Work password storage and usage practices
The Work password storage and usage practices survey shows how your team really handles the keys to your systems. It reveals where people keep work passwords, whether they reuse them, how often they get locked out, and what stops them from following secure habits. The results turn vague assumptions about password hygiene into a concrete picture you can act on.
What the “Work password storage and usage practices” survey measures
The survey captures the everyday reality of password management: where passwords live — an approved or personal password manager, the browser, a corporate secret vault, notes and documents, on paper, or only in memory — how often people have to reset a forgotten or locked password, and how frequently the same password is reused across services. It gauges confidence in whether passwords are truly unique, strong, and not reused, checks which good practices people actually follow (unique passwords, passphrases, a manager, 2FA, no sharing, separate accounts), surfaces recent risk events like urgent recoveries, missing 2FA access, suspected compromise, or being asked to share access, and pinpoints the barriers that push people toward shortcuts.
Who the “Work password storage and usage practices” template is for
It suits IT and security teams, IT admins, and CISOs rolling out or evaluating a password manager, 2FA, or single sign-on. Operations and team leads managing shared tools and contractor access get a clear view of where credentials leak out of process, and compliance owners can document practices for audits. It works for startups tightening their first policies and for larger organizations checking adoption across departments.
How to adapt the template to your needs
Rename the storage options to match your approved tools (your specific password manager, SSO, or vault), and adjust the reset-frequency scale to your reality. If you enforce a rotation policy, add a question about it; if you rely on SSO, add items about that experience. You can add branching so that anyone who reports storing passwords in the browser, in notes, or on paper is asked a follow-up about what would make an approved manager easier to adopt, and you can trim the practices list for teams with fewer systems.
Questions and answer options
Answer options:
— In a company-approved password manager
— In a personal password manager
— In the browser (saved passwords)
— In a corporate system/secret vault (if available)
— In notes/a document (e.g., a file/page)
— On paper
— I memorize them and don’t store them anywhere
Answer options:
— Several times a month
— About once a month
— Several times per quarter
— Less often
— Almost never
Answer options:
— Often
— Sometimes
— Rarely
— Never
— Hard to say
Answer options:
— I use unique passwords for different services
— I use long passwords/passphrases
— I store passwords in a password manager
— I do not share my password with other people (even colleagues)
— I use 2FA where available
— I regularly review and update passwords for critical systems
— I use separate accounts instead of shared accounts
— I check that I’m not entering a password on suspicious pages
Answer options:
— I needed to urgently recover/reset a password to continue working
— I didn’t have access to 2FA/email/phone during password recovery
— A service rejected a new password due to requirements (complexity/history)
— I had to keep a password “handy” due to frequent logins
— I suspected compromise (unusual login/notification)
— I was asked to share access/password to complete a task
— I had to use a shared account
Answer options:
— Too many services and passwords
— Frequent re-login requests
— The password manager is inconvenient or unavailable
— Unclear/too strict password requirements
— It’s hard to move passwords between devices
— There is no clear process for “team” access (without sharing passwords)
— Not enough time/attention to organize passwords
— I’m not sure which storage methods are allowed by the rules