note anyone can read.
None of this takes a technical background. It takes an afternoon and the decision to stop asking your memory to do a job it was never built for.
If you'd rather not sort through the options alone — or you want a hand rolling it out across a team without the headaches — that's a big part of what we do at BVTech. No pressure and no jargon; just a straight answer about what fits a shop your size. Either way, please don't let that sticky note keep doing your security thinking for you.
— Jordan Polasek