Latest — Jul 16, 2026
One weak credential. Billions exposed. The 2025–2026 breaches show the same pattern: unmanaged access, unpatched software, and data no one remembered was still there.

The two-year period from 2025 to 2026 produced the largest credential exposure in recorded history. A single support portal account with no MFA gave an attacker access to records on 60 million students and 10 million educators across 18,000 school districts. The most expensive cyberattack in British corporate history shut down factory production for weeks and cost an estimated £1.9–2.1 billion (around 2,2–2,5 billion €).

Large incidents get investigated thoroughly: root causes published, attack chains reconstructed, regulatory findings released. That makes them the clearest window into how attackers actually operate.

This article breaks down what made 2025–2026 different: the five structural shifts in attacker behavior, the specific breaches that defined the period, and a six-step framework for closing the credential gaps that made most of them possible.

Key takeaways

  • Credential reuse is a structural risk, not a user behavior problem. 16 billion credentials in one searchable corpus means any reused password is effectively public. Unique credentials per service, enforced at the vault level, is the only reliable fix.
  • Third-party access is your access surface. 48% of 2026 breaches traced to a vendor or SaaS integration. Your security posture is only as strong as the weakest OAuth grant you've forgotten about.
  • Privileged accounts outside governance are the highest-risk accounts you have. SSA and PowerSchool both failed on the same point: accounts with unrestricted access that existed outside normal IAM controls.
  • Unpatched ERP software is now a confirmed, financially quantified attack vector. CVE-2025-31324 cost JLR an estimated £1.9–2.1 billion. Patch windows for internet-facing enterprise software are measured in hours, not weeks.
  • Data you don't delete is data you're responsible for. The University of Hawaiʻi was liable for records from 1993. Data minimization is a security control, not a compliance checkbox.
  • Social engineering bypasses technical controls entirely. M&S lost £300 million not to zero-day but to a phone call to a helpdesk agent. No firewall stops that.

The 2025–2026 period marked a structural shift in how attackers operate — away from encrypting systems and toward stealing data and threatening to publish it. 

Five trends defined the period.

1. Data-theft extortion replaced ransomware as the dominant model. Cybercriminal groups like ShinyHunters industrialized the approach: exfiltrate data, set a deadline, publish if unpaid. Attackers no longer need to manage decryption keys or negotiate recovery — exfiltration and a leak site are sufficient.

2. Third-party supply chain attacks became the primary entry vector. The Verizon 2025 DBIR found third-party involvement in 30% of confirmed incidents. By 2026, that share reached 48% — meaning nearly half of all breaches now trace back to a vendor, SaaS provider, or OAuth integration rather than a direct attack on the organization itself (Verizon 2026 DBIR).

3. Education and healthcare became high-value targets. Student information systems and patient records now hold SSNs, medical histories, and insurance data — and both sectors consistently lag on basic controls like MFA and privileged access monitoring. 

4. Vulnerability exploitation overtook credential theft as the top initial access vector — 31% versus 13% in 2026, the first time in the DBIR's history. AI compressed the window between disclosure and active exploitation from months to hours. Compromised credentials still appear in 39% of all breaches when the full attack chain is considered.

5. Privileged access became an attack surface in its own right. A single account with unrestricted access and no monitoring can expose more data than a sophisticated external intrusion — no privilege escalation required.

The breaches below show how each of these patterns played out in practice.

Date Company Compromised data
January 2025 PowerSchool Personal data of 70 million students and staff, including Social Security numbers (SSNs)
March 2025 SSA / DOGE 300+ million Social Security records allegedly exported
March 2025 Conduent Business Services Personal and healthcare data of 62.2 million individuals
April 2025 NYC Health + Hospitals Personal, medical and biometric data of 1.8 million patients*
April 2025 Marks & Spencer Customer and employee data, resulting in a prolonged disruption of online operations
April 2025 Jaguar Land Rover Corporate systems and business operations affected through the SAP NetWeaver compromise
May 2025 Navia 2.7 million benefit records exposed through an unsecured API
May 2025–2026 Salesforce Experience Cloud Customer CRM data from approximately 100 organizations
June 2025 16-billion credential mega-leak 16 billion usernames, passwords and authentication records aggregated from 30 datasets
July 2025 University of Hawaiʻi Personal records of 1.2 million students, employees and applicants
August 2025 Miljödata / Volvo Group 870,000 user accounts across public and private organizations
February 2026 France Titres / ANTS Personal data from 11.7 million government portal accounts
June 2026 Klue Customer CRM data from Salesforce, HubSpot and Gong affecting multiple enterprise customers

The 16-billion credential mega-leak (June 2025)

The June 2025 credential mega-leak is the largest password exposure in recorded history: 16 billion login credentials across 30 separate databases, discovered by Cybernews researchers. The data was an aggregation of infostealer malware logs and prior breach compilations, assembled into a searchable corpus available on darknet markets for $10.

Infostealers harvest saved credentials from browsers and session cookies after the user has already authenticated. Credential reuse turns a single infection into an enterprise problem: according to Heimdal Security's analysis of Verizon DBIR 2025 data, 94% of passwords appear in multiple accounts. An employee whose personal account credentials were harvested may be using the same password on a corporate VPN or cloud console.

A centralized password vault that generates unique credentials per service, combined with phishing-resistant MFA, eliminates credential reuse as an attack surface.

Passwork's self-hosted vault generates and stores unique credentials for every service, making credential reuse structurally impossible. Audit logs show exactly who accessed what, and when. See how it works — https://passwork.pro/


SaaS supply chain under attack: Klue, Salesforce Experience Cloud, and Volvo/Miljödata

Third-party SaaS risk operates at three distinct levels simultaneously: credential theft, misconfiguration, and vendor concentration. 

The Klue breach (June 2026)

The Klue breach illustrates the credential theft vector. A legacy service account credential — the kind that gets created during an integration project and never rotated — was used to harvest OAuth tokens across dozens of connected platforms. The affected companies included HackerOne, Recorded Future, Jamf, and Tanium. Their CRM data in Salesforce, HubSpot, and Gong was exposed not because those platforms were breached, but because a single stale credential in a connected service gave an attacker the OAuth token needed to read data across all of them. OAuth token abuse at this scale is a direct consequence of ungoverned third-party integrations — shadow IT that security teams often cannot see until after the fact.

The Salesforce Experience Cloud misconfiguration (2025–2026) 

ShinyHunters exploited a Salesforce Experience Cloud misconfiguration to expose data across telecom, finance, and government organizations. Administrators had granted guest users broader read permissions than intended. The platforms were not breached — they were misconfigured. ShinyHunters claimed to have stolen data from around 100 high-profile companies, but Salesforce did not confirm that figure. 

The Miljödata ransomware attack (August 2025)

The DataCarry group attacked Miljödata, a Swedish HR software provider serving Volvo Group, approximately 25 other private companies, 200 Swedish municipalities, and multiple educational institutions. One vendor breach became hundreds of victims. According to Have I Been Pwned, 870,000 accounts were exposed, including government-issued identity numbers. Volvo Group North America began notifying employees on September 29, 2025, confirming that names and Social Security numbers had been exposed — data that originated in Volvo's HR processes but was stored in a third-party system Volvo did not control.

Together, these three cases show that third-party risk management cannot be reduced to a vendor questionnaire. It requires continuous monitoring of OAuth grants, SaaS permission audits, and an honest assessment of how many critical processes depend on a single external provider.

👉
Read our Supply Chain Security Guide 2026 to learn how to protect your business from third-party breaches.

Healthcare under fire: NYC Health + Hospitals, Conduent, and Navia

Healthcare is the most expensive sector to breach. According to the IBM 2025 Cost of a Data Breach Report, the average cost of a healthcare breach reached $7.42 million — nearly double the global average of $4.44 million. The 2025-2026 period produced three incidents that show why.

The NYC Health + Hospitals data breach (2025)

1.8 million patients' records were exposed via a third-party vendor compromise.The NYC Health + Hospitals data breach included biometric templates — fingerprints and palm prints. Unlike passwords, biometric identifiers cannot be changed. An employee whose password is stolen can reset it. An employee whose fingerprint template is stolen has no equivalent recovery option. The permanent nature of biometric exposure makes IAM controls around biometric data storage categorically more critical than those around password storage.

Health benefits administrator Navia exposed 2.7 million records through an unauthenticated public API endpoint reachable from the open internet — a misconfiguration that mirrors the database exposure pattern above, applied to the application layer.

The Conduent Business Services breach (2025)

Attackers from the SafePay group were inside Conduent's network for 84 days before detection. Conduent processes payments, documents, and medical records for insurers and government agencies across North America. 

By the time the full scope was confirmed in June 2026, the breach had affected 62.2 million individuals, making it the third-largest healthcare data breach in recorded history. Among the confirmed victims: Premera Blue Cross, Humana, and multiple Blue Cross Blue Shield branches. The attackers never touched the insurers directly. They went through the vendor.

Healthcare's combination of high-value data, legacy infrastructure, and complex vendor ecosystems makes it the sector most consistently hit by both credential-based and extortion-based attacks.

Passwork enforces role-based access control across all credential types, including API keys and service account passwords. Explore how Passwork handles enterprise credential governance — https://passwork.pro/

When privilege becomes a weapon: SSA and PowerSchool

The DOGE/SSA incident illustrates that the most dangerous credential threat is not always external. A single privileged account with unchecked access can expose more data than any external breach.

The Social Security Administration data export (2025) 

The SSA case is the clearest argument for why privileged access management (PAM) and the principle of least privilege matter even inside organizations. DOGE operators with privileged access to SSA systems allegedly exported a full live database dump of SSN records — covering more than 300 million Americans — to an unsecured external server. No external attacker was involved. 

The PowerSchool breach (2025) 

A single support portal account, lacking MFA, session monitoring, and anomaly detection, exposed records of 60 million students and 10 million educators across the US, Canada, and the UK. 83% of affected students had their Social Security numbers exposed, along with medical records. The support account already had unrestricted access — no privilege escalation or lateral movement was needed.

Both incidents point to the same gap in IAM architecture: privileged accounts that exist outside the normal credential governance process. Support portals, vendor accounts, and administrative backdoors are frequently excluded from password rotation policies, MFA enforcement, and audit logging — the exact controls that would have prevented both breaches.

A detailed breakdown of what privileged access management is and best practices from industry experience — in this article.

Europe under attack: Marks & Spencer, Jaguar, and the cost of social engineering

Three European incidents from 2025–2026 produced the most financially documented losses of the period.

The Marks & Spencer breach (2025) 

The breach exposed personal data across M&S's customer base — names, addresses, phone numbers, dates of birth, and order history. M&S did not disclose the exact number of affected customers. Scattered Spider, a cybercriminal group known for stealing sensitive data from Fortune 500 companies, gained initial access through a third-party managed IT services provider by impersonating an employee to a helpdesk agent via SIM-swapping. From there, they moved through Active Directory. Online sales were suspended for 46 days. M&S confirmed a £300 million (around €353 million) profit impact in its annual results.

The Jaguar Land Rover breach (2025) 

It’s the most expensive security breach in British corporate history, estimated at £1.9–2.1 billion (around €2.4 billion) by the Cyber Monitoring Centre. An unpatched SAP NetWeaver vulnerability (CVE-2025-31324, patched April 2025) halted production at factories globally. Wholesale deliveries fell 24.2% year-on-year in JLR's fiscal second quarter and 43% in the third. The Bank of England's manufacturing PMI for September 2025 fell to 46.2, with JLR's shutdown cited as a contributing factor.

The France Titres / ANTS breach (2026) 

Attackers exfiltrated 11.7 million accounts from France's national passport and ID portal. Government identity portals hold verified, legally binding identity data — which makes them high-value targets precisely because the data cannot be disputed or replaced.

The M&S and JLR cases confirm two attack vectors that are now financially quantified: social engineering against third-party contractors, and exploitation of unpatched enterprise ERP software.


The shadow data problem: University of Hawaiʻi and the legacy archive risk

The University of Hawaiʻi breach (2025) exposed records from 1993 to 2007 — data that had never been deleted, encrypted, or audited, demonstrating that data minimization is a direct security control.

A ransomware attack exposed 1.2 million records, including research archives created before modern encryption standards existed. Data from 1993 to 2007 was never subject to current access controls, yet it remained on live infrastructure — queryable, exfiltrable, and legally the university's liability.

Shadow IT and shadow data are two sides of the same governance failure. Shadow IT is the unauthorized application running on your network. Shadow data is the dataset that was created for a project in 2001, never deleted, and never included in any data inventory. Both are invisible to security controls because they were never registered in the first place.

The control is data minimization: retain only what is operationally necessary, and audit legacy datasets on a defined schedule. Organizations that cannot answer "what data do we hold, where is it, and who can access it?" cannot defend it.


How to protect your enterprise from the next mega-leak

The Enterprise Credential Defense Framework maps each control directly to a breach pattern from this article.

Step 1. Deploy a centralized enterprise password vault.

Eliminates credential reuse and provides a single audit trail for all credential access. A centralized password vault with role-based access control means that when a credential is compromised, the blast radius is contained to what that credential was authorized to access — not everything the employee happened to know.

Step 2. Enforce minimum 15-character passwords and phishing-resistant MFA.

Legacy password policies — 90-day mandatory rotation, complexity rules requiring symbols and mixed case — are counterproductive. NIST SP 800-63B Rev. 4 removes both requirements. The reasoning is empirical: forced rotation produces predictable incremental changes (Password1! → Password2!), and complexity rules generate passwords that are hard for humans to remember but easy for automated tools to crack.

Criterion Old approach NIST SP 800-63B Rev. 4
Minimum length 8 characters 15 characters (recommended)
Complexity rules Uppercase, number, symbol required No composition rules
Expiration 90-day rotation No periodic expiration
Rotation trigger Calendar-based Compromise-driven only
MFA requirement Optional Phishing-resistant MFA at AAL2+
Banned passwords Rarely enforced Check against known-breach lists

For MFA specifically: SMS-based OTP is not recommended at AAL2. Hardware keys and passkeys meet the phishing-resistant threshold. The Verizon 2025 DBIR notes that MFA bypass techniques are growing — token theft accounts for 31% of bypass methods, MFA fatigue for 22% — but having MFA enabled still eliminates the vast majority of credential-based attacks.

Step 3. Audit and revoke ungoverned third-party SaaS integrations and OAuth grants.

Run a quarterly audit of all OAuth grants in your identity provider. Revoke any grant that cannot be attributed to an active, documented integration. Legacy service accounts should be rotated on a defined schedule and decommissioned when the integration is retired.

Step 4. Apply PAM controls and the principle of least privilege.

No account — internal or external — should have access beyond what its documented function requires. Privileged accounts should be time-limited, session-recorded, and subject to the same MFA requirements as any other account.

Step 5. Enforce data minimization and audit legacy datasets.

Establish a data retention schedule. Run an annual audit of datasets older than five years. Data that has no current operational purpose should be deleted, not archived on a live server.

Step 6. Eliminate arbitrary password expiration; adopt compromise-driven rotation.

Rotate credentials when a compromise is detected or suspected — not on a calendar. Integrate your password vault with breach intelligence feeds so that rotation is triggered by evidence, not by a 90-day clock that trains users to make predictable changes.


Conclusion

Three root causes appear in breach after breach across this article: credentials that were unmanaged or reused, access that was unchecked or over-permissioned, and data retained long past any operational purpose. Every incident covered here, from the 16-billion credential dump to the £1.9 billion JLR shutdown, maps to at least one of those three failures.

Every control in the Enterprise Credential Defense Framework maps to a documented failure in a named breach above. The question for your organization: which of those failures are you replicating right now?

Start with a credential audit: every privileged account, every OAuth grant, every service account in your environment. If you cannot answer those questions in under an hour, you have a visibility problem before you have a security problem.

Passwork is a self-hosted password and secrets manager built for exactly that audit: centralized vaults, role-based access, and zero-knowledge encryption, so you always know who has access to what. Explore deployment options — passwork.pro


Frequently asked questions

What was the biggest data breach in 2025?

The 16-billion credential mega-leak in June 2025 is the largest password exposure in recorded history. Cybernews researchers discovered 30 separate databases containing 16 billion login credentials aggregated from infostealer malware logs and prior breach compilations. The data was available on criminal markets for as little as $10 per access.

How do data-theft extortion attacks work?

Attackers exfiltrate sensitive data, set a ransom deadline, and publish if unpaid. No encryption is deployed — there is no technical recovery path. The only leverage is the threat of publication. This model requires no decryption key management and no negotiation over system restoration, which is why groups like ShinyHunters adopted it at scale. The only effective defense is preventing exfiltration in the first place: access controls, egress monitoring, and least-privilege enforcement.

What is the most common initial access vector in 2025–2026 breaches?

Vulnerability exploitation overtook credential theft for the first time in the Verizon 2026 DBIR, accounting for 31% of initial access versus 13% for stolen credentials. But compromised credentials still appear in 39% of all breaches when the full attack chain is considered — most commonly through infostealer malware harvesting reused passwords from personal accounts and applying them to corporate systems.

How does third-party risk translate into a direct breach?

A vendor, SaaS provider, or OAuth integration with access to your systems is an extension of your attack surface. The Conduent breach affected 62.2 million individuals across dozens of insurers — none of whom were directly attacked. The Klue breach exposed CRM data across HackerOne, Recorded Future, Jamf, and Tanium through a single stale service account credential. By 2026, 48% of confirmed breaches traced back to a third party (Verizon 2026 DBIR).

Can biometric data be recovered after a breach?

No. Unlike passwords, biometric identifiers such as fingerprints and palm prints cannot be changed or reissued. The NYC Health + Hospitals breach exposed biometric templates for 1.8 million patients. Those individuals have no equivalent of a password reset — their biometric identifiers are permanently compromised for any system that relies on them.

What made the Marks & Spencer breach so expensive?

The £300 million loss came from operational disruption, not from the breach itself. Scattered Spider used SIM-swapping and helpdesk impersonation to obtain credentials for a third-party contractor, then moved through Active Directory. Online sales were suspended for 46 days. The attack required no technical exploit — a phone call to a helpdesk agent was sufficient. That is what makes social engineering disproportionately costly: it bypasses technical controls entirely.

Passwork vs 1Password: Best Password Manager for EU
GDPR, NIS2, ANSSI 2027 — the regulatory pressure keeps building. We compare Passwork and 1Password on the criteria that matter to European businesses: data sovereignty, audit readiness, deployment model, and real total cost of ownership.
Team password management: The complete guide for 2026
Learn how teams share credentials securely in 2026 — RBAC, audit logs, offboarding checklists, NIST SP 800-63B Rev. 4 requirements, and self-hosted vs. cloud deployment.
11 password reuse risks and how to avoid them
Reusing a password feels harmless. It isn’t. Here’s why one leaked credential can unravel your entire organization’s security — and how to stop it from happening.

Is your data safe? The most high-profile leaks of 2025-2026 explained

16 billion leaked credentials. A €2.2–2.5 billion shutdown at JLR. One stale service account exposed data across four major firms. Here's what the biggest data breaches of 2025–2026 reveal about credential risk, and the six controls that would have stopped most of them.

Jul 16, 2026 — 17 min read
Secure password sharing at work: A guide for IT managers

Secure password sharing is the practice of granting access to shared credentials through an encrypted vault, where users authenticate to the vault rather than receiving the raw password. It preserves individual accountability and provides a revocable, auditable access trail — the two properties that informal sharing methods structurally cannot provide.

Most organizations are nowhere near that standard. Credentials move through the business in ways nobody designed and nobody tracks: a database password sent over Slack, an admin account emailed to a contractor, a payroll login in a spreadsheet that three people in Finance can open. The access is real. The audit trail is not.


Key takeaways

  • Credential breaches take 241 days to detect on average. IBM's 2025 Cost of a Data Breach Report puts the global average breach cost at $4.44 million. Without centralized credential governance, there is no reliable way to know a credential is compromised until the damage is done.
  • Credentials shared via Slack, email, or spreadsheets leave no audit trail. When a team member leaves, there is no reliable way to identify every system they could access. The accountability gap is architectural: the credential has been shared, but ownership has never been transferred.
  • A password manager with AD/LDAP integration automates provisioning on day one and revokes all vault access the moment an AD account is disabled. Without it, offboarding stays manual and former employees keep access longer than anyone intends.
  • NIST SP 800-63B Rev. 4 raises the minimum password length to 15 characters and prohibits mandatory periodic rotation. If your policy still mandates 90-day rotation, it is out of date: forced rotation drives predictable incremental changes, not stronger credentials.
  • Audit logs turn a security incident from a guessing game into a structured investigation. A timestamped record of who accessed which credential, when, and from where tells you exactly what was exposed — and who had access at the time.
  • Shared admin logins make individual attribution impossible. When five people use the same credential, there is no way to know who changed a setting, who authenticated during an incident, or whose access needs to be revoked. Vault-mediated sharing assigns access to a person, not a password.
  • One-time secure links and time-limited access eliminate the manual revocation problem. The link expires after use, the permission expires on a set date. No offboarding ticket required.

Why is secure password sharing in teams critical?

The financial stakes are concrete. According to IBM's 2025 Cost of a Data Breach Report, the global average cost of a data breach was $4.44 million, and breaches involving compromised credentials take an average of 241 days to identify and contain. That is nearly eight months of undetected exposure — long enough for an attacker to map your infrastructure, exfiltrate data, and establish persistence before anyone notices.

The 241-day figure is not a worst-case scenario. It is the median. Organizations that lack centralized credential governance have no reliable mechanism to detect that a credential has been compromised until the damage is already done. Structured credential management reduces the detection gap that makes breaches expensive.

Insecure password sharing: risks and solutions

Insecure method Security and compliance risks Secure alternative
Messaging apps and email Credentials remain in chat histories indefinitely, increasing exposure to hijacking and phishing. Missing audit trails violate GDPR and NIS2 standards. Vault-mediated sharing keeps credentials encrypted. One-time secure links for external contractors expire automatically after use.
Shared spreadsheets and local files Shared access points eliminate individual accountability, lack granular permissions, and increase bulk exfiltration risks. Role-based access control restricts permissions to Read, Edit, or Admin. Departmental vaults limit the blast radius.
Manual offboarding Orphaned accounts leave residual access to environments because IT cannot track every system a former employee accessed. Active Directory and LDAP integration automates provisioning. Disabling an AD account instantly revokes all associated vault access.
Shared admin logins Shared passwords prevent individual attribution during incidents and fail SOC 2 controls. Forced rotation leads to weak passwords. Centralized governance replaces shared logins with individual vault accounts. Vault access requires phishing-resistant MFA and NIST-compliant passwords.

The problem with insecure password sharing: Messengers, spreadsheets, and email

According to the 2026 Verizon Data Breach Investigations Report, сompromised credentials are the initial access vector in 13% of breaches, but appear somewhere in the attack chain in 39% of all incidents — a significant share across more than 22,000 confirmed breaches analyzed in the report.

In the median case, only 49% of a user's passwords across different services are unique, meaning one leaked credential routinely opens access to multiple systems through credential stuffing — a finding from Verizon's own supplemental 2025 DBIR credential research that remains current.

The root problem is architectural. When credentials are shared via Slack, email, or a spreadsheet, there is no audit trail. When a team member leaves, there is no reliable way to identify every system they could access. The credential exists somewhere outside the vault (in an inbox, a chat history, a screenshot) and there is no revocation mechanism short of rotating the password across every affected system manually.

This is the accountability gap. The credential has been shared, but ownership has not been transferred. Nobody knows who has it, where it is stored, or whether it has already been forwarded. A vault-mediated access model closes that gap by design: access is granted to a person, not a password, and it can be revoked in a single action.

💡
Passwork insight: Internal telemetry from organizations migrating to Passwork indicates that 64% of IT departments discover that at least 15% of their active credentials belonged to former employees or inactive contractors who left the company months prior.

A guide to secure shared password management

The architecture of secure credential sharing rests on three decisions: which tool you use, how you structure access, and what permissions model you apply. Get these right and the rest of the implementation follows.

Step 1: Choose an enterprise password manager with zero-knowledge architecture

The vault provider must never have access to stored credentials. Zero-knowledge architecture means encryption and decryption happen on the client side. The server holds only ciphertext.

This is the foundational requirement for GDPR data sovereignty: if the vendor cannot read your credentials, a vendor-side breach cannot expose them. For EU organizations, on-premise deployment or EU-hosted cloud (with data residency in EU jurisdiction) eliminates US Cloud Act exposure entirely.

💡
Passwork tip: Zero-knowledge encryption protects data in transit and at rest, but true data sovereignty requires control over the hosting environment. For organizations in highly regulated sectors, deploying the vault on-premise is the only way to eliminate third-party cloud risks and guarantee complete compliance with local data residency laws.

Step 2: Structure vaults by team and sensitivity level 

Organize shared credentials by department, project, or system — Development, Operations, Finance, Marketing. This structure limits the blast radius of a compromised account.

Example of vault structure in Passwork

If a Marketing team member's vault access is compromised, the attacker reaches marketing credentials, not production database strings. It also makes access reviews tractable: you are reviewing a bounded set of permissions, not an undifferentiated list of every credential in the organization.

💡
Passwork tip: Passwork’s flexible vault types allow you to mirror your organizational structure. You can assign dedicated administrators to specific departmental vaults while maintaining a global administrator who manages system configurations — without having access to the credentials stored within those vaults.

Step 3: Implement a three-tier role-based access model

The three-tier model is the minimum viable governance structure for secure credential sharing in teams:

  • Read: The user can view and copy the raw password within the vault but cannot modify or delete it. Appropriate for team members who need to authenticate to a system directly, but should have no ability to change or delete the credential.
  • Edit: The user can update and manage credentials within their assigned group. Appropriate for team leads and system owners who are responsible for keeping credentials current.
  • Administration: The user manages group membership, permissions, and access policies. Restricted to IT administrators and security leads.

This model ensures that permissions are scoped to responsibility: team members authenticate and read, leads manage, administrators govern. Changing someone's role is a single permission update.


Password sharing best practices for secure credential sharing

Beyond the basic vault structure, five operational practices separate a compliant system from one that merely looks compliant on paper.

When a vendor or freelancer needs access to a specific credential, a one-time link generates a URL that expires after a single use or after a defined time window. The recipient accesses the credential without being added to the vault as a permanent user. Once the link expires, access ends automatically. There is no manual revocation step, no forgotten offboarding ticket, no residual access.

Picture the alternative: a contractor finishes a six-week engagement. Someone on the IT team is supposed to remove their vault access. That ticket sits in a queue for two weeks. The contractor, now working for a different client, still has access to your staging environment. One-time links make that scenario structurally impossible.

Time-limited access for temporary projects 

Most enterprise password managers support access grants with a defined expiration date. Set it when you provision the contractor — if the engagement runs six weeks, access expires on week six. No offboarding ticket required, no manual follow-up, no access that quietly outlasts the project. This eliminates the most common source of credential sprawl: former users who were never properly removed.

Phishing-resistant MFA on the vault itself 

According to Okta's 2025 Secure Sign-In Trends Report, workforce MFA adoption reached 70% — meaning nearly 30% of users still lack it entirely. For vault access, phishing-resistant MFA (FIDO2 hardware keys or device-bound passkeys) is the operative standard under NIS2. 

SMS-based OTPs are not recommended: they are vulnerable to SIM-swapping and real-time phishing proxies, and NIS2 auditors are increasingly aware of the distinction.

Password length aligned with NIST Rev. 4 

The 2025 update to NIST SP 800-63B Rev. 4 raises the minimum password length to 15 characters when a password is used as the sole authenticator, and explicitly deprecates mandatory periodic rotation, replacing it with compromise-triggered credential changes.

This is the most significant revision to federal password guidance in nearly a decade. If your policy still mandates 90-day rotation, it is already out of date and actively counterproductive: forced rotation drives users toward predictable incremental changes (Password1! → Password2!) rather than genuinely stronger credentials.

💡
Passwork tip: Transitioning to a 15-character minimum while eliminating forced rotation actually reduces IT support tickets. When companies disable mandatory 90-day rotations, password-related helpdesk requests drop by an average of 40% within the first year.

Comprehensive access auditing 

Audit logs must capture who accessed which credential, when, and from where. For GDPR and NIS2 compliance, this is the primary evidence auditors request — ahead of policy documents, ahead of architecture diagrams, ahead of anything else. A timestamped log showing exactly who accessed the production database credential at 2:14 AM on a Tuesday carries more weight in an audit than a hundred pages of access control policy.

Operational best practices for secure credential sharing

Best practice Operational value Compliance and security impact
One-time secure links Generate expiring URLs for external contractors to provide single-use credential access without adding permanent users to the vault. Eliminates manual revocation steps and prevents residual access from forgotten offboarding tickets.
Time-limited access Set automatic expiration dates on vault permissions for temporary project engagements. Prevents credential sprawl by ensuring former users lose access automatically when a project ends.
Phishing-resistant MFA Enforce FIDO2 hardware keys or device-bound passkeys for all primary vault logins. Meets active NIS2 standards and blocks advanced threats like SIM-swapping and real-time phishing proxies.
NIST-aligned password policy Enforce a 15-character minimum length and replace periodic rotation with compromise-triggered changes. Aligns with NIST SP 800-63B Rev. 4 guidelines and stops users from creating weak, predictable credentials.
Comprehensive access auditing Capture timestamped logs detailing who accessed which credential, when, and from where. Provides the primary evidence required for GDPR and NIS2 compliance audits.

Regulatory requirements: GDPR, NIS2, SOC 2, and ISO 27001

Unmanaged credentials create both a security exposure and a compliance failure — often simultaneously. GDPR Article 32 requires "appropriate technical and organisational measures" to protect personal data. Shared credentials with no audit trail fail that standard directly: demonstrating appropriate access controls requires evidence of who had access to what, and when.

Framework Relevant requirement How centralized password management addresses it
GDPR (Art. 32) Appropriate technical measures to protect personal data Encrypted vault, RBAC, audit logs, and zero-knowledge architecture
NIS2 (Art. 21) Documented access control policies and MFA deployment Role-based access model, phishing-resistant MFA, and access review records
SOC 2 (CC6.1) Logical access controls tied to individual identities Individual vault accounts replace shared logins; every action is attributed
ISO 27001 (A.5.15 / A.5.16) Access control policy and user access management Centralized provisioning, deprovisioning, and periodic access reviews

NIS2 enforcement is active. Fines reach €10 million or 2% of global annual turnover. Pre-audit findings from Q4 2025 across Germany, the Netherlands, and Austria consistently flagged missing MFA, over-privileged accounts, and unmanaged service credentials as primary failures.

The pattern across failed audits is consistent: organizations had controls in place but could produce no logs, no access review records, no credential hygiene reports. Auditors treat undocumented controls the same as absent ones.

The skills gap compounds the problem. According to ENISA's NIS Investments 2025 report (published December 2025), 76% of EU organizations report difficulties recruiting qualified cybersecurity profiles, and 45% cite a lack of required skills as their main barrier.

For understaffed teams, automated tooling covers the gap that headcount cannot: vault-based access control, AD integration, and scheduled access reviews run continuously without requiring a dedicated IAM team to operate them manually.

Read our NIS2 compliance guide for a detailed mapping of compliance requirements to specific technical controls.


Practical implementation steps: The 4-step password governance model

The 4-step password governance model gives IT managers a concrete deployment sequence that surfaces problems early and builds organizational adoption before a company-wide rollout.

Step 1: Run a pilot with the IT department

Start with the team that will administer the system. A two-week pilot surfaces integration issues, user experience friction, and policy gaps before they affect the broader organization. It also gives your IT team direct experience with the tool before they are expected to support it.

Passwork deploys on-premise or in the EU cloud, so the pilot environment mirrors your production setup exactly — no separate infrastructure required. Your IT team can validate the vault structure, test AD sync, and confirm audit log output before rolling out to the rest of the organization.

Step 2: Integrate with Active Directory or LDAP

Integrating with Active Directory or LDAP is the single most important technical step. AD/LDAP integration automates user provisioning: new employees appear in the vault on their first day, with access determined by their AD group membership. When an AD account is disabled (at offboarding) all associated vault access is revoked immediately. No manual offboarding ticket. No two-week queue. No former employee with active access to your staging environment.

This matters because the alternative is a manual process that doesn't scale. When you have 200 employees and 40 shared credential groups, tracking who has access to what without automated sync becomes a guessing game rather than a governance process.

Passwork's AD and LDAP integration handles this natively. Group membership in AD maps directly to vault permissions — when someone moves from the Development team to Operations, their vault access updates automatically on the next sync.

💡
Passwork insight: Organizations using Passwork with active AD or LDAP integration report that automating this workflow eliminates the lag between an employee’s departure and credential revocation — ensuring access is terminated instantly.

Step 3: Train the team on the new workflow 

The secure path must be faster than the insecure workaround. If sharing a credential through a password manager takes 5 minutes while sharing it via Slack takes 5 seconds, people will use Slack. Training should focus on the three most common scenarios: 

  1. Sharing a credential with a new team member. 
  2. Granting temporary access to a contractor through a one-time link, and revoking access when a project ends. 
  3. Keeping it task-oriented rather than policy-oriented.

Keep it task-oriented rather than policy-oriented. In Passwork, all three scenarios take under a minute from the vault interface — generating a one-time link for a contractor requires two clicks and produces a URL that expires automatically after first use or after a defined time window. That speed is what makes adoption stick.

Step 4: Establish ongoing monitoring and quarterly access reviews 

Schedule quarterly reviews to identify stale permissions, unused credentials, and accounts that were never properly offboarded. Audit logs make this tractable: the review becomes a structured query rather than a manual investigation.

You are looking for accounts that haven't been accessed in 90 days, credentials that haven't been rotated since a known compromise window, and contractor accounts that should have expired. Passwork's security audit tools surface these automatically — weak passwords, inactive accounts, and over-privileged users appear in a single report rather than requiring a manual sweep across every vault.


Conclusion

Secure password sharing is an access governance problem. Moving credentials into a vault is the first step. RBAC, audit logs, phishing-resistant MFA, and AD integration are what separate a compliant, auditable system from a slightly more organized version of the same risk.

The 4-step password governance model gives you a workable sequence: pilot with IT, connect to AD, train on the actual workflow, review quarterly. Skip AD integration and offboarding stays manual. Skip training and people keep using Slack.

If your password policy predates August 2025, it needs a review. If your organization is in scope for NIS2 and cannot produce access logs on demand, the gap is real, measurable, and fixable. The tooling to close it exists — the question is whether it fits your infrastructure and compliance requirements.

Passwork is built for exactly that context: organizations that need full credential governance without surrendering data to a third-party cloud. It deploys on-premise or in the EU cloud, integrates natively with AD and LDAP, and produces the audit trails NIS2 auditors ask for by default. If the 4-step model described in this article is where you want to land, Passwork is the infrastructure that makes each step operational.

Passwork offers a fully functional trial — no feature restrictions, no sales call required to get started. Deploy it in your own infrastructure, connect it to your AD, and run through the governance model with your IT team before committing. If you're evaluating options for NIS2 compliance or just need to get credentials out of spreadsheets and into a controlled system, start your free trial or explore deployment options.

Frequently Asked Questions

What is secure password sharing in teams?

Secure password sharing in teams is the practice of using encrypted, centrally managed vaults with role-based access controls to distribute credentials without exposing the actual passwords to end users. It preserves individual accountability and provides a revocable, auditable access trail — the two properties that email and chat-based sharing cannot provide.

How does a password manager help with NIS2 compliance?

A password manager helps with NIS2 compliance by enforcing strong authentication policies, providing centralized audit logs of all credential access, and enabling rapid revocation of access when users leave or change roles. These controls address the documented access control requirements of NIS2 Article 21 directly, and the audit logs serve as the primary evidence regulators request.

What is the difference between a one-time secure link and time-limited access?

A one-time secure link expires after a single use, making it suited for sharing a credential with an external contractor who needs access once. Time-limited access grants a user ongoing access to a vault entry until a defined expiration date, suited for temporary project engagements. Both eliminate the manual revocation step that most offboarding processes miss.

What does NIST SP 800-63B Rev. 4 require for enterprise passwords?

The August 2025 revision of NIST SP 800-63B requires a minimum password length of 15 characters when a password is used as the sole authenticator, and explicitly prohibits mandatory periodic password rotation. Passwords should only be changed when there is evidence of compromise — not on a fixed schedule.

How does Active Directory integration improve credential security?

AD/LDAP integration automates vault provisioning and deprovisioning. When a new employee's AD account is created, they receive vault access based on their group membership automatically. When their AD account is disabled at offboarding, vault access is revoked immediately — eliminating the most common source of post-employment credential exposure.

Is RBAC overkill for a small team?

No. A three-tier model (read, edit, and administration) is the minimum viable structure and scales down to teams of any size. Even with five people, that distinction matters: a contractor on Read can't accidentally overwrite a production credential, and an Administrator is the only one who can add or remove other users from a vault.

Insecure password sharing: 2026 risks and secure solutions
Every time a credential moves through Slack or email, you lose accountability, audit trail, and compliance posture in one step. This guide covers the real risks of insecure password sharing in 2026, why employees do it anyway, and how to migrate to vault-mediated access without disrupting your team.
Password chaos: Why it’s a business problem and how to fix it
A forgotten password costs $70. A breach costs $4.44 million. Both start the same way — credentials shared over Slack, stored in spreadsheets, never rotated. Here’s what password chaos actually costs and how to eliminate it.
Password management for teams: The fix every SMB needs
Storing passwords in Slack and browsers exposes your business to breaches. Discover why personal tools fail teams, how to securely offboard departing employees in one click, and why the latest NIST guidelines recommend against forced password rotation.

Secure password sharing at work: A guide for IT managers

Learn how to implement secure password sharing in teams. Discover best practices for RBAC, NIS2 compliance, and AD integration to protect shared credentials.

Jul 9, 2026 — 12 min read
Aktuelle NIS2-Compliance-Nachrichten: Update Juni 2026

Die EU-Vertragsverletzungsmaschinerie ist im Juli 2026 von Warnungen zu Gerichtsverweisungen übergegangen. Irland, Spanien, Frankreich und die Niederlande sehen sich nun finanziellen Sanktionen gegenüber, weil sie die NIS2-Umsetzungsfrist vom Oktober 2024 verpasst haben — tägliche Strafen laufen auf, bis jedes Land der Kommission die vollständige Umsetzung meldet.

Gleichzeitig nimmt die Durchsetzungsinfrastruktur Gestalt an. Das deutsche BSI prüft aktiv registrierte Einrichtungen. Die Niederlande haben ihr nationales Gesetz einen Tag vor der Gerichtsverweisung verabschiedet. Die NIS-Kooperationsgruppe hat das bisher detaillierteste Mapping-Dokument zu Artikel 21 veröffentlicht. Und die Kommission hat NIS2 erstmals explizit mit KI-gestützter Bedrohungserkennung verknüpft.

Dieser Artikel behandelt alle wesentlichen NIS2-Entwicklungen: was sich geändert hat, welche Fristen aktuell gelten und worauf Ihr Team jetzt reagieren muss. Für die Entwicklungen des Vormonats siehe Aktuelle NIS2-Nachrichten: Mai 2026.


Wichtigste Erkenntnisse

  • Gerichtsverweisungen gegen vier Mitgliedstaaten eingereicht. Am 8. Juli 2026 hat die Europäische Kommission Irland, Spanien, Frankreich und die Niederlande an den Gerichtshof der EU verwiesen, weil sie NIS2 nicht vollständig umgesetzt haben. Für jedes Land werden finanzielle Sanktionen beantragt.
  • Das niederländische Cyberbeveiligingswet tritt am 15. August 2026 in Kraft. Der niederländische Senat hat das Gesetz am 7. Juli verabschiedet. Mehr als 8.000 Organisationen müssen sich beim NCSC registrieren, risikobasierte Sicherheitsmaßnahmen umsetzen und bis zu diesem Datum eine Aufsicht auf Vorstandsebene sicherstellen.
  • Das deutsche BSI prüft jetzt aktiv, nicht nur Registrierungen. Die aktive Aufsichtsphase begann am 6. März 2026. Das BSI kann Nachweise über Sicherheitsmaßnahmen anfordern, ohne auf einen Vorfall zu warten. Eine sekundäre Registrierungsfrist vom 31. Juli gilt für den erheblichen Anteil der 29.000 betroffenen Einrichtungen, die den März-Termin verpasst haben.
  • Die NIS-Kooperationsgruppe hat ihr Artikel-21-Mapping-Dokument veröffentlicht. Im Juni 2026 veröffentlicht, ordnet es NIS2-Pflichten und die Durchführungsverordnung 2024/2690 ISO 27001, NIST CSF 2.0, IEC 62443 und nationalen Rahmenwerken zu — die bisher konkreteste EU-weite Compliance-Orientierung.
  • Irlands NCSC hat Leitlinien zur Cyber-Governance auf Vorstandsebene veröffentlicht. Am 7. Juli 2026 veröffentlicht, richtet sich das Dokument an CEOs, CIOs und CISOs in NIS2-regulierten Organisationen und basiert auf dem NIST-basierten CyFun-Framework.
  • ENISA hat den Raumfahrtsektor auf hohe Kritikalität angehoben. Der NIS360-Bericht 2026 stellt Raumfahrt neben Banken, Elektrizität und Luftfahrt. Sieben Sektoren verbleiben in der Risikozone, wo die Reife hinter den Kritikalitätsanforderungen zurückbleibt.
  • Der EU-Aktionsplan zu Cybersicherheit und KI wurde am 7. Juli 2026 veröffentlicht. Es ist das erste EU-Dokument, das NIS2-Compliance formal mit KI-gestützter Bedrohungserkennung als erwartete operative Praxis verknüpft.
  • Das britische Cyber Security and Resilience Bill hat das Unterhaus am 16. Juni passiert. Es wurde am 17. Juni ins Oberhaus eingebracht und ist für eine zweite Lesung am 14. Juli vorgesehen. Managed-Service-Provider und Rechenzentrumsbetreiber fallen erstmals in den Geltungsbereich.

EU-Kommission verklagt Irland, Spanien, Frankreich und die Niederlande wegen NIS2-Verzögerungen

EU-Kommission verklagt Irland, Spanien, Frankreich und die Niederlande wegen NIS2-Verzögerungen

Am 8. Juli 2026 hat die Europäische Kommission Irland, Spanien, Frankreich und die Niederlande an den Gerichtshof der EU verwiesen, weil sie die vollständige Umsetzung der NIS2-Richtlinie nicht gemeldet haben. Die Verweisungen beinhalten einen Antrag auf finanzielle Sanktionen: einen Pauschalbetrag plus tägliche Strafen, die auflaufen, bis jedes Land die vollständige Umsetzung meldet.

Die Umsetzungsfrist war der 17. Oktober 2024. Die Kommission sandte im November 2024 förmliche Mahnschreiben an nicht konforme Mitgliedstaaten und im Mai 2025 mit Gründen versehene Stellungnahmen. Die Gerichtsverweisung ist die dritte und letzte Stufe des EU-Vertragsverletzungsverfahrens.

Der Zeitpunkt ist für die Niederlande bemerkenswert. Der niederländische Senat hat das Cyberbeveiligingswet am 7. Juli verabschiedet — einen Tag bevor die Verweisung eingereicht wurde (mehr dazu unten). Das Gesetz tritt am 15. August 2026 in Kraft, aber die förmliche Mitteilung der Umsetzung an die Kommission war zum Zeitpunkt der Verweisung noch nicht eingereicht. Die täglichen Strafen werden nicht mehr auflaufen, sobald die Mitteilung abgeschlossen ist.

Für Spanien, Frankreich und Irland ist kein entsprechendes nationales Gesetz verabschiedet worden. Spaniens Umsetzung wird für Ende 2026 erwartet. Frankreich und Irland haben keine festen Zeitpläne angekündigt.

Die Vertragsverletzungsverfahren haben individuelle Fallnummern:

Die Verweisungen bekräftigen einen Punkt, den Compliance-Teams in diesen Ländern bereits kennen sollten: Die Anforderungen der NIS2-Richtlinie sind unabhängig vom nationalen Umsetzungsstatus verbindlich. Gerichtsverfahren setzen die zugrunde liegenden Verpflichtungen nicht aus — sie erhöhen den finanziellen Druck auf Regierungen, die Lücke schneller zu schließen.

Quelle: Europäische Kommission, 2026


Niederlande: Cyberbeveiligingswet verabschiedet, tritt am 15. August in Kraft

Niederlande — Cyberbeveiligingswet verabschiedet, tritt am 15. August in Kraft

Am 7. Juli 2026 hat der niederländische Senat sowohl das Cyberbeveiligingswet (die niederländische Umsetzung von NIS2) als auch das Critical Entities Resilience Act (Wwke) verabschiedet, das die EU-Richtlinie über die Resilienz kritischer Einrichtungen (CER) umsetzt. Beide Gesetze treten am 15. August 2026 in Kraft.

Mehr als 8.000 Organisationen fallen in den Geltungsbereich: Ministerien, Gemeinden, Wasserbehörden, Provinzen, unabhängige Verwaltungsorgane und interkommunale Partnerschaften. Ab dem 15. August müssen sie:

  1. Sich beim National Cyber Security Centre (NCSC) über das Entitätenregister registrieren.
  2. Angemessene technische, betriebliche und organisatorische Maßnahmen auf Basis einer Risikobewertung umsetzen — einschließlich Lieferkettenabhängigkeiten.
  3. Schwerwiegende Cybersicherheitsvorfälle dem zuständigen CSIRT und der zuständigen Aufsichtsbehörde innerhalb der gesetzlichen Fristen melden.
  4. Aufsicht auf Vorstandsebene sicherstellen: Mitglieder der Leitungsorgane müssen über ausreichende Cybersicherheitskenntnisse verfügen und entsprechende Schulungen absolvieren.

Die Durchsetzung liegt bei den benannten Aufsichtsbehörden, einschließlich der niederländischen Behörde für digitale Infrastruktur. Das Cyberbeveiligingswet führt eine Geschäftsführerhaftung ein: Aufsichtsbehörden können verbindliche Anweisungen erteilen, Inspektionen durchführen und Geschäftsführer bei Bedarf suspendieren.

Für Organisationen des öffentlichen Sektors zählt die Einhaltung des Standards Baseline Information Security Government (BIO) 2 zur Erfüllung der Sicherheitsanforderungen des Cbw.

Das Inkrafttreten am 15. August ist eine harte Frist. Die Registrierung beim NCSC sollte vor diesem Datum beginnen — das NCSC selbst empfiehlt, sich im Voraus vorzubereiten, um Engpässe im Registrierungsprozess zu vermeiden.

Quelle: NL Digital Government, 2026


EU-weit: Neues Referenzdokument zu Sicherheitsmaßnahmen veröffentlicht

EU-weit: Neues Referenzdokument zu Sicherheitsmaßnahmen veröffentlicht

Im Juni 2026 veröffentlicht, gibt das Referenzdokument zu Sicherheitsmaßnahmen der NIS-Kooperationsgruppe Organisationen die bisher konkreteste EU-weite Orientierung zur Einhaltung von NIS2 Artikel 21. Das Dokument etabliert einen gemeinsamen europäischen Rahmen für Cybersicherheitsziele und enthält eine Mapping-Tabelle, die NIS2-Pflichten und die Europäische Durchführungsverordnung 2024/2690 verknüpft mit:

  • ISO/IEC 27001
  • IEC 62443
  • NIST Cybersecurity Framework 2.0
  • nationalen Cybersicherheitsrahmenwerken
  • dem CyberFundamentals Framework, CyFun®

Das Dokument ist nicht verbindlich. Es ersetzt weder nationale NIS2-Gesetzgebung noch sektorspezifische Leitlinien. Aber für Compliance-Teams, die bereits gegen ISO 27001 oder NIST CSF 2.0 arbeiten, beantwortet es eine Frage, die seit Verabschiedung der Richtlinie offen war: Wie genau ordnen sich meine bestehenden Kontrollen den NIS2-Anforderungen zu?

Das Mapping ist besonders nützlich für Organisationen, die in mehreren Mitgliedstaaten tätig sind. Anstatt separate Gap-Analysen pro Jurisdiktion zu pflegen, können Teams das Referenzdokument als gemeinsame Basis verwenden und dann nationale Abweichungen darüber legen.

Zugangskontrolle, Authentifizierung und Privileged Access Management erscheinen explizit in den gemappten Zielen — Bereiche, in denen sich die Orientierung des Referenzdokuments direkt mit NIS2 Artikel 21(2)(j) zur Verwendung von Multi-Faktor-Authentifizierung und sicheren Kommunikationssystemen deckt.

Wo Sie die Dokumente finden
Das Referenzdokument zu Sicherheitsmaßnahmen für NIS2-Einrichtungen und die begleitende Mapping-Tabelle (Anhang) sind auf der offiziellen Seite der NIS-Kooperationsgruppe auf der Website der Europäischen Kommission zur digitalen Strategie veröffentlicht.

Quellen: Center for Cybersecurity Belgium, 2026; Europäische Kommission, 2026


Irland: NCSC veröffentlicht Leitlinien zur Cyber-Governance auf Vorstandsebene für NIS2-Einrichtungen

Irland: NCSC veröffentlicht Leitlinien zur Cyber-Governance auf Vorstandsebene für NIS2-Einrichtungen

Am 7. Juli 2026 hat Irlands National Cyber Security Centre Leitlinien zur Cyber-Governance für Mitglieder von Leitungsorganen in NIS2-regulierten Organisationen veröffentlicht. Das Dokument richtet sich an CEOs, Geschäftsführer, CIOs und CISOs — die Führungskräfte, die unter NIS2 persönlich für das Cybersicherheits-Risikomanagement verantwortlich sind.

Die Leitlinien konzentrieren sich auf das Cyber Fundamentals Framework (CyFun), Irlands bevorzugtes nationales Framework für NIS2-Compliance. CyFun basiert auf dem NIST Cybersecurity Framework und gibt Vorständen einen strukturierten, risikobasierten Ansatz zur Erfüllung ihrer rechtlichen Verpflichtungen, ohne tiefes technisches Fachwissen zu erfordern.

Das Dokument deckt drei praktische Bereiche ab: Verständnis, welche Fragen Vorstände zu Cyberrisiken stellen sollten, Identifizierung und Management von Lieferkettenrisiken sowie Aufbau einer Organisationskultur, in der Cybersicherheit als Governance-Thema behandelt wird, nicht als Problem der IT-Abteilung.

Der Zeitpunkt ist bewusst gewählt. Irland ist derzeit Gegenstand eines EU-Vertragsverletzungsverfahrens wegen nicht vollständiger Umsetzung von NIS2 in nationales Recht — die Kommission hat das Land am 8. Juli 2026 an den Gerichtshof verwiesen. Die Veröffentlichung von Leitlinien auf Vorstandsebene vor der formellen Umsetzung signalisiert, dass das NCSC Organisationen unabhängig vom Stand des Gesetzgebungsverfahrens zur Compliance führt.

Guidance on Cyber Governance for Management Board Members in NIS2 Entities ist direkt beim NCSC verfügbar: PDF herunterladen

Quelle: Offizielles Portal der irischen Regierung, 2026


ENISA NIS360 2026: Raumfahrtsektor auf hohe Kritikalität angehoben

ENISA NIS360 2026: Raumfahrtsektor auf hohe Kritikalität angehoben

Der ENISA NIS360-Bericht 2026 ist die dritte jährliche Bewertung der Cybersicherheitsreife und Kritikalität aller Sektoren aus Anhang I der NIS2-Richtlinie. Die Haupterkenntnis: Der Raumfahrtsektor hat sich zu Banken, Elektrizität, Luftfahrt und digital-nativen Diensten im höchsten Kritikalitätsband gesellt.

Die Anhebung spiegelt die wachsende Rolle der Raumfahrtinfrastruktur als Abhängigkeitsschicht für andere Sektoren wider: Navigation, Kommunikation, Finanzabwicklung und Militärlogistik laufen alle über Satellitensysteme. Höhere Abhängigkeit bedeutet höhere Auswirkungen bei Störungen und höhere Zeitkritikalität bei der Wiederherstellung.

Sieben Sektoren fallen in die NIS360-Risikozone 2026, in der die Cybersicherheitsreife hinter dem Niveau zurückbleibt, das ihre Kritikalität erfordert:

  1. Gesundheit
  2. Schienenverkehr
  3. Seeverkehr
  4. IKT-Dienstleistungsmanagement
  5. Raumfahrt
  6. Öffentliche Verwaltung
  7. Trink- und Abwasser

Drei Sektoren erreichten das hohe Reifeband: Vertrauensdienste, Luftfahrt und Finanzmarktinfrastrukturen. Der Gassektor hat begonnen, sich aus der Risikozone zu bewegen, angetrieben durch verbesserten Informationsaustausch und stärkere Umsetzung von Risikomanagementmaßnahmen.

Die Zusammensetzung der Risikozone ist operativ relevant. Aufsichtsbehörden nutzen NIS360-Daten zur Priorisierung ihrer Auditkalender. Wenn Ihre Organisation im Gesundheitswesen, Schienenverkehr oder der öffentlichen Verwaltung tätig ist, erwarten Sie in der zweiten Jahreshälfte 2026 erhöhte aufsichtliche Aufmerksamkeit.

Die ENISA NIS Investments 2025-Studie ergab, dass 70% der befragten Organisationen NIS2-, DORA- und CRA-Compliance als Haupttreiber der Cybersicherheitsausgaben nannten — eine Zahl, die wahrscheinlich steigen wird, wenn Aufsichtsbehörden von der Registrierung zur aktiven Prüfung übergehen.

Quelle: ENISA, 2026


Deutschland: BSI tritt in aktive Aufsichtsphase ein

Deutschland: BSI tritt in aktive Aufsichtsphase ein

Das deutsche BSI trat am 6. März 2026 in die aktive Aufsichtsphase ein — das Datum, an dem die Registrierungsfrist gemäß dem NIS2-Umsetzungsgesetz (NIS2UmsuCG) ablief. Das Gesetz wurde am 6. Dezember 2025 erlassen. Bis Juni 2026 war es sechs Monate in Kraft.

Die Analyse von SecurityToday.de vom 16. Juni zum Aufsichtswechsel stellte fest, dass sich die Frage geändert hat: nicht mehr, ob eine Einrichtung registriert ist, sondern ob ihre gemeldeten Maßnahmen einer Prüfung standhalten.

Das BSI-Registrierungsportal wurde am 6. Januar 2026 eröffnet. Ein erheblicher Anteil der etwa 29.000 betroffenen Einrichtungen hat die März-Frist verpasst. Das BSI hat eine sekundäre Registrierungsfrist auf den 31. Juli 2026 gesetzt. Eine späte Registrierung bleibt möglich, schafft aber keinen sicheren Hafen — die Compliance-Pflichten gelten seit Dezember 2025, unabhängig vom Registrierungsstatus.

Was aktive Aufsicht in der Praxis bedeutet:

  • Das BSI kann proaktiv Nachweise über Sicherheitsmaßnahmen anfordern — ohne auf einen Vorfall zu warten.
  • Vor-Ort- und Fernprüfungen sind jetzt im Umfang enthalten.
  • Bußgelder für wesentliche Einrichtungen erreichen bis zu 10 Millionen Euro oder 2% des weltweiten Jahresumsatzes, je nachdem, welcher Betrag höher ist.
  • Mitglieder von Leitungsorganen tragen persönliche Haftung, einschließlich möglicher vorübergehender Verbote zur Ausübung von Leitungsfunktionen.

Deutschlands Umsetzung geht bei der Geschäftsführerhaftung über das EU-Minimum hinaus. Das NIS2UmsuCG verlangt ausdrücklich, dass Leitungsorgane Cybersicherheitsmaßnahmen genehmigen, deren Umsetzung überwachen und persönliche Kompetenz nachweisen. Aufsichtsbehörden können einzelne Führungskräfte persönlich für systemische Versäumnisse zur Verantwortung ziehen.

Es gibt einen praktischen Vorteil von Deutschlands strengerem Standard. Organisationen, die die NIS2UmsuCG-Anforderungen erfüllen, erfüllen das EU-Minimum mit Spielraum. Für Unternehmen, die in mehreren Mitgliedstaaten tätig sind, wird eine Sicherheitslage, die der BSI-Prüfung standhält, in der Regel auch bei benachbarten Aufsichtsbehörden bestehen.

Für späte Registranten ist die Prioritätenreihenfolge klar: zuerst registrieren, dann dokumentierte Nachweise über Maßnahmen erstellen. Wenn ein meldepflichtiger Vorfall eintritt, bevor Maßnahmen nachweislich vorhanden sind, ist eine versäumte oder verspätete Registrierung ein erschwerender Faktor.

Quelle: SecurityToday.de, 2026


EU-Aktionsplan zu Cybersicherheit und KI veröffentlicht

EU-Aktionsplan zu Cybersicherheit und KI veröffentlicht

Am 7. Juli 2026 hat die Europäische Kommission den EU-Aktionsplan zu Cybersicherheit und Künstlicher Intelligenz veröffentlicht. Das Dokument legt einen koordinierten EU-Ansatz für KI-gestützte Cybersicherheit über Mitgliedstaaten, Behörden und Unternehmen hinweg fest.

Der Plan ist auf drei Ziele ausgerichtet: Förderung einer sicheren und verantwortungsvollen Nutzung fortschrittlicher KI, Stärkung der EU-Cybersicherheit und -Resilienz sowie Ausbau der KI-Fähigkeiten Europas für Cybersicherheitszwecke.

Auf der NIS2-Seite nennt der Aktionsplan explizit die NIS2-Richtlinie als Teil des bestehenden Rechtsrahmens, auf dem er aufbaut, und ermutigt Organisationen, die NIS2 unterliegen, KI (einschließlich Open-Source-Modelle) zur schnelleren Erkennung und Behebung von Schwachstellen einzusetzen. Dies ist das erste EU-Dokument, das NIS2-Compliance formal mit KI-gestützter Bedrohungserkennung als erwartete operative Praxis verknüpft.

Konkrete Maßnahmen umfassen:

  • Einen European Blueprint für sicheren Zugang zu fortschrittlichen KI-Systemen für Cybersicherheitszwecke, der mit ENISA entwickelt werden soll.
  • Eine sichere Testplattform für Organisationen in kritischen Sektoren (Energie, Verkehr, Gesundheit, Finanzen und öffentliche Verwaltung) zum sicheren Testen und Einsetzen von KI-Lösungen.
  • Eine EU Grand Challenge zu KI für Cybersicherheit, die Industrie, Forscher und Open-Source-Communities zusammenbringt.

Der Aktionsplan steht neben dem AI Act, dem Cyber Resilience Act, DORA und dem Cyber Solidarity Act. Er schafft selbst keine neuen verbindlichen Verpflichtungen, signalisiert aber, wohin die Kommission erwartet, dass Durchsetzungsschwerpunkte und Investitionen im nächsten Gesetzgebungszyklus gehen.

Der vollständige Aktionsplan steht zum Download bei der Europäischen Kommission bereit

Quelle: Europäische Kommission, 2026


UK: Cyber Security and Resilience Bill passiert Unterhaus, geht ins Oberhaus

UK: Cyber Security and Resilience Bill passiert Unterhaus, geht ins Oberhaus

Am 16. Juni 2026 hat das Cyber Security and Resilience (Network and Information Systems) Bill seine dritte Lesung und Berichtsphase im House of Commons abgeschlossen. Es erhielt seine erste Lesung im House of Lords am 17. Juni und ist für eine zweite Lesung im Lords am 14. Juli 2026 vorgesehen.

Das Gesetz wurde am 12. November 2025 ins Parlament eingebracht und aktualisiert die bestehenden Network and Information Systems Regulations 2018 (NIS1). Es setzt NIS2 nicht um (das Vereinigte Königreich ist nicht mehr an EU-Recht gebunden), aber es nähert die UK-Anforderungen erheblich dem NIS2-Standard in Umfang und Durchsetzung an.

Was das Gesetz hinzufügt:

  • Managed-Service-Provider fallen erstmals in den Geltungsbereich. Relevant Managed Service Providers (RMSPs) müssen sich beim ICO registrieren, Risikomanagementmaßnahmen umsetzen und einen UK-Vertreter benennen, wenn sie nicht im UK ansässig sind.
  • Rechenzentrumsbetreiber werden ebenfalls in den Geltungsbereich aufgenommen.
  • Fristen für die Vorfallsmeldung werden verschärft: 24-Stunden-Erstmeldung, 72-Stunden-Vollmeldung — entsprechend der NIS2-Artikel-23-Struktur.
  • Bezeichnung kritischer Lieferanten: Das ICO erhält die Befugnis, Lieferanten zu bezeichnen, deren Kompromittierung wesentliche Dienste oder RMSPs beeinträchtigen würde.
  • Strafen steigen auf bis zu 17 Millionen Pfund oder 4% des weltweiten Jahresumsatzes bei schwerwiegenden Verstößen; bis zu 10 Millionen Pfund oder 2% bei weniger schwerwiegenden.

Die Vorfallsdefinition wird ebenfalls erweitert: Das Gesetz erfasst Vorfälle, die „geeignet sind, eine nachteilige Auswirkung" auf regulierte Dienste zu haben, nicht nur solche mit einer nachgewiesenen tatsächlichen Auswirkung. Dies ist eine bedeutsame Änderung für Organisationen, die derzeit ihre Meldeschwellen kalibrieren.

63 Änderungsanträge wurden während der Gesetzespassage vorgeschlagen. Zwei im Juni eingereichte Änderungsanträge, darunter einer zur Aufnahme der Lebensmittellieferkette als regulierten wesentlichen Dienst, erhielten in der Berichtsphase keine Entscheidung.

Die Regierung erwartet, 2026 eine Konsultation zu sekundärer Gesetzgebung durchzuführen, die spezifische Risikomanagementmaßnahmen und Meldepflichten abdeckt. Einige Bestimmungen werden ab dem ersten Tag oder zweiten Monat nach der königlichen Zustimmung in Kraft treten; andere werden durch sekundäre Gesetzgebung folgen.

Quellen: UK Parliament, 2026; Parallel Parliament, 2026


Zusammenfassung

Der Zeitraum von Juni bis Anfang Juli 2026 markiert den Punkt, an dem die NIS2-Durchsetzung von politischem Druck zu aktiven rechtlichen und aufsichtlichen Maßnahmen übergegangen ist. Gerichtsverweisungen sind eingereicht. Nationale Gesetze treten in Kraft. Aufsichtsbehörden fordern Nachweise über Sicherheitsmaßnahmen an, nicht nur Registrierungsbestätigungen.

Für Organisationen in Irland, Spanien, Frankreich und den Niederlanden ändern die Vertragsverletzungsverfahren nichts an den zugrunde liegenden Verpflichtungen. NIS2-Anforderungen sind seit Oktober 2024 verbindlich, unabhängig vom nationalen Umsetzungsstatus. Die Verfahren fügen finanzielle Konsequenzen für Regierungen hinzu — sie schaffen keine Schonfrist für regulierte Einrichtungen.

Für Organisationen in Deutschland und den Niederlanden ist der Compliance-Kalender jetzt festgelegt. Das BSI prüft. Das Cyberbeveiligingswet tritt am 15. August in Kraft. Das im Juni 2026 von der NIS-Kooperationsgruppe veröffentlichte Artikel-21-Mapping-Dokument ist das umsetzbarste Ergebnis dieses Zeitraums: Wenn Ihr Team bereits gegen ISO 27001 oder NIST CSF 2.0 arbeitet, bietet es einen direkten Weg, Ihre NIS2-Gap-Analyse abzuschließen, bevor eine Aufsichtsbehörde dies für Sie übernimmt.

Credential-Management unter NIS2 Artikel 21
Das Mapping-Dokument der NIS-Kooperationsgruppe vom Juni 2026 verknüpft NIS2 Artikel 21 direkt mit Zugangskontrolle, Authentifizierung und Privileged Access Management — Bereiche, die Aufsichtsbehörden prüfen werden. Passwork ist ein Enterprise-Passwort- und Secrets-Manager, der für EU-Compliance-Anforderungen entwickelt wurde. Erfahren Sie, wie Passwork sich zu NIS2 zuordnet
NIS2-Zugangskontrollen für Lieferkettensicherheit
48% der Sicherheitsverletzungen betreffen mittlerweile Dritte. NIS2 Artikel 21 macht Lieferanten-Zugangs-Governance zu einer rechtlichen Verpflichtung. Hier erfahren Sie, wie Sie Lieferantenzugriffe erfassen, MFA und Least Privilege durchsetzen und Audit-Nachweise führen, die Ihre Kontrollen belegen.
Schatten-IT vs. Schatten-KI: Warum KI die größere Bedrohung ist
Mitarbeiter nutzen KI-Tools, die Sie nicht genehmigt haben, auf Konten, die Sie nicht überwachen können, mit Daten, die Sie nicht wiederherstellen können. Hier erfahren Sie, wie das Risiko tatsächlich aussieht und was Governance adressieren muss.
Mitarbeiter-Offboarding: Leitfaden zur sicheren Zugangsentziehung 2026
Das Deaktivieren eines SSO-Kontos entzieht nicht den Zugang. API-Schlüssel, KI-Agenten-Credentials und geteilte Passwörter überleben es. Dieser Leitfaden behandelt das vollständige Offboarding-Playbook — von Zero-Hour-Triggern bis zur NHI-Bereinigung.

NIS2-Compliance: Neuigkeiten zum Durchsetzungsstand Juni und Juli 2026

Vier EU-Mitgliedstaaten vor Gericht, das niederländische NIS2-Gesetz tritt am 15. August in Kraft, das BSI prüft 29.000 Einrichtungen, und die EU veröffentlichte ihren ersten KI-Cybersicherheits-Aktionsplan. Alle Änderungen von Juni–Juli 2026.

Jul 9, 2026 — 15 min read
Últimas noticias sobre el cumplimiento de NIS2: actualización de aplicación de junio y julio de 2026

El mecanismo de infracción de la UE pasó de las advertencias a las remisiones judiciales en julio de 2026. Irlanda, España, Francia y los Países Bajos enfrentan ahora sanciones económicas por incumplir el plazo de transposición de NIS2 de octubre de 2024 — con penalizaciones diarias que se acumulan hasta que cada país notifique la transposición completa a la Comisión.

Al mismo tiempo, la infraestructura de aplicación se está consolidando. La BSI de Alemania está auditando activamente a las entidades registradas. Los Países Bajos aprobaron su ley nacional un día antes de que se presentara la remisión. El Grupo de Cooperación NIS publicó el documento de mapeo del Artículo 21 más detallado hasta la fecha. Y la Comisión vinculó explícitamente NIS2 con la detección de amenazas asistida por IA por primera vez.

Este artículo cubre todos los desarrollos materiales de NIS2: qué cambió, qué plazos están vigentes y qué necesita abordar su equipo ahora. Para los desarrollos del mes anterior, consulte Últimas noticias de NIS2: mayo de 2026.


Puntos clave

  • Remisiones judiciales presentadas contra cuatro Estados miembros. El 8 de julio de 2026, la Comisión Europea remitió a Irlanda, España, Francia y los Países Bajos al Tribunal de Justicia de la UE por no transponer completamente NIS2. Se solicitan sanciones económicas para cada país.
  • La Cyberbeveiligingswet de los Países Bajos entra en vigor el 15 de agosto de 2026. El Senado neerlandés aprobó la ley el 7 de julio. Más de 8.000 organizaciones deben registrarse ante el NCSC, implementar medidas de seguridad basadas en riesgos y garantizar la supervisión a nivel de consejo directivo para esa fecha.
  • La BSI de Alemania ahora audita, no solo registra. La fase de supervisión activa comenzó el 6 de marzo de 2026. La BSI puede solicitar evidencia de medidas de seguridad sin esperar a que ocurra un incidente. Un plazo de registro secundario del 31 de julio se aplica a la parte significativa de las 29.000 entidades dentro del ámbito que no cumplieron en marzo.
  • El Grupo de Cooperación NIS publicó su documento de mapeo del Artículo 21. Publicado en junio de 2026, mapea las obligaciones de NIS2 y el Reglamento de Implementación 2024/2690 con ISO 27001, NIST CSF 2.0, IEC 62443 y marcos nacionales — la guía de cumplimiento más concreta a nivel de la UE publicada hasta la fecha.
  • El NCSC de Irlanda publicó orientación sobre gobernanza cibernética a nivel de consejo directivo. Publicado el 7 de julio de 2026, el documento está dirigido a CEO, CIO y CISO en organizaciones reguladas por NIS2 y se basa en el marco CyFun basado en NIST.
  • ENISA elevó el sector espacial a alta criticidad. El informe NIS360 2026 coloca el espacio junto con la banca, la electricidad y la aviación. Siete sectores permanecen en la zona de riesgo, donde la madurez no alcanza las demandas de criticidad.
  • El Plan de Acción de la UE sobre Ciberseguridad e IA se publicó el 7 de julio de 2026. Es el primer documento a nivel de la UE que vincula formalmente el cumplimiento de NIS2 con la detección de amenazas asistida por IA como práctica operativa esperada.
  • El proyecto de ley de Ciberseguridad y Resiliencia del Reino Unido fue aprobado por los Comunes el 16 de junio. Ingresó a los Lores el 17 de junio y está programado para una segunda lectura el 14 de julio. Los proveedores de servicios gestionados y los operadores de centros de datos entran en el ámbito por primera vez.

La Comisión de la UE lleva a Irlanda, España, Francia y los Países Bajos ante los tribunales por retrasos en NIS2

La Comisión de la UE lleva a Irlanda, España, Francia y los Países Bajos ante los tribunales por retrasos en NIS2

El 8 de julio de 2026, la Comisión Europea remitió a Irlanda, España, Francia y los Países Bajos al Tribunal de Justicia de la UE por no notificar la transposición completa de la Directiva NIS2. Las remisiones incluyen una solicitud de sanciones económicas: una suma global más penalizaciones diarias que se acumulan hasta que cada país notifique la transposición completa.

El plazo de transposición fue el 17 de octubre de 2024. La Comisión envió notificaciones formales a los Estados miembros incumplidores en noviembre de 2024 y dictámenes motivados en mayo de 2025. La remisión judicial es la tercera y última etapa del procedimiento de infracción de la UE.

El momento es notable para los Países Bajos. El Senado neerlandés aprobó la Cyberbeveiligingswet el 7 de julio — un día antes de que se presentara la remisión (más información al respecto a continuación). La ley entra en vigor el 15 de agosto de 2026, pero la notificación formal de transposición a la Comisión aún no se había presentado en el momento de la remisión. Las penalizaciones diarias dejarán de acumularse una vez que se complete la notificación.

Para España, Francia e Irlanda, no se ha aprobado ninguna ley nacional equivalente. Se espera que la transposición de España se realice a finales de 2026. Francia e Irlanda no han anunciado plazos firmes.

Los casos de infracción tienen números de caso individuales:

Las remisiones refuerzan un punto que los equipos de cumplimiento en estos países ya deberían conocer: los requisitos de la Directiva NIS2 son vinculantes independientemente del estado de transposición nacional. Los procedimientos judiciales no suspenden las obligaciones subyacentes — añaden presión financiera sobre los gobiernos para cerrar la brecha más rápidamente.

Fuente: Comisión Europea, 2026


Países Bajos: Cyberbeveiligingswet aprobada, entra en vigor el 15 de agosto

Países Bajos — Cyberbeveiligingswet aprobada, entra en vigor el 15 de agosto

El 7 de julio de 2026, el Senado neerlandés aprobó tanto la Cyberbeveiligingswet (la transposición neerlandesa de NIS2) como la Ley de Resiliencia de Entidades Críticas (Wwke), que implementa la Directiva de Resiliencia de Entidades Críticas (CER) de la UE. Ambas leyes entran en vigor el 15 de agosto de 2026.

Más de 8.000 organizaciones están dentro del ámbito: ministerios, municipios, autoridades del agua, provincias, organismos administrativos independientes y asociaciones intermunicipales. A partir del 15 de agosto, deben:

  1. Registrarse ante el Centro Nacional de Ciberseguridad (NCSC) a través del Registro de Entidades.
  2. Implementar medidas técnicas, operativas y organizativas apropiadas basadas en una evaluación de riesgos — incluyendo dependencias de la cadena de suministro.
  3. Notificar incidentes de ciberseguridad importantes al CSIRT correspondiente y a la autoridad de supervisión competente dentro de los plazos legales.
  4. Garantizar la supervisión a nivel de consejo directivo: los miembros del órgano de dirección deben tener conocimientos suficientes de ciberseguridad y completar la formación adecuada.

La aplicación recae en las autoridades de supervisión designadas, incluyendo la Autoridad Neerlandesa para la Infraestructura Digital. La Cyberbeveiligingswet introduce la responsabilidad de los directores: los supervisores pueden emitir instrucciones vinculantes, realizar inspecciones y suspender a los directores cuando sea necesario.

Para las organizaciones del sector público, el cumplimiento del estándar Baseline Information Security Government (BIO) 2 cuenta para cumplir los requisitos de seguridad de la Cbw.

La fecha de entrada en vigor del 15 de agosto es un plazo estricto. El registro ante el NCSC debería comenzar antes de esa fecha — el propio NCSC recomienda prepararse con antelación para evitar cuellos de botella en el proceso de registro.

Fuente: NL Digital Government, 2026


A nivel de la UE: Publicado nuevo documento de referencia sobre medidas de seguridad

A nivel de la UE: Publicado nuevo documento de referencia sobre medidas de seguridad

Publicado en junio de 2026, el documento de referencia sobre medidas de seguridad del Grupo de Cooperación NIS ofrece a las organizaciones la guía más concreta a nivel de la UE sobre el cumplimiento del Artículo 21 de NIS2 hasta la fecha. El documento establece un marco europeo común para objetivos de ciberseguridad e incluye una tabla de mapeo que vincula las obligaciones de NIS2 y el Reglamento de Implementación Europeo 2024/2690 con:

  • ISO/IEC 27001
  • IEC 62443
  • NIST Cybersecurity Framework 2.0
  • marcos nacionales de ciberseguridad
  • el CyberFundamentals Framework, CyFun®

El documento no es vinculante. No reemplaza la legislación nacional de NIS2 ni las directrices específicas del sector. Pero para los equipos de cumplimiento que ya trabajan con ISO 27001 o NIST CSF 2.0, responde a una pregunta que ha estado abierta desde que se aprobó la directiva: ¿cómo se mapean exactamente mis controles existentes con los requisitos de NIS2?

El mapeo es particularmente útil para organizaciones que operan en múltiples Estados miembros. En lugar de mantener análisis de brechas separados por jurisdicción, los equipos pueden usar el documento de referencia como una línea base compartida y luego añadir las desviaciones nacionales encima.

El control de acceso, la autenticación y la gestión de acceso privilegiado aparecen explícitamente en los objetivos mapeados — áreas donde la guía del documento de referencia se alinea directamente con el Artículo 21(2)(j) de NIS2 sobre el uso de autenticación multifactor y sistemas de comunicación seguros.

Dónde encontrar los documentos
El documento de referencia sobre medidas de seguridad para entidades NIS2 y la tabla de mapeo adjunta (Anexo) están publicados en la página oficial del Grupo de Cooperación NIS del sitio web de Estrategia Digital de la Comisión Europea.

Fuentes: Centro de Ciberseguridad de Bélgica, 2026; Comisión Europea, 2026


Irlanda: El NCSC publica orientación sobre gobernanza cibernética a nivel de consejo directivo para entidades NIS2

Irlanda: El NCSC publica orientación sobre gobernanza cibernética a nivel de consejo directivo para entidades NIS2

El 7 de julio de 2026, el Centro Nacional de Ciberseguridad de Irlanda publicó orientación sobre gobernanza cibernética para miembros de consejos de administración en organizaciones reguladas por NIS2. El documento está dirigido a CEO, directores generales, CIO y CISO — los ejecutivos que asumen responsabilidad personal por la gestión de riesgos de ciberseguridad bajo NIS2.

La orientación se centra en el Cyber Fundamentals Framework (CyFun), el marco nacional preferido de Irlanda para el cumplimiento de NIS2. CyFun está basado en el NIST Cybersecurity Framework y proporciona a los consejos un enfoque estructurado y basado en riesgos para cumplir sus obligaciones legales sin requerir experiencia técnica profunda.

El documento cubre tres áreas prácticas: comprender qué preguntas deberían hacer los consejos sobre el riesgo cibernético, identificar y gestionar los riesgos de la cadena de suministro, y construir una cultura organizacional donde la ciberseguridad se trate como un tema de gobernanza, no como un problema del departamento de TI.

El momento es deliberado. Irlanda está actualmente sujeta a procedimientos de infracción de la UE por no transponer completamente NIS2 a la legislación nacional — la Comisión remitió al país al Tribunal de Justicia el 8 de julio de 2026. Publicar orientación a nivel de consejo directivo antes de la transposición formal señala que el NCSC está moviendo a las organizaciones hacia el cumplimiento independientemente de dónde se encuentre el proceso legislativo.

La Orientación sobre Gobernanza Cibernética para Miembros del Consejo de Administración en Entidades NIS2 está disponible directamente desde el NCSC: descargar PDF

Fuente: Portal oficial del Gobierno de Irlanda, 2026


ENISA NIS360 2026: El sector espacial elevado a alta criticidad

ENISA NIS360 2026: El sector espacial elevado a alta criticidad

El informe ENISA NIS360 2026 es la tercera evaluación anual de madurez y criticidad en ciberseguridad en todos los sectores del Anexo I bajo la Directiva NIS2. El hallazgo principal: el sector espacial se ha unido a la banca, la electricidad, la aviación y los servicios digitales por defecto en la banda de mayor criticidad.

La elevación refleja el creciente papel de la infraestructura espacial como capa de dependencia para otros sectores: la navegación, las comunicaciones, la liquidación financiera y la logística militar funcionan con sistemas satelitales. Mayor dependencia significa mayor impacto ante una interrupción y mayor criticidad temporal en la recuperación.

Siete sectores caen en la zona de riesgo de NIS360 2026, donde la madurez en ciberseguridad está por debajo del nivel que exige su criticidad:

  1. Salud
  2. Ferrocarril
  3. Marítimo
  4. Gestión de servicios TIC
  5. Espacio
  6. Administración pública
  7. Agua potable y residual

Tres sectores alcanzaron la banda de alta madurez: servicios de confianza, aviación e infraestructuras del mercado financiero. El sector del gas ha comenzado a salir de la zona de riesgo, impulsado por una mejor compartición de información y una implementación más sólida de medidas de gestión de riesgos.

La composición de la zona de riesgo importa operativamente. Las autoridades de supervisión utilizan los datos de NIS360 para priorizar los calendarios de auditoría. Si su organización opera en salud, ferrocarril o administración pública, espere mayor atención supervisora en la segunda mitad de 2026.

El estudio ENISA NIS Investments 2025 encontró que el 70% de las organizaciones encuestadas citaron el cumplimiento de NIS2, DORA y CRA como el principal impulsor del gasto en ciberseguridad — una cifra que probablemente aumentará a medida que los supervisores pasen del registro a la revisión activa.

Fuente: ENISA, 2026


Alemania: La BSI entra en fase de supervisión activa

Alemania: La BSI entra en fase de supervisión activa

La BSI de Alemania entró en la fase de supervisión activa el 6 de marzo de 2026 — la fecha en que expiró el plazo de registro bajo la NIS2-Umsetzungsgesetz (NIS2UmsuCG). La ley se promulgó el 6 de diciembre de 2025. Para junio de 2026, había estado en vigor durante seis meses.

El análisis del 16 de junio de SecurityToday.de sobre el cambio de supervisión señaló que la pregunta ha cambiado: ya no se trata de si una entidad está registrada, sino de si las medidas declaradas resisten el escrutinio.

El portal de registro de la BSI abrió el 6 de enero de 2026. Una parte significativa de las aproximadamente 29.000 entidades dentro del ámbito no cumplió el plazo de marzo. La BSI estableció un plazo de registro secundario del 31 de julio de 2026. El registro tardío sigue siendo posible pero no crea ningún puerto seguro — las obligaciones de cumplimiento se aplican desde diciembre de 2025, independientemente del estado de registro.

Lo que significa la supervisión activa en la práctica:

  • La BSI puede solicitar proactivamente evidencia de medidas de seguridad — sin esperar a que ocurra un incidente.
  • Las auditorías presenciales y remotas están ahora dentro del ámbito.
  • Las multas para entidades esenciales alcanzan hasta 10 millones de euros o el 2% de la facturación anual global, lo que sea mayor.
  • Los miembros del órgano de dirección enfrentan responsabilidad personal, incluyendo posibles prohibiciones temporales para ejercer funciones de gestión.

La implementación de Alemania va más allá del mínimo de la UE en cuanto a responsabilidad ejecutiva. La NIS2UmsuCG requiere explícitamente que los órganos de dirección aprueben las medidas de ciberseguridad, supervisen su implementación y demuestren competencia personal. Los supervisores pueden responsabilizar personalmente a ejecutivos individuales por fallos sistémicos.

Hay una ventaja práctica en el estándar más estricto de Alemania. Las organizaciones que cumplen los requisitos de la NIS2UmsuCG satisfacen el mínimo de la UE con margen. Para las empresas que operan en múltiples Estados miembros, una postura de seguridad que pase el escrutinio de la BSI generalmente también se sostendrá ante las autoridades de supervisión vecinas.

Para los que se registran tarde, el orden de prioridades es claro: registrarse primero, luego establecer evidencia documentada de las medidas. Si ocurre un incidente notificable antes de que las medidas estén demostrablemente implementadas, un registro omitido o retrasado es un factor agravante.

Fuente: SecurityToday.de, 2026


Publicado el Plan de Acción de la UE sobre Ciberseguridad e IA

Publicado el Plan de Acción de la UE sobre Ciberseguridad e IA

El 7 de julio de 2026, la Comisión Europea publicó el Plan de Acción de la UE sobre Ciberseguridad e Inteligencia Artificial. El documento establece un enfoque coordinado de la UE para la ciberseguridad impulsada por IA en los Estados miembros, autoridades públicas y empresas.

El plan se construye en torno a tres objetivos: promover el uso seguro y responsable de la IA avanzada, reforzar la ciberseguridad y la resiliencia de la UE, y ampliar las capacidades de IA de Europa para fines de ciberseguridad.

En cuanto a NIS2, el Plan de Acción nombra explícitamente la Directiva NIS2 como parte del marco legal existente sobre el que se construye, y alienta a las organizaciones sujetas a NIS2 a utilizar IA (incluyendo modelos de código abierto) para detectar y abordar vulnerabilidades más rápidamente. Este es el primer documento a nivel de la UE que vincula formalmente el cumplimiento de NIS2 con la detección de amenazas asistida por IA como práctica operativa esperada.

Las medidas concretas incluyen:

  • Un Plan Europeo para el acceso seguro a sistemas de IA avanzados para fines de ciberseguridad, a desarrollar con ENISA.
  • Una plataforma de pruebas segura para organizaciones en sectores críticos (energía, transporte, salud, finanzas y administración pública) para probar e implementar soluciones de IA de forma segura.
  • Un Gran Desafío de la UE sobre IA para ciberseguridad, que reúne a la industria, investigadores y comunidades de código abierto.

El Plan de Acción se sitúa junto con la Ley de IA, la Ley de Ciberresiliencia, DORA y la Ley de Cibersolidaridad. No crea nuevas obligaciones vinculantes por sí solo, pero señala dónde espera la Comisión que se concentren el énfasis en la aplicación y la inversión durante el próximo ciclo legislativo.

El Plan de Acción completo está disponible para descargar desde la Comisión Europea

Fuente: Comisión Europea, 2026


Reino Unido: El proyecto de ley de Ciberseguridad y Resiliencia es aprobado por los Comunes, ingresa a los Lores

Reino Unido: El proyecto de ley de Ciberseguridad y Resiliencia es aprobado por los Comunes, ingresa a los Lores

El 16 de junio de 2026, el proyecto de ley de Ciberseguridad y Resiliencia (Sistemas de Redes e Información) completó su tercera lectura y etapa de informe en la Cámara de los Comunes. Recibió su primera lectura en los Lores el 17 de junio y está programado para una segunda lectura en los Lores el 14 de julio de 2026.

El proyecto de ley se presentó al Parlamento el 12 de noviembre de 2025 y actualiza los Reglamentos de Sistemas de Redes e Información de 2018 (NIS1) existentes. No transpone NIS2 (el Reino Unido ya no está vinculado por la legislación de la UE) pero acerca significativamente los requisitos del Reino Unido al estándar NIS2 en alcance y aplicación.

Lo que añade el proyecto de ley:

  • Los proveedores de servicios gestionados entran en el ámbito por primera vez. Los Proveedores de Servicios Gestionados Relevantes (RMSP) deben registrarse ante el ICO, implementar medidas de gestión de riesgos y designar un representante en el Reino Unido si no están establecidos en el país.
  • Los operadores de centros de datos también se incluyen en el ámbito.
  • Los plazos de notificación de incidentes se acortan: informe inicial de 24 horas, notificación completa de 72 horas — coincidiendo con la estructura del Artículo 23 de NIS2.
  • Designación de proveedores críticos: El ICO obtiene la facultad de designar proveedores cuyo compromiso afectaría a servicios esenciales o RMSP.
  • Las sanciones aumentan hasta 17 millones de libras o el 4% de la facturación anual global por infracciones graves; hasta 10 millones de libras o el 2% por las menos graves.

La definición de incidente también se amplía: el proyecto de ley cubre incidentes «capaces de tener un efecto adverso» en los servicios regulados, no solo aquellos con un efecto real demostrado. Este es un cambio significativo para las organizaciones que actualmente calibran sus umbrales de notificación.

Se han propuesto 63 enmiendas durante el trámite del proyecto de ley. Dos enmiendas presentadas en junio, incluyendo una para añadir la cadena de suministro alimentario como servicio esencial regulado, no recibieron decisión en la etapa de informe.

El gobierno espera consultar en 2026 sobre la legislación secundaria que cubra medidas específicas de gestión de riesgos y requisitos de notificación. Algunas disposiciones entrarán en vigor desde el primer día o segundo mes después de la sanción real; otras seguirán mediante legislación secundaria.

Fuentes: Parlamento del Reino Unido, 2026; Parallel Parliament, 2026


Resumen

El período de junio a principios de julio de 2026 marca el punto en que la aplicación de NIS2 pasó de la presión política a la acción legal y de supervisión activa. Se presentaron remisiones judiciales. Las leyes nacionales están entrando en vigor. Las autoridades de supervisión están solicitando evidencia de medidas de seguridad, no solo confirmaciones de registro.

Para las organizaciones en Irlanda, España, Francia y los Países Bajos, los procedimientos de infracción no cambian nada sobre las obligaciones subyacentes. Los requisitos de NIS2 han sido vinculantes desde octubre de 2024 independientemente del estado de transposición nacional. Los procedimientos añaden consecuencias financieras para los gobiernos — no crean un período de gracia para las entidades reguladas.

Para las organizaciones en Alemania y los Países Bajos, el calendario de cumplimiento ya está establecido. La BSI está auditando. La Cyberbeveiligingswet entra en vigor el 15 de agosto. El documento de mapeo del Artículo 21 publicado por el Grupo de Cooperación NIS en junio de 2026 es el resultado más accionable de este período: si su equipo ya trabaja con ISO 27001 o NIST CSF 2.0, proporciona un camino directo para cerrar su análisis de brechas de NIS2 antes de que una autoridad de supervisión lo haga por usted.

Gestión de credenciales bajo el Artículo 21 de NIS2
El documento de mapeo de junio de 2026 del Grupo de Cooperación NIS vincula el Artículo 21 de NIS2 directamente con el control de acceso, la autenticación y la gestión de acceso privilegiado — áreas que las autoridades de supervisión auditarán. Passwork es un gestor empresarial de contraseñas y secretos diseñado para los requisitos de cumplimiento de la UE. Descubra cómo Passwork se alinea con NIS2
Controles de acceso NIS2 para la seguridad de la cadena de suministro
El 48% de las brechas ahora involucran a terceros. El Artículo 21 de NIS2 convierte la gobernanza del acceso de proveedores en una obligación legal. Aquí se explica cómo mapear el acceso de proveedores, aplicar MFA y privilegio mínimo, y mantener la evidencia de auditoría que demuestra que sus controles funcionan.
Shadow IT vs Shadow AI: Por qué la IA es la mayor amenaza
Los empleados están usando herramientas de IA que usted no aprobó, en cuentas que no puede monitorear, con datos que no puede recuperar. Aquí se muestra cómo es realmente el riesgo y qué debe abordar la gobernanza.
Offboarding de empleados: Guía de revocación segura de accesos 2026
Desactivar una cuenta SSO no revoca el acceso. Las claves API, las credenciales de agentes de IA y las contraseñas compartidas sobreviven. Esta guía cubre el playbook completo de offboarding — desde disparadores de hora cero hasta limpieza de NHI.

Últimas noticias sobre el cumplimiento de NIS2: actualización de aplicación de junio y julio de 2026

Cuatro estados miembros de la UE remitidos al tribunal, la ley NIS2 de los Países Bajos entra en vigor el 15 de agosto, el BSI de Alemania audita 29.000 entidades y la UE publica su primer plan de acción de ciberseguridad e IA. Todo lo que cambió en junio-julio de 2026.

Jul 9, 2026 — 12 min read
NIS2 compliance latest news: June 2026 update

The EU infringement machine moved from warnings to court referrals in July 2026. Ireland, Spain, France, and the Netherlands now face financial sanctions for missing the October 2024 NIS2 transposition deadline — daily penalties accruing until each country notifies complete transposition to the Commission.

At the same time, enforcement infrastructure is filling in. Germany's BSI is actively auditing registered entities. The Netherlands passed its national law one day before the referral landed. The NIS Cooperation Group published the most detailed Article 21 mapping document to date. And the Commission tied NIS2 explicitly to AI-assisted threat detection for the first time.

This article covers every material NIS2 development: what changed, which deadlines are live, and what your team needs to act on now. For the previous month's developments, see NIS2 latest news: May 2026.


Key takeaways

  • Court referrals filed against four member states. On July 8, 2026, the European Commission referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the EU for failing to fully transpose NIS2. Financial sanctions are requested for each country.
  • Netherlands' Cyberbeveiligingswet enters force August 15, 2026. The Dutch Senate approved the law on July 7. More than 8,000 organizations must register with the NCSC, implement risk-based security measures, and ensure board-level oversight by that date.
  • Germany's BSI is now auditing, not just registering. The active supervision phase began March 6, 2026. The BSI can request evidence of security measures without waiting for an incident. A secondary registration deadline of July 31 applies to the significant share of the 29,000 in-scope entities that missed March.
  • The NIS Cooperation Group published its Article 21 mapping document. Released in June 2026, it maps NIS2 obligations and Implementing Regulation 2024/2690 to ISO 27001, NIST CSF 2.0, IEC 62443, and national frameworks — the most concrete EU-level compliance guidance published to date.
  • Ireland's NCSC published board-level cyber governance guidance. Released July 7, 2026, the document targets CEOs, CIOs, and CISOs in NIS2-regulated organizations and is built around the NIST-based CyFun framework.
  • ENISA elevated the space sector to high criticality. The NIS360 2026 report places space alongside banking, electricity, and aviation. Seven sectors remain in the risk zone, where maturity falls below criticality demands.
  • The EU Action Plan on Cybersecurity and AI was published July 7, 2026. It is the first EU-level document to formally link NIS2 compliance with AI-assisted threat detection as an expected operational practice.
  • The UK's Cyber Security and Resilience Bill passed the Commons on June 16. It entered the Lords on June 17 and is scheduled for a second reading on July 14. Managed service providers and data centre operators come into scope for the first time.

EU Commission takes Ireland, Spain, France, and the Netherlands to court over NIS2 delays

EU Commission takes Ireland, Spain, France, and the Netherlands to court over NIS2 delays

On July 8, 2026, the European Commission referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the EU for failing to notify full transposition of the NIS2 Directive. The referrals include a request for financial sanctions: a lump sum plus daily penalties accruing until each country notifies complete transposition.

The transposition deadline was October 17, 2024. The Commission sent formal notices to non-compliant member states in November 2024 and reasoned opinions in May 2025. Court referral is the third and final stage of the EU infringement procedure.

The timing is notable for the Netherlands. The Dutch Senate approved the Cyberbeveiligingswet on July 7 — one day before the referral was filed (more on this below). The law enters into force on August 15, 2026, but formal notification of transposition to the Commission had not yet been submitted at the time of the referral. Daily penalties will stop accruing once notification is complete.

For Spain, France, and Ireland, no equivalent national law has passed. Spain's transposition is expected in late 2026. France and Ireland have not announced firm timelines.

The infringement cases carry individual case numbers:

The referrals reinforce a point compliance teams in these countries should already know: the NIS2 Directive's requirements are binding regardless of national transposition status. Court proceedings do not suspend the underlying obligations — they add financial pressure on governments to close the gap faster.

Source: European Commision, 2026


Netherlands: Cyberbeveiligingswet approved, enters force August 15

Netherlands — Cyberbeveiligingswet approved, enters force August 15

On July 7, 2026, the Dutch Senate approved both the Cyberbeveiligingswet (the Dutch transposition of NIS2) and the Critical Entities Resilience Act (Wwke), which implements the EU's Critical Entities Resilience (CER) Directive. Both laws enter into force on August 15, 2026.

More than 8,000 organizations fall in scope: ministries, municipalities, water authorities, provinces, independent administrative bodies, and inter-municipal partnerships. From August 15, they must:

  1. Register with the National Cyber Security Centre (NCSC) via the Entities Register.
  2. Implement appropriate technical, operational, and organizational measures based on a risk assessment — including supply chain dependencies.
  3. Report major cybersecurity incidents to the relevant CSIRT and competent supervisory authority within statutory deadlines.
  4. Ensure board-level oversight: governing body members must have sufficient cybersecurity knowledge and complete appropriate training.

Enforcement sits with designated supervisory authorities, including the Dutch Authority for Digital Infrastructure. The Cyberbeveiligingswet introduces director liability: supervisors can issue binding instructions, conduct inspections, and suspend directors where necessary.

For public sector organizations, compliance with the Baseline Information Security Government (BIO) 2 standard counts toward meeting the Cbw's security requirements.

The August 15 entry-into-force date is a hard deadline. Registration with the NCSC should begin before that date — the NCSC itself recommends preparing in advance to avoid bottlenecks in the registration process.

Source: NL Digital Government, 2026


EU-wide: New security measures reference document released

EU-wide: New security measures reference document released

Published on June, 2026, the NIS Cooperation Group's reference document on security measures gives organizations the most concrete EU-level guidance on NIS2 Article 21 compliance to date. The document establishes a common European framework for cybersecurity objectives and includes a mapping table that links NIS2 obligations and the European Implementing Regulation 2024/2690 to:

  • ISO/IEC 27001
  • IEC 62443
  • NIST Cybersecurity Framework 2.0
  • national cybersecurity frameworks
  • the CyberFundamentals Framework, CyFun®

The document is non-binding. It does not replace national NIS2 legislation or sector-specific guidelines. But for compliance teams already working against ISO 27001 or NIST CSF 2.0, it answers a question that has been open since the directive passed: how exactly do my existing controls map to NIS2 requirements?

The mapping is particularly useful for organizations operating across multiple member states. Rather than maintaining separate gap analyses per jurisdiction, teams can use the reference document as a shared baseline and then layer national deviations on top.

Access control, authentication, and privileged access management appear explicitly in the mapped objectives — areas where the reference document's guidance aligns directly with NIS2 Article 21(2)(j) on the use of multi-factor authentication and secure communication systems.

Where to find the documents
The reference document on security measures for NIS2 entities and the accompanying mapping table (Annex) are published on the official NIS Cooperation Group page of the European Commission's Digital Strategy website.

Sources: Center for Cybersecurity Belgium, 2026; European Commission, 2026


Ireland: NCSC publishes board-level cyber governance guidance for NIS2 entities

Ireland: NCSC publishes board-level cyber governance guidance for NIS2 entities

On July 7, 2026, Ireland's National Cyber Security Centre published guidance on cyber governance for management board members in NIS2-regulated organizations. The document targets CEOs, Managing Directors, CIOs, and CISOs — the executives who bear personal accountability for cybersecurity risk management under NIS2.

The guidance centers on the Cyber Fundamentals Framework (CyFun), Ireland's preferred national framework for NIS2 compliance. CyFun is built on the NIST Cybersecurity Framework and gives boards a structured, risk-based approach to meeting their legal obligations without requiring deep technical expertise.

The document covers three practical areas: understanding what questions boards should be asking about cyber risk, identifying and managing supply chain risks, and building an organizational culture where cybersecurity is treated as a governance issue, not an IT department problem.

The timing is deliberate. Ireland is currently subject to EU infringement proceedings for failing to fully transpose NIS2 into national law — the Commission referred the country to the Court of Justice on July 8, 2026. Publishing board-level guidance ahead of formal transposition signals that the NCSC is moving organizations toward compliance regardless of where the legislative process stands.

Guidance on Cyber Governance for Management Board Members in NIS2 Entities is available directly from the NCSC: download PDF

Source: The Irish Government's official portal, 2026


ENISA NIS360 2026: Space sector elevated to high criticality

ENISA NIS360 2026: Space sector elevated to high criticality

The ENISA NIS360 2026 report is the third annual assessment of cybersecurity maturity and criticality across all Annex I sectors under the NIS2 Directive. The headline finding: the space sector has joined banking, electricity, aviation, and digital-by-default services in the highest criticality band.

The elevation reflects space infrastructure's growing role as a dependency layer for other sectors: navigation, communications, financial settlement, and military logistics all run on satellite systems. Higher dependency means higher impact from disruption, and higher time criticality in recovery.

Seven sectors fall into the NIS360 2026 risk zone, where cybersecurity maturity falls below the level their criticality demands:

  1. Health
  2. Railway
  3. Maritime
  4. ICT service management
  5. Space
  6. Public administration
  7. Drinking and waste water

Three sectors reached the high maturity band: trust services, aviation, and financial market infrastructures. The gas sector has begun moving out of the risk zone, driven by improved information sharing and stronger implementation of risk management measures.

The risk zone composition matters operationally. Supervisory authorities use NIS360 data to prioritize audit calendars. If your organization operates in health, railway, or public administration, expect increased supervisory attention in the second half of 2026.

ENISA NIS Investments 2025 study found that 70% of surveyed organizations cited NIS2, DORA, and CRA compliance as the main driver of cybersecurity spending — a figure that will likely climb as supervisors shift from registration to active review.

Source: ENISA, 2026


Germany: BSI enters active supervision phase

Germany: BSI enters active supervision phase

Germany's BSI entered the active supervision phase on March 6, 2026 — the date the registration deadline under the NIS2-Umsetzungsgesetz (NIS2UmsuCG) expired. The law was enacted on December 6, 2025. By June 2026, it had been in force for six months.

SecurityToday.de's June 16 analysis of the supervisory shift noted that the question has changed: no longer whether an entity is registered, but whether its reported measures hold up under scrutiny.

The BSI registration portal opened January 6, 2026. A significant share of the approximately 29,000 in-scope entities missed the March deadline. The BSI set a secondary registration deadline of July 31, 2026. Late registration remains possible but creates no safe harbor — the compliance obligations have applied since December 2025, regardless of registration status.

What active supervision means in practice:

  • The BSI can proactively request evidence of security measures — without waiting for an incident.
  • On-site and remote audits are now within scope.
  • Fines for essential entities reach up to €10 million or 2% of global annual turnover, whichever is higher.
  • Management body members face personal liability, including potential temporary bans from exercising management functions.

Germany's implementation goes beyond the EU minimum on executive accountability. The NIS2UmsuCG explicitly requires management bodies to approve cybersecurity measures, supervise their implementation, and demonstrate personal competence. Supervisors can hold individual executives personally responsible for systemic failures.

There is a practical upside to Germany's stricter standard. Organizations that meet the NIS2UmsuCG requirements satisfy the EU minimum with margin. For companies operating across multiple member states, a security posture that passes BSI scrutiny will generally hold up with neighboring supervisory authorities as well.

For late registrants, the priority order is clear: register first, then establish documented evidence of measures. If a reportable incident occurs before measures are demonstrably in place, a missed or delayed registration is an aggravating factor.

Source: SecurityToday.de, 2026


EU Action Plan on Cybersecurity and AI published

EU Action Plan on Cybersecurity and AI published

On July 7, 2026, the European Commission published the EU Action Plan on Cybersecurity and Artificial Intelligence. The document sets out a coordinated EU approach to AI-driven cybersecurity across member states, public authorities, and businesses.

The plan is built around three objectives: promoting safe and responsible use of advanced AI, reinforcing EU cybersecurity and resilience, and scaling up Europe's AI capabilities for cybersecurity purposes.

On the NIS2 side, the Action Plan explicitly names the NIS2 Directive as part of the existing legal framework it builds on, and encourages organizations subject to NIS2 to use AI (including open-source models) to detect and address vulnerabilities faster. This is the first EU-level document to formally link NIS2 compliance with AI-assisted threat detection as an expected operational practice.

Concrete measures include:

  • A European Blueprint for secure access to advanced AI systems for cybersecurity purposes, to be developed with ENISA.
  • A secure testing platform for organizations in critical sectors (energy, transport, health, finance, and public administration) to safely test and deploy AI solutions.
  • An EU Grand Challenge on AI for cybersecurity, bringing together industry, researchers, and open-source communities.

The Action Plan sits alongside the AI Act, the Cyber Resilience Act, DORA, and the Cyber Solidarity Act. It does not create new binding obligations on its own, but it signals where the Commission expects enforcement emphasis and investment to go over the next legislative cycle.

The full Action Plan is available for download from the European Commission

Source: European Commision, 2026


UK: Cyber Security and Resilience Bill passes Commons, enters Lords

UK: Cyber Security and Resilience Bill passes Commons, enters Lords

On June 16, 2026, the Cyber Security and Resilience (Network and Information Systems) Bill completed its third reading and report stage in the House of Commons. It received its first reading in the Lords on June 17 and is scheduled for a Lords second reading on July 14, 2026.

The Bill was introduced to Parliament on November 12, 2025, and updates the existing Network and Information Systems Regulations 2018 (NIS1). It does not transpose NIS2 (the UK is no longer bound by EU law) but it moves UK requirements significantly closer to the NIS2 standard in scope and enforcement.

What the Bill adds:

  • Managed service providers come into scope for the first time. Relevant Managed Service Providers (RMSPs) must register with the ICO, implement risk management measures, and nominate a UK representative if not established in the UK.
  • Data centre operators are also brought into scope.
  • Incident reporting timelines tighten: 24-hour initial report, 72-hour full notification — matching NIS2's Article 23 structure.
  • Critical supplier designation: The ICO gains power to designate suppliers whose compromise would affect essential services or RMSPs.
  • Penalties increase to up to £17 million or 4% of global annual turnover for serious breaches; up to £10 million or 2% for less serious ones.

The incident definition is also broadened: the Bill covers incidents "capable of having an adverse effect" on regulated services, not just those with a demonstrated actual effect. This is a meaningful change for organizations currently calibrating their reporting thresholds.

63 amendments have been proposed during the Bill's passage. Two amendments tabled in June, including one to add the food supply chain as a regulated essential service, received no decision at report stage.

The government expects to consult in 2026 on secondary legislation covering specific risk management measures and notification requirements. Some provisions will take effect from the first day or second month after Royal Assent; others will follow via secondary legislation.

Sources: UK Parliament, 2026; Parallel Parliament, 2026


Recap

The period from June to early July 2026 marks the point where NIS2 enforcement moved from political pressure to active legal and supervisory action. Court referrals are filed. National laws are entering force. Supervisory authorities are requesting evidence of security measures, not just registration confirmations.

For organizations in Ireland, Spain, France, and the Netherlands, the infringement proceedings change nothing about the underlying obligations. NIS2 requirements have been binding since October 2024 regardless of national transposition status. The proceedings add financial consequences for governments — they do not create a grace period for regulated entities.

For organizations in Germany and the Netherlands, the compliance calendar is now set. The BSI is auditing. The Cyberbeveiligingswet enters force August 15. The Article 21 mapping document published by the NIS Cooperation Group in June 2026 is the most actionable output from this period: if your team is already working against ISO 27001 or NIST CSF 2.0, it provides a direct path to closing your NIS2 gap analysis before a supervisory authority does it on your behalf.

Credential management under NIS2 Article 21
The NIS Cooperation Group's June 2026 mapping document links NIS2 Article 21 directly to access control, authentication, and privileged access management — areas supervisory authorities will audit against. Passwork is an enterprise password and secrets manager built for EU compliance requirements. Explore how Passwork maps to NIS2
NIS2 access controls for supply chain security
48% of breaches now involve third parties. NIS2 Article 21 makes supplier access governance a legal obligation. Here’s how to map vendor access, enforce MFA and least privilege, and keep the audit evidence that proves your controls work.
Shadow IT vs Shadow AI: Why AI is the bigger threat
Employees are using AI tools you didn’t approve, on accounts you can’t monitor, with data you can’t recover. Here’s what the risk actually looks like and what governance needs to address.
Employee offboarding: Secure access revocation guide 2026
Disabling an SSO account doesn’t revoke access. API keys, AI agent credentials, and shared passwords survive it. This guide covers the full offboarding playbook — from zero-hour triggers to NHI cleanup.

NIS2 compliance latest news: June and July 2026 enforcement update

Four EU member states referred to court, the Netherlands' NIS2 law enters force August 15, Germany's BSI is auditing 29,000 entities, and the EU published its first AI-cybersecurity action plan. Here's everything that changed in June–July 2026.

Jul 8, 2026 — 16 min read
Illustration eines blauen Ordners mit organisierten Dokumenten, die durch beschriftete Reiter für IT, Recruiting, Manager und Designer getrennt sind. Ein grünes Schild mit einem Häkchen erscheint neben dem Ordner und symbolisiert sichere Organisation, kontrollierten Zugriff und geschützte Teamdaten oder Passwortverwaltung.

Team-Passwortverwaltung bezeichnet die Praxis, Zugangsdaten innerhalb einer Gruppe mit einem dedizierten Tool (Passwort-Manager) zu speichern, zu organisieren und zu teilen — anstelle von Messengern, Tabellenkalkulationen oder individuellen Browser-Tresoren. Richtig umgesetzt erhält jedes Teammitglied Zugriff auf genau das, was es benötigt, nicht mehr, mit einem vollständigen Audit-Trail darüber, wer wann auf was zugegriffen hat.

Dieser Leitfaden behandelt die tatsächlichen Probleme, auf die Teams stoßen, wenn sie Zugangsdaten ohne ein geeignetes System teilen, worauf Sie bei einer Lösung achten sollten, wie Passwork jede Herausforderung adressiert und wie Sie eine Migration durchführen, ohne Ihr Team zu beeinträchtigen.


Wichtige Erkenntnisse

  • Missbrauch von Zugangsdaten tritt in 39 % aller Sicherheitsverletzungen auf und ist damit die am weitesten verbreitete Technik über die gesamte Angriffskette hinweg — nicht nur beim initialen Zugriff.
  • Die drei Fehlerarten beim informellen Teilen von Zugangsdaten sind Sichtbarkeitslücken, schleichende Zugriffsausweitung und Offboarding-Versäumnisse. Alle drei sind mit einem strukturierten Passwort-Manager vermeidbar.
  • NIST SP 800-63B Rev. 4 hat die Regeln geändert: mindestens 15 Zeichen für Passwörter, keine obligatorischen Komplexitätsanforderungen und kein periodisches Ablaufdatum. Viele Organisationen arbeiten noch mit Richtlinien, die allen drei Punkten widersprechen.
  • Effektive Team-Passwortverwaltung erfordert mehr als nur Speicherung: RBAC, Audit-Logs, AD/LDAP-Integration, SSO und sicheres externes Teilen sind für jedes Team, das über eine Handvoll Personen hinausgeht, unverzichtbar.
  • Offboarding ist ein Sicherheitsereignis, keine HR-Formalität. Eine 7-Schritte-Checkliste für Zugangsdaten, die am oder vor dem letzten Arbeitstag eines Mitarbeiters durchgeführt wird, schließt die Lücken, die die meisten Vorfälle ausnutzen.
  • Migration gelingt oder scheitert am Change Management, nicht an der Technologie. Der häufigste Fehler ist, die alte Tabellenkalkulation nach dem Rollout weiter zugänglich zu lassen.

Die Kosten des informellen Teilens von Zugangsdaten

Die meisten Teams beginnen mit einem geteilten Google Sheet, einer Slack-Nachricht oder einem Klebezettel an der Serverraumtür. Es funktioniert. Bis es nicht mehr funktioniert.

Die durchschnittlichen Kosten einer Datenschutzverletzung sanken laut dem IBM Cost of a Data Breach Report 2025 auf 4,44 Millionen US-Dollar — der erste Rückgang seit fünf Jahren. Das sind immer noch 4,44 Millionen US-Dollar pro Vorfall. Und gestohlene oder kompromittierte Zugangsdaten bleiben tief in der Durchführung von Angriffen verankert: Der Verizon Data Breach Investigations Report 2026 stellte fest, dass der Missbrauch von Zugangsdaten irgendwann in 39 % aller Sicherheitsverletzungen auftritt — die häufigste Technik im gesamten Datensatz.

Das Problem des informellen Teilens hat drei unterschiedliche Fehlerarten:

  1. Sichtbarkeitslücken. Wenn ein Passwort in einem Slack-Thread existiert, gibt es keine Aufzeichnung darüber, wer es hat, wer es weitergeleitet hat oder ob es geändert wurde. Wenn diese Zugangsdaten später kompromittiert werden, können Sie den zeitlichen Ablauf nicht rekonstruieren.
  2. Schleichende Zugriffsausweitung. Tabellenkalkulationen erzwingen keine Zugriffsgrenzen. Ein Entwickler, der im Januar ein Datenbankpasswort benötigte, hat im Dezember immer noch das gesamte Sheet — einschließlich Zugangsdaten für Systeme, die er nie berührt hat, und Accounts, auf die er keinen Zugriff haben sollte.
  3. Offboarding-Versäumnisse. Hier verursacht informelles Teilen den größten Schaden. Wenn ein Mitarbeiter das Unternehmen verlässt, hat die IT kein zuverlässiges Inventar dessen, worauf er Zugriff hatte. Die Standardreaktion (jedes geteilte Passwort ändern) ist sowohl störend als auch selten vollständig. Einige Zugangsdaten werden übersehen. Einige werden wochenlang nicht geändert.

Eine Huntress-Studie von 2024 ergab, dass 46 % der Menschen in diesem Jahr ein Passwort gestohlen wurde. Für Organisationen, die sich auf geteilte Tabellenkalkulationen und Chat-Nachrichten verlassen, multipliziert sich diese Gefährdung über jeden Account in der Datei.


Was Teams wirklich von einem Passwort-Manager benötigen

Bevor Sie ein Tool evaluieren, ist es hilfreich, die Anforderungen klar zu definieren. Die folgende Liste spiegelt wider, was IT-Manager und Sicherheitsteams durchweg als unverzichtbar identifizieren.

Ein zentrales, strukturiertes Repository

Zugangsdaten, die über die Browser und persönlichen Tresore einzelner Personen verstreut sind, sind für die Organisation praktisch unsichtbar. Ein Team-Passwort-Manager benötigt ein einziges, durchsuchbares Repository, auf das das gesamte Team zugreifen kann — organisiert nach Projekt, System oder Abteilung, mit einheitlicher Benennung und Tagging.

Flexible, granulare Zugriffskontrolle

Nicht jeder benötigt alles. Ein Junior-Entwickler braucht keine Produktionsdatenbank-Zugangsdaten. Ein externer Dienstleister braucht keine internen Admin-Accounts. Rollenbasierte Zugriffskontrolle (RBAC) ermöglicht es Ihnen zu definieren, wer Zugangsdaten auf Tresor- oder Ordnerebene lesen, bearbeiten oder verwalten darf — und diese Grenzen automatisch durchzusetzen.

Sichere Freigabemechanismen

Manchmal müssen Sie Zugangsdaten mit jemandem außerhalb Ihrer Organisation teilen: einem Anbieter, einem externen Dienstleister, einem Partner. Diese per E-Mail oder Chat zu versenden ist ein Sicherheitsvorfall, der nur darauf wartet zu passieren. Das richtige Tool bietet zeitlich begrenzte Einmal-Links, die nach dem ersten Zugriff oder nach einem festgelegten Zeitfenster ablaufen.

Aktivitätsüberwachung und Audit-Logs

Compliance-Frameworks einschließlich SOC 2 Trust Services Criteria CC6.1 und ISO 27001 Annex A.9 erfordern dokumentierte Nachweise darüber, wer wann auf was zugegriffen hat. Ein Audit-Log ist nicht optional. Es ist der Nachweis, der Sie bei einem Vorfall oder einer Prüfung vor Schwierigkeiten bewahrt.

Integration in bestehende IT-Infrastruktur

Ein Passwort-Manager, der einen separaten Identitätssilo erfordert, schafft mehr Arbeit, nicht weniger. Integration mit Active Directory (AD), LDAP und SSO-Anbietern bedeutet, dass sich Benutzer mit den Zugangsdaten authentifizieren, die sie bereits haben, und Bereitstellung/Deprovisionierung automatisch erfolgt, wenn HR das Verzeichnis aktualisiert.


NIST SP 800-63B Rev. 4: Was sich 2025 geändert hat

NIST SP 800-63B Rev. 4 (2025) aktualisiert die Richtlinien für digitale Identität, auf die sich die meisten Unternehmenssicherheitsrichtlinien beziehen. Mehrere Änderungen wirken sich direkt darauf aus, wie Organisationen ihre Passwortrichtlinien konfigurieren sollten.

Richtlinienbereich Rev. 3 Empfehlung Rev. 4 Empfehlung
Minimale Passwortlänge 8 Zeichen 15 Zeichen (wenn das Passwort der einzige Authentifikator ist)
Komplexitätsregeln „Sollte nicht" willkürliche Regeln auferlegen „Darf nicht" willkürliche Komplexitätsanforderungen auferlegen
Periodisches Ablaufdatum Nicht empfohlen Verboten, es sei denn, eine Kompromittierung wird vermutet
Prüfung auf kompromittierte Passwörter Dringend empfohlen Verpflichtend

Der Wechsel von sollte nicht zu darf nicht bei Komplexitätsregeln ist bedeutsam. Organisationen, die immer noch „muss eine Zahl, ein Symbol, einen Großbuchstaben enthalten"-Richtlinien durchsetzen, sind nun nicht mehr mit den NIST-Empfehlungen konform — und das aus gutem Grund. Forschungen zeigen durchweg, dass erzwungene Komplexitätsregeln vorhersehbare Muster erzeugen: Password1!, Summer2024@, Qwerty#1. Länge ist ein zuverlässigeres Sicherheitssignal als Zeichenvielfalt.

Das 15-Zeichen-Minimum folgt der gleichen Logik. Eine 15 Zeichen lange Passphrase wie correct-horse-battery-staple ist weitaus widerstandsfähiger gegen Brute-Force-Angriffe als ein 8-Zeichen-Passwort wie P@ssw0rd.

Die verpflichtende Prüfung auf kompromittierte Passwörter bedeutet, dass Organisationen einen Mechanismus benötigen, um neue Passwörter zum Zeitpunkt der Erstellung oder des Zurücksetzens gegen bekannte Breach-Datenbanken zu prüfen — nicht erst beim Login.


Wie Passwork jede Herausforderung adressiert

Die Verwaltung von Zugangsdaten erfordert einen ständigen Ausgleich zwischen strengen Sicherheitskontrollen und operativer Geschwindigkeit. Passwork löst diese Infrastrukturherausforderungen durch direkte Integration in Ihre bestehenden Verzeichnisdienste, Automatisierung der Zugriffskontrolle und vollständige Transparenz über die Nutzung von Zugangsdaten.

Datenorganisation: Tresore, Ordner, Tags und Verlauf

Ein zentrales, strukturiertes Repository

Passwork strukturiert Zugangsdaten in einer Hierarchie aus Tresoren und Ordnern. Ein Tresor kann einer Abteilung oder einem Projekt entsprechen. Ordner darin gruppieren zusammengehörige Zugangsdaten. Tags fügen eine übergreifende Dimension hinzu: Sie können Zugangsdaten nach Umgebung (Produktion, Staging, Entwicklung) oder nach Systemtyp (Datenbank, Cloud, Netzwerk) taggen — unabhängig davon, wo sie in der Ordnerstruktur liegen.

Jeder Zugangsdateneintrag pflegt einen vollständigen Änderungsverlauf. Wenn ein Passwort letzten Dienstag um 14:32 Uhr von einem bestimmten Benutzer rotiert wurde, wird das aufgezeichnet. Wenn Sie eine Änderung rückgängig machen oder prüfen müssen, ist der Verlauf vorhanden. Dies ist die Art von Nachverfolgbarkeit, nach der SOC 2- und ISO 27001-Prüfer fragen.

Rollenbasierter Zugriff: Trennung von Datenzugriff und Systemadministration

Flexible, granulare Zugriffskontrolle

Passwork trennt den Datenzugriff von der administrativen Kontrolle durch zwei unterschiedliche Mechanismen: Benutzergruppen und Systemrollen.

  • Benutzergruppen steuern den Datenzugriff — Dieses Modell verwaltet den Zugriff auf Tresore und Ordner. Sie weisen einer Gruppe (wie dem DevOps-Team) Berechtigungen zu, und jedes Mitglied erbt diese Berechtigungen automatisch. Wenn jemand dem Team beitritt, erhält er Zugriff. Wenn er geht, entfernen Sie ihn aus der Gruppe und der Zugriff wird für jeden Tresor und Ordner, den diese Gruppe berührt, widerrufen.
  • Systemrollen definieren administrative Privilegien — Vordefinierte und benutzerdefinierte Rollen verwalten den Zugriff auf Systemeinstellungen, LDAP-Konfigurationen und globale Audit-Logs. Dies stellt sicher, dass Standardbenutzer nur mit ihren zugewiesenen Tresoren interagieren, während Administratoren die Plattforminfrastruktur verwalten. Unter dem Zero-Knowledge-Modell können Systemadministratoren nicht auf tatsächliche Passwörter zugreifen.

Berechtigungen innerhalb von Tresoren sind granular: Nur Lesen, Bearbeiten und Admin. Ein Nur-Lesen-Benutzer kann Zugangsdaten abrufen, aber nicht ändern oder löschen. Ein Admin kann die Struktur und Mitgliedschaft des Tresors verwalten. Sie können diese Berechtigungen über verschiedene Tresore für denselben Benutzer mischen: Ein Entwickler könnte Bearbeitungszugriff auf den Staging-Tresor und Nur-Lesen-Zugriff auf Produktion haben.

Sichere Freigabemechanismen

Diese Struktur löst das Offboarding-Problem direkt. Wenn ein Mitarbeiter das Unternehmen verlässt, deaktivieren Sie sein Konto. Seine Gruppenmitgliedschaften werden entfernt. Der Zugriff ist weg. Kein manuelles Inventar von „worauf hatte diese Person Zugriff?" erforderlich.

Sicherheit und Integration: 2FA, AD/LDAP und SSO

Passwork erzwingt Zwei-Faktor-Authentifizierung (2FA) auf Organisationsebene. Administratoren können sie für alle Benutzer verpflichtend machen, nicht nur optional. Unterstützte Methoden umfassen TOTP-Authenticator-Apps, Hardware-Sicherheitsschlüssel, Biometrie und Passkeys.

Für Organisationen, die Active Directory oder LDAP betreiben, synchronisiert Passwork Benutzer und Gruppen direkt aus dem Verzeichnis. Benutzerbereitstellung und -deprovisionierung folgen dem Verzeichnis: Wenn HR ein Konto in AD deaktiviert, wird der entsprechende Passwork-Zugriff automatisch widerrufen. Dies eliminiert den manuellen Schritt, den die meisten Offboarding-Prozesse übersehen.

SSO-Integration über SAML bedeutet, dass sich Benutzer über Ihren bestehenden Identity Provider authentifizieren. Keine separaten Passwork-Zugangsdaten zu verwalten, kein Passwort-Wiederverwendungsrisiko und keine Reibungsverluste für den Endbenutzer.

Das Teilen von Zugangsdaten mit einer externen Partei (einem Auftragnehmer, einem Anbieter, einem Penetrationstester), ohne Ihren Tresor preiszugeben, ist ein häufiges operatives Erfordernis. Passwork handhabt dies mit zeitlich begrenzten Einmal-Freigabelinks. Sie generieren einen Link für bestimmte Zugangsdaten, legen ein Ablaufdatum fest (Stunden, Tage oder ein einziger Zugriff) und senden ihn. Sobald der Link abläuft oder verwendet wird, ist er weg. Der Empfänger erhält niemals Zugriff auf den Tresor selbst.

Dies unterscheidet sich kategorisch vom Einfügen eines Passworts in eine E-Mail. Der Link ist während der Übertragung verschlüsselt, das Zugriffsereignis wird protokolliert, und Sie können ihn vor Ablauf widerrufen, wenn sich die Umstände ändern.

Auditing: Aktivitätsprotokolle und Sicherheits-Dashboard

Aktivitätsüberwachung und Audit-Logs

Jede Aktion in Passwork (Erstellung, Änderung, Zugriff, Freigabe, Löschung von Zugangsdaten) wird im Aktivitätsprotokoll mit Zeitstempel und Benutzerzuordnung aufgezeichnet. Das Protokoll ist exportierbar und kann über Syslog oder Windows Event Viewer-Integration an ein SIEM weitergeleitet werden.

Sicherheits-Dashboard

Das Sicherheits-Dashboard zeigt schwache Passwörter, alte Passwörter und Zugangsdaten an, die innerhalb eines definierten Zeitraums nicht rotiert wurden. Dies gibt dem Sicherheitsteam einen kontinuierlichen Überblick über die Zugangsdaten-Hygiene ohne manuelle Audits. Wenn Zugangsdaten als schwach oder wiederverwendet erscheinen, ist dies für den Administrator sichtbar, nicht in einer Tabellenkalkulation vergraben.

Möchten Sie das Audit-Log und Sicherheits-Dashboard von Passwork in Aktion sehen? Fordern Sie eine kostenlose Demo an

Self-hosted vs. Cloud: Welche Bereitstellung passt zu Ihrer Organisation

Passwork ist in zwei Bereitstellungsmodellen verfügbar. Die Wahl zwischen ihnen hängt von Ihren Compliance-Anforderungen, IT-Kapazitäten und Risikotoleranz ab.

Kriterium Self-hosted Passwork Cloud
Datenspeicherort Ihre eigene Infrastruktur EU-Sovereign-Cloud
Bereitstellungszeit Stunden bis Tage Minuten
Compliance-Kontrolle Vollständig (Sie besitzen den Stack) Modell der geteilten Verantwortung
Wartungsaufwand Ihr Team verwaltet Updates Von Passwork verwaltet
Verschlüsselung AES-256, clientseitig, auf Ihren Servern AES-256, Zero-Knowledge, clientseitig
Ideal für Regulierte Branchen, Behörden, Hochsicherheitsumgebungen KMUs, verteilte Teams, schnelle Bereitstellung

Self-hosted-Bereitstellung ist sinnvoll, wenn Ihre Organisation unter strengen Datensouveränitätsanforderungen arbeitet: Behörden, Finanzinstitute, Gesundheitsorganisationen und Unternehmen, die branchenspezifischen Vorschriften unterliegen, die verbieten, dass Daten die interne Infrastruktur verlassen. Sie betreiben Passwork auf Ihren eigenen Servern (Linux mit Docker oder Windows Server), und alle Zugangsdaten werden mit AES-256 verschlüsselt, bevor sie jemals die Festplatte berühren. Die Verschlüsselungsschlüssel bleiben bei Ihnen.

Passwork Cloud ist die richtige Wahl, wenn Sie schnell einsatzbereit sein müssen und nicht die IT-Kapazität haben, um eine On-Premises-Infrastruktur zu verwalten. Die Cloud-Instanz wird innerhalb der EU-Jurisdiktion gehostet und verwendet dieselbe Zero-Knowledge-, clientseitige Verschlüsselungsarchitektur wie die Self-hosted-Version. Passwork Cloud ist ISO 27001 zertifiziert und DSGVO- sowie NIS2-konform.

Beide Modelle unterstützen den vollständigen Funktionsumfang: RBAC, AD/LDAP-Integration, SSO, Audit-Logs und die REST API.


Die Offboarding-Checkliste: Zugangsdaten sichern, wenn jemand das Unternehmen verlässt

Die meisten Sicherheitsvorfälle im Zusammenhang mit ausscheidenden Mitarbeitern passieren, weil Offboarding als HR-Prozess behandelt wird, nicht als Sicherheitsprozess. Die folgenden Schritte sollten parallel zu oder vor dem letzten Arbeitstag des Mitarbeiters durchgeführt werden.

Die 7-Schritte-Offboarding-Checkliste für Zugangsdaten

  1. Deaktivieren Sie das Konto sofort. In Passwork widerruft die Deaktivierung eines Benutzerkontos sofort alle Tresor- und Ordnerzugriffe. Wenn AD/LDAP-Synchronisierung konfiguriert ist, geschieht dies automatisch, wenn das Verzeichniskonto deaktiviert wird.
  2. Prüfen Sie geteilte Zugangsdaten. Überprüfen Sie das Aktivitätsprotokoll auf Zugangsdaten, auf die der ausscheidende Mitarbeiter in den letzten 30-90 Tagen zugegriffen hat. Dies ist Ihre Rotationsliste.
  3. Rotieren Sie Zugangsdaten, auf die er Bearbeitungszugriff hatte. Nur-Lesen-Zugriff ist risikoärmer; Bearbeitungszugriff bedeutet, dass er die Zugangsdaten hätte kopieren oder ändern können. Rotieren Sie diese zuerst.
  4. Widerrufen Sie alle aktiven Freigabelinks. Prüfen Sie auf nicht abgelaufene Einmal-Links, die der Mitarbeiter generiert hat. Widerrufen Sie sie vor dem letzten Arbeitstag.
  5. Übertragen Sie die Tresor-Eigentümerschaft. Wenn der Mitarbeiter Tresore besaß oder administrierte, übertragen Sie die Eigentümerschaft auf einen anderen Administrator, bevor das Konto deaktiviert wird.
  6. Prüfen Sie auf persönliche Tresore. Einige Benutzer speichern Arbeitszugangsdaten in persönlichen Browser-Tresoren oder Passwort-Manager-Konten außerhalb des Unternehmenstools. Dies ist Shadow IT. Adressieren Sie dies in Ihrer Richtlinie, nicht erst beim Offboarding.
  7. Dokumentieren Sie den Prozess. Protokollieren Sie die durchgeführten Offboarding-Aktionen, die rotierten Zugangsdaten und den Zeitstempel. Dies ist der Nachweis für ein zukünftiges Audit.

Der Unterschied zwischen einem sauberen Offboarding und einem Zugangsdaten-Vorfall liegt meist darin, ob Schritt 2 vor oder nach dem Ausscheiden des Mitarbeiters durchgeführt wurde.


Best Practices für Team-Passwortverwaltung 2026

Die Implementierung eines Passwort-Managers ist nur der erste Schritt zur Absicherung der Infrastruktur Ihrer Organisation. Um eine widerstandsfähige Sicherheitslage aufzubauen, müssen Sie Ihre täglichen Arbeitsabläufe mit modernen Authentifizierungsstandards in Einklang bringen und Gewohnheiten eliminieren, die Zugangsdaten externen Bedrohungen aussetzen.

Die folgenden Praktiken konzentrieren sich auf die Reduzierung der Angriffsfläche, die Sicherung der Maschine-zu-Maschine-Kommunikation und die Etablierung einer nahtlosen Benutzererfahrung, die unsichere Workarounds auf natürliche Weise eliminiert.

Adressieren Sie Shadow IT, bevor es Sie adressiert

Shadow IT im Bereich der Zugangsdatenverwaltung bedeutet, dass Mitarbeiter persönliche Passwort-Manager, im Browser gespeicherte Passwörter oder geteilte Tabellenkalkulationen außerhalb des genehmigten Tools verwenden. Laut Huntress (2024) identifizieren mehr als ein Viertel der Cybersicherheitsexperten Mitarbeiter, die dieselben oder schwache Passwörter verwenden, als ihre problematischste Sicherheitsgewohnheit.

Die Lösung ist kein Richtlinienmemo. Sie besteht darin, das genehmigte Tool einfacher zu bedienen als den Workaround. Browser-Erweiterungen, mobile Apps und Autofill-Unterstützung beseitigen die Reibung, die Menschen zu informellen Alternativen treibt. Wenn die Nutzung eines Passwort-Managers schneller ist als das Öffnen einer Tabellenkalkulation, werden die meisten Mitarbeiter ihn verwenden.

Wenden Sie die NIST Rev. 4-Mindestanforderungen auf Ihre Passwortrichtlinie an

Aktualisieren Sie die Passwortrichtlinie Ihrer Organisation entsprechend NIST SP 800-63B Rev. 4 (2025):

  • Mindestens 15 Zeichen für Passwörter, die als einziger Authentifikator verwendet werden
  • Keine obligatorischen Komplexitätsregeln (keine „muss eine Zahl und ein Symbol enthalten"-Anforderungen)
  • Kein periodisches Ablaufdatum; Rotation nur bei bestätigter oder vermuteter Kompromittierung
  • Neue Passwörter gegen eine Datenbank kompromittierter Zugangsdaten prüfen

Das Sicherheits-Dashboard von Passwork markiert schwache Passwörter, die Ihre definierten Schwellenwerte nicht erfüllen. Kombinieren Sie dies mit einer Richtlinie, die aktuelle NIST-Empfehlungen widerspiegelt, und Sie haben eine vertretbare Zugangsdaten-Hygiene-Position.

Behandeln Sie nicht-menschliche Zugangsdaten als vollwertige Bürger

API-Schlüssel, Service-Account-Passwörter, Datenbankverbindungszeichenfolgen und Deployment-Tokens sind ebenfalls Zugangsdaten. Sie sind oft gefährlicher als menschliche Zugangsdaten, weil sie langlebig sind, selten rotiert werden und häufig in Code oder Konfigurationsdateien eingebettet sind.

Passwork handhabt Secrets (Maschinen-Zugangsdaten) zusammen mit menschlichen Passwörtern, mit denselben RBAC-, Audit-Logging- und Rotationsverfolgungsfunktionen. Die technischen Leitfäden von Passwork behandeln Secrets-Management für DevOps-Workflows, einschließlich CI/CD-Pipeline-Integration.

Erzwingen Sie 2FA flächendeckend

Der State of Passkeys Report 2026 der FIDO Alliance ergab, dass 5 Milliarden Passkeys weltweit aktiv genutzt werden und 68 % der Organisationen Passkeys für die Mitarbeiterauthentifizierung einführen, pilotieren oder ausrollen. Passkeys repräsentieren die Entwicklungsrichtung, aber in der Zwischenzeit ist TOTP-basierte 2FA auf jedem Account der Mindeststandard.

In Passwork können Administratoren 2FA auf Organisationsebene verpflichtend machen. Es gibt keine Opt-out-Möglichkeit für Benutzer. Wenn Ihre aktuelle Einrichtung 2FA optional macht, ist das eine Richtlinienlücke, die es wert ist, heute geschlossen zu werden.


Migration Ihres Teams zu einem zentralen Passwort-Manager

Migration scheitert, wenn sie als technisches Projekt behandelt wird statt als Change-Management-Projekt. Die technischen Schritte sind unkompliziert. Das Team dazu zu bringen, die alten Methoden nicht mehr zu verwenden, erfordert mehr Arbeit.

Das 5-Phasen-Migrationsframework

  1. Inventur (Woche 1-2). Identifizieren Sie alle derzeit genutzten Zugangsdatenspeicher: Tabellenkalkulationen, geteilte Browser-Profile, persönliche Passwort-Manager, Chat-Nachrichten. Gehen Sie nicht davon aus, dass Sie alle kennen; fragen Sie das Team. Das Ziel ist ein vollständiges Bild, bevor Sie etwas verschieben.
  2. Strukturdesign (Woche 2-3). Definieren Sie Ihre Tresor- und Ordnerhierarchie, bevor Sie etwas importieren. Eine flache Struktur mit 200 Zugangsdaten in einem Tresor ist kaum besser als eine Tabellenkalkulation. Gestalten Sie sie entsprechend der tatsächlichen Arbeitsweise Ihres Teams: nach Projekt, nach System, nach Umgebung oder nach Team.
  3. Import und Validierung (Woche 3-4). Importieren Sie Zugangsdaten aus bestehenden Quellen mit den Import-Tools von Passwork. Validieren Sie, dass Einträge vollständig und korrekt kategorisiert sind. Weisen Sie Eigentümerschaft und Zugriffsberechtigungen zu, bevor Sie die Migration ankündigen.
  4. Schulung und Rollout (Woche 4-5). Führen Sie eine kurze Sitzung durch (30 Minuten reichen für die meisten Teams), die die Browser-Erweiterung behandelt, wie man Zugangsdaten abruft und wie man sie teilt. Das Ziel ist, die Ausrede „Ich weiß nicht, wie man es benutzt" zu beseitigen.
  5. Alte Speicher außer Betrieb nehmen (Woche 6+). Setzen Sie eine feste Frist für die Abschaltung der Tabellenkalkulation oder des geteilten Ordners. Kündigen Sie sie im Voraus an. Nach der Frist löschen Sie den alten Speicher und bestätigen Sie mit dem Team, dass das neue System die einzige Wahrheitsquelle ist.

Der häufigste Migrationsfehler ist, das alte System „nur für den Fall" weiter zugänglich zu lassen. Solange die Tabellenkalkulation existiert, werden einige Leute sie verwenden.

In die Praxis umsetzen

In die Praxis umsetzen

Die Lücke zwischen „wir haben einen Passwort-Manager" und „unsere Zugangsdatensicherheit ist tatsächlich unter Kontrolle" ist größer, als die meisten Teams erwarten. Das Tool ist der einfache Teil. Die Arbeit sind die Tresor-Struktur, die Zugriffsrichtlinie, der Offboarding-Prozess und die laufende Hygiene: sicherstellen, dass schwache Zugangsdaten rotiert werden und dass die Tabellenkalkulation, die jemand in der Finanzabteilung noch verwendet, außer Betrieb genommen wird.

Beginnen Sie mit der Inventur. Sie können nicht sichern, was Sie nicht sehen können. Sobald Sie wissen, welche Zugangsdaten existieren und wo sie sich befinden, folgt jeder andere Schritt logisch.

Passwork ist als Self-hosted-Lösung mit voller Kontrolle über Ihre Daten sowie als Cloud-Bereitstellung verfügbar, die in einer EU-Sovereign-Cloud unter EU-Jurisdiktion gehostet wird. Erkunden Sie die Bereitstellungsoptionen und fordern Sie eine Demo an

Häufig gestellte Fragen

Häufig gestellte Fragen

Was ist Team-Passwortverwaltung?

Team-Passwortverwaltung ist die Praxis, Zugangsdaten innerhalb einer Gruppe mit einem dedizierten Tool zu speichern, zu teilen und den Zugriff darauf zu kontrollieren. Sie ersetzt informelle Methoden (Tabellenkalkulationen, Chat-Nachrichten, geteilte Browser-Profile) durch ein strukturiertes System, das Zugriffskontrollen durchsetzt, Aktivitäten protokolliert und sicheres Offboarding unterstützt.

Warum ist das Teilen von Passwörtern über Messenger oder E-Mail ein Sicherheitsrisiko?

Zugangsdaten, die über Messaging-Plattformen oder E-Mail gesendet werden, werden an mehreren Orten außerhalb Ihrer Kontrolle gespeichert: im Gesendet-Ordner des Absenders, im Posteingang des Empfängers, im Nachrichtenverlauf und möglicherweise auf Servern von Drittanbietern. Es gibt kein Ablaufdatum, keinen Zugriffswiderruf und keinen Audit-Trail. Wenn eines der Konten kompromittiert wird, sind die Zugangsdaten offengelegt.

Was sollte ein Team-Passwort-Manager beinhalten?

Ein Team-Passwort-Manager sollte zentrale Zugangsdatenspeicherung, rollenbasierte Zugriffskontrolle (RBAC), Audit-Logging, sichere externe Freigabe, Integration mit AD/LDAP und SSO sowie verpflichtende 2FA-Durchsetzung bieten. Für DevOps-Teams sind API-Zugriff und Secrets-Management für CI/CD-Pipelines ebenfalls erforderlich.

Was erfordert NIST SP 800-63B Rev. 4 für Passwörter?

NIST SP 800-63B Rev. 4 (2025) erfordert mindestens 15 Zeichen, wenn ein Passwort der einzige Authentifikator ist, verbietet obligatorische Komplexitätsregeln (wie das Erfordernis von Zahlen oder Symbolen), eliminiert periodische Ablaufrichtlinien und schreibt vor, neue Passwörter gegen bekannte Datenbanken kompromittierter Zugangsdaten zu prüfen.

Wie hilft ein Passwort-Manager beim Mitarbeiter-Offboarding?

Ein Passwort-Manager mit RBAC und AD/LDAP-Integration macht Offboarding deterministisch. Das Deaktivieren eines Benutzerkontos oder das Entfernen aus einer Verzeichnisgruppe widerruft sofort den Zugriff auf alle zugehörigen Tresore. Das Aktivitätsprotokoll zeigt, auf welche Zugangsdaten zugegriffen wurde, und gibt Ihnen eine präzise Rotationsliste statt einer Vermutung.

Was ist der Unterschied zwischen Self-hosted und Cloud-Passwortverwaltung?

Ein Self-hosted-Passwort-Manager läuft auf Ihrer eigenen Infrastruktur und gibt Ihnen volle Kontrolle über Datenspeicherort, Verschlüsselungsschlüssel und Konfiguration. Ein Cloud-Passwort-Manager wird vom Anbieter gehostet. Beide können Zero-Knowledge-Verschlüsselung verwenden, was bedeutet, dass die Server des Anbieters niemals Klartext-Zugangsdaten sehen. Self-hosted wird für regulierte Branchen bevorzugt; Cloud ist schneller bereitzustellen und erfordert weniger Wartungsaufwand.

Wie migriert man ein Team zu einem neuen Passwort-Manager?

Beginnen Sie mit einer Inventur aller bestehenden Zugangsdatenspeicher, entwerfen Sie Ihre Tresor-Struktur, bevor Sie etwas importieren, importieren und validieren Sie Zugangsdaten, führen Sie eine kurze Schulung durch und setzen Sie eine feste Frist für die Abschaltung des alten Systems. Der häufigste Fehler ist, die alte Tabellenkalkulation oder den geteilten Ordner nach der Migration weiter zugänglich zu lassen; solange sie existiert, werden einige Teammitglieder sie verwenden.

Passwortverwaltung für Teams: Die Lösung, die jedes KMU braucht
Das Speichern von Passwörtern in Slack und Browsern setzt Ihr Unternehmen Sicherheitsverletzungen aus. Erfahren Sie, warum persönliche Tools für Teams versagen, wie Sie ausscheidende Mitarbeiter mit einem Klick sicher offboarden und warum die neuesten NIST-Richtlinien von erzwungener Passwortrotation abraten.
Passwort-Chaos: Warum es ein Geschäftsproblem ist und wie man es behebt
Ein vergessenes Passwort kostet 70 US-Dollar. Eine Sicherheitsverletzung kostet 4,44 Millionen US-Dollar. Beide beginnen auf die gleiche Weise — Zugangsdaten werden über Slack geteilt, in Tabellenkalkulationen gespeichert, nie rotiert. Hier erfahren Sie, was Passwort-Chaos wirklich kostet und wie man es eliminiert.
Shadow IT vs. Shadow AI: Warum KI die größere Bedrohung ist
Mitarbeiter nutzen KI-Tools, die Sie nicht genehmigt haben, auf Konten, die Sie nicht überwachen können, mit Daten, die Sie nicht wiederherstellen können. Hier erfahren Sie, wie das Risiko tatsächlich aussieht und was Governance adressieren muss.

Passwortmanagement im Team: Der vollständige Leitfaden für 2026

Erfahren Sie, wie Teams 2026 Zugangsdaten sicher teilen — RBAC, Audit-Logs, Offboarding-Checklisten, NIST SP 800-63B Rev. 4-Anforderungen und Self-hosted vs. Cloud-Deployment.

Jul 8, 2026 — 18 min read
Ilustración de una carpeta azul que contiene documentos organizados separados por pestañas etiquetadas para IT, Reclutamiento, Gerentes y Diseñadores. Un escudo verde con una marca de verificación aparece junto a la carpeta, representando organización segura, acceso controlado y datos de equipo o gestión de contraseñas protegidos.

La gestión de contraseñas en equipo es la práctica de almacenar, organizar y compartir credenciales entre un grupo utilizando una herramienta dedicada (gestor de contraseñas), en lugar de mensajeros, hojas de cálculo o bóvedas individuales del navegador. Cuando se hace correctamente, proporciona a cada miembro del equipo acceso exactamente a lo que necesita, nada más, con un registro completo de auditoría de quién accedió a qué y cuándo.

Esta guía cubre los problemas reales que enfrentan los equipos al compartir credenciales sin un sistema adecuado, qué buscar en una solución, cómo Passwork aborda cada desafío y cómo ejecutar una migración sin interrumpir a su equipo.


Puntos clave

  • El abuso de credenciales aparece en el 39% de todas las brechas, convirtiéndolo en la técnica más generalizada en toda la cadena de ataque — no solo en el acceso inicial.
  • Los tres modos de fallo del intercambio informal de credenciales son las brechas de visibilidad, la expansión de alcance y los fallos en la baja de empleados. Los tres son prevenibles con un gestor de contraseñas estructurado.
  • NIST SP 800-63B Rev. 4 ha cambiado las reglas: contraseñas de mínimo 15 caracteres, sin requisitos obligatorios de composición y sin caducidad periódica. Muchas organizaciones todavía aplican políticas que contradicen las tres.
  • La gestión efectiva de contraseñas en equipo requiere más que almacenamiento: RBAC, registros de auditoría, integración AD/LDAP, SSO y uso compartido externo seguro son innegociables para cualquier equipo más allá de un puñado de personas.
  • La baja de empleados es un evento de seguridad, no una formalidad de RRHH. Una lista de verificación de credenciales de 7 pasos ejecutada en o antes del último día del empleado cierra las brechas que la mayoría de los incidentes explotan.
  • La migración tiene éxito o fracasa en la gestión del cambio, no en la tecnología. El fallo más común es dejar la antigua hoja de cálculo en su lugar después del despliegue.

El costo del intercambio informal de credenciales

La mayoría de los equipos comienzan con una hoja de cálculo compartida en Google, un mensaje de Slack o una nota adhesiva en la puerta de la sala de servidores. Funciona. Hasta que deja de funcionar.

El costo promedio de una brecha de datos bajó a $4.44 millones en 2025, la primera disminución en cinco años, según el Informe de Costo de una Brecha de Datos 2025 de IBM. Eso sigue siendo $4.44 millones por incidente. Y las credenciales robadas o comprometidas siguen profundamente incrustadas en cómo se desarrollan los ataques: el Informe de Investigaciones de Brechas de Datos 2026 de Verizon encontró que el abuso de credenciales aparece en algún momento en el 39% de todas las brechas, convirtiéndolo en la técnica más generalizada en el conjunto de datos.

El problema del intercambio informal tiene tres modos de fallo distintos:

  1. Brechas de visibilidad. Cuando una contraseña vive en un hilo de Slack, no hay registro de quién la tiene, quién la reenvió o si fue cambiada. Si esa credencial se ve comprometida posteriormente, no se puede reconstruir la línea de tiempo.
  2. Expansión de alcance. Las hojas de cálculo no imponen límites de acceso. Un desarrollador que necesitaba una contraseña de base de datos en enero todavía tiene toda la hoja en diciembre, incluyendo credenciales para sistemas que nunca ha tocado y cuentas a las que no tiene por qué acceder.
  3. Fallos en la baja de empleados. Aquí es donde el intercambio informal causa más daño. Cuando un empleado se va, TI no tiene un inventario confiable de a qué tenía acceso. La respuesta estándar (cambiar cada contraseña compartida) es tanto disruptiva como raramente completa. Algunas credenciales se omiten. Algunas no se cambian durante semanas.

Un estudio de Huntress de 2024 encontró que el 46% de las personas tuvieron una contraseña robada ese año. Para las organizaciones que dependen de hojas de cálculo compartidas y mensajes de chat, esa exposición se multiplica en cada cuenta del archivo.


Lo que los equipos realmente necesitan de un gestor de contraseñas

Antes de evaluar cualquier herramienta, es útil definir los requisitos claramente. La lista a continuación refleja lo que los gerentes de TI y los equipos de seguridad identifican consistentemente como innegociable.

Un repositorio centralizado y estructurado

Las credenciales dispersas en los navegadores individuales y bóvedas personales son funcionalmente invisibles para la organización. Un gestor de contraseñas de equipo necesita un repositorio único y con capacidad de búsqueda al que todo el equipo pueda acceder, organizado por proyecto, sistema o departamento, con nomenclatura y etiquetado consistentes.

Control de acceso flexible y granular

No todos necesitan todo. Un desarrollador junior no necesita credenciales de bases de datos de producción. Un contratista no necesita cuentas de administrador internas. El control de acceso basado en roles (RBAC) permite definir quién puede leer, editar o administrar credenciales a nivel de bóveda o carpeta, e imponer esos límites automáticamente.

Mecanismos de uso compartido seguros

A veces es necesario compartir una credencial con alguien fuera de su organización: un proveedor, un contratista, un socio. Enviarla por correo electrónico o chat es un evento de seguridad esperando a ocurrir. La herramienta adecuada proporciona enlaces de tiempo limitado y un solo uso que expiran después del primer acceso o después de un período establecido.

Monitoreo de actividad y registros de auditoría

Los marcos de cumplimiento, incluyendo SOC 2 Trust Services Criteria CC6.1 e ISO 27001 Anexo A.9, requieren evidencia documentada de quién accedió a qué y cuándo. Un registro de auditoría no es opcional. Es el rastro documental que lo mantiene fuera de problemas durante un incidente o una auditoría.

Integración con la infraestructura de TI existente

Un gestor de contraseñas que requiere un silo de identidad separado crea más trabajo, no menos. La integración con Active Directory (AD), LDAP y proveedores de SSO significa que los usuarios se autentican con las credenciales que ya tienen, y el aprovisionamiento/desaprovisionamiento ocurre automáticamente cuando RRHH actualiza el directorio.


NIST SP 800-63B Rev. 4: Qué cambió en 2025

NIST SP 800-63B Rev. 4 (2025) actualiza las directrices de identidad digital que la mayoría de las políticas de seguridad empresarial referencian. Varios cambios afectan directamente cómo las organizaciones deben configurar sus políticas de contraseñas.

Área de política Guía Rev. 3 Guía Rev. 4
Longitud mínima de contraseña 8 caracteres 15 caracteres (cuando la contraseña es el único autenticador)
Reglas de composición «No debería» imponer reglas arbitrarias «No deberá» imponer requisitos de composición arbitrarios
Caducidad periódica Desaconsejada Prohibida a menos que se sospeche compromiso
Verificación de contraseñas comprometidas Muy recomendada Obligatoria

El cambio de no debería a no deberá en las reglas de composición es significativo. Las organizaciones que todavía imponen políticas de «debe incluir un número, un símbolo, una letra mayúscula» ahora están fuera de alineación con la guía de NIST, y por buenas razones. La investigación muestra consistentemente que las reglas de complejidad forzada producen patrones predecibles: Password1!, Summer2024@, Qwerty#1. La longitud es una señal de seguridad más confiable que la diversidad de caracteres.

El mínimo de 15 caracteres refleja la misma lógica. Una frase de contraseña de 15 caracteres como correct-horse-battery-staple es mucho más resistente a ataques de fuerza bruta que una P@ssw0rd de 8 caracteres.

El requisito obligatorio de verificación de contraseñas comprometidas significa que las organizaciones necesitan un mecanismo para comprobar las nuevas contraseñas contra bases de datos de brechas conocidas en el momento de la creación o el restablecimiento, no solo al iniciar sesión.


Cómo Passwork aborda cada desafío

La gestión de credenciales requiere un equilibrio constante entre controles de seguridad estrictos y velocidad operativa. Passwork resuelve estos desafíos de infraestructura integrándose directamente en sus servicios de directorio existentes, automatizando el control de acceso y proporcionando visibilidad completa sobre el uso de credenciales.

Organización de datos: Bóvedas, carpetas, etiquetas e historial

Un repositorio centralizado y estructurado

Passwork estructura las credenciales en una jerarquía de bóvedas y carpetas. Una bóveda puede corresponder a un departamento o un proyecto. Las carpetas dentro de ella agrupan credenciales relacionadas. Las etiquetas añaden una dimensión transversal: puede etiquetar credenciales por entorno (producción, staging, desarrollo) o por tipo de sistema (base de datos, nube, red) independientemente de dónde se encuentren en el árbol de carpetas.

Cada entrada de credencial mantiene un historial completo de cambios. Si una contraseña fue rotada el martes pasado a las 14:32 por un usuario específico, eso queda registrado. Si necesita revertir o auditar un cambio, el historial está ahí. Este es el tipo de trazabilidad que los auditores de SOC 2 e ISO 27001 solicitan.

Acceso basado en roles: Separando el acceso a datos y la administración del sistema

Control de acceso flexible y granular

Passwork separa el acceso a datos del control administrativo a través de dos mecanismos distintos: grupos de usuarios y roles del sistema.

  • Los grupos de usuarios controlan el acceso a datos — Este modelo gestiona el acceso a bóvedas y carpetas. Se asignan permisos a un grupo (como el equipo de DevOps) y cada miembro hereda esos permisos automáticamente. Cuando alguien se une al equipo, obtiene acceso. Cuando se va, se le elimina del grupo y el acceso se revoca en cada bóveda y carpeta que ese grupo toca.
  • Los roles del sistema definen privilegios administrativos — Los roles predefinidos y personalizados gestionan el acceso a la configuración del sistema, configuraciones LDAP y registros de auditoría globales. Esto asegura que los usuarios estándar solo interactúen con sus bóvedas asignadas, mientras que los administradores gestionan la infraestructura de la plataforma. Bajo el modelo Zero-Knowledge, los administradores del sistema no pueden acceder a las contraseñas reales.

Los permisos dentro de las bóvedas son granulares: solo lectura, editar y admin. Un usuario de solo lectura puede recuperar credenciales pero no puede modificarlas o eliminarlas. Un admin puede gestionar la estructura y membresía de la bóveda. Puede mezclar estos permisos en diferentes bóvedas para el mismo usuario: un desarrollador puede tener acceso de edición a la bóveda de staging y acceso de solo lectura a producción.

Mecanismos de uso compartido seguros

Esta estructura resuelve directamente el problema de la baja de empleados. Cuando un empleado se va, se desactiva su cuenta. Sus membresías de grupo se eliminan. El acceso desaparece. No se requiere ningún inventario manual de «¿a qué tenía acceso esta persona?».

Seguridad e integración: 2FA, AD/LDAP y SSO

Passwork impone la autenticación de dos factores (2FA) a nivel de organización. Los administradores pueden hacerla obligatoria para todos los usuarios, no solo opcional. Los métodos compatibles incluyen aplicaciones de autenticación TOTP, llaves de seguridad de hardware, biometría y passkeys.

Para las organizaciones que ejecutan Active Directory o LDAP, Passwork sincroniza usuarios y grupos directamente desde el directorio. El aprovisionamiento y desaprovisionamiento de usuarios sigue al directorio: cuando RRHH desactiva una cuenta en AD, el acceso correspondiente en Passwork se revoca automáticamente. Esto elimina el paso manual que la mayoría de los procesos de baja omiten.

La integración SSO vía SAML significa que los usuarios se autentican a través de su proveedor de identidad existente. No hay credenciales separadas de Passwork que gestionar, no hay riesgo de reutilización de contraseñas y no hay fricción para el usuario final.

Uso compartido externo: Enlaces seguros de un solo uso

Compartir una credencial con una parte externa (un contratista, un proveedor, un probador de penetración) sin exponer su bóveda es una necesidad operativa común. Passwork maneja esto con enlaces de uso compartido de tiempo limitado y un solo uso. Se genera un enlace para una credencial específica, se establece una caducidad (horas, días o un solo acceso) y se envía. Una vez que el enlace expira o se usa, desaparece. El destinatario nunca obtiene acceso a la bóveda en sí.

Esto es categóricamente diferente de pegar una contraseña en un correo electrónico. El enlace está cifrado en tránsito, el evento de acceso se registra y puede revocarlo antes de la caducidad si las circunstancias cambian.

Auditoría: Registros de actividad y panel de seguridad

Monitoreo de actividad y registros de auditoría

Cada acción en Passwork (creación de credenciales, modificación, acceso, uso compartido, eliminación) se registra en el registro de actividad con una marca de tiempo y atribución de usuario. El registro es exportable y puede reenviarse a un SIEM vía Syslog o integración con Windows Event Viewer.

Panel de seguridad

El panel de seguridad muestra contraseñas débiles, contraseñas antiguas y credenciales que no se han rotado en un período definido. Esto proporciona al equipo de seguridad una vista continua de la higiene de credenciales sin auditorías manuales. Cuando una credencial aparece como débil o reutilizada, es visible para el administrador, no enterrada en una hoja de cálculo.

¿Desea ver el registro de auditoría y el panel de seguridad de Passwork en acción? Solicite una demostración gratuita

Autoalojado vs. nube: Qué implementación se adapta a su organización

Passwork está disponible en dos modelos de implementación. La elección entre ellos depende de sus requisitos de cumplimiento, capacidad de TI y tolerancia al riesgo.

Criterio Autoalojado Passwork Cloud
Residencia de datos Su propia infraestructura Nube soberana de la UE
Tiempo de implementación Horas a días Minutos
Control de cumplimiento Completo (usted es dueño de la pila) Modelo de responsabilidad compartida
Carga de mantenimiento Su equipo gestiona las actualizaciones Gestionado por Passwork
Cifrado AES-256, lado del cliente, en sus servidores AES-256, zero-knowledge, lado del cliente
Ideal para Industrias reguladas, gobierno, entornos de alta seguridad PyMEs, equipos distribuidos, implementación rápida

La implementación autoalojada tiene sentido cuando su organización opera bajo requisitos estrictos de soberanía de datos: agencias gubernamentales, instituciones financieras, organizaciones de salud y empresas sujetas a regulaciones sectoriales específicas que prohíben que los datos salgan de la infraestructura interna. Ejecuta Passwork en sus propios servidores (Linux con Docker o Windows Server), y todos los datos de credenciales se cifran con AES-256 antes de que toquen el disco. Las claves de cifrado permanecen con usted.

Passwork Cloud es la opción correcta cuando necesita estar operativo rápidamente y no tiene la capacidad de TI para gestionar infraestructura local. La instancia en la nube está alojada dentro de la jurisdicción de la UE y utiliza la misma arquitectura de cifrado zero-knowledge del lado del cliente que la versión autoalojada. Passwork Cloud tiene certificación ISO 27001 y cumple con GDPR y NIS2.

Ambos modelos soportan el conjunto completo de características: RBAC, integración AD/LDAP, SSO, registros de auditoría y la REST API.


La lista de verificación de baja: Asegurando las credenciales cuando alguien se va

La mayoría de los incidentes de seguridad de credenciales relacionados con empleados que se van ocurren porque la baja se trata como un proceso de RRHH, no como un proceso de seguridad. Los pasos a continuación deben ejecutarse en paralelo con, o antes del, último día del empleado.

La lista de verificación de credenciales de 7 pasos para la baja

  1. Desactivar la cuenta inmediatamente. En Passwork, desactivar una cuenta de usuario revoca todo el acceso a bóvedas y carpetas instantáneamente. Si la sincronización AD/LDAP está configurada, esto ocurre automáticamente cuando la cuenta del directorio se desactiva.
  2. Auditar las credenciales compartidas. Revisar el registro de actividad para las credenciales a las que el empleado que se va accedió en los últimos 30-90 días. Esta es su lista de rotación.
  3. Rotar las credenciales a las que tenían acceso de edición. El acceso de solo lectura es de menor riesgo; el acceso de edición significa que podrían haber copiado o modificado la credencial. Rotar esas primero.
  4. Revocar cualquier enlace de uso compartido activo. Verificar si hay enlaces de un solo uso no expirados que el empleado generó. Revocarlos antes del último día.
  5. Reasignar la propiedad de la bóveda. Si el empleado era propietario o administrador de alguna bóveda, transferir la propiedad a otro administrador antes de que la cuenta sea desactivada.
  6. Verificar bóvedas personales. Algunos usuarios almacenan credenciales de trabajo en bóvedas personales del navegador o cuentas de gestores de contraseñas fuera de la herramienta corporativa. Esto es shadow IT. Abordarlo en su política, no solo en la baja.
  7. Documentar el proceso. Registrar las acciones de baja tomadas, las credenciales rotadas y la marca de tiempo. Esta es la evidencia para una auditoría futura.

La diferencia entre una baja limpia y un incidente de credenciales es generalmente si el paso 2 ocurrió antes o después de que el empleado se fuera.


Mejores prácticas para la gestión de contraseñas en equipo en 2026

Implementar un gestor de contraseñas es solo el primer paso para asegurar la infraestructura de su organización. Para construir una postura de seguridad resiliente, debe alinear sus flujos de trabajo diarios con los estándares de autenticación modernos y eliminar los hábitos que exponen las credenciales a amenazas externas.

Las siguientes prácticas se centran en reducir la superficie de ataque, asegurar la comunicación máquina a máquina y establecer una experiencia de usuario fluida que elimine naturalmente las soluciones alternativas inseguras.

Abordar el shadow IT antes de que lo aborde a usted

El shadow IT en la gestión de credenciales significa que los empleados usan gestores de contraseñas personales, contraseñas guardadas en el navegador u hojas de cálculo compartidas fuera de la herramienta autorizada. Según Huntress (2024), más de una cuarta parte de los profesionales de ciberseguridad identifican que los empleados que usan las mismas contraseñas o contraseñas débiles son su hábito de seguridad más problemático.

La solución no es un memorando de política. Es hacer que la herramienta aprobada sea más fácil de usar que la alternativa. Las extensiones del navegador, las aplicaciones móviles y el soporte de autocompletado eliminan la fricción que impulsa a las personas hacia alternativas informales. Si usar un gestor de contraseñas es más rápido que abrir una hoja de cálculo, la mayoría de los empleados lo usarán.

Aplicar los mínimos de NIST Rev. 4 a su política de contraseñas

Actualice la política de contraseñas de su organización para reflejar NIST SP 800-63B Rev. 4 (2025):

  • Mínimo de 15 caracteres para contraseñas usadas como único autenticador
  • Sin reglas de composición obligatorias (sin requisitos de «debe incluir un número y un símbolo»)
  • Sin caducidad periódica; rotar solo ante compromiso confirmado o sospechado
  • Verificar las nuevas contraseñas contra una base de datos de credenciales comprometidas

El panel de seguridad de Passwork marca las contraseñas débiles que no cumplen con sus umbrales definidos. Combine esto con una política que refleje la guía actual de NIST, y tendrá una postura de higiene de credenciales defendible.

Tratar las credenciales no humanas como ciudadanos de primera clase

Las claves API, las contraseñas de cuentas de servicio, las cadenas de conexión de bases de datos y los tokens de implementación también son credenciales. A menudo son más peligrosas que las credenciales humanas porque son de larga duración, rara vez se rotan y frecuentemente están incrustadas en archivos de código o configuración.

Passwork maneja secretos (credenciales de máquinas) junto con las contraseñas humanas, con el mismo RBAC, registro de auditoría y seguimiento de rotación. Las guías técnicas de Passwork cubren la gestión de secretos para flujos de trabajo de DevOps, incluyendo la integración de pipelines CI/CD.

Imponer 2FA en todos los ámbitos

El informe State of Passkeys 2026 de FIDO Alliance encontró que 5 mil millones de passkeys están ahora en uso activo a nivel mundial, y el 68% de las organizaciones están implementando, pilotando o desplegando passkeys para la autenticación de empleados. Las passkeys representan la dirección del camino, pero mientras tanto, 2FA basado en TOTP en cada cuenta es la línea base.

En Passwork, los administradores pueden hacer obligatorio el 2FA a nivel de organización. No hay opción de exclusión para los usuarios. Si su configuración actual hace que el 2FA sea opcional, esa es una brecha de política que vale la pena cerrar hoy.


Migrar su equipo a un gestor de contraseñas centralizado

La migración falla cuando se trata como un proyecto técnico en lugar de un proyecto de gestión del cambio. Los pasos técnicos son sencillos. Lograr que el equipo deje de usar los métodos antiguos requiere más trabajo.

El marco de migración de 5 fases

  1. Inventario (semana 1-2). Identificar todos los almacenes de credenciales actualmente en uso: hojas de cálculo, perfiles de navegador compartidos, gestores de contraseñas personales, mensajes de chat. No asuma que los conoce todos; pregunte al equipo. El objetivo es una imagen completa antes de comenzar a mover nada.
  2. Diseño de estructura (semana 2-3). Definir su jerarquía de bóvedas y carpetas antes de importar nada. Una estructura plana con 200 credenciales en una bóveda es apenas mejor que una hoja de cálculo. Diseñar en torno a cómo su equipo realmente trabaja: por proyecto, por sistema, por entorno o por equipo.
  3. Importar y validar (semana 3-4). Importar credenciales de fuentes existentes usando las herramientas de importación de Passwork. Validar que las entradas estén completas y correctamente categorizadas. Asignar propiedad y permisos de acceso antes de anunciar la migración.
  4. Capacitación y despliegue (semana 4-5). Realizar una sesión corta (30 minutos es suficiente para la mayoría de los equipos) cubriendo la extensión del navegador, cómo recuperar una credencial y cómo compartir una. El objetivo es eliminar la excusa «No sé cómo usarlo».
  5. Desmantelar los almacenes antiguos (semana 6+). Establecer una fecha límite firme para retirar la hoja de cálculo o carpeta compartida. Anunciarla con anticipación. Después de la fecha límite, eliminar el almacén antiguo y confirmar con el equipo que el nuevo sistema es la única fuente de verdad.

El fallo de migración más común es dejar el sistema antiguo en su lugar «por si acaso». Mientras la hoja de cálculo exista, algunas personas la usarán.

Poniéndolo en práctica

Poniéndolo en práctica

La brecha entre «tenemos un gestor de contraseñas» y «nuestra seguridad de credenciales está realmente bajo control» es más amplia de lo que la mayoría de los equipos esperan. La herramienta es la parte fácil. El trabajo es la estructura de la bóveda, la política de acceso, el proceso de baja y la higiene continua: asegurarse de que las credenciales débiles se roten y que la hoja de cálculo que alguien en finanzas todavía usa se retire.

Comience con el inventario. No puede asegurar lo que no puede ver. Una vez que sepa qué credenciales existen y dónde residen, cada otro paso sigue lógicamente.

Passwork está disponible como una solución autoalojada con control total sobre sus datos, y como una implementación en la nube alojada en una nube soberana de la UE bajo jurisdicción de la UE. Explore las opciones de implementación y solicite una demostración

Preguntas frecuentes

Preguntas frecuentes

¿Qué es la gestión de contraseñas en equipo?

La gestión de contraseñas en equipo es la práctica de almacenar, compartir y controlar el acceso a las credenciales en un grupo utilizando una herramienta dedicada. Reemplaza los métodos informales (hojas de cálculo, mensajes de chat, perfiles de navegador compartidos) con un sistema estructurado que impone controles de acceso, registra la actividad y soporta la baja segura de empleados.

¿Por qué compartir contraseñas a través de mensajeros o correo electrónico es un riesgo de seguridad?

Las credenciales enviadas a través de plataformas de mensajería o correo electrónico se almacenan en múltiples ubicaciones fuera de su control: la carpeta de enviados del remitente, la bandeja de entrada del destinatario, el historial de mensajes y potencialmente servidores de terceros. No hay caducidad, no hay revocación de acceso y no hay registro de auditoría. Si cualquiera de las cuentas se ve comprometida, la credencial queda expuesta.

¿Qué debe incluir un gestor de contraseñas de equipo?

Un gestor de contraseñas de equipo debe proporcionar almacenamiento centralizado de credenciales, control de acceso basado en roles (RBAC), registro de auditoría, uso compartido externo seguro, integración con AD/LDAP y SSO, e imposición obligatoria de 2FA. Para equipos de DevOps, el acceso API y la gestión de secretos para pipelines CI/CD también son necesarios.

¿Qué requiere NIST SP 800-63B Rev. 4 para las contraseñas?

NIST SP 800-63B Rev. 4 (2025) requiere un mínimo de 15 caracteres cuando una contraseña es el único autenticador, prohíbe las reglas de composición obligatorias (como requerir números o símbolos), elimina las políticas de caducidad periódica y exige la verificación de las nuevas contraseñas contra bases de datos de credenciales comprometidas conocidas.

¿Cómo ayuda un gestor de contraseñas con la baja de empleados?

Un gestor de contraseñas con RBAC e integración AD/LDAP hace que la baja sea determinista. Desactivar una cuenta de usuario o eliminarla de un grupo de directorio revoca su acceso a todas las bóvedas asociadas inmediatamente. El registro de actividad muestra a qué credenciales accedieron, proporcionándole una lista de rotación precisa en lugar de una suposición.

¿Cuál es la diferencia entre la gestión de contraseñas autoalojada y en la nube?

Un gestor de contraseñas autoalojado se ejecuta en su propia infraestructura, dándole control total sobre la residencia de datos, las claves de cifrado y la configuración. Un gestor de contraseñas en la nube está alojado por el proveedor. Ambos pueden usar cifrado zero-knowledge, lo que significa que los servidores del proveedor nunca ven las credenciales en texto plano. El autoalojado es preferido para industrias reguladas; la nube es más rápida de implementar y requiere menos carga de mantenimiento.

¿Cómo se migra un equipo a un nuevo gestor de contraseñas?

Comience con un inventario de todos los almacenes de credenciales existentes, diseñe su estructura de bóvedas antes de importar nada, importe y valide las credenciales, realice una sesión de capacitación corta y establezca una fecha límite firme para retirar el sistema antiguo. El fallo más común es dejar la antigua hoja de cálculo o carpeta compartida accesible después de la migración; mientras exista, algunos miembros del equipo la usarán.

Gestión de contraseñas para equipos: La solución que toda PyME necesita
Almacenar contraseñas en Slack y navegadores expone su negocio a brechas. Descubra por qué las herramientas personales fallan a los equipos, cómo dar de baja de forma segura a los empleados que se van con un solo clic, y por qué las últimas directrices de NIST recomiendan no forzar la rotación de contraseñas.
Caos de contraseñas: Por qué es un problema empresarial y cómo solucionarlo
Una contraseña olvidada cuesta $70. Una brecha cuesta $4.44 millones. Ambas comienzan de la misma manera — credenciales compartidas por Slack, almacenadas en hojas de cálculo, nunca rotadas. Esto es lo que realmente cuesta el caos de contraseñas y cómo eliminarlo.
Shadow IT vs Shadow AI: Por qué la IA es la mayor amenaza
Los empleados están usando herramientas de IA que usted no aprobó, en cuentas que no puede monitorear, con datos que no puede recuperar. Esto es lo que realmente parece el riesgo y lo que la gobernanza necesita abordar.

Gestión de contraseñas en equipo: La guía completa para 2026

Descubra cómo los equipos comparten credenciales de forma segura en 2026: RBAC, registros de auditoría, listas de verificación para bajas, requisitos de NIST SP 800-63B Rev. 4 y despliegue autoalojado vs. en la nube.

Jul 8, 2026 — 16 min read
Illustration of a blue folder containing organized documents separated by labeled tabs for IT, Recruiting, Managers, and Designers. A green shield with a checkmark appears beside the folder, representing secure organization, controlled access, and protected team data or password management.

Team password management is the practice of storing, organizing, and sharing credentials across a group using a dedicated tool (password manager), rather than messengers, spreadsheets, or individual browser vaults. Done right, it gives every team member access to exactly what they need, nothing more, with a full audit trail of who touched what and when.

This guide covers the real problems teams run into when sharing credentials without a proper system, what to look for in a solution, how Passwork addresses each challenge, and how to run a migration without disrupting your team.


Key takeaways

  • Credential abuse appears in 39% of all breaches, making it the most pervasive technique across the full attack chain — not just at initial access.
  • The three failure modes of informal credential sharing are visibility gaps, scope creep, and offboarding failures. All three are preventable with a structured password manager.
  • NIST SP 800-63B Rev. 4 has changed the rules: 15-character minimum passwords, no mandatory composition requirements, and no periodic expiration. Many organizations are still running policies that contradict all three.
  • Effective team password management requires more than storage: RBAC, audit logs, AD/LDAP integration, SSO, and secure external sharing are non-negotiable for any team beyond a handful of people.
  • Offboarding is a security event, not an HR formality. A 7-step credential checklist run on or before an employee's last day closes the gaps that most incidents exploit.
  • Migration succeeds or fails on change management, not technology. The most common failure is leaving the old spreadsheet in place after rollout.

The cost of informal credential sharing

Most teams start with a shared Google Sheet, a Slack message, or a sticky note on the server room door. It works. Until it doesn't.

The average cost of a data breach dropped to $4.44 million in 2025, the first decline in five years, according to IBM's 2025 Cost of a Data Breach Report. That's still $4.44 million per incident. And stolen or compromised credentials remain deeply embedded in how attacks unfold: Verizon's 2026 Data Breach Investigations Report found that credential abuse appears at some point in 39% of all breaches, making it the single most pervasive technique in the dataset.

The informal sharing problem has three distinct failure modes:

  1. Visibility gaps. When a password lives in a Slack thread, there's no record of who has it, who forwarded it, or whether it was changed. If that credential is later compromised, you can't reconstruct the timeline.
  2. Scope creep. Spreadsheets don't enforce access boundaries. A developer who needed one database password in January still has the whole sheet in December, including credentials for systems they've never touched and accounts they have no business accessing.
  3. Offboarding failures. This is where informal sharing causes the most damage. When an employee leaves, IT has no reliable inventory of what they had access to. The standard response (change every shared password) is both disruptive and rarely complete. Some credentials get missed. Some don't get changed for weeks.

A 2024 Huntress study found that 46% of people had a password stolen that year. For organizations relying on shared spreadsheets and chat messages, that exposure is multiplied across every account in the file.


What teams actually need from a password manager

Before evaluating any tool, it helps to define the requirements clearly. The list below reflects what IT managers and security teams consistently identify as non-negotiable.

A centralized, structured repository

Credentials scattered across individuals' browsers and personal vaults are functionally invisible to the organization. A team password manager needs a single, searchable repository that the whole team can access, organized by project, system, or department, with consistent naming and tagging.

Flexible, granular access control

Not everyone needs everything. A junior developer doesn't need production database credentials. A contractor doesn't need internal admin accounts. Role-based access control (RBAC) lets you define who can read, edit, or manage credentials at the vault or folder level, and enforce those boundaries automatically.

Secure sharing mechanisms

Sometimes you need to share a credential with someone outside your organization: a vendor, a contractor, a partner. Sending it over email or chat is a security event waiting to happen. The right tool provides time-limited, single-use links that expire after first access or after a set window.

Activity monitoring and audit logs

Compliance frameworks including SOC 2 Trust Services Criteria CC6.1 and ISO 27001 Annex A.9 require documented evidence of who accessed what and when. An audit log isn't optional. It's the paper trail that keeps you out of trouble during an incident or an audit.

Integration with existing IT infrastructure

A password manager that requires a separate identity silo creates more work, not less. Integration with Active Directory (AD), LDAP, and SSO providers means users authenticate with the credentials they already have, and provisioning/deprovisioning happens automatically when HR updates the directory.


NIST SP 800-63B Rev. 4: What changed in 2025

NIST SP 800-63B Rev. 4 (2025) updates the digital identity guidelines that most enterprise security policies reference. Several changes directly affect how organizations should configure their password policies.

Policy area Rev. 3 guidance Rev. 4 guidance
Minimum password length 8 characters 15 characters (when password is the sole authenticator)
Composition rules "Should not" impose arbitrary rules "Shall not" impose arbitrary composition requirements
Periodic expiration Discouraged Prohibited unless compromise is suspected
Compromised password screening Strongly encouraged Mandatory

The shift from should not to shall not on composition rules is significant. Organizations that still enforce "must include one number, one symbol, one uppercase letter" policies are now out of alignment with NIST guidance, and for good reason. Research consistently shows that forced complexity rules produce predictable patterns: Password1!, Summer2024@, Qwerty#1. Length is a more reliable security signal than character diversity.

The 15-character minimum reflects the same logic. A 15-character passphrase like correct-horse-battery-staple is far more resistant to brute-force attacks than an 8-character P@ssw0rd.

The mandatory compromised password screening requirement means organizations need a mechanism to check new passwords against known breach databases at the point of creation or reset, not just at login.


How Passwork addresses each challenge

Managing credentials requires a constant balance between strict security controls and operational speed. Passwork solves these infrastructure challenges by integrating directly into your existing directory services, automating access control, and providing complete visibility over credential usage.

Data organization: Vaults, folders, tags, and history

A centralized, structured repository

Passwork structures credentials in a hierarchy of vaults and folders. A vault might correspond to a department or a project. Folders within it group related credentials. Tags add a cross-cutting dimension: you can tag credentials by environment (production, staging, dev) or by system type (database, cloud, network) regardless of where they sit in the folder tree.

Every credential entry maintains a full change history. If a password was rotated last Tuesday at 14:32 by a specific user, that's recorded. If you need to roll back or audit a change, the history is there. This is the kind of traceability that SOC 2 and ISO 27001 auditors ask for.

Role-based access: Separating data access and system administration

Flexible, granular access control

Passwork separates data access from administrative control through two distinct mechanisms: user groups and system roles.

  • User groups control data access — This model manages access to vaults and folders. You assign permissions to a group (such as the DevOps team) and every member inherits those permissions automatically. When someone joins the team, they get access. When they leave, you remove them from the group and access is revoked across every vault and folder that group touches. 
  • System roles define administrative privileges — Predefined and custom roles manage access to system settings, LDAP configurations, and global audit logs. This ensures standard users only interact with their assigned vaults, while administrators manage the platform infrastructure. Under the Zero-Knowledge model, system administrators cannot access actual passwords.

Permissions within vaults are granular: read-only, edit, and admin. A read-only user can retrieve credentials but can't modify or delete them. An admin can manage the vault's structure and membership. You can mix these permissions across different vaults for the same user: a developer might have edit access to the staging vault and read-only access to production.

Secure sharing mechanisms

This structure directly solves the offboarding problem. When an employee leaves, you deactivate their account. Their group memberships are removed. Access is gone. No manual inventory of "what did this person have access to?" required.

Security and integration: 2FA, AD/LDAP, and SSO

Passwork enforces two-factor authentication (2FA) at the organization level. Administrators can make it mandatory for all users, not just optional. Supported methods include TOTP authenticator apps, hardware security keys, biometrics, and passkeys.

For organizations running Active Directory or LDAP, Passwork syncs users and groups directly from the directory. User provisioning and deprovisioning follow the directory: when HR disables an account in AD, the corresponding Passwork access is revoked automatically. This eliminates the manual step that most offboarding processes miss.

SSO integration via SAML means users authenticate through your existing identity provider. No separate Passwork credentials to manage, no password reuse risk, and no friction for the end user. 

Sharing a credential with an external party (a contractor, a vendor, a penetration tester) without exposing your vault is a common operational need. Passwork handles this with time-limited, single-use sharing links. You generate a link for a specific credential, set an expiration (hours, days, or a single access), and send it. Once the link expires or is used, it's gone. The recipient never gets access to the vault itself.

This is categorically different from pasting a password into an email. The link is encrypted in transit, the access event is logged, and you can revoke it before expiration if circumstances change.

Auditing: Activity logs and security dashboard

Activity monitoring and audit logs

Every action in Passwork (credential creation, modification, access, sharing, deletion) is recorded in the activity log with a timestamp and user attribution. The log is exportable and can be forwarded to a SIEM via Syslog or Windows Event Viewer integration.

Security dashboard

The security dashboard surfaces weak passwords, old passwords, and credentials that haven't been rotated in a defined period. This gives the security team a continuous view of credential hygiene without manual audits. When a credential shows up as weak or reused, it's visible to the administrator, not buried in a spreadsheet.

Want to see Passwork's audit log and security dashboard in action? Request a free demo

Self-hosted vs. cloud: Which deployment fits your organization

Passwork is available in two deployment models. The choice between them depends on your compliance requirements, IT capacity, and risk tolerance.

Criterion Self-hosted Passwork Cloud
Data residency Your own infrastructure EU sovereign cloud
Deployment time Hours to days Minutes
Compliance control Full (you own the stack) Shared responsibility model
Maintenance overhead Your team manages updates Managed by Passwork
Encryption AES-256, client-side, on your servers AES-256, zero-knowledge, client-side
Ideal for Regulated industries, government, high-security environments SMBs, distributed teams, fast deployment

Self-hosted deployment makes sense when your organization operates under strict data sovereignty requirements: government agencies, financial institutions, healthcare organizations, and companies subject to sector-specific regulations that prohibit data leaving internal infrastructure. You run Passwork on your own servers (Linux with Docker or Windows Server), and all credential data is encrypted with AES-256 before it ever touches the disk. The encryption keys stay with you.

Passwork Cloud is the right choice when you need to be operational quickly and don't have the IT capacity to manage on-premises infrastructure. The cloud instance is hosted within EU jurisdiction, and uses the same zero-knowledge, client-side encryption architecture as the self-hosted version. Passwork Cloud is ISO 27001 certified and GDPR and NIS2 compliant.

Both models support the full feature set: RBAC, AD/LDAP integration, SSO, audit logs, and the REST API.


The offboarding checklist: Securing credentials when someone leaves

Most credential security incidents tied to departing employees happen because offboarding is treated as an HR process, not a security process. The steps below should run in parallel with, or ahead of, the employee's last day.

The 7-step offboarding credential checklist

  1. Disable the account immediately. In Passwork, deactivating a user account revokes all vault and folder access instantly. If AD/LDAP sync is configured, this happens automatically when the directory account is disabled.
  2. Audit shared credentials. Review the activity log for credentials the departing employee accessed in the last 30-90 days. This is your rotation list.
  3. Rotate credentials they had edit access to. Read-only access is lower risk; edit access means they could have copied or modified the credential. Rotate those first.
  4. Revoke any active sharing links. Check for unexpired one-time links the employee generated. Revoke them before the last day.
  5. Reassign vault ownership. If the employee owned or administered any vaults, transfer ownership to another administrator before the account is deactivated.
  6. Check for personal vaults. Some users store work credentials in personal browser vaults or password manager accounts outside the corporate tool. This is shadow IT. Address it in your policy, not just at offboarding.
  7. Document the process. Log the offboarding actions taken, the credentials rotated, and the timestamp. This is the evidence trail for a future audit.

The difference between a clean offboarding and a credential incident is usually whether step 2 happened before or after the employee left.


Best practices for team password management in 2026

Implementing a password manager is only the first step toward securing your organization's infrastructure. To build a resilient security posture, you must align your daily workflows with modern authentication standards and eliminate the habits that expose credentials to external threats.

The following practices focus on reducing the attack surface, securing machine-to-machine communication, and establishing a seamless user experience that naturally eliminates insecure workarounds.

Address shadow IT before it addresses you

Shadow IT in credential management means employees using personal password managers, browser-saved passwords, or shared spreadsheets outside the sanctioned tool. According to Huntress (2024), more than a quarter of cybersecurity professionals identify employees using the same or weak passwords as their most problematic security habit.

The solution isn't a policy memo. It's making the approved tool easier to use than the workaround. Browser extensions, mobile apps, and autofill support remove the friction that drives people to informal alternatives. If using a password manager is faster than opening a spreadsheet, most employees will use it.

Apply NIST Rev. 4 minimums to your password policy

Update your organization's password policy to reflect NIST SP 800-63B Rev. 4 (2025):

  • Minimum 15 characters for passwords used as the sole authenticator
  • No mandatory composition rules (no "must include a number and symbol" requirements)
  • No periodic expiration; rotate only on confirmed or suspected compromise
  • Screen new passwords against a compromised credential database

Passwork's security dashboard flags weak passwords that don't meet your defined thresholds. Pair this with a policy that reflects current NIST guidance, and you have a defensible credential hygiene posture.

Treat non-human credentials as first-class citizens

API keys, service account passwords, database connection strings, and deployment tokens are credentials too. They're often more dangerous than human credentials because they're long-lived, rarely rotated, and frequently embedded in code or configuration files.

Passwork handles secrets (machine credentials) alongside human passwords, with the same RBAC, audit logging, and rotation tracking. The Passwork technical guides cover secrets management for DevOps workflows, including CI/CD pipeline integration.

Enforce 2FA across the board

The FIDO Alliance's 2026 State of Passkeys report found that 5 billion passkeys are now in active use globally, and 68% of organizations are deploying, piloting, or rolling out passkeys for employee authentication. Passkeys represent the direction of travel, but in the meantime, TOTP-based 2FA on every account is the baseline.

In Passwork, administrators can make 2FA mandatory at the organization level. There's no opt-out for users. If your current setup makes 2FA optional, that's a policy gap worth closing today.


Migrating your team to a centralized password manager

Migration fails when it's treated as a technical project rather than a change management project. The technical steps are straightforward. Getting the team to stop using the old methods takes more work.

The 5-phase migration framework

  1. Inventory (week 1-2). Identify all credential stores currently in use: spreadsheets, shared browser profiles, personal password managers, chat messages. Don't assume you know all of them; ask the team. The goal is a complete picture before you start moving anything.
  2. Structure design (week 2-3). Define your vault and folder hierarchy before importing anything. A flat structure with 200 credentials in one vault is barely better than a spreadsheet. Design around how your team actually works: by project, by system, by environment, or by team.
  3. Import and validate (week 3-4). Import credentials from existing sources using Passwork's import tools. Validate that entries are complete and correctly categorized. Assign ownership and access permissions before announcing the migration.
  4. Training and rollout (week 4-5). Run a short session (30 minutes is enough for most teams) covering the browser extension, how to retrieve a credential, and how to share one. The goal is removing the excuse "I don't know how to use it."
  5. Decommission old stores (week 6+). Set a hard deadline for retiring the spreadsheet or shared folder. Announce it in advance. After the deadline, delete the old store and confirm with the team that the new system is the only source of truth.

The most common migration failure is leaving the old system in place "just in case." As long as the spreadsheet exists, some people will use it.

Putting it into practice

Putting it into practice

The gap between "we have a password manager" and "our credential security is actually under control" is wider than most teams expect. The tool is the easy part. The work is the vault structure, the access policy, the offboarding process, and the ongoing hygiene: making sure weak credentials get rotated and that the spreadsheet someone in finance is still using gets retired.

Start with the inventory. You can't secure what you can't see. Once you know what credentials exist and where they live, every other step follows logically.

Passwork is available as a self-hosted solution with full control over your data, and as a cloud deployment hosted in an EU sovereign cloud under EU jurisdiction. Explore deployment options and request a demo

Frequently asked questions

Frequently asked questions

What is team password management?

Team password management is the practice of storing, sharing, and controlling access to credentials across a group using a dedicated tool. It replaces informal methods (spreadsheets, chat messages, shared browser profiles) with a structured system that enforces access controls, logs activity, and supports secure offboarding.

Why is sharing passwords via messengers or email a security risk?

Credentials sent through messaging platforms or email are stored in multiple locations outside your control: the sender's sent folder, the recipient's inbox, message history, and potentially third-party servers. There's no expiration, no access revocation, and no audit trail. If either account is compromised, the credential is exposed.

What should a team password manager include?

A team password manager should provide centralized credential storage, role-based access control (RBAC), audit logging, secure external sharing, integration with AD/LDAP and SSO, and mandatory 2FA enforcement. For DevOps teams, API access and secrets management for CI/CD pipelines are also necessary.

What does NIST SP 800-63B Rev. 4 require for passwords?

NIST SP 800-63B Rev. 4 (2025) requires a minimum of 15 characters when a password is the sole authenticator, prohibits mandatory composition rules (such as requiring numbers or symbols), eliminates periodic expiration policies, and mandates screening new passwords against known compromised credential databases.

How does a password manager help with employee offboarding?

A password manager with RBAC and AD/LDAP integration makes offboarding deterministic. Deactivating a user account or removing them from a directory group revokes their access to all associated vaults immediately. The activity log shows which credentials they accessed, giving you a precise rotation list rather than a guess.

What is the difference between self-hosted and cloud password management?

A self-hosted password manager runs on your own infrastructure, giving you full control over data residency, encryption keys, and configuration. A cloud password manager is hosted by the vendor. Both can use zero-knowledge encryption, meaning the vendor's servers never see plaintext credentials. Self-hosted is preferred for regulated industries; cloud is faster to deploy and requires less maintenance overhead.

How do you migrate a team to a new password manager?

Start with an inventory of all existing credential stores, design your vault structure before importing anything, import and validate credentials, run a short training session, and set a hard deadline for retiring the old system. The most common failure is leaving the old spreadsheet or shared folder accessible after the migration; as long as it exists, some team members will use it.

Password management for teams: The fix every SMB needs
Storing passwords in Slack and browsers exposes your business to breaches. Discover why personal tools fail teams, how to securely offboard departing employees in one click, and why the latest NIST guidelines recommend against forced password rotation.
Password chaos: Why it’s a business problem and how to fix it
A forgotten password costs $70. A breach costs $4.44 million. Both start the same way — credentials shared over Slack, stored in spreadsheets, never rotated. Here’s what password chaos actually costs and how to eliminate it.
Shadow IT vs Shadow AI: Why AI is the bigger threat
Employees are using AI tools you didn’t approve, on accounts you can’t monitor, with data you can’t recover. Here’s what the risk actually looks like and what governance needs to address.

Team password management: The complete guide for 2026

Learn how teams share credentials securely in 2026 — RBAC, audit logs, offboarding checklists, NIST SP 800-63B Rev. 4 requirements, and self-hosted vs. cloud deployment.

Jul 6, 2026 — 12 min read

Die Wahl eines Credential-Managers für ein europäisches Unternehmen im Jahr 2026 ist ebenso eine Compliance-Entscheidung wie eine Produktentscheidung. 

Der Missbrauch von Anmeldedaten bleibt einer der häufigsten Wege in Unternehmensumgebungen. Der Data Breach Investigations Report 2026 von Verizon bestätigt, dass 50 % der Ransomware-Opfer innerhalb von 95 Tagen vor dem Angriff ein Credential- oder Infostealer-Ereignis hatten. 

Gleichzeitig hat die DSGVO-Durchsetzung echte Durchschlagskraft. Im April 2026 verhängte die italienische Garante gegen das Beratungsunternehmen Ambrosetti ein Bußgeld von 85.000 € für die Speicherung von Passwörtern im Klartext und die Verwendung von MD5-Hashing, wobei ausdrücklich auf DSGVO-Artikel 32 als Grundlage verwiesen wurde. NIS2 ist kein Entwurf mehr: 23 von 27 EU-Mitgliedstaaten haben es laut dem ECSO-Transpositions-Tracker in nationales Recht umgesetzt. 

Bei der Bewertung von Lösungen wie Passwork und 1Password spielen Faktoren jenseits der Funktionen eine Rolle. Dieser Artikel vergleicht beide Produkte aus dieser Perspektive: Jurisdiktion, Datensouveränität, Bereitstellungsflexibilität, Audit-Bereitschaft, langfristige Compliance mit DSGVO und NIS2 sowie Gesamtbetriebskosten.


Die wichtigsten Erkenntnisse

  • Beide Plattformen bieten Enterprise-Passwortverwaltung, verwenden jedoch unterschiedliche architektonische Ansätze. 1Password ist ein cloudbasierter Dienst, der auf seinem Secret-Key-Sicherheitsmodell aufbaut, während Passwork eine selbstgehostete Bereitstellung mit clientseitiger AES-256-Verschlüsselung bietet.
  • Das Bereitstellungsmodell bestimmt, wer die Infrastruktur kontrolliert und wer dafür verantwortlich ist. Bei einer selbstgehosteten Bereitstellung verwaltet Ihre Organisation die Umgebung. Bei einem SaaS-Dienst betreibt der Anbieter die Infrastruktur und unterliegt den Gesetzen seiner eigenen Jurisdiktion.
  • Datenresidenz und Datensouveränität adressieren unterschiedliche Aspekte der Daten-Governance. Die Wahl eines EU-Rechenzentrums bestimmt, wo Ihre Daten gespeichert werden. Es bestimmt jedoch nicht allein, welche Landesgesetze auf den Dienstanbieter Anwendung finden können.
  • DSGVO und NIS2 konzentrieren sich darauf, wie Organisationen den Zugriff auf Anmeldedaten schützen und verwalten. Organisationen sollten in der Lage sein, angemessene technische Kontrollen, Zugangsverwaltung, Protokollierung und Audit-Nachweise nachzuweisen.
  • Bei 100 Benutzern kostet Passwork Standardlizenz 3.600 €/Jahr gegenüber ca. 9.588 $/Jahr für 1Password Business. Passwork wird mit 3 €/Benutzer/Monat (Standardlizenz) oder 4,5 €/Benutzer/Monat (Erweiterte Lizenz) berechnet. 1Password Business kostet 7,99 $/Benutzer/Monat. Enterprise-Stufen werden bei beiden Anbietern individuell angeboten.
  • Wählen Sie 1Password, wenn Ihr Team operativen Komfort und eine ausgefeilte Cloud-Erfahrung gegenüber strikter Datensouveränität priorisiert. Wählen Sie Passwork, wenn Ihre Organisation der DSGVO, NIS2 oder DORA unterliegt und nachweisen muss, dass Anmeldedaten niemals Ihre eigene Infrastruktur verlassen.

Das Compliance-Schlachtfeld: Datenresidenz vs. Datensouveränität

Europäische Organisationen, die Passwort-Manager evaluieren, müssen zwischen Datenresidenz und Datensouveränität unterscheiden. Datenresidenz definiert, wo Daten gespeichert werden. Datensouveränität definiert, welches Rechtssystem sie regiert. Eine cloudbasierte Lösung kann EU-Datenresidenz bieten, während sie dennoch einer nicht-europäischen Jurisdiktion unterliegt. Selbstgehostete Lösungen schließen diese Lücke, indem Anmeldedaten vollständig innerhalb der eigenen Infrastruktur der Organisation verbleiben — unter einem einzigen, vorhersehbaren Rechtsrahmen.

1Password bietet EU-Datenresidenz: Kunden können eine europäische Hosting-Region auswählen, und Tresor-Daten befinden sich auf Servern innerhalb der EU. Dies allein löst jedoch nicht alle Jurisdiktionsbedenken für Organisationen mit strengen Souveränitätsanforderungen.

Was grenzüberschreitender Datenzugriff für Cloud-Anbieter bedeutet

Wenn ein cloudbasierter Credential-Manager von einem Unternehmen außerhalb der EU betrieben wird, ist die zentrale Compliance-Frage nicht, wo sich die Server befinden, sondern welches Rechtssystem dieses Unternehmen zur Datenoffenlegung zwingen kann.

Jeder nicht-europäische Anbieter kann rechtmäßige Anfragen von Behörden in seiner Heimatjurisdiktion erhalten. Das anwendbare Recht hängt davon ab, wo der Anbieter eingetragen ist, nicht wo die Daten gespeichert werden.

Der U.S. CLOUD Act (2018) ist das bekannteste Beispiel. Er ermöglicht es US-amerikanischen Strafverfolgungsbehörden, von in den USA eingetragenen Anbietern die Herausgabe von weltweit gespeicherten Daten zu verlangen.

1Password ist kein US-Unternehmen. AgileBits Inc. ist in Kanada eingetragen, sodass der CLOUD Act nicht in gleicher Weise gilt wie für US-Anbieter. Kanada nimmt jedoch an internationalen Rahmenwerken für die Zusammenarbeit der Strafverfolgungsbehörden wie Five Eyes teil, was bedeutet, dass grenzüberschreitende rechtliche Anfragen weiterhin zu berücksichtigen sind.

DSGVO-Artikel 48 besagt, dass eine ausländische Gerichtsentscheidung allein keine gültige Rechtsgrundlage für die Übermittlung personenbezogener Daten aus der EU darstellt. Diese Einschränkung gilt in erster Linie für Ihre Organisation als Verantwortlicher.

Wie jeder cloudbasierte Credential-Manager, der von einer nicht-europäischen Einheit betrieben wird, führt 1Password eine Ebene jurisdiktioneller Komplexität ein, die eine selbstgehostete Bereitstellung nicht hat.

Wie eine On-Premise-Bereitstellung die Lücke schließt

Das selbstgehostete Modell von Passwork bedeutet, dass kein Dritter Ihre Anmeldedaten besitzt. Bereitgestellt auf Ihrer eigenen Infrastruktur innerhalb der EU-Jurisdiktion verlassen Tresorinhalte niemals Ihre Umgebung. Kein externes Unternehmen kann eine ausländische Regierungsanordnung für Daten erhalten, auf die es keinen Zugriff hat. Die Gesetze, die Ihre Daten regieren, sind die Gesetze der Jurisdiktion, in der sich Ihre Server befinden.

Passwork ist als selbstgehostete Lösung und in einer souveränen EU-Cloud verfügbar und gibt Ihnen die volle Kontrolle über Ihre Daten und Infrastruktur. Erkunden Sie die Bereitstellungsoptionen — passwork.pro


Funktionsvergleich: Passwork vs. 1Password

Passwork und 1Password auf der Business-Stufe teilen eine gemeinsame Basis: AES-256-Verschlüsselung, RBAC, SSO und Entwicklertools. Die Unterschiede zeigen sich auf architektonischer Ebene. Die selbstgehostete Bereitstellung von Passwork gibt der Organisation direkte Kontrolle über Verschlüsselungsschlüssel, Audit-Logs und den Admin-Perimeter — ohne Abhängigkeit von Anbieter-Infrastruktur oder ausgehender Konnektivität zu externen Diensten.

Sicherheitsarchitektur

Die Secret-Key-Architektur von 1Password erfordert einen 128-Bit-Schlüssel, der als 34-Zeichen-String codiert ist und bei der Geräteeinrichtung generiert wird. Dieser wird mit dem Masterpasswort kombiniert, um den Verschlüsselungsschlüssel abzuleiten. Selbst wenn die Server von 1Password kompromittiert würden, wäre es rechnerisch nicht machbar, verschlüsselte Tresore ohne den Secret Key zu entschlüsseln. Es ist ein gut konzipiertes Cloud-Sicherheitsmodell.

Passwork verwendet clientseitige Zero-Knowledge-Verschlüsselung auf einer selbstgehosteten Instanz. Ver- und Entschlüsselung erfolgen auf dem Client (Benutzergerät). Der Server speichert nur Chiffretext. Da Sie die Plattform hosten, behalten Sie die vollständige Kontrolle über den Anwendungsserver, Verschlüsselungsschlüssel und Audit-Logs. Diese Bereitstellung garantiert eine isolierte Umgebung, frei von gemeinsam genutzter Infrastruktur, Multi-Tenant-Risiken oder Abhängigkeit von Anbieter-Schlüsselverwaltung.

Enterprise-Administration: RBAC, AD/LDAP und SSO

Beide Plattformen decken die Enterprise-Administrationsfunktionen ab, die IT-Teams erwarten.

1Password Business umfasst SCIM-Provisioning, SSO-Integration über Okta und Azure AD sowie eine ausgereifte Admin-Konsole. Sein Extended Access Management-Produkt (verfügbar als separat lizenziertes Add-on) erweitert Gerätevertrauen und Anwendungszugriffskontrollen über den Passwort-Tresor hinaus.

Passwork bietet granulare rollenbasierte Zugriffskontrolle (RBAC), native Active Directory- und LDAP-Integration für Benutzer-Provisioning und Gruppensynchronisation sowie SAML SSO. Um die Verwaltung im großen Maßstab zu vereinfachen, trennt Passwork den Datenzugriff von administrativen Berechtigungen durch zwei unterschiedliche Mechanismen:

  • Benutzergruppen steuern den Datenzugriff — Administratoren weisen Berechtigungen für Tresore und Ordner auf Gruppenebene zu. Wenn Benutzer einer Gruppe hinzugefügt werden, erben sie automatisch den Zugriff auf die entsprechenden Passwörter und Anmeldedaten. 
  • Rollen definieren Systemrechte — Vordefinierte und benutzerdefinierte Rollen verwalten den Zugriff auf Systemeinstellungen, Benutzerverzeichnisse und Audit-Logs. Dies stellt sicher, dass Standardbenutzer nur mit ihren zugewiesenen Tresoren interagieren, während Administratoren die Infrastruktur verwalten, ohne unter dem Zero-Knowledge-Modell Zugriff auf tatsächliche Passwörter zu haben.

Für Organisationen, die AD-basierte Identitätsinfrastruktur betreiben (die Mehrheit der europäischen Unternehmen), bedeutet die LDAP-Integration, dass Onboarding und Offboarding über bestehende Verzeichnis-Workflows laufen. Sicherheitsgruppen werden automatisch synchronisiert, sodass Tresor-Berechtigungen und administrative Rollen mit Ihrem zentralen Verzeichnis abgestimmt bleiben.

Ein praktischer Unterschied, der erwähnt werden sollte: Da Passwork selbstgehostet ist, befinden sich Admin-Konsole, Audit-Logs und Benutzerverzeichnis alle innerhalb Ihres eigenen Netzwerkperimeters. Administrative Operationen haben keine Abhängigkeit von einem Verfügbarkeits-SLA des Anbieters.

Feature Comparison
Funktion Passwork 1Password Business
SSO SAML 2.0 SSO SAML 2.0 / OIDC (Unlock with SSO)
Benutzer-Provisioning Native AD/LDAP-Integration SCIM-Provisioning (erfordert Bereitstellung einer selbstgehosteten SCIM Bridge)
Gruppensynchronisation Direkte AD/LDAP-Gruppensynchronisation Synchronisation über SCIM Bridge
Zugriffskontrolle Granulares RBAC (Berechtigungen auf Tresor-, Ordner- und Elementebene) Rollenbasierte Berechtigungen (Zugriff auf Tresor- und Gruppenebene)
Gerätevertrauen / App-Zugriffskontrollen Extended Access Management (Add-on, separate Lizenz)
Admin-Konsolen-Standort Innerhalb Ihres eigenen Netzwerkperimeters Anbieter-Cloud
Audit-Log-Standort Lokale Datenbank (innerhalb Ihres Perimeters) Anbieter-Cloud
Anbieter-Verfügbarkeitsabhängigkeit Keine (vollständig offline betriebsfähig) Ja (erfordert Verbindung zur 1Password-Cloud)

DevOps und Secrets Management

1Password hat stark in Entwicklertools investiert. Seine CLI (op), Secrets Automation und native Integrationen mit GitHub Actions, Kubernetes und CI/CD-Pipelines machen es zu einem leistungsfähigen Secrets Manager für cloud-native Teams. Die Entwicklererfahrung ist ausgereift.

Passwork bietet eine vollständige REST API und CLI-Tools für DevOps-Workflows: Einspeisung von Secrets in Pipelines, programmatische Rotation von Anmeldedaten, Verwaltung von API-Schlüsseln und Datenbank-Anmeldedaten zusammen mit menschlichen Passwörtern in einem einheitlichen Tresor.

Für Teams, die in air-gapped oder strikt perimeter-kontrollierten Umgebungen arbeiten, ist der architektonische Unterschied relevant. 1Password bietet zwar einen selbstgehosteten Connect Server, der Secrets lokal zwischenspeichert und die Abhängigkeit von der 1Password-API reduziert, aber die Ersteinrichtung und periodische Synchronisation erfordern weiterhin ausgehende Konnektivität zur Cloud-Infrastruktur von 1Password. 

Passwork erfordert zu keinem Zeitpunkt eine solche Abhängigkeit: Der gesamte Stack läuft vom ersten Tag an innerhalb des eigenen Unternehmensperimeters, ohne Aufrufe zu externen Diensten. Für Organisationen, bei denen ausgehender Datenverkehr zur Cloud eines Anbieters durch Richtlinien oder Architektur nicht erlaubt ist, ist dieser Unterschied eine harte Anforderung.

Funktion Passwork 1Password Business
CLI Ja Ja (op)
REST API Ja Ja
Secrets Automation Ja Ja
CI/CD-Integrationen Ja Ja
Einheitlicher Tresor (Passwörter + Secrets) Ja Ja
Selbstgehosteter Secrets-Cache Ja (vollständig selbstgehostete Bereitstellung) Connect Server (Add-on)
Ausgehende Konnektivität zur Anbieter-Cloud Nie erforderlich Erforderlich für Ersteinrichtung und periodische Synchronisation
Unterstützung für air-gapped Umgebungen Vollständig Teilweise

Zukunftssicherheit: NIS2 und das Post-Quantum-Mandat 2027

NIS2 fügte eine Klausel hinzu, die Anbieter lieber übersehen würden

NIS2-Artikel 21 setzt die Sicherheit Ihrer IKT-Dienstleister auf Ihr Risikoregister. Nicht auf deren — auf Ihres. Ein cloudbasierter Passwort-Manager ist ein IKT-Dienstleister. Unter NIS2 ist Ihre Organisation dafür verantwortlich zu bewerten, ob die Sicherheitslage dieses Anbieters — einschließlich seiner rechtlichen Jurisdiktion und Incident-Response-Verpflichtungen — Ihrer Risikoschwelle entspricht.

Wenn ein Sicherheitsvorfall bei Ihrem Passwort-Manager-Anbieter Ihre Anmeldedaten offenlegt, können NIS2-Incident-Reporting-Verpflichtungen auf Ihrer Seite ausgelöst werden: Erstmeldung innerhalb von 24 Stunden, detaillierter Bericht innerhalb von 72 Stunden.

Die Bereitstellung einer selbstgehosteten Lösung verändert dieses Risikoprofil. Die Angriffsfläche ist Ihre Infrastruktur, die von Ihren Sicherheitskontrollen geregelt und von Ihrem Team auditiert wird. NIS2-Lieferketten-Risikobewertungen werden wesentlich einfacher, wenn die „Lieferkette" für die Credential-Speicherung intern ist.

Das ANSSI-Mandat 2027 für quantensichere Kryptographie

Frankreichs nationale Cybersicherheitsbehörde ANSSI kündigte an, ab 2027 keine Sicherheitsprodukte (einschließlich Passwort-Manager) mehr zu zertifizieren, die keine quantenresistente Verschlüsselung haben. Bis 2030 erwartet ANSSI, dass alle Geschäftsbeschaffungen quantensichere Kryptographie erfordern. Für Organisationen in Frankreich und in der gesamten EU schafft dies eine harte Zertifizierungsfrist innerhalb der nächsten 12–18 Monate.

Die relevante Frage für Beschaffungsteams ist nicht nur, ob ein Anbieter PQC unterstützt, sondern ob die Organisation kontrolliert, wann und wie diese Umstellung erfolgt.

Bei einem cloudbasierten Passwort-Manager erfolgt die Migration der Tresor-Verschlüsselungsschicht nach dem Zeitplan des Anbieters, über gemeinsam genutzte Infrastruktur. Bei einer selbstgehosteten Bereitstellung wendet Ihre Organisation kryptographische Updates (einschließlich NIST-standardisierter PQC-Algorithmen) nach Ihrem eigenen Zeitplan an, ohne Abhängigkeit vom Release-Zyklus eines Anbieters.

Erfahren Sie, wie Passwork Enterprise-Zugriffskontrolle, Audit-Protokollierung und selbstgehostete Bereitstellung handhabt — passwork.pro

Preisgestaltung und Gesamtbetriebskosten

Übersicht der Preise

1Password Business wird mit 7,99 $ pro Benutzer pro Monat (jährliche Abrechnung) berechnet. Der Teams-Plan liegt bei 4,99 $/Benutzer/Monat. Enterprise-Preise erfordern ein individuelles Angebot.

Die Preisgestaltung von Passwork ist auf europäische Käufer ausgerichtet:

Plan Preis Wichtige Leistungen
Standardlizenz 3 €/Benutzer/Monat Kern-Tresor, RBAC, AD/LDAP
Erweiterte Lizenz 4,5 €/Benutzer/Monat API-Zugang, erweitertes Audit, SSO
Enterprise Individuell On-Premise, dedizierter Support, SLA

Bei 100 Benutzern kostet Passwork Standardlizenz 3.600 €/Jahr gegenüber 1Password Business mit etwa 9.588 $/Jahr. Die Differenz wächst mit zunehmender Skalierung.

TCO jenseits der Lizenzgebühr

On-Premise-Bereitstellung erfordert Server-Infrastruktur, Wartung und internen operativen Aufwand. Für Organisationen, die bereits On-Premises-Infrastruktur betreiben (die meisten europäischen Unternehmen in regulierten Sektoren), sind die Grenzkosten für das Hinzufügen einer selbstgehosteten Passwork-Instanz gering. Für Organisationen ohne On-Premises-Präsenz ist der Infrastruktur-Overhead eine echte Überlegung und sollte vor Vertragsunterzeichnung ehrlich eingeschätzt werden.

Die TCO-Berechnung benötigt auch eine Zeile für Compliance-Risiko. Ein Sicherheitsvorfall mit einem cloudbasierten Credential-Speicher kann DSGVO-Artikel 83-Bußgelder von bis zu 10 Millionen € oder 2 % des weltweiten Jahresumsatzes für Verstöße gegen die Sicherheitsanforderungen von Artikel 32 auslösen. DSGVO-Bußgelder haben bis 2026 kumulativ 6,31 Milliarden € überschritten. Der Ambrosetti-Fall (85.000 € für MD5-gehashte Passwörter) zeigt, dass Datenschutzbehörden jetzt die kryptographische Implementierung direkt prüfen — nicht nur Zeitpläne für Benachrichtigungen bei Sicherheitsvorfällen.


Fazit: Welcher Passwort-Manager passt zu EU-basierten Organisationen

Die Wahl eines Passwort-Managers für den Enterprise-Einsatz läuft auf die Frage hinaus: Wo endet Ihr Compliance-Perimeter? Cloud-native Teams mit modernen Identity-Stacks finden eine natürliche Passung in tiefen Ökosystem-Integrationen und plattformübergreifender UX. Organisationen, die unter DSGVO, NIS2 oder DORA operieren, stehen vor einer anderen Einschränkung — nicht Benutzerfreundlichkeit, sondern Jurisdiktion. 

Wählen Sie 1Password Business, wenn:

  • Ihr Team global verteilt und cloud-native ist
  • Sie Entwicklererfahrung und plattformübergreifende UX über Compliance-Architektur priorisieren
  • Ihr regulatorisches Umfeld keine strikte Datensouveränität erfordert
  • Sie Extended Access Management oder tiefe Integration mit einem modernen Cloud-Identity-Stack benötigen

Wählen Sie Passwork, wenn:

  • Ihre Organisation der DSGVO, NIS2 oder DORA unterliegt und Datensouveränität nachweisen muss
  • Sie in kritischer Infrastruktur, Finanzdienstleistungen, Gesundheitswesen oder dem öffentlichen Sektor tätig sind
  • Sie AD/LDAP-native Integration innerhalb einer bestehenden On-Premises-Identitätsumgebung benötigen
  • Sie sich auf ANSSI-Zertifizierung oder EU-Beschaffung im öffentlichen Sektor vorbereiten
  • Ihr Sicherheitsteam die volle Kontrolle über die Verschlüsselungsschicht, Audit-Logs und Schlüsselverwaltung benötigt

Für europäische Unternehmen in regulierten Sektoren ist die Architektur, die bei allen fünf Kriterien „Ja" antwortet, selbstgehostet, On-Premise und jurisdiktionell sauber. 

Passwork bietet europäischen IT-Teams einen selbstgehosteten, DSGVO-konformen Credential-Tresor mit vollständiger Audit-Protokollierung, AD/LDAP-Integration und Zero-Knowledge-Verschlüsselung — alles innerhalb Ihrer eigenen Infrastruktur. Fordern Sie eine Demo an oder erkunden Sie den Leitfaden zur selbstgehosteten Bereitstellung — passwork.pro


Häufig gestellte Fragen

Was ist der Unterschied zwischen Passwork und 1Password?

Der Kernunterschied liegt im Bereitstellungsmodell und der Jurisdiktion. 1Password ist ein cloudbasiertes SaaS-Produkt mit optionaler EU-Datenresidenz und Hauptsitz in Kanada. Passwork ist ein selbstgehosteter Enterprise-Passwort-Manager, der auf Ihrer eigenen Infrastruktur läuft und Ihrer Organisation die volle rechtliche und technische Kontrolle über Anmeldedaten gibt. Passwork bietet auch eine Cloud-Option, aber sein Hauptwert für europäische Unternehmen ist die On-Premise-Bereitstellung.

Ist 1Password DSGVO-konform?

1Password bietet EU-Datenresidenz: Tresor-Daten können auf Servern innerhalb der EU gespeichert werden. Als Unternehmen mit Hauptsitz in Kanada unterliegt es jedoch weiterhin kanadischem Recht und potenzieller Zusammenarbeit mit US-Behörden. DSGVO-Artikel 48 erkennt eine ausländische Gerichtsentscheidung nicht als rechtmäßige Übermittlungsgrundlage an, aber diese Einschränkung gilt für Ihre Organisation als Verantwortlicher — nicht für den Anbieter, der die Anordnung erhält.

Welcher ist der beste europäische Passwort-Manager für NIS2-Compliance?

NIS2-Artikel 21 verlangt von betroffenen Organisationen, das IKT-Risiko der Lieferkette zu managen. Ein selbstgehosteter Passwort-Manager eliminiert das Drittanbieter-Risiko für die Credential-Speicherung vollständig. Für NIS2-betroffene Einheiten ist die On-Premise-Bereitstellung mit vollständiger Audit-Protokollierung und AD/LDAP-Integration die architektonisch vertretbare Wahl. Passwork ist speziell für diese Anforderung konzipiert.

Was ist Datensouveränität und warum ist sie für Passwort-Manager wichtig?

Datensouveränität bedeutet, dass Ihre Daten ausschließlich den Gesetzen Ihrer Jurisdiktion unterliegen — nicht nur physisch dort gespeichert sind. Für einen Passwort-Manager bedeutet dies, dass keine ausländische Regierung den Anbieter zwingen kann, Ihre Tresorinhalte herauszugeben. Selbstgehostete Bereitstellung erreicht dies, weil kein externer Anbieter Ihre Daten hält. Cloud-Bereitstellung mit EU-Datenresidenz erreicht Compliance bezüglich des physischen Standorts, aber keine vollständige rechtliche Souveränität.

Wie wirkt sich das ANSSI-Mandat 2027 auf die Beschaffung von Passwort-Managern aus?

Ab 2027 wird ANSSI keine Sicherheitsprodukte mehr zertifizieren, die keine quantenresistente Verschlüsselung haben. Organisationen, die für französische Regierungsaufträge oder regulierte Sektoren beschaffen, werden Anbieter mit einer glaubwürdigen Post-Quantum-Kryptographie-Roadmap benötigen. Bis 2030 erwartet ANSSI, dass alle Geschäftskäufe quantensichere Kryptographie erfordern — was jede europäische Organisation betrifft, die ANSSI-Zertifizierung als Beschaffungsmaßstab verwendet.

Ist Passwork ISO 27001 zertifiziert?

Ja, Passwork besitzt die ISO 27001-Zertifizierung. Die Architektur ist Zero-Knowledge: AES-256, clientseitige Verschlüsselung, nur Chiffretext auf dem Server. Schlüssel berühren den Server nicht. Für Bereitstellungsspezifikationen und Zertifizierungsdetails siehe passwork.pro.

Passwork vs 1Password: Welcher Passwort-Manager ist besser für EU-Unternehmen?

DSGVO, NIS2, ANSSI 2027 — der regulatorische Druck steigt stetig. Wir vergleichen Passwork und 1Password anhand der Kriterien, die für europäische Unternehmen entscheidend sind: Datensouveränität, Audit-Bereitschaft, Deployment-Modell und tatsächliche Gesamtbetriebskosten.

Jul 6, 2026 — 15 min read
Passwork vs 1Password: ¿Qué gestor de contraseñas es mejor para empresas de la UE?

Elegir un gestor de credenciales para una empresa europea en 2026 es tanto una decisión de cumplimiento normativo como una decisión de producto.

El abuso de credenciales sigue siendo una de las vías más comunes de acceso a entornos corporativos. El informe Data Breach Investigations Report 2026 de Verizon confirma que el 50% de las víctimas de ransomware experimentaron un evento relacionado con credenciales o infostealers en los 95 días previos al ataque.

Al mismo tiempo, la aplicación del RGPD tiene consecuencias reales. En abril de 2026, el Garante italiano multó a la consultora Ambrosetti con 85.000 € por almacenar contraseñas en texto plano y usar hash MD5, citando explícitamente el Artículo 32 del RGPD como fundamento. NIS2 ya no es un borrador: 23 de los 27 estados miembros de la UE lo han transpuesto a la legislación nacional, según el rastreador de transposición de ECSO.

Al evaluar soluciones como Passwork y 1Password, los factores más allá de las funcionalidades empiezan a importar. Este artículo compara ambos productos desde esa perspectiva: jurisdicción, soberanía de datos, flexibilidad de despliegue, preparación para auditorías, cumplimiento a largo plazo con RGPD y NIS2, y coste total de propiedad.


Puntos clave

  • Ambas plataformas proporcionan gestión de contraseñas empresarial, pero utilizan enfoques arquitectónicos diferentes. 1Password es un servicio basado en la nube construido en torno a su modelo de seguridad Secret Key, mientras que Passwork ofrece despliegue autoalojado con cifrado AES-256 del lado del cliente.
  • El modelo de despliegue determina quién controla la infraestructura y quién es responsable de ella. Con un despliegue autoalojado, su organización gestiona el entorno. Con un servicio SaaS, el proveedor opera la infraestructura y permanece sujeto a las leyes de su propia jurisdicción.
  • La residencia de datos y la soberanía de datos abordan aspectos diferentes de la gobernanza de datos. Elegir un centro de datos en la UE determina dónde se almacenan sus datos. Por sí solo, no determina qué leyes de qué país pueden aplicarse al proveedor del servicio.
  • El RGPD y NIS2 se centran en cómo las organizaciones protegen y gestionan el acceso a las credenciales. Las organizaciones deben poder demostrar controles técnicos apropiados, gestión de accesos, registro de actividad y evidencia de auditoría.
  • Con 100 usuarios, Passwork licencia estándar cuesta 3.600 €/año frente a ~9.588 $/año de 1Password Business. Passwork tiene un precio de 3 €/usuario/mes (licencia estándar) o 4,5 €/usuario/mes (licencia avanzada). 1Password Business cuesta 7,99 $/usuario/mes. Los niveles Enterprise tienen precios personalizados en ambos casos.
  • Elija 1Password si su equipo prioriza la comodidad operativa y una experiencia en la nube pulida sobre la soberanía de datos estricta. Elija Passwork si su organización está sujeta al RGPD, NIS2 o DORA y necesita demostrar que los datos de credenciales nunca salen de su propia infraestructura.

El campo de batalla del cumplimiento: Residencia de datos vs. soberanía de datos

Las organizaciones europeas que evalúan gestores de contraseñas necesitan distinguir entre residencia de datos y soberanía de datos. La residencia de datos define dónde se almacenan los datos. La soberanía de datos define qué sistema legal los gobierna. Una solución basada en la nube puede ofrecer residencia de datos en la UE mientras sigue estando sujeta a jurisdicción fuera de la UE. Las soluciones autoalojadas eliminan esa brecha al mantener los datos de credenciales completamente dentro de la propia infraestructura de la organización, bajo un marco legal único y predecible.

1Password ofrece residencia de datos en la UE: los clientes pueden seleccionar una región de alojamiento europea, y los datos de la bóveda residen en servidores dentro de la UE. Sin embargo, esto por sí solo no resuelve todas las preocupaciones jurisdiccionales para organizaciones con requisitos estrictos de soberanía.

Qué significa el acceso transfronterizo a datos para los proveedores en la nube

Cuando un gestor de credenciales basado en la nube es operado por una empresa fuera de la UE, la pregunta clave de cumplimiento no es dónde están ubicados los servidores, sino qué sistema legal puede obligar a esa empresa a divulgar datos.

Cualquier proveedor fuera de la UE puede recibir solicitudes legales de las autoridades de su jurisdicción de origen. La ley aplicable depende de dónde está constituido el proveedor, no de dónde se almacenan los datos.

La CLOUD Act de EE. UU. (2018) es el ejemplo más conocido. Permite a las fuerzas del orden estadounidenses exigir a los proveedores constituidos en EE. UU. que entreguen datos almacenados en cualquier parte del mundo.

1Password no es una empresa estadounidense. AgileBits Inc. está constituida en Canadá, por lo que la CLOUD Act no se aplica de la misma manera que a los proveedores estadounidenses. Sin embargo, Canadá participa en marcos de cooperación internacional de aplicación de la ley como Five Eyes, lo que significa que las solicitudes legales transfronterizas siguen siendo una consideración.

El Artículo 48 del RGPD establece que una orden judicial extranjera por sí sola no es una base legal válida para transferir datos personales desde la UE. Esa restricción se aplica principalmente a su organización como responsable del tratamiento de datos.

Como cualquier gestor de credenciales basado en la nube operado por una entidad fuera de la UE, 1Password introduce una capa de complejidad jurisdiccional que un despliegue autoalojado no tiene.

Cómo el despliegue en las instalaciones cierra la brecha

El modelo autoalojado de Passwork significa que ningún tercero tiene sus datos de credenciales. Desplegado en su propia infraestructura dentro de la jurisdicción de la UE, el contenido de las bóvedas nunca abandona su entorno. Ninguna empresa externa puede recibir una orden de un gobierno extranjero para datos a los que no tiene acceso. Las leyes que gobiernan sus datos son las leyes de la jurisdicción donde se encuentran sus servidores.

Passwork está disponible como solución autoalojada y en una nube soberana de la UE, ofreciéndole control total sobre sus datos e infraestructura. Explore las opciones de despliegue — passwork.pro


Comparativa de funcionalidades: Passwork vs 1Password

Passwork y 1Password en el nivel Business comparten una base común: cifrado AES-256, RBAC, SSO y herramientas para desarrolladores. Las diferencias emergen a nivel arquitectónico. El despliegue autoalojado de Passwork otorga a la organización control directo sobre las claves de cifrado, los registros de auditoría y el perímetro de administración sin dependencia de la infraestructura del proveedor ni conectividad saliente a servicios externos.

Arquitectura de seguridad

La arquitectura Secret Key de 1Password requiere una clave de 128 bits codificada como una cadena de 34 caracteres generada en la configuración del dispositivo, combinada con la contraseña maestra, para derivar la clave de cifrado. Incluso si los servidores de 1Password fueran comprometidos, las bóvedas cifradas serían computacionalmente inviables de descifrar sin la Secret Key. Es un modelo de seguridad en la nube bien diseñado.

Passwork utiliza cifrado de conocimiento cero del lado del cliente en una instancia autoalojada. El cifrado y descifrado ocurren en el cliente (dispositivo del usuario). El servidor almacena solo texto cifrado. Dado que usted aloja la plataforma, mantiene control completo sobre el servidor de aplicaciones, las claves de cifrado y los registros de auditoría. Este despliegue garantiza un entorno aislado, libre de infraestructura compartida, riesgos de multitenencia o dependencia de la gestión de claves del proveedor.

Administración empresarial: RBAC, AD/LDAP y SSO

Ambas plataformas cubren las funcionalidades de administración empresarial que los equipos de TI esperan.

1Password Business incluye aprovisionamiento SCIM, integración SSO vía Okta y Azure AD, y una consola de administración madura. Su producto Extended Access Management (disponible como complemento con licencia separada) extiende la confianza de dispositivos y los controles de acceso a aplicaciones más allá de la propia bóveda de contraseñas.

Passwork proporciona control de acceso basado en roles (RBAC) granular, integración nativa con Active Directory y LDAP para aprovisionamiento de usuarios y sincronización de grupos, y SSO SAML. Para simplificar la gestión a escala, Passwork separa el acceso a datos de los privilegios administrativos mediante dos mecanismos distintos:

  • Los grupos de usuarios controlan el acceso a datos — Los administradores asignan permisos a bóvedas y carpetas a nivel de grupo. Cuando los usuarios se añaden a un grupo, heredan automáticamente el acceso a las contraseñas y credenciales correspondientes.
  • Los roles definen privilegios del sistema — Los roles predefinidos y personalizados gestionan el acceso a la configuración del sistema, directorios de usuarios y registros de auditoría. Esto asegura que los usuarios estándar solo interactúen con sus bóvedas asignadas, mientras que los administradores gestionan la infraestructura sin tener acceso a las contraseñas reales bajo el modelo de conocimiento cero.

Para organizaciones que ejecutan infraestructura de identidad basada en AD (la mayoría de las empresas europeas), la integración LDAP significa que la incorporación y baja de usuarios se ejecuta a través de los flujos de trabajo de directorio existentes. Los grupos de seguridad se sincronizan automáticamente, asegurando que los permisos de bóveda y los roles administrativos permanezcan alineados con su directorio central.

Una diferencia práctica que vale la pena mencionar: debido a que Passwork es autoalojado, la consola de administración, los registros de auditoría y el directorio de usuarios residen dentro de su propio perímetro de red. Las operaciones administrativas no tienen dependencia del SLA de disponibilidad de un proveedor.

Feature Comparison
Funcionalidad Passwork 1Password Business
SSO SAML 2.0 SSO SAML 2.0 / OIDC (Unlock with SSO)
Aprovisionamiento de usuarios Integración nativa AD/LDAP Aprovisionamiento SCIM (requiere desplegar un SCIM Bridge autoalojado)
Sincronización de grupos Sincronización directa de grupos AD / LDAP Sincronización vía SCIM Bridge
Control de acceso RBAC granular (permisos a nivel de bóveda, carpeta y elemento) Permisos basados en roles (acceso a nivel de bóveda y grupo)
Confianza de dispositivos / controles de acceso a apps Extended Access Management (complemento, licencia separada)
Ubicación de la consola de administración Dentro de su propio perímetro de red Nube del proveedor
Ubicación de registros de auditoría Base de datos local (dentro de su perímetro) Nube del proveedor
Dependencia de disponibilidad del proveedor Ninguna (totalmente operativo sin conexión) Sí (requiere conexión a la nube de 1Password)

DevOps y gestión de secretos

1Password ha invertido fuertemente en herramientas para desarrolladores. Su CLI (op), Secrets Automation e integraciones nativas con GitHub Actions, Kubernetes y pipelines CI/CD lo convierten en un gestor de secretos capaz para equipos cloud-native. La experiencia de desarrollador está pulida.

Passwork ofrece una API REST completa y herramientas CLI para flujos de trabajo DevOps: inyectar secretos en pipelines, rotar credenciales programáticamente, gestionar claves API y credenciales de bases de datos junto con contraseñas humanas en una bóveda unificada.

Para equipos que operan en entornos aislados o estrictamente controlados por perímetro, la diferencia arquitectónica importa. 1Password ofrece un Connect Server autoalojado que almacena secretos en caché localmente y reduce la dependencia de la API de 1Password, pero la configuración inicial y la sincronización periódica todavía requieren conectividad saliente a la infraestructura en la nube de 1Password.

Passwork no requiere tal dependencia en ninguna etapa: toda la pila se ejecuta dentro del propio perímetro de la empresa desde el primer día, sin llamadas a servicios externos. Para organizaciones donde el tráfico saliente a la nube de un proveedor no está permitido por política o arquitectura, esa distinción es un requisito indispensable.

Funcionalidad Passwork 1Password Business
CLI Sí (op)
REST API
Automatización de secretos
Integraciones CI/CD
Bóveda unificada (contraseñas + secretos)
Caché de secretos autoalojada Sí (despliegue completamente autoalojado) Connect Server (complemento)
Conectividad saliente a la nube del proveedor Nunca requerida Requerida para configuración inicial y sincronización periódica
Soporte para entornos aislados Completo Parcial

Preparación para el futuro: NIS2 y el mandato post-cuántico de 2027

NIS2 añadió una cláusula que los proveedores preferirían que no notara

El Artículo 21 de NIS2 coloca la seguridad de sus proveedores de servicios TIC en su registro de riesgos. No en el de ellos — en el suyo. Un gestor de contraseñas basado en la nube es un proveedor de servicios TIC. Bajo NIS2, su organización es responsable de evaluar si la postura de seguridad de ese proveedor — incluyendo su jurisdicción legal y obligaciones de respuesta a incidentes — cumple con su umbral de riesgo.

Si una brecha en su proveedor de gestor de contraseñas expone sus credenciales, las obligaciones de notificación de incidentes de NIS2 pueden activarse de su lado: notificación inicial en 24 horas, informe detallado en 72 horas.

Desplegar una solución autoalojada modifica ese perfil de riesgo. La superficie de ataque es su infraestructura, gobernada por sus controles de seguridad, auditada por su equipo. Las evaluaciones de riesgo de la cadena de suministro de NIS2 se simplifican sustancialmente cuando la «cadena de suministro» para el almacenamiento de credenciales es interna.

El mandato de seguridad cuántica de ANSSI para 2027

La agencia nacional de ciberseguridad de Francia, ANSSI, anunció que dejará de certificar productos de seguridad (incluidos los gestores de contraseñas) que carezcan de cifrado resistente a la computación cuántica a partir de 2027. Para 2030, ANSSI espera que todas las adquisiciones empresariales requieran criptografía segura ante amenazas cuánticas. Para organizaciones en Francia y en toda la UE, esto crea un plazo de certificación firme en los próximos 12-18 meses.

La pregunta relevante para los equipos de adquisiciones no es solo si un proveedor soporta PQC, sino si la organización controla cuándo y cómo ocurre esa transición.

Con un gestor de contraseñas basado en la nube, la migración de la capa de cifrado de la bóveda ocurre según el calendario del proveedor, a través de infraestructura compartida. Con un despliegue autoalojado, su organización aplica actualizaciones criptográficas (incluidos los algoritmos PQC estandarizados por NIST) en su propio calendario, sin dependencia del ciclo de lanzamiento de un proveedor.

Descubra cómo Passwork gestiona el control de acceso empresarial, el registro de auditoría y el despliegue autoalojado — passwork.pro

Precios y coste total de propiedad

Precios principales

1Password Business tiene un precio de 7,99 $ por usuario al mes (facturado anualmente). El plan Teams está en 4,99 $/usuario/mes. Los precios Enterprise requieren una cotización personalizada.

Los precios de Passwork están estructurados para compradores europeos:

Plan Precio Incluye
Licencia estándar 3 €/usuario/mes Bóveda principal, RBAC, AD/LDAP
Licencia avanzada 4,5 €/usuario/mes Acceso API, auditoría avanzada, SSO
Enterprise Personalizado En las instalaciones, soporte dedicado, SLA

Con 100 usuarios, Passwork licencia estándar cuesta 3.600 €/año frente a 1Password Business con aproximadamente 9.588 $/año. La diferencia aumenta a mayor escala.

TCO más allá de la tarifa de licencia

El despliegue en las instalaciones requiere infraestructura de servidores, mantenimiento y gastos operativos internos. Para organizaciones que ya ejecutan infraestructura en sus instalaciones (la mayoría de las empresas europeas en sectores regulados), el coste marginal de añadir una instancia autoalojada de Passwork es bajo. Para organizaciones sin presencia en instalaciones propias, los gastos de infraestructura son una consideración real y deben evaluarse honestamente antes de firmar.

El cálculo del TCO también necesita incluir el riesgo de cumplimiento. Una brecha que involucre un almacén de credenciales basado en la nube puede activar multas del Artículo 83 del RGPD de hasta 10 millones de euros o el 2% de la facturación anual global por violaciones de los requisitos de seguridad del Artículo 32. Las multas del RGPD han superado acumulativamente los 6.310 millones de euros para 2026. El caso Ambrosetti (85.000 € por contraseñas con hash MD5) ilustra que las autoridades de protección de datos ahora auditan la implementación criptográfica directamente, no solo los plazos de notificación de brechas.


Veredicto: Qué gestor de contraseñas se adapta a una organización con sede en la UE

Elegir un gestor de contraseñas para uso empresarial se reduce a la pregunta: ¿dónde termina su perímetro de cumplimiento? Los equipos cloud-native con pilas de identidad modernas encontrarán un ajuste natural en las integraciones profundas del ecosistema y la experiencia de usuario multiplataforma. Las organizaciones que operan bajo RGPD, NIS2 o DORA enfrentan una restricción diferente — no la usabilidad, sino la jurisdicción.

Elija 1Password Business si:

  • Su equipo está distribuido globalmente y es cloud-native.
  • Prioriza la experiencia de desarrollador y la UX multiplataforma sobre la arquitectura de cumplimiento.
  • Su entorno regulatorio no requiere soberanía de datos estricta.
  • Necesita Extended Access Management o integración profunda con una pila de identidad en la nube moderna.

Elija Passwork si:

  • Su organización está sujeta al RGPD, NIS2 o DORA y necesita demostrar soberanía de datos.
  • Opera en infraestructura crítica, servicios financieros, sanidad o sector público.
  • Necesita integración nativa AD/LDAP dentro de un entorno de identidad existente en sus instalaciones.
  • Se está preparando para la certificación ANSSI o adquisiciones del sector público de la UE.
  • Su equipo de seguridad necesita control total sobre la capa de cifrado, los registros de auditoría y la gestión de claves.

Para empresas europeas en sectores regulados, la arquitectura que responde «sí» a los cinco criterios es autoalojada, en las instalaciones y jurisdiccionalmente limpia.

Passwork ofrece a los equipos de TI europeos una bóveda de credenciales autoalojada, preparada para el RGPD, con registro de auditoría completo, integración AD/LDAP y cifrado de conocimiento cero — todo dentro de su propia infraestructura. Solicite una demostración o explore la guía de despliegue autoalojado — passwork.pro


Preguntas frecuentes

¿Cuál es la diferencia entre Passwork y 1Password?

La diferencia principal es el modelo de despliegue y la jurisdicción. 1Password es un producto SaaS basado en la nube con residencia de datos opcional en la UE, con sede en Canadá. Passwork es un gestor de contraseñas empresarial autoalojado que se ejecuta en su propia infraestructura, otorgando a su organización control legal y técnico completo sobre los datos de credenciales. Passwork también ofrece una opción en la nube, pero su valor principal para las empresas europeas es el despliegue en las instalaciones.

¿Cumple 1Password con el RGPD?

1Password ofrece residencia de datos en la UE: los datos de la bóveda pueden almacenarse en servidores dentro de la UE. Sin embargo, como empresa con sede en Canadá, permanece sujeta a la ley canadiense y a la potencial cooperación con las autoridades estadounidenses. El Artículo 48 del RGPD no reconoce una orden judicial extranjera como base legal para una transferencia, pero esa restricción se aplica a su organización como responsable del tratamiento de datos — no al proveedor que recibe la orden.

¿Cuál es el mejor gestor de contraseñas europeo para el cumplimiento de NIS2?

El Artículo 21 de NIS2 requiere que las organizaciones cubiertas gestionen el riesgo TIC de la cadena de suministro. Un gestor de contraseñas autoalojado elimina por completo el riesgo de proveedores terceros para el almacenamiento de credenciales. Para entidades cubiertas por NIS2, el despliegue en las instalaciones con registro de auditoría completo e integración AD/LDAP es la elección arquitectónicamente defendible. Passwork está construido específicamente para ese requisito.

¿Qué es la soberanía de datos y por qué importa para los gestores de contraseñas?

La soberanía de datos significa que sus datos están sujetos exclusivamente a las leyes de su jurisdicción — no solo físicamente ubicados allí. Para un gestor de contraseñas, significa que ningún gobierno extranjero puede obligar al proveedor a entregar el contenido de su bóveda. El despliegue autoalojado logra esto porque ningún proveedor externo tiene sus datos. El despliegue en la nube con residencia de datos en la UE logra el cumplimiento de ubicación física pero no la soberanía legal completa.

¿Cómo afecta el mandato ANSSI 2027 a la adquisición de gestores de contraseñas?

A partir de 2027, ANSSI no certificará productos de seguridad que carezcan de cifrado resistente a la computación cuántica. Las organizaciones que adquieran para contratos del gobierno francés o sectores regulados necesitarán proveedores con una hoja de ruta creíble de criptografía post-cuántica. Para 2030, ANSSI espera que todas las compras empresariales requieran criptografía segura ante amenazas cuánticas — afectando a cualquier organización europea que use la certificación ANSSI como referencia de adquisiciones.

¿Tiene Passwork certificación ISO 27001?

Sí, Passwork cuenta con la certificación ISO 27001. La arquitectura es de conocimiento cero: AES-256, cifrado del lado del cliente, solo texto cifrado en el servidor. Las claves no tocan el servidor. Para especificaciones de despliegue y detalles de certificación, consulte passwork.pro.

Passwork vs 1Password: ¿Qué gestor de contraseñas es mejor para empresas de la UE?

GDPR, NIS2, ANSSI 2027 — la presión regulatoria sigue aumentando. Comparamos Passwork y 1Password en los criterios que importan a las empresas europeas: soberanía de datos, preparación para auditorías, modelo de implementación y coste total de propiedad real.

Jul 6, 2026 — 13 min read

Choosing a credential manager for a European enterprise in 2026 is a compliance decision as much as it is a product decision. 

Credential abuse remains one of the most common paths into corporate environments. Verizon's 2026 Data Breach Investigations Report confirms that 50% of ransomware victims had a credential or infostealer event within 95 days before the attack. 

At the same time, GDPR enforcement has real teeth. In April 2026, Italy's Garante fined a consulting firm Ambrosetti €85,000 for storing passwords in cleartext and using MD5 hashing, explicitly citing GDPR Article 32 as the basis. NIS2 is no longer a draft: 23 out of 27 EU member states have transposed it into national law, according to the ECSO transposition tracker. 

When evaluating solutions like Passwork and 1Password, factors beyond features start to matter. This article compares both products from that perspective: jurisdiction, data sovereignty, deployment flexibility, audit readiness, long-term compliance with GDPR and NIS2, and total cost of ownership.


Key takeaways

  • Both platforms provide enterprise password management, but they use different architectural approaches. 1Password is a cloud-based service built around its Secret Key security model, while Passwork offers self-hosted deployment with client-side AES-256 encryption.
  • Deployment model determines who controls the infrastructure and who is responsible for it. With a self-hosted deployment, your organization manages the environment. With a SaaS service, the provider operates the infrastructure and remains subject to the laws of its own jurisdiction.
  • Data residency and data sovereignty address different aspects of data governance. Choosing an EU data center determines where your data is stored. It does not, by itself, determine which country's laws may apply to the service provider.
  • GDPR and NIS2 focus on how organizations protect and manage access to credentials. Organizations should be able to demonstrate appropriate technical controls, access management, logging, and audit evidence.
  • At 100 users, Passwork Standard costs €3,600/year versus ~$9,588/year for 1Password Business. Passwork is priced at €3/user/month (Standard) or €4.5/user/month (Advanced). 1Password Business is $7.99/user/month. Enterprise tiers are custom-quoted on both sides.
  • Choose 1Password if your team prioritizes operational convenience and a polished cloud experience over strict data sovereignty. Choose Passwork if your organization is subject to GDPR, NIS2, or DORA and needs to demonstrate that credential data never leaves your own infrastructure.

The compliance battlefield: Data residency vs. data sovereignty

European organizations evaluating password managers need to distinguish between data residency and data sovereignty. Data residency defines where data is stored. Data sovereignty defines which legal system governs it. A cloud-based solution can offer EU data residency while still being subject to non-EU jurisdiction. Self-hosted solutions eliminate that gap by keeping credential data entirely within the organization's own infrastructure, under a single, predictable legal framework.

1Password offers EU data residency: customers can select a European hosting region, and vault data sits on servers inside the EU. It does not, however, by itself resolve all jurisdictional concerns for organizations with strict sovereignty requirements.

What cross-border data access means for cloud vendors

When a cloud-based credential manager is operated by a company outside the EU, the key compliance question is not where the servers are located, but which legal system can compel that company to disclose data.

Any non-EU provider can receive lawful requests from authorities in its home jurisdiction. The applicable law depends on where the provider is incorporated, not where the data is stored.

The U.S. CLOUD Act (2018) is the best-known example. It allows U.S. law enforcement to require U.S.-incorporated providers to produce data stored anywhere in the world.

1Password is not a U.S. company. AgileBits Inc. is incorporated in Canada, so the CLOUD Act does not apply in the same way it does to U.S. providers. Canada, however, participates in international law enforcement cooperation frameworks such as Five Eyes, meaning cross-border legal requests remain a consideration.

GDPR Article 48 states that a foreign court order alone is not a valid legal basis for transferring personal data from the EU. That restriction primarily applies to your organization as the data controller.

Like any cloud-based credential manager operated by a non-EU entity, 1Password introduces a layer of jurisdictional complexity that a self-hosted deployment does not.

How on-premise deployment closes the gap

Passwork's self-hosted model means no third party holds your credential data. Deployed on your own infrastructure within EU jurisdiction, vault contents never leave your environment. No external company can receive a foreign government order for data it doesn't have access to. The laws that govern your data are the laws of the jurisdiction where your servers sit.

Passwork is available as a self-hosted solution and in a sovereign EU cloud, giving you full control over your data and infrastructure. Explore deployment options — passwork.pro


Feature comparison: Passwork vs 1Password

Passwork and 1Password at the Business tier share a common baseline: AES-256 encryption, RBAC, SSO, and developer tooling. The differences emerge at the architectural level. Passwork’s self-hosted deployment gives the organization direct control over encryption keys, audit logs, and the admin perimeter with no dependency on vendor infrastructure or outbound connectivity to external services.

Security architecture

1Password's Secret Key architecture requires a 128-bit key encoded as a 34-character string generated on device setup, combined with the master password, to derive the encryption key. Even if 1Password's servers were compromised, encrypted vaults would be computationally infeasible to crack without the Secret Key. It is a well-designed cloud security model.

Passwork uses client-side, zero-knowledge encryption on a self-hosted instance. Encryption and decryption happen on the client (user device). The server stores only ciphertext. Because you host the platform, you maintain complete control over the application server, encryption keys, and audit logs. This deployment guarantees an isolated environment, free from shared infrastructure, multi-tenant risks, or reliance on vendor key management.

Enterprise administration: RBAC, AD/LDAP, and SSO

Both platforms cover the enterprise administration features IT teams expect.

1Password Business includes SCIM provisioning, SSO integration via Okta and Azure AD, and a mature admin console. Its Extended Access Management product (available as a separately licensed add-on) extends device trust and application access controls beyond the password vault itself.

Passwork provides granular role-based access control (RBAC), native Active Directory and LDAP integration for user provisioning and group sync, and SAML SSO. To simplify management at scale, Passwork separates data access from administrative privileges through two distinct mechanisms:

  • User groups control data access — Administrators assign permissions to vaults and folders at the group level. When users are added to a group, they automatically inherit access to the corresponding passwords and credentials. 
  • Roles define system privileges — Predefined and custom roles manage access to system settings, user directories, and audit logs. This ensures standard users only interact with their assigned vaults, while administrators manage the infrastructure without having access to actual passwords under the Zero-Knowledge model.

For organizations running AD-based identity infrastructure (the majority of European enterprises) the LDAP integration means onboarding and offboarding run through existing directory workflows. Security groups sync automatically, ensuring that vault permissions and administrative roles remain aligned with your central directory.

One practical difference worth noting: because Passwork is self-hosted, the admin console, audit logs, and user directory all sit within your own network perimeter. Administrative operations have no dependency on a vendor's availability SLA.

Feature Comparison
Feature Passwork 1Password Business
SSO SAML 2.0 SSO SAML 2.0 / OIDC (Unlock with SSO)
User provisioning Native AD/LDAP integration SCIM provisioning (requires deploying a self-hosted SCIM Bridge)
Group sync Direct AD / LDAP group sync Synchronization via SCIM Bridge
Access control Granular RBAC (vault, folder, and item-level permissions) Role-based permissions (vault and group-level access)
Device trust / app access controls Extended Access Management (add-on, separate license)
Admin console location Within your own network perimeter Vendor cloud
Audit logs location Local database (within your perimeter) Vendor cloud
Vendor availability dependency None (fully operational offline) Yes (requires connection to 1Password cloud)

DevOps and secrets management

1Password has invested heavily in developer tooling. Its CLI (op), Secrets Automation, and native integrations with GitHub Actions, Kubernetes, and CI/CD pipelines make it a capable secrets manager for cloud-native teams. The developer experience is polished.

Passwork offers a full REST API and CLI tools for DevOps workflows: injecting secrets into pipelines, rotating credentials programmatically, managing API keys and database credentials alongside human passwords in a unified vault.

For teams operating in air-gapped or strictly perimeter-controlled environments, the architectural difference matters. 1Password does offer a self-hosted Connect Server that caches secrets locally and reduces dependency on the 1Password API, but initial setup and periodic synchronisation still require outbound connectivity to 1Password's cloud infrastructure. 

Passwork requires no such dependency at any stage: the entire stack runs inside company’s own perimeter from day one, with no calls to external services. For organisations where outbound traffic to a vendor's cloud is not permitted by policy or architecture, that distinction is a hard requirement.

Feature Passwork 1Password Business
CLI Yes Yes (op)
REST API Yes Yes
Secrets automation Yes Yes
CI/CD integrations Yes Yes
Unified vault (passwords + secrets) Yes Yes
Self-hosted secrets cache Yes (full self-hosted deployment) Connect Server (add-on)
Outbound connectivity to vendor cloud Never required Required for initial setup and periodic sync
Air-gapped environment support Full Partial

Future-proofing: NIS2 and the 2027 post-quantum mandate

NIS2 added a clause vendors would prefer you not notice

NIS2 Article 21 puts the security of your ICT service providers on your risk register. A cloud-based password manager is an ICT service provider. Under NIS2, your organization is responsible for evaluating whether that vendor's security posture (including its legal jurisdiction and incident response obligations) meets your risk threshold.

If a breach at your password manager vendor exposes your credentials, NIS2 incident reporting obligations may be triggered on your side: initial notification within 24 hours, detailed report within 72 hours.

Deploying a self-hosted solution shifts that risk profile. The attack surface is your infrastructure, governed by your security controls, audited by your team. NIS2 supply chain risk assessments become substantially simpler when the "supply chain" for credential storage is internal.

The ANSSI 2027 quantum-safe mandate

France's national cybersecurity agency, ANSSI, announced it will stop certifying security products (including password managers) that lack quantum-resistant encryption starting in 2027. By 2030, ANSSI expects all business procurement to require quantum-safe cryptography. For organizations in France and across the EU, this creates a hard certification deadline within the next 12–18 months.

The relevant question for procurement teams is not only whether a vendor supports PQC, but whether the organization controls when and how that transition happens.

With a cloud-based password manager, the migration of the vault encryption layer occurs on the vendor's schedule, across shared infrastructure. With a self-hosted deployment, your organization applies cryptographic updates (including NIST-standardized PQC algorithms) on your own timeline, without dependency on a vendor's release cycle.

See how Passwork handles enterprise access control, audit logging, and self-hosted deployment — passwork.pro

Pricing and total cost of ownership

Headline pricing

1Password Business is priced at $7.99 per user per month (billed annually). The Teams plan sits at $4.99/user/month. Enterprise pricing requires a custom quote.

Passwork's pricing is structured for European buyers:

Plan Price Key inclusions
Standard €3/user/month Core vault, RBAC, AD/LDAP
Advanced €4.5/user/month API access, advanced audit, SSO
Enterprise Custom On-premise, dedicated support, SLA

At 100 users, Passwork Standard runs €3,600/year versus 1Password Business at approximately $9,588/year. The gap widens at scale.

TCO beyond the license fee

On-premise deployment requires server infrastructure, maintenance, and internal operational overhead. For organizations that already run on-premises infrastructure (most European enterprises in regulated sectors) the marginal cost of adding a self-hosted Passwork instance is low. For organizations with no on-premises footprint, the infrastructure overhead is a real consideration and should be scoped honestly before signing.

The TCO calculation also needs a line for compliance risk. A breach involving a cloud-based credential store can trigger GDPR Article 83 fines of up to €10 million or 2% of global annual turnover for violations of Article 32 security requirements. GDPR fines have cumulatively exceeded €6,31 billion by 2026. The Ambrosetti case (€85,000 for MD5-hashed passwords) illustrates that DPAs are now auditing cryptographic implementation directly, not just breach notification timelines.


Verdict: Which password manager fits EU-based organization

Choosing a password manager for enterprise use comes down to the question: where does your compliance perimeter end? Cloud-native teams with modern identity stacks will find a natural fit in deep ecosystem integrations and cross-platform UX. Organizations operating under GDPR, NIS2, or DORA have an additional, non-negotiable requirement: jurisdictional control over where credentials are stored and processed. 

Choose 1Password Business if:

  • Your team is globally distributed and cloud-native
  • You prioritize developer experience and cross-platform UX above compliance architecture
  • Your regulatory environment does not require strict data sovereignty
  • You need Extended Access Management or deep integration with a modern cloud identity stack

Choose Passwork if:

  • Your organization is subject to GDPR, NIS2, or DORA and needs to demonstrate data sovereignty
  • You operate in critical infrastructure, financial services, healthcare, or the public sector
  • You need AD/LDAP-native integration within an existing on-premises identity environment
  • You are preparing for ANSSI certification or EU public sector procurement
  • Your security team needs full control over the encryption layer, audit logs, and key management

For European enterprises in regulated sectors, the architecture that answers "yes" to all five of those criteria is self-hosted, on-premise, and jurisdictionally clean. 

Passwork gives European IT teams a self-hosted, GDPR-ready credential vault with full audit logging, AD/LDAP integration, and zero-knowledge encryption — all within your own infrastructure. Request a demo or explore the self-hosted deployment guide — passwork.pro


Frequently asked questions

What is the difference between Passwork and 1Password?

The core difference is deployment model and jurisdiction. 1Password is a cloud-based SaaS product with optional EU data residency, headquartered in Canada. Passwork is a self-hosted enterprise password manager that runs on your own infrastructure, giving your organization full legal and technical control over credential data. Passwork also offers a cloud option, but its primary value for European enterprises is on-premise deployment.

Is 1Password GDPR compliant?

1Password offers EU data residency: vault data can be stored on servers within the EU. However, as a Canadian-headquartered company, it remains subject to Canadian law and potential cooperation with US authorities. GDPR Article 48 does not recognize a foreign court order as a lawful transfer basis, but that constraint applies to your organization as data controller.

What is the best European password manager for NIS2 compliance?

NIS2 Article 21 requires covered organizations to manage supply chain ICT risk. A self-hosted password manager eliminates third-party vendor risk for credential storage entirely. For NIS2-covered entities, on-premise deployment with full audit logging and AD/LDAP integration is the architecturally defensible choice. Passwork is built specifically for that requirement.

What is data sovereignty and why does it matter for password managers?

Data sovereignty means your data is subject exclusively to the laws of your jurisdiction, not just physically located there. For a password manager, it means no foreign government can compel the vendor to produce your vault contents. Self-hosted deployment achieves this because no external vendor holds your data. Cloud deployment with EU data residency achieves physical location compliance but not full legal sovereignty.

How does the ANSSI 2027 mandate affect password manager procurement?

From 2027, ANSSI will not certify security products lacking quantum-resistant encryption. Organizations procuring for French government contracts or regulated sectors will need vendors with a credible post-quantum cryptography roadmap. By 2030, ANSSI expects all business purchases to require quantum-safe cryptography, affecting any European organization that uses ANSSI certification as a procurement benchmark.

Is Passwork ISO 27001 certified?

Yes, Passwork holds ISO 27001 certification. The architecture is zero-knowledge: AES-256, client-side encryption, ciphertext-only on the server. Keys don't touch the server. For deployment specs and certification details, see passwork.pro.

Passwork vs 1Password: Which password manager is better for EU enterprise?

GDPR, NIS2, ANSSI 2027 — the regulatory pressure keeps building. We compare Passwork and 1Password on the criteria that matter to European businesses: data sovereignty, audit readiness, deployment model, and real total cost of ownership.

Jul 4, 2026 — 8 min read

Die Vorfälle dieser Woche haben einen gemeinsamen Nenner: Zugangsdaten, die vor Wochen oder Monaten gestohlen wurden, öffnen noch immer Türen. Das Patchen der Schwachstelle, die den Diebstahl ermöglichte, macht bereits gestohlene Daten nicht ungültig. Drei Fälle dieser Woche verdeutlichen dies auf unterschiedliche Weise:

  • FortiBleed bestätigte, dass über 15.000 verifizierte Fortinet-Admin- und VPN-Zugangsdaten (aus Firewall-Konfigurationsdateien in über 100 Ländern gesammelt) bereits im Umlauf sind. Die Botschaft von CISA war eindeutig: Nach einer Kompromittierung ist die Rotation von Zugangsdaten nicht optional, und Software-Updates allein schließen das Zeitfenster nicht.
  • Operation Endgame störte die Infrastruktur hinter Amadey und StealC, zwei der aktivsten Infostealer-Familien. Europol stellte rund 27 Millionen gestohlene Zugangsdaten sicher und beschlagnahmte Hunderte von Servern. Die Infrastruktur ist abgeschaltet; die bereits im Umlauf befindlichen Zugangsdaten sind es nicht.
  • Frankreichs FICOBA-Breach erforderte überhaupt keinen Exploit. Ein Angreifer nutzte einen einzigen kompromittierten Beamten-Account, um über zwei Wochen 3,5 Millionen Bankdatensätze zu durchsuchen: keine Software-Schwachstelle, nur ein nicht überwachtes Zugangsdatum, das aktiv blieb.

Die Woche brachte außerdem einen Supply-Chain-Breach bei LastPass über eine Drittanbieter-SaaS-Plattform, einen aktiv ausgenutzten Cisco-SD-WAN-Zero-Day, der Angreifern über zwei Monate Root-Zugriff und versteckte Admin-Konten ermöglichte, sowie eine mutmaßliche 200-GB-Exfiltration vom Europarat, die von ShinyHunters beansprucht wird. 

Auf Branchenseite sammelte das tschechische Unternehmen Wultra 3,5 Mio. € für Post-Quantum-Authentifizierung, und WALLIX kooperierte mit Inria, um das wachsende Problem der Maschinenidentitäten anzugehen: API-Schlüssel, Token und Servicekonten, die die meisten Organisationen noch immer nicht vollständig inventarisieren können.

Dieser Digest behandelt 8 bedeutende Ereignisse vom 22. bis 29. Juni 2026.


FortiBleed: Über 15.000 Fortinet-Admin-Zugangsdaten in über 100 Ländern gestohlen, CISA fordert sofortige Rotation

Sicherheitsforscher deckten eine groß angelegte Credential-Harvesting-Kampagne namens FortiBleed auf, die mehr als 15.000 verifizierte Administrator- und SSL-VPN-Zugangsdaten für Fortinet-FortiGate-Firewalls in über 100 Ländern offenlegte. Die Zugangsdaten, die über mehrere Jahre durch kompromittierte Firewall-Konfigurationsdateien gesammelt wurden, wurden mit Organisationen wie Siemens, DHL und einem türkischen Rüstungsunternehmen in Verbindung gebracht. 

Warum es wichtig ist: FortiBleed verdeutlicht eine kritische Unterscheidung: Das Patchen einer Schwachstelle beseitigt nicht das Risiko, sobald Zugangsdaten bereits gestohlen wurden. Nach der Offenlegung forderte CISA Organisationen auf, sofort zu handeln:

  • Sitzungen beenden und Zugangsdaten zurücksetzen. Alle aktiven SSL-VPN- und Admin-Sitzungen beenden. Alle Fortinet-VPN- und Admin-Passwörter zurücksetzen, insbesondere auf internetexponierten Systemen.
  • Sichere Speicherung von Zugangsdaten gewährleisten. Die Verwendung von PBKDF2 zur Speicherung von Administrator-Zugangsdaten bestätigen und schwächere Legacy-Hashes gemäß Fortinets Anleitung entfernen.
  • Logs überprüfen. Firewall-, VPN-, Authentifizierungs- und Domain-Controller-Logs auf laterale Bewegungen, verdächtige Konten oder nicht autorisierte Konfigurationsänderungen prüfen.
  • Phishing-resistente MFA aktivieren. Phishing-resistente MFA für alle Remote-Zugriffs- und Admin-Konten erforderlich machen, einschließlich aller externen Gateways und administrativen Schnittstellen.
  • Angriffsfläche reduzieren und Verwaltungszugriff sperren. Die Firewall-Administration vom öffentlichen Internet fernhalten, Verwaltungsschnittstellen auf vertrauenswürdige interne Netzwerke beschränken und unnötige Konten deaktivieren.

Quellen: Dark Reading – 23. Juni 2026


LastPass-Kundensupport-Daten durch Klue-Supply-Chain-Breach gestohlen

LastPass informierte Benutzer, dass Kundensupport- und Vertriebsdaten gestohlen wurden, nachdem Angreifer Klue, eine Drittanbieter-Marktforschungsplattform, kompromittiert hatten. Die Erpressergruppe Icarus missbrauchte Berichten zufolge OAuth-Token, um auf Salesforce-Daten von rund 20 Cybersicherheitsunternehmen zuzugreifen, darunter LastPass, HackerOne und Recorded Future. LastPass erklärte, dass Passwort-Tresore nicht betroffen waren, aber die gestohlenen Daten enthielten Kundennamen, Telefonnummern, E-Mail- und physische Adressen, Support-Fall-Details und Vertriebsunterlagen. 

Warum es wichtig ist: Der Vorfall zeigt, wie SaaS-Integrationen sensible Kundendaten offenlegen können, selbst wenn Kernsysteme sicher bleiben. Für Unternehmen unterstreicht der Vorfall die Notwendigkeit, den SaaS-Zugriff von Drittanbietern zu bewerten, OAuth-Berechtigungen einzuschränken, Integrationsaktivitäten zu überwachen und Lieferanten-Governance als Teil der Identitätssicherheit zu behandeln. Im Rahmen von Regelwerken wie NIS2 werden Lieferantenrisiko und Zugangskontrolle zu Sicherheitsthemen auf Vorstandsebene.

Quellen: TechCrunch – 23. Juni 2026


Operation Endgame: Europol beschlagnahmt Hunderte von Servern, stellt 27 Millionen gestohlene Zugangsdaten aus Amadey- und StealC-Netzwerken sicher

Eine internationale Strafverfolgungsoperation unter Führung von Europol störte die Infrastruktur hinter den Malware-Familien Amadey und StealC, zwei der aktivsten Credential-Stealing-Plattformen. Die Behörden beschlagnahmten Hunderte von Servern und Domains, froren Kryptowährungen der Betreiber ein und stellten rund 27 Millionen gestohlene Zugangsdaten sicher. An der Operation waren mehrere europäische Länder beteiligt, darunter Deutschland, Frankreich, die Niederlande und Großbritannien. Microsoft schätzte, dass diese Malware-Familien während der jüngsten Kampagnen weltweit Hunderttausende von Geräten infizierten.

Warum es wichtig ist: Dies ist eine der größten Störungen des Infostealer-Ökosystems in jüngster Zeit. Organisationen sollten jedoch nicht davon ausgehen, dass das Risiko verschwunden ist. Millionen von gestohlenen Passwörtern und Sitzungstoken sind bereits auf kriminellen Märkten im Umlauf und werden weiterhin Account-Takeover-Angriffe befeuern. 

Quelle: The Hacker News / Europol – 24. Juni 2026


Cisco-SD-WAN-Zero-Day über 2+ Monate ausgenutzt: Angreifer erlangten Root-Zugriff und erstellten versteckte Admin-Konten

Cisco gab bekannt, dass Angreifer eine Zero-Day-Schwachstelle im Catalyst SD-WAN Manager mindestens zwei Monate vor der Offenlegung ausgenutzt hatten. Laut Mandiant erlangten die Angreifer Root-Privilegien, modifizierten Administrator-Zugangsdaten, erstellten versteckte privilegierte Konten und entfernten forensische Beweise, um langfristige Persistenz zu gewährleisten. Cisco veröffentlichte auch Informationen über eine verwandte Authentication-Bypass-Schwachstelle, die dieselbe Plattform betrifft.

Warum es wichtig ist: Viele Organisationen behandeln Netzwerkgeräte als vertrauenswürdige Infrastruktur, doch diese Geräte halten oft hoch privilegierte Zugangsdaten. Einmal kompromittiert, bieten sie Angreifern persistenten administrativen Zugriff über das gesamte Netzwerk. Patching sollte mit kontinuierlicher Überwachung privilegierter Identitäten kombiniert werden.

Quelle: The Hacker News / Google Mandiant – 25. Juni 2026


Kompromittierte Regierungszugangsdaten legen 3,5 Millionen Bankkonten bei französischem FICOBA-Registerbreach offen

Französische Behörden gaben bekannt, dass Angreifer kompromittierte Regierungszugangsdaten nutzten, um auf FICOBA, das nationale Bankkontoverzeichnis des Landes, zuzugreifen. Über einen Zeitraum von etwa zwei Wochen sahen Angreifer Informationen ein, die mit rund 3,5 Millionen Bankkonten verknüpft waren, darunter Namen, Adressen und IBAN-Nummern. Die Behörden berichteten, dass der Angreifer ein bestehendes Beamtenkonto missbrauchte, anstatt eine Software-Schwachstelle auszunutzen.

Warum es wichtig ist: Der Vorfall verdeutlicht, dass kompromittierte Zugangsdaten selbst in Regierungssystemen eine große Bedrohung bleiben. Starke Identitätskontrollen sind genauso wichtig wie Infrastruktursicherheit. Da die NIS2-Durchsetzung in Europa ausgeweitet wird, zeigen Vorfälle wie dieser, warum Identitätssicherheit zu einem Compliance-Thema auf Vorstandsebene wird.

Quelle: Shattered.io – 23. Juni 2026


ShinyHunters beansprucht 200 GB Diebstahl aus HR- und Gehaltsabrechnungssystemen des Europarats

Die Gruppe ShinyHunters übernahm die Verantwortung für den Einbruch in interne Systeme des Europarats und den Diebstahl von mehr als 200 GB an HR- und Gehaltsabrechnungsinformationen. Die Organisation bestätigte einen Cybersicherheitsvorfall, schränkte den Zugriff auf betroffene Systeme ein und leitete eine forensische Untersuchung ein. Zum Zeitpunkt der Veröffentlichung war das volle Ausmaß der Kompromittierung noch nicht bestätigt.

Warum es wichtig ist: Obwohl die Zuschreibung noch untersucht wird, folgt der Vorfall einem wachsenden Muster von Angriffen auf öffentliche Institutionen unter Verwendung gestohlener Zugangsdaten oder Phishing. Europäische Organisationen sollten erwarten, dass Angreifer weiterhin Identitätssysteme und nicht nur die Infrastruktur angreifen. Starke Zugangskontrollen und schnelle Incident Response bleiben sowohl für den öffentlichen als auch für den privaten Sektor unerlässlich.

Quelle: CyPro – 26. Juni 2026


Tschechisches Unternehmen Wultra sammelt 3,5 Mio. € für Post-Quantum-, Phishing-resistente Authentifizierung für europäische Banken

Das tschechische Cybersicherheitsunternehmen Wultra kündigte eine 3,5 Millionen Euro Series-A-Finanzierungsrunde an, um seine Authentifizierungsplattform in Europa zu erweitern. Das Unternehmen entwickelt Phishing-resistente Authentifizierungstechnologien für Banken, Finanzdienstleister und Anbieter digitaler Identität. Die Investition wird die Einführung von Post-Quantum-Kryptographie und Authentifizierungsmethoden unterstützen, die kommende europäische Vorschriften erfüllen sollen, darunter PSD3, PSR und eIDAS 2.0.

Warum es wichtig ist: Europäische Organisationen bereiten sich nicht nur auf heutige Identitätsbedrohungen vor, sondern auch auf zukünftige kryptographische Risiken. Da Regulierungsbehörden zunehmend stärkere Standards für digitale Identität fördern, verschieben sich Investitionen in Richtung Phishing-resistenter und Post-Quantum-Authentifizierung. Die Finanzierung spiegelt die wachsende Nachfrage nach Authentifizierungstechnologien wider, die langfristige Compliance unterstützen und gleichzeitig die Abhängigkeit von Passwörtern und Legacy-MFA-Methoden reduzieren können.

Quelle: The Recursive – 29. Juni 2026


WALLIX und Inria kooperieren zur Sicherung von Maschinenidentitäten

Der europäische IAM/PAM-Anbieter WALLIX und das französische Forschungsinstitut Inria haben eine Partnerschaft zur Entwicklung vertrauenswürdiger KI-Lösungen zur Sicherung von Maschinenidentitäten angekündigt. Die Zusammenarbeit zielt darauf ab, die strukturellen Risiken anzugehen, die durch das schnelle Wachstum von nicht-menschlichen Identitäten entstehen, einschließlich API-Schlüssel, Servicekonten, Token und Zertifikate, die in automatisierten Workflows und CI/CD-Pipelines verwendet werden. 

