top of page

Your Password Manager Is Not About Passwords

  • Aug 28
  • 5 min read

It is the third week of August. The one person who can reach the firm’s tax filing account is on a boat off Sardinia, and the deadline does not move.


Nobody did anything wrong. He opened the account in 2019, he has always handled it, and until this week the arrangement worked perfectly well.


Today’s post is about the tool that turns this into a ninety-second problem, and about why nearly everything valuable it does has nothing to do with remembering passwords. Last week we promised to come back to the thing that sits underneath passkeys, and to say what a vault removes from a due diligence questionnaire. Both are here.


TWO WORDS, DEFINED

A credential is the username and password for one account. Your firm has hundreds, spread across custodians, administrators, market data, tax portals, and systems your own staff built.


A vault is a secure application that holds those credentials, locks them behind one strong password that only the user knows, and keeps an encrypted copy on every device that user works from. Encrypted means the company that makes the vault cannot read the contents.


Most principals believe that is the whole product. A tidy drawer for passwords. It is the least interesting thing it does.


IT SHARES WITHOUT SENDING

At a firm with a vault, sharing without sending takes ninety seconds. The operations lead grants a colleague access. They open the site, sign in, and access the files. They never see the password, and the password never travels through email or text. Remove the access on Monday and they stop being able to open it.


Without a vault, the answer is a satellite call to Sardinia, followed by a text message with a password in it.


That text does not go away. Once a password lands in a message, it lives on two phones, at one carrier, and inside whatever backup each phone runs, long after the colleague has moved to another firm.


IT CLOSES THE DOOR ON THE WAY OUT

An analyst resigns on a Friday afternoon. In a firm running a vault, their access ends in one motion, across everything they could reach, before they clear their desk. You can show an allocator the timestamp.


Without a vault, somebody spends the next week rebuilding a list from memory. Which systems did he use? Did he have the wire portal? The answers arrive eventually, and the distance between Friday and eventually is what a diligence analyst probes when she asks about offboarding.


IT KEEPS A RECORD

Who held access to what, and when. A vault answers that in a few clicks.


That question is rarely asked. Then it appears on a questionnaire from an allocator, in an examination request, or in a renewal application from your insurer.


Managers who can answer respond in a short paragraph with bullet points. Managers who cannot, write an explanation, and an explanation never reads as well as a list.


The regulatory backdrop points the same way. The SEC placed cybersecurity and access controls among its examination priorities for fiscal 2026. Amended Regulation S-P requires advisers to maintain incident response programs covering unauthorized access to customer information. Neither names a password manager. Both describe a firm that has one.


IT HOLDS YOUR PASSKEYS

Last week’s subject, and the reason these two posts belong together. A passkey kept in a vault travels with the person. A passkey kept inside one phone belongs to that phone. The vault keeps passwordless sign-in portable rather than scattered across systems that do not speak to each other.


WHAT THE NUMBERS SHOW

Here is the figure most people expect, then the one that matters more.


This year, for the first time in nineteen editions of Verizon’s annual breach study, stolen credentials lost the top spot as the way attackers first get in. Software flaws took it at 31 percent, credential abuse fell to 13.


Now the second. Counted anywhere in an attack rather than only at the entry point, credential abuse still appears in 39 percent of breaches, more than any other technique. And 73 percent of ransomware victims had a credential leak or infostealer infection in the prior year.


Passwords are no longer mainly how an intruder gets in. They remain how an attacker moves once inside, which is exactly why a vault is not really about passwords.


WHY THE DELIVERY METHOD DECIDES HOW THIS GOES

Deploying a vault is not difficult. Structuring one is, because structure means deciding who may reach which credentials, and that requires knowing how your firm works.


Much of the managed services industry spent recent years assembling itself into private equity platforms. Those firms hold real capability. They also carry consolidated help desks and rotating account managers, and a vault built by someone who met your firm last Tuesday gets organized for a generic client rather than for yours.


Roark has remained independent since 1998, with no outside investors and no debt. Our CTO has led our technical team since 2007. Our Service Desk Manager joined us in 2008 and continues to oversee our helpdesk services. They know how your firm is put together because they helped put it together.


WHAT WE DO, AND WHAT STAYS YOURS

We deploy the vault and we maintain it. We build the structure, meaning the groups that determine which credentials sit where. We document recovery, we test it, and we handle enrollment.


You decide who may see what. That is not a courtesy we extend. It is how the tool is built. We create the container. We cannot read what you put inside it, and neither can the company that makes the vault.


That architecture has a second use. When an allocator asks whether your technology provider can reach your credentials, you answer no, and point to how the system works rather than to an assurance.


So, two responsibilities stay with you.


  • Somebody at your firm decides who belongs in which group, because we don’t know your reporting lines or which positions are sensitive as well as you do.


  • Each person keeps one strong password in their own head.


And when the question arrives at an awkward hour, someone answers it. Not a queue. Not a form. An engineer who knows your environment and who will still be here next year.


"WHAT IF SOMEONE FORGETS THE ONE PASSWORD?"

The right question, and the honest answer is that nobody can recover it. Not the vault company. Not us. That is precisely what makes the vault secure.


So, we build the answer before we deploy. We set up emergency access, we generate recovery codes and document where they live, and we configure an administrator recovery path for firm accounts. Then we test all of it, because an untested recovery plan is a theory rather than a control.


WHY NOW

Not because something bad is coming. Because the ordinary events of a manager’s year go easier when the answer already exists. A hire. A departure. A questionnaire. An examination. A renewal. Each takes ten minutes at a firm with a vault and most of a week at a firm without one.


If you are not certain how your firm holds its credentials today, tell us. We will look and tell you what moving would involve.


If a peer mentions their next ODD review over dinner, forward this along. They will get more out of it than you did.

Independently owned since 1998, with no outside investors and no debt, Roark Tech Services delivers White Glove technology and security services to demanding organizations across multiple time zones.


bottom of page