Estimated reading time: 8 minutes
Multi-factor authentication proves a real person logged in. It never proves whose credential they used. That gap runs through almost every small business on the market.
Multi-factor authentication confirms that a real person logged in. It does not confirm who owns the credential they used.
Chris Skipworth has built a company around that gap. He is the CEO of Passpack, a zero-knowledge credential manager aimed at small businesses and managed service providers. He joined the Cyber Insurance News and Information Podcast to talk about credential management and cyber insurance. The conversation kept returning to ordinary failures that put small companies on a claims file.
The through line is ownership. Not strength. Not length. And it isn’t complexity. Who holds this credential, and does that person still work here?
Get The Podcast Here
Watch On YouTube
Watch Or Listen On Spotify
Listen On Apple Podcasts
Listen On Amazon Music
Credential Management Starts With A Question Most Owners Cannot Answer
Skipworth has a test he puts to business owners. It takes one sentence, and it usually ends the conversation.
“How long would it take you to identify who owns which credentials?” he asked. Then he answered his own question. “A lot of owners could not answer that question.”
The problem grows quietly. A company adds a CRM. It adds online banking. It adds an automation tool, a shipping portal, and a payroll system. Each one needs a credential. Then the company hires. Each new person needs access to some of those systems.
“Credential sprawl is a big issue within an organization,” Skipworth said. A founder who starts with fifteen logins can pass a thousand without noticing. Nobody decided to lose track. It simply happened, one integration at a time.
That inventory question should sound familiar to underwriters. It is the same question the industry has been asking about assets, endpoints, and vendors for a decade. Credentials are the version nobody has counted.
The Offboarding Failure Behind Small Business Breaches
Skipworth names offboarding as the most common way a small business gets breached.
His example is a law firm. A large matter comes in. The firm brings in contract staff and grants them access to the systems the case requires. The matter settles. The team disbands. The credentials stay live.
Development shops have the same shape of problem. A departing engineer walks to a competitor holding working access to internal systems. Trade secrets follow.
“It’s a bit like not changing the lock on your front door,” Skipworth said.
The physical analogy holds up better than most. You would ask for the key back. You would change the alarm code. And you would wonder whether a copy exists. Very few small companies apply that instinct to a Slack account or a shared vendor login.
For a carrier, this is the difference between a control that exists and a control that works. A policy that says access is revoked on departure means nothing without a record of who held what.
Why The Insurance Industry Has A Credential Problem Of Its Own
The most pointed part of the conversation turns the question back on the industry.
Insurance is an old business running on old systems. Those systems were built before anyone thought hard about access control. Layered on top is a distribution model that depends on outside parties. Agents. Brokers. MGAs. Third-party administrators. Each relationship needs credentials.
“Every time you issue a credential to a particular partner, you have a potential point of attack,” Skipworth said.
Then he asked the question carriers may not enjoy. Insurers demand high cybersecurity standards from their clients. Are they running those same standards inside their own walls?
Skipworth thinks the industry is improving and compares the trajectory to banking. He also thinks it takes time. He pointed to the Change Healthcare breach, the claims-processing subsidiary of UnitedHealth Group, as the illustration. Entry at one point in the chain, damage that traveled downstream to providers who had no relationship with the attacker.
That is aggregation risk described from the vendor side of the table.
AI Raises The Cost Of Weak Credential Management
Skipworth is direct about what artificial intelligence changed. It did not invent new attacks. It made the old ones cheap.
Phishing scales. Impersonation improves. Voice cloning defeats systems that were designed when a familiar voice counted as proof of identity. Attribution gets harder, because the identity on the other end may never have existed.
“AI can do a much better job in cracking weak passwords,” Skipworth said. “It’s got the tools at its disposal.”
His favorite illustration comes from Paris. Leaked audit documents on the Louvre reported a video surveillance password no stronger than something a home user would pick. Museums are not special. Neither are routers, which ship with admin credentials that almost nobody changes.
He is blunt about one habit in particular. “Please do not use your browser password manager if you’re serious about security.” One compromise at the desktop opens bank details, card numbers, and addresses in a single pass.
Where MFA Stops, And Credential Ownership Begins
Skipworth is a supporter of multi-factor authentication. He calls it a fundamental part of any security posture and tells owners to enable it wherever a system allows it.
He also draws its limits clearly, and this is the sharpest idea in the episode.
“What it doesn’t do is supply the ownership of that particular credential,” he said. “You can’t tell who owns it via an MFA login.”
Worse, the second factor can walk out of the building. “The MFA code could well leave with a credential when a person is off-boarded.”
That sits directly against ground CINI has covered before. Three weeks ago on this show, Julien Richard of Lastwall was asked a similar question. He declined to say that passwordless authentication alone should move a premium. Carriers should price audited controls across the whole estate, he argued, not reward a single technology. Skipworth was asked whether adopting a credential manager makes a company a better risk.
“It’s that simple in many cases,” he said. “Especially for the small to medium-sized business.”
Two vendors, two positions, one open question for underwriters. Readers can weigh both.
Three Credential Management Steps Before Your Next Renewal
Asked what an owner should do on a Monday morning, Skipworth gave three answers.
- Turn on multi-factor authentication across every critical system that supports it. He describes this as work you can start this afternoon.
- Put every credential in one encrypted place and record who owns each one. Share access by role, not by default. “Not everybody has access to everything,” he said.
- Rotate credentials on a schedule. A password left alone for years will eventually surface somewhere it should not.
None of that is exotic. That is Skipworth’s point. He argues that most small business exposure closes with basic hygiene, applied consistently. That depends on people finding the tool easy enough to use.
Passpack sells that tool. The ownership gap is real; whoever fixes it.
FAQ – Credential Management Cyber Insurance
Password management stores logins. Credential management adds ownership, access control, and an audit record. It tracks who holds each credential and what that credential opens. Skipworth argues the difference shows up most during offboarding and compliance reviews.
Carriers vary. Skipworth says adopting one makes a small business a better risk, and calls the case that simple. Other guests on this show have disagreed. Most underwriters weigh the full control set at renewal rather than any single tool.
MFA confirms that an authorized person completed a login. It carries no record of who owns the credential. The second factor can also leave with a departing employee, keeping the account live.
The provider stores encrypted data and holds no key. Passpack employees cannot read customer credentials. The comparison used in the episode is a safe deposit box. The bank controls the vault. The bank does not know the contents.
Credentials multiply as a company adds systems and staff. Old accounts linger. Ownership blurs. A small business can pass a thousand active credentials with no record of who holds them.
Enable MFA on every critical system that supports it. Move all credentials into one encrypted place with recorded ownership. Rotate them on a schedule.
Full Transcript
Download the full transcript of this episode. Transcripts are machine-generated and lightly edited. Accuracy is not guaranteed. Please refer to the audio for the record.
Related Cyber Insurance Posts
- “Critical Security Gap” Amid Escalating Financial Sector Cybersecurity Threats
- Ireland Leads in Cyber Attacks, but Also in Cyber Insurance Ownership – Report(Opens in a new browser tab)
- MFA Security Gap: Why It Puts Cyber Insurance Coverage and Business Security at Risk(Opens in a new browser tab)
- Are Cyber Insurers and their Clients Putting Too Much Trust in MFA (Multifactor Authentication) to Stop Ransomware? (Opens in a new browser tab)
- Are Cyber Insurers and their Clients Putting Too Much Trust in MFA (Multifactor Authentication) to Stop Ransomware? (Opens in a new browser tab)