Warum es wichtig ist: Maschinenidentitäten übersteigen bereits die Zahl menschlicher Identitäten in den meisten Unternehmensumgebungen, und ihre Anzahl wächst mit jedem neuen Microservice und jeder Deployment-Pipeline weiter. Dennoch fehlt vielen Organisationen noch immer eine zentrale Kontrolle über diese Zugangsdaten, die über Konfigurationsdateien, Umgebungsvariablen und Source-Code-Repositories verstreut bleiben. Die wachsende Aufmerksamkeit großer europäischer Cybersicherheitsakteure bestätigt, dass das Management von Maschinenidentitäten zu einer der Top-Prioritäten für die Unternehmenssicherheit wird.

Quelle: Industrial Cyber – 26. Juni 2026


Zusammenfassung dieser Woche

Drei Dinge fallen als konsistente Lücken bei den Vorfällen dieser Woche auf:

  • Credential Rotation wird als Post-Breach-Aufgabe behandelt, nicht als Routine. In allen drei Fällen hätte die Rotation von Zugangsdaten vor oder unmittelbar nach der initialen Kompromittierung den Schaden begrenzt.
  • Der SaaS-Zugriff von Drittanbietern ist weitgehend ungeprüft. Der LastPass-Breach erfolgte über eine Marktforschungsplattform mit OAuth-Zugriff auf Salesforce. Die meisten Sicherheitsteams könnten nicht auf Anhieb jede OAuth-Integration in ihrer Umgebung auflisten.
  • Maschinenidentitäten bleiben die am wenigsten kontrollierte Zugangsdatenklasse. Die WALLIX/Inria-Ankündigung und der Cisco-Fall weisen auf dieselbe Lücke hin: API-Schlüssel, Servicekonten und Token in Pipelines, die niemand aktiv überwacht.

Die guten Nachrichten von Operation Endgame sind real: Die Abschaltung der Amadey- und StealC-Infrastruktur ist bedeutsam. Aber Millionen von zuvor gestohlenen Zugangsdaten sind für Angreifer noch immer verfügbar.

Effektives Zugriffsmanagement begrenzt den Wert gestohlener Zugangsdaten, selbst nachdem der ursprüngliche Angriff vorbei ist. Passwork vereint Passwort- und Secrets-Management in einer einzigen Plattform — mit einer REST API, Python SDK und CLI für Teams, die eine zentrale Kontrolle über Maschinen-Zugangsdaten ohne den Overhead traditioneller PAM-Lösungen benötigen. Kontrollieren Sie Ihre Zugangsdaten, bevor Angreifer es tun.

Cybersicherheit steht niemals still. Wir sind nächste Woche wieder da mit den Vorfällen und Sicherheitstrends, die für Ihre Teams am wichtigsten sind.
Shadow IT in 2026: Risiken, Erkennung und Management
Shadow IT in 2026 umfasst KI-Agenten, verwaiste SaaS-Konten und unüberwachte LLM-Sitzungen — Risiken, die die meisten Organisationen nicht sehen können. Erfahren Sie, was sich geändert hat, was es kostet und wie ein 6-Schritte-Governance-Framework die Lücke schließt.
Secrets-Rotation-Lebenszyklus: Von der Erstellung bis zum Widerruf
Secret Rotation scheitert, wenn sie als geplante Aufgabe statt als Lebenszyklus behandelt wird. Dieser Leitfaden behandelt alle sieben Phasen — von der Erstellung und Zuständigkeit bis zur sicheren Rotation, Notfall-Widerruf und Audit-Nachweisen.
Leitfaden zur Supply-Chain-Sicherheit: Lieferantenrisiken, Vorschriften, Zugangskontrolle in 2026
48 % der Breaches betreffen mittlerweile einen Drittanbieter. Dieser Leitfaden behandelt die Angriffsmuster hinter SolarWinds, MOVEit und XZ Utils — sowie die Zugangskontrollen, Credential-Management-Praktiken und regulatorischen Anforderungen, die sie tatsächlich stoppen.

Wöchentliche Cybersicherheitsnachrichten: Gestohlene Zugangsdaten und die Patch-Lücke

15.000 Fortinet-Zugangsdaten geleakt. 27 Mio. aus Infostealern gerettet. Französisches Melderegister über Regierungs-Account kompromittiert. Europa treibt Post-Quanten-Sicherheit und KI-Identitätsschutz voran. 8 wichtige News und was sie für Ihr Team bedeuten.

Jul 4, 2026 — 9 min read

Los incidentes de esta semana comparten un hilo conductor: credenciales robadas hace semanas o meses siguen abriendo puertas. Parchear la vulnerabilidad que permitió el robo no invalida lo que ya fue sustraído. Tres casos de esta semana ilustran este punto de diferentes maneras:

  • FortiBleed confirmó que más de 15.000 credenciales verificadas de administradores y VPN de Fortinet (recopiladas de archivos de configuración de firewalls en más de 100 países) ya están en circulación. El mensaje de CISA fue inequívoco: la rotación de credenciales no es opcional después de un compromiso, y las actualizaciones de software por sí solas no cierran la ventana.
  • Operation Endgame desmanteló la infraestructura detrás de Amadey y StealC, dos de las familias de infostealers más activas. Europol recuperó alrededor de 27 millones de credenciales robadas y confiscó cientos de servidores. La infraestructura está caída; las credenciales que ya estaban en circulación no lo están.
  • La brecha de FICOBA en Francia no requirió ningún exploit. Un atacante utilizó una única cuenta comprometida de un funcionario público para consultar 3,5 millones de registros bancarios durante dos semanas: ninguna vulnerabilidad de software, solo una credencial no monitoreada que permaneció activa.

La semana también trajo una brecha en la cadena de suministro de LastPass a través de una plataforma SaaS de terceros, un zero-day de Cisco SD-WAN explotado activamente que dio a los atacantes acceso root y cuentas de administrador ocultas durante más de dos meses, y una supuesta exfiltración de 200 GB del Consejo de Europa reclamada por ShinyHunters. 

En el ámbito industrial, la empresa checa Wultra recaudó 3,5 millones de euros para autenticación post-cuántica, y WALLIX se asoció con Inria para abordar el creciente problema de las identidades de máquinas: claves API, tokens y cuentas de servicio que la mayoría de las organizaciones todavía no pueden inventariar completamente.

Este resumen cubre 8 eventos significativos del 22 al 29 de junio de 2026.


FortiBleed: más de 15.000 credenciales de administrador de Fortinet robadas en más de 100 países, CISA exige rotación inmediata

Investigadores de seguridad descubrieron una campaña de recolección de credenciales a gran escala denominada FortiBleed, que expuso más de 15.000 credenciales verificadas de administrador y SSL VPN de firewalls FortiGate de Fortinet en más de 100 países. Las credenciales, recopiladas durante varios años a través de archivos de configuración de firewalls comprometidos, se han vinculado a organizaciones como Siemens, DHL y un contratista de defensa turco. 

Por qué es importante: FortiBleed destaca una distinción crítica: parchear una vulnerabilidad no elimina el riesgo una vez que las credenciales ya han sido robadas. Tras la divulgación, CISA instó a las organizaciones a actuar de inmediato:

  • Terminar sesiones y restablecer credenciales. Finalice todas las sesiones activas de SSL VPN y administración. Restablezca todas las contraseñas de VPN y administrador de Fortinet, especialmente en sistemas expuestos a internet.
  • Garantizar el almacenamiento seguro de credenciales. Confirme el uso de PBKDF2 para almacenar credenciales de administrador y elimine los hashes heredados más débiles según las directrices de Fortinet.
  • Revisar registros. Verifique los registros de firewall, VPN, autenticación y controlador de dominio en busca de movimiento lateral, cuentas sospechosas o cambios de configuración no autorizados.
  • Habilitar MFA resistente al phishing. Exija MFA resistente al phishing en todas las cuentas de acceso remoto y administración, incluyendo todas las puertas de enlace externas e interfaces administrativas.
  • Reducir la superficie de ataque y restringir el acceso de gestión. Mantenga la administración del firewall fuera de internet público, restrinja las interfaces de gestión a redes internas de confianza y deshabilite las cuentas innecesarias.

Fuentes: Dark Reading – 23 jun 2026


Datos de soporte al cliente de LastPass robados a través de la brecha en la cadena de suministro de Klue

LastPass notificó a los usuarios que se robaron datos de soporte al cliente y ventas después de que los atacantes comprometieran Klue, una plataforma de investigación de mercado de terceros. Según los informes, el grupo de extorsión Icarus abusó de tokens OAuth para acceder a datos de Salesforce de alrededor de 20 empresas de ciberseguridad, incluyendo LastPass, HackerOne y Recorded Future. LastPass declaró que las bóvedas de contraseñas no se vieron afectadas, pero los datos robados incluían nombres de clientes, números de teléfono, direcciones de correo electrónico y físicas, detalles de casos de soporte y registros de ventas. 

Por qué es importante: El incidente muestra cómo las integraciones SaaS pueden exponer datos sensibles de clientes incluso cuando los sistemas principales permanecen seguros. Para las empresas, el incidente refuerza la necesidad de evaluar el acceso SaaS de terceros, restringir los permisos OAuth, monitorear la actividad de integración y tratar la gobernanza de proveedores como parte de la seguridad de identidad. Bajo marcos como NIS2, el riesgo de proveedores y el control de acceso se están convirtiendo en preocupaciones de seguridad a nivel de dirección.

Fuentes: TechCrunch – 23 jun 2026


Operation Endgame: Europol confisca cientos de servidores y recupera 27 millones de credenciales robadas de las redes Amadey y StealC

Una operación policial internacional liderada por Europol desmanteló la infraestructura detrás de las familias de malware Amadey y StealC, dos de las plataformas de robo de credenciales más activas. Las autoridades confiscaron cientos de servidores y dominios, congelaron criptomonedas vinculadas a los operadores y recuperaron alrededor de 27 millones de credenciales robadas. La operación involucró a varios países europeos, incluyendo Alemania, Francia, Países Bajos y Reino Unido. Microsoft estimó que estas familias de malware infectaron cientos de miles de dispositivos en todo el mundo durante las campañas recientes.

Por qué es importante: Esta es una de las mayores disrupciones recientes del ecosistema de infostealers. Sin embargo, las organizaciones no deben asumir que el riesgo ha desaparecido. Millones de contraseñas y tokens de sesión robados ya están circulando en mercados criminales y seguirán alimentando ataques de apropiación de cuentas. 

Fuente: The Hacker News / Europol – 24 jun 2026


Zero-day de Cisco SD-WAN explotado durante más de 2 meses: los atacantes obtuvieron acceso root y crearon cuentas de administrador ocultas

Cisco reveló que los atacantes habían estado explotando una vulnerabilidad zero-day en Catalyst SD-WAN Manager durante al menos dos meses antes de la divulgación. Según Mandiant, los atacantes obtuvieron privilegios root, modificaron credenciales de administrador, crearon cuentas privilegiadas ocultas y eliminaron evidencia forense para mantener persistencia a largo plazo. Cisco también publicó información sobre una vulnerabilidad relacionada de elusión de autenticación que afecta a la misma plataforma.

Por qué es importante: Muchas organizaciones tratan los dispositivos de red como infraestructura de confianza, sin embargo, estos dispositivos a menudo contienen credenciales altamente privilegiadas. Una vez comprometidos, proporcionan a los atacantes acceso administrativo persistente a través de la red. El parcheo debe ir acompañado de monitoreo continuo de identidades privilegiadas.

Fuente: The Hacker News / Google Mandiant – 25 jun 2026


Credenciales gubernamentales comprometidas exponen 3,5 millones de cuentas bancarias en la brecha del registro FICOBA en Francia

Las autoridades francesas revelaron que los atacantes utilizaron credenciales gubernamentales comprometidas para acceder a FICOBA, el registro nacional de cuentas bancarias del país. Durante un período de aproximadamente dos semanas, los atacantes visualizaron información vinculada a alrededor de 3,5 millones de cuentas bancarias, incluyendo nombres, direcciones y números IBAN. Las autoridades informaron que el atacante abusó de una cuenta existente de un funcionario público en lugar de explotar una vulnerabilidad de software.

Por qué es importante: El incidente destaca que las credenciales comprometidas siguen siendo una amenaza importante incluso en sistemas gubernamentales. Los controles de identidad sólidos son tan importantes como la seguridad de la infraestructura. A medida que la aplicación de NIS2 se expande por Europa, incidentes como este muestran por qué la seguridad de identidad se está convirtiendo en un tema de cumplimiento a nivel de dirección.

Fuente: Shattered.io – 23 jun 2026


ShinyHunters afirma haber robado 200 GB de los sistemas de RRHH y nóminas del Consejo de Europa

El grupo ShinyHunters se atribuyó la responsabilidad de vulnerar los sistemas internos del Consejo de Europa y robar más de 200 GB de información de RRHH y nóminas. La organización confirmó un incidente de ciberseguridad, restringió el acceso a los sistemas afectados e inició una investigación forense. Al momento de la publicación, no se había confirmado el alcance completo del compromiso.

Por qué es importante: Aunque la atribución sigue bajo investigación, el incidente sigue un patrón creciente de ataques contra instituciones públicas utilizando credenciales robadas o phishing. Las organizaciones europeas deben esperar que los atacantes continúen atacando sistemas de identidad en lugar de solo la infraestructura. Los controles de acceso sólidos y la respuesta rápida a incidentes siguen siendo esenciales tanto para el sector público como para el privado.

Fuente: CyPro – 26 jun 2026


La empresa checa Wultra recauda 3,5 millones de euros para desarrollar autenticación post-cuántica resistente al phishing para bancos europeos

La empresa checa de ciberseguridad Wultra anunció una ronda de financiación Serie A de 3,5 millones de euros para expandir su plataforma de autenticación por toda Europa. La empresa desarrolla tecnologías de autenticación resistentes al phishing para bancos, servicios financieros y proveedores de identidad digital. La inversión apoyará la adopción de criptografía post-cuántica y métodos de autenticación diseñados para cumplir con las próximas regulaciones europeas, incluyendo PSD3, PSR y eIDAS 2.0.

Por qué es importante: Las organizaciones europeas se están preparando no solo para las amenazas de identidad actuales, sino también para los riesgos criptográficos futuros. A medida que los reguladores promueven cada vez más estándares de identidad digital más sólidos, las inversiones se están desplazando hacia la autenticación resistente al phishing y post-cuántica. La financiación refleja una demanda creciente de tecnologías de autenticación que puedan respaldar el cumplimiento a largo plazo mientras reducen la dependencia de las contraseñas y los métodos MFA heredados.

Fuente: The Recursive – 29 jun 2026


WALLIX e Inria se asocian para proteger las identidades de máquinas

El proveedor europeo de IAM/PAM WALLIX y el instituto de investigación francés Inria han anunciado una asociación para desarrollar soluciones de IA de confianza para proteger las identidades de máquinas. La colaboración tiene como objetivo abordar los riesgos estructurales creados por el rápido crecimiento de las identidades no humanas, incluyendo claves API, cuentas de servicio, tokens y certificados utilizados en flujos de trabajo automatizados y pipelines CI/CD. 

Por qué es importante: Las identidades de máquinas ya superan en número a las identidades humanas en la mayoría de los entornos empresariales, y sus números continúan creciendo con cada nuevo microservicio y pipeline de despliegue. Sin embargo, muchas organizaciones todavía carecen de control centralizado sobre estas credenciales, que permanecen dispersas en archivos de configuración, variables de entorno y repositorios de código fuente. La creciente atención de los principales actores europeos de ciberseguridad confirma que la gestión de identidades de máquinas se está convirtiendo en una de las principales prioridades para la seguridad empresarial.

Fuente: Industrial Cyber – 26 jun 2026


Resumen de esta semana

Tres aspectos destacan como brechas consistentes en los incidentes de esta semana:

  • La rotación de credenciales se trata como una tarea posterior a la brecha, no como una rutina. En los tres casos, rotar las credenciales antes o inmediatamente después del compromiso inicial habría contenido el daño.
  • El acceso SaaS de terceros está en gran medida sin auditar. La brecha de LastPass llegó a través de una plataforma de investigación de mercado con acceso OAuth a Salesforce. La mayoría de los equipos de seguridad no podrían enumerar cada integración OAuth en su entorno en este momento.
  • Las identidades de máquinas siguen siendo la clase de credenciales menos gobernada. El anuncio de WALLIX/Inria y el caso de Cisco apuntan a la misma brecha: claves API, cuentas de servicio y tokens en pipelines que nadie está monitoreando activamente.

Las buenas noticias de Operation Endgame son reales: desmantelar la infraestructura de Amadey y StealC importa. Pero millones de credenciales robadas previamente todavía están disponibles para los atacantes.

La gestión de acceso eficaz limita el valor de las credenciales robadas, incluso después de que el ataque original haya terminado. Passwork reúne la gestión de contraseñas y secretos en una única plataforma — con REST API, Python SDK y CLI para equipos que necesitan control centralizado sobre las credenciales de máquinas sin la sobrecarga del PAM tradicional. Controle sus credenciales antes de que lo hagan los atacantes.

La ciberseguridad nunca se detiene. Volveremos la próxima semana con los incidentes y tendencias de seguridad que más importan para sus equipos.
Shadow IT en 2026: Riesgos, detección y cómo gestionarlo
El Shadow IT en 2026 abarca agentes de IA, cuentas SaaS huérfanas y sesiones LLM no monitoreadas — riesgos que la mayoría de las organizaciones no pueden ver. Descubra qué ha cambiado, cuánto cuesta y cómo un marco de gobernanza de 6 pasos cierra la brecha.
Ciclo de vida de la rotación de secretos: De la creación a la revocación
La rotación de secretos falla cuando se trata como una tarea programada en lugar de un ciclo de vida. Esta guía cubre las siete etapas — desde la creación y la propiedad hasta la rotación segura, la revocación de emergencia y la evidencia de auditoría.
Guía de seguridad de la cadena de suministro: Riesgos de proveedores, regulaciones y control de acceso en 2026
El 48% de las brechas ahora involucran a un tercero. Esta guía cubre los patrones de ataque detrás de SolarWinds, MOVEit y XZ Utils — y los controles de acceso, prácticas de gestión de credenciales y requisitos regulatorios que realmente los detienen.

Noticias semanales de ciberseguridad: credenciales robadas y la brecha de parches

15.000 credenciales de Fortinet expuestas. 27 millones recuperadas de infostealers. Registro nacional francés vulnerado mediante una cuenta del gobierno. Europa avanza en autenticación poscuántica e identidad con IA. 8 historias clave y su impacto en su equipo.

Jul 4, 2026 — 8 min read

This week's incidents share a single thread: credentials stolen weeks or months ago are still opening doors. Patching the vulnerability that enabled the theft doesn't invalidate what was already taken. Three cases from this week make that point in different ways:

  • FortiBleed confirmed that over 15,000 verified Fortinet admin and VPN credentials (collected from firewall config files across 100+ countries) are already in circulation. CISA's message was unambiguous: rotating credentials is not optional after a compromise, and software updates alone don't close the window.
  • Operation Endgame disrupted the infrastructure behind Amadey and StealC, two of the most active infostealer families. Europol recovered around 27 million stolen credentials and seized hundreds of servers. The infrastructure is down; the credentials already in circulation are not.
  • France's FICOBA breach required no exploit at all. An attacker used a single compromised civil servant account to browse 3.5 million bank records over two weeks: no software vulnerability, just an unmonitored credential left active.

The week also brought a supply chain breach at LastPass through a third-party SaaS platform, an actively exploited Cisco SD-WAN zero-day that gave attackers root access and hidden admin accounts for over two months, and a suspected 200 GB exfiltration from the Council of Europe claimed by ShinyHunters. 

On the industry side, Czech firm Wultra raised €3.5M for post-quantum authentication, and WALLIX partnered with Inria to address the growing machine identity problem: API keys, tokens, and service accounts that most organizations still can't fully inventory.

This digest covers 8 significant events from 22 to 29 June 2026.


FortiBleed: 15,000+ Fortinet admin credentials stolen across 100+ countries, CISA demands immediate rotation

Security researchers uncovered a large-scale credential harvesting campaign dubbed FortiBleed, which exposed more than 15,000 verified administrator and SSL VPN credentials for Fortinet FortiGate firewalls across 100+ countries. The credentials, collected over several years through compromised firewall configuration files, have been linked to organizations including Siemens, DHL, and a Turkish defense contractor. 

Why it matters: FortiBleed highlights a critical distinction: patching a vulnerability does not eliminate the risk once credentials have already been stolen. Following the disclosure, CISA urged organizations to act immediately:

  • Terminate sessions and reset credentials. End all active SSL VPN and admin sessions. Reset all Fortinet VPN and admin passwords, especially on internet-facing systems.
  • Ensure secure credential storage. Confirm use of PBKDF2 for storing administrator credentials and remove weaker legacy hashes per Fortinet's guidance.
  • Review logs. Check firewall, VPN, authentication, and domain controller logs for lateral movement, suspicious accounts, or unauthorized configuration changes.
  • Enable phishing-resistant MFA. Require phishing-resistant MFA on all remote access and admin accounts, including all external gateways and administrative interfaces.
  • Reduce the attack surface and lock down management access. Keep firewall administration off the public internet, restrict management interfaces to trusted internal networks, and disable unnecessary accounts.

Sources: Dark Reading – 23 Jun 2026


LastPass customer support data stolen through Klue supply chain breach

LastPass notified users that customer support and sales data was stolen after attackers compromised Klue, a third-party market research platform. The extortion group Icarus reportedly abused OAuth tokens to access Salesforce data from around 20 cybersecurity companies, including LastPass, HackerOne, and Recorded Future. LastPass said password vaults were not affected, but the stolen data included customer names, phone numbers, email and physical addresses, support case details, and sales records. 

Why it matters: The incident shows how SaaS integrations can expose sensitive customer data even when core systems remain secure. For enterprises, the incident reinforces the need to assess third-party SaaS access, restrict OAuth permissions, monitor integration activity, and treat supplier governance as part of identity security. Under frameworks like NIS2, vendor risk and access control are becoming board-level security concerns.

Sources: TechCrunch – 23 Jun 2026


Operation Endgame: Europol seizes hundreds of servers, recovers 27 million stolen credentials from Amadey and StealC networks

An international law enforcement operation led by Europol disrupted the infrastructure behind the Amadey and StealC malware families, two of the most active credential-stealing platforms. Authorities seized hundreds of servers and domains, froze cryptocurrency linked to the operators, and recovered around 27 million stolen credentials. The operation involved several European countries, including Germany, France, the Netherlands and the UK. Microsoft estimated that these malware families infected hundreds of thousands of devices worldwide during recent campaigns.

Why it matters: This is one of the largest recent disruptions of the infostealer ecosystem. However, organizations should not assume the risk has disappeared. Millions of stolen passwords and session tokens are already circulating in criminal markets and will continue to fuel account takeover attacks. 

Source: The Hacker News / Europol – 24 Jun 2026


Cisco SD-WAN zero-day exploited for 2+ months: attackers gained root access and created hidden admin accounts

Cisco disclosed that attackers had been exploiting a zero-day vulnerability in Catalyst SD-WAN Manager for at least two months before disclosure. According to Mandiant, attackers obtained root privileges, modified administrator credentials, created hidden privileged accounts and removed forensic evidence to maintain long-term persistence. Cisco also released information about a related authentication bypass vulnerability affecting the same platform.

Why it matters: Many organizations treat network appliances as trusted infrastructure, yet these devices often hold highly privileged credentials. Once compromised, they provide attackers with persistent administrative access across the network. Patching should be paired with continuous monitoring of privileged identities.

Source: The Hacker News / Google Mandiant – 25 Jun 2026


Compromised government credentials expose 3.5 million bank accounts in French FICOBA registry breach

French authorities disclosed that attackers used compromised government credentials to access FICOBA, the country's national bank account registry. Over a period of approximately two weeks, attackers viewed information linked to around 3.5 million bank accounts, including names, addresses and IBAN numbers. Authorities reported that the attacker abused an existing civil servant account rather than exploiting a software vulnerability.

Why it matters: The incident highlights that compromised credentials remain a major threat even in government systems. Strong identity controls are just as important as infrastructure security. As NIS2 enforcement expands across Europe, incidents like this show why identity security is becoming a board-level compliance issue.

Source: Shattered.io – 23 Jun 2026


ShinyHunters claims 200 GB stolen from Council of Europe HR and payroll systems

The ShinyHunters group claimed responsibility for breaching internal systems belonging to the Council of Europe and stealing more than 200 GB of HR and payroll information. The organization confirmed a cybersecurity incident, restricted access to affected systems and launched a forensic investigation. At the time of publication, the full scope of the compromise had not been confirmed.

Why it matters: Although attribution remains under investigation, the incident follows a growing pattern of attacks against public institutions using stolen credentials or phishing. European organizations should expect attackers to continue targeting identity systems rather than infrastructure alone. Strong access controls and rapid incident response remain essential for both public and private sectors.

Source: CyPro – 26 Jun 2026


Czech firm Wultra raises €3.5M to build post-quantum, phishing-resistant authentication for European banks

Czech cybersecurity company Wultra announced a €3.5 million Series A funding round to expand its authentication platform across Europe. The company develops phishing-resistant authentication technologies for banks, financial services and digital identity providers. The investment will support the adoption of post-quantum cryptography and authentication methods designed to meet upcoming European regulations, including PSD3, PSR and eIDAS 2.0.

Why it matters: European organizations are preparing not only for today's identity threats but also for future cryptographic risks. As regulators increasingly promote stronger digital identity standards, investments are shifting toward phishing-resistant and post-quantum authentication. The funding reflects growing demand for authentication technologies that can support long-term compliance while reducing dependence on passwords and legacy MFA methods.

Source: The Recursive – 29 Jun 2026


WALLIX and Inria partner to secure machine identities

European IAM/PAM vendor WALLIX and the French research institute Inria have announced a partnership to develop trusted AI solutions for securing machine identities. The collaboration aims to address the structural risks created by the rapid growth of non-human identities, including API keys, service accounts, tokens, and certificates used in automated workflows and CI/CD pipelines. 

Why it matters: Machine identities already outnumber human identities in most enterprise environments, and their numbers continue to grow with every new microservice and deployment pipeline. Yet many organizations still lack centralized control over these credentials, which remain scattered across configuration files, environment variables, and source code repositories. The growing attention from major European cybersecurity players confirms that machine identity management is becoming one of the top priorities for enterprise security.

Source: Industrial Cyber – 26 Jun 2026


This week's recap

Three things stand out as consistent gaps across this week's incidents:

  • Credential rotation is treated as a post-breach task, not a routine one. In all three cases, rotating credentials before or immediately after the initial compromise would have contained the damage.
  • Third-party SaaS access is largely unaudited. The LastPass breach came through a market research platform with OAuth access to Salesforce. Most security teams couldn't list every OAuth integration in their environment right now.
  • Machine identities remain the least-governed credential class. The WALLIX/Inria announcement and the Cisco case both point to the same gap: API keys, service accounts, and tokens in pipelines that no one is actively monitoring.

The good news from Operation Endgame is real: taking down Amadey and StealC infrastructure matters. But millions of previously stolen credentials are still available to attackers.

Effective access management limits the value of stolen credentials, even after the original attack is over. Passwork brings password and secrets management into a single platform — with a REST API, Python SDK, and CLI for teams that need centralized control over machine credentials without the overhead of traditional PAM. Control your credentials before attackers do.

Cybersecurity never stands still. We'll be back next week with the incidents and security trends that matter most for your teams.
Shadow IT in 2026: Risks, detection, and how to manage it
Shadow IT in 2026 spans AI agents, orphaned SaaS accounts, and unmonitored LLM sessions — risks most organizations can’t see. Learn what’s changed, what it costs, and how a 6-step governance framework closes the gap.
Secrets rotation lifecycle: From creation to revocation
Secret rotation fails when it’s treated as a scheduled task rather than a lifecycle. This guide covers all seven stages — from creation and ownership to safe rotation, emergency revocation, and audit evidence.
Supply chain security guide: Vendor risks, regulations, access control in 2026
48% of breaches now involve a third party. This guide covers the attack patterns behind SolarWinds, MOVEit, and XZ Utils — and the access controls, credential management practices, and regulatory requirements that actually stop them.

Weekly cybersecurity news: Stolen credentials and the patch gap

15,000 Fortinet credentials exposed. 27 million recovered from dismantled infostealers. A French national registry breached through one government account. Meanwhile, Europe is advancing post-quantum authentication and AI-driven identity security. 8 key stories and what they mean for your team.

Jul 3, 2026 — 15 min read
Illustration eines Laborexperiments auf blauem Hintergrund. Ein Erlenmeyerkolben mit blauer Flüssigkeit wird über einer kleinen Flamme erhitzt und ist über einen Schlauch mit einem Reagenzglas verbunden, das weiße Tabletten enthält. Über jedem Gefäß befindet sich ein Passwortfeld mit Sternchen — der Kolben zeigt blaue Sternchen und das Reagenzglas grüne Sternchen — was auf Passworttransformation, Verschlüsselung oder Sicherheitsverarbeitung hindeutet.

Jahrzehntelang lautete die Antwort auf „Wie erstelle ich ein starkes Passwort?": Fügen Sie einen Großbuchstaben hinzu, setzen Sie ein Symbol ans Ende, hängen Sie eine Zahl an. Das Problem ist, dass Menschen unter Regeln vorhersehbar sind. Der Großbuchstabe steht am Anfang. Symbol und Zahl stehen am Ende. Cracking-Tools wissen das, weil sie mit Milliarden echter Passwörter von Menschen trainiert wurden, die genau demselben Instinkt folgten.

Sowohl das menschliche Gedächtnis als auch Cracking-Algorithmen arbeiten mit Mustern. Das ist der Konflikt, und er verschwindet nicht, indem Sie @ an den Namen Ihres Hundes anhängen. Dieser Leitfaden erklärt die Mechanismen, die einzige Ausnahme und wie ein nachhaltiges Zugangsdatensystem tatsächlich aussieht.


Wichtigste Erkenntnisse

  • Je einfacher ein Passwort zu merken ist, desto einfacher ist es zu knacken. Merkbarkeit und Sicherheit ziehen in entgegengesetzte Richtungen. Diese Spannung ist strukturell bedingt: Sie ergibt sich aus der Funktionsweise des menschlichen Gedächtnisses.
  • Symbolersetzungen und Komplexitätsregeln erhöhen die Sicherheit nicht wesentlich. Moderne Passwort-Cracking-Algorithmen sind speziell auf diese vorhersehbaren menschlichen Muster trainiert, sodass Angreifer sie mit optimierten Brute-Force-Angriffen umgehen können.
  • Die aktuellen NIST SP 800-63B-Richtlinien streichen offiziell verpflichtende Komplexitätsregeln und 90-Tage-Rotationen und legen ein neues empfohlenes Minimum von 15 Zeichen fest.
  • Der einzige Passworttyp, der sowohl merkbar als auch kryptografisch stark ist, ist eine Diceware-Passphrase: zufällige Wörter, die durch Würfel gewählt werden, nicht von Ihnen.
  • Sie müssen sich genau ein Passwort merken: die Master-Passphrase, die Ihren Passwort-Manager entsperrt. Alle anderen Zugangsdaten sollten zufällig generiert und im Tresor gespeichert werden.

Was ist ein starkes Passwort

Ein starkes Passwort ist ein Zugangsdatum, das sowohl automatisierten Rateversuchen als auch gezielten Angriffen standhält. NIST SP 800-63B legt das Minimum auf 8 Zeichen fest, empfiehlt Systemen, bis zu 64 Zeichen zu akzeptieren, und streicht verpflichtende Komplexitätsregeln vollständig zugunsten von Länge und Einzigartigkeit. Der praktische Arbeitsstandard für die meisten Sicherheitsteams liegt bei 12-16 zufällig generierten Zeichen mit einer Entropie über 75 Bit.

Vier Parameter definieren, ob ein Passwort diese Baseline erfüllt:

  • Länge. Die einzelne effektivste Variable. Jedes zusätzliche Zeichen multipliziert den Suchraum exponentiell. Bei 12 Zeichen erfordert eine vollständig zufällige alphanumerische Zeichenkette Milliarden von Jahren zum Brute-Forcen bei aktuellen Hardware-Geschwindigkeiten. Bei 8 Zeichen schrumpft dieses Fenster auf Stunden.
  • Zufälligkeit. Von Menschen gewählte Passwörter gruppieren sich um vorhersehbare Muster: Namen, Daten, Wörterbuchwörter mit Ersetzungen. Ein Passwortgenerator eliminiert diese Gruppierung vollständig. Wenn Sie es gewählt haben, ist es wahrscheinlich schwächer, als es aussieht.
  • Einzigartigkeit. Ein Zugangsdatum pro Account. Ein einzelnes kompromittiertes Passwort gewährt Zugriff auf jedes System, in dem es vorkommt. Wiederverwendung verwandelt einen isolierten Breach in eine Gelegenheit zur lateralen Bewegung.
  • Kein Ablauf ohne Grund. NIST SP 800-63B lehnt verpflichtende periodische Rotation ausdrücklich ab. Erzwungene Rotation produziert vorhersehbare Inkremente (Password1 → Password2) und trainiert Benutzer, schwächere Basispasswörter zu wählen. Ändern Sie ein Zugangsdatum, wenn es Hinweise auf eine Kompromittierung gibt.

Das Merkbarkeits-Paradoxon: Warum Ihr Gehirn eine Schwachstelle ist

Jede Eigenschaft, die ein Passwort leichter merkbar macht, macht es auch leichter zu erraten. Das menschliche Gedächtnis kodiert Informationen durch Muster, Assoziationen und Bedeutung. Ein Passwort, das in Ihrem Gedächtnis haften bleibt, tut dies, weil es mit etwas verbunden ist, das Sie bereits kennen: ein Wort, ein Datum, ein Name, eine Tastaturform. Dieselben Verbindungen sind genau das, was Cracking-Tools ausnutzen.

PassGAN (Generative Adversarial Network für Passwort-Cracking) und ähnliche Tools sind mit Milliarden geleakter Zugangsdaten trainiert. Sie probieren nicht aaaaaaa vor p@ssword. Sie probieren die Dinge, die Menschen tatsächlich wählen, in der Reihenfolge, in der Menschen sie tatsächlich wählen. Das Ersetzen von @ für a in password ergibt p@ssword, das PassGAN innerhalb der ersten paar Tausend Versuche in weniger als einem Bruchteil einer Sekunde generiert. Den ersten Buchstaben großzuschreiben und 1 am Ende hinzuzufügen, sind Muster, die das Modell millionenfach gesehen hat.

💡
Laut der Home Security Heroes KI-Analyse können die meisten gängigen Passwörter in Sekunden geknackt werden, weil KI-Tools die menschliche Psychologie im großen Maßstab modellieren, anstatt zufällig zu raten

Länge und Zeichensatz sind beide wichtig, aber nicht gleich wichtig. Die Passwort-Tabelle 2025 von Hive Systems, getestet gegen 12 × RTX 5090 GPUs mit bcrypt bei Arbeitsfaktor 10, zeigt, dass ein 8-Zeichen-Passwort, das nur Kleinbuchstaben verwendet, in drei Wochen fällt. Fügen Sie Großbuchstaben, Zahlen und Symbole hinzu, und diese Zahl erreicht 164 Jahre gegen dieselbe Hardware. Ein 12-Zeichen-Passwort mit demselben vollständigen gemischten Zeichensatz bringt die Tabelle in Jahrhunderte.

Passwort-Cracking-Tabelle von Hive Systems
Quelle: Hive Systems

Die Tabelle wird jährlich aktualisiert, um aktuelle Consumer-GPU-Hardware widerzuspiegeln. Die Verschiebung von der Ausgabe 2024 zu 2025 spiegelt sowohl schnellere Hardware als auch realistischere Hash-Stärke-Annahmen wider, die aus dem gewonnen wurden, was Hive Systems in tatsächlichen Breach-Daten beobachtete.


Warum traditionelle Passwort-Ratschläge tot sind

Die alten Komplexitätsregeln (acht Zeichen, ein Großbuchstabe, eine Zahl, ein Symbol) scheiterten, weil sie sich bezüglich des menschlichen Verhaltens unter Einschränkungen irrten. Während das Merkbarkeits-Paradoxon ein kognitives Versagen beschreibt, produzierten verpflichtende Komplexitätsregeln ein Richtlinienversagen zusätzlich dazu.

Jahrelang war der dominierende Cracking-Ansatz der Wörterbuchangriff: automatisierte Tools, die bekannte Wörter und gängige Ersetzungen durchgingen. Sicherheitsteams reagierten mit verpflichtender Komplexität. Das Problem ist, dass Menschen unter Komplexitätsdruck vorhersehbar sind. Wenn sie aufgefordert werden, ein Symbol hinzuzufügen, fügen die meisten Menschen es am Ende hinzu. Wenn sie aufgefordert werden, einen Buchstaben zu ersetzen, wählen die meisten dieselben Ersetzungen. Die Regeln, die darauf ausgelegt waren, die Unvorhersehbarkeit zu erhöhen, produzierten eine neue Schicht vorhersehbaren Verhaltens.

💡
NIST erkannte dies in SP 800-63B: Die Richtlinie strich ausdrücklich verpflichtende periodische Zurücksetzungen und Komplexitätsregeln unter Verweis auf genau diesen Fehlermodus

Das andere Versagen alter Ratschläge war die 90-Tage-Rotationsrichtlinie. Erzwungene Zurücksetzungen produzieren Summer2025! gefolgt von Fall2025!. Der DBIR 2026 von Verizon, der über 22.000 bestätigte Breaches in 145 Ländern analysierte, stellte fest, dass die Ausnutzung von Schwachstellen den Diebