The password spreadsheet that will not die.
The scenario:
Somewhere in your client base there is a spreadsheet called passwords.xlsx. It has been “temporary” for four years. Half your team knows which client it is.
The fix is not a lecture about password managers. The fix is a migration path so small and boring the client cannot object to it.
Frame it as risk transfer, because it is. While credentials sit in a shared file, every leaver, every stolen laptop, and every phish puts the whole client at stake, and the client believes you have it handled. One compromised spreadsheet has turned into a full incident response bill more times than anyone admits. The migration is an afternoon of work spread over a fortnight.
The prompt:
You are building a credential hygiene migration plan for an MSP client still using shared spreadsheets for passwords.
Context: [client size, the systems in the spreadsheet, the password manager you offer]
Build:
A 30-minute audit checklist to find every credential store the client uses, not only the one you know about
A migration order: which credentials move first and why, admin accounts at the top
The client-facing one-pager explaining what changes for their staff, in plain language
A closure step: the date the spreadsheet is deleted, confirmed in writing
Make the whole plan fit inside two weeks of normal workload.
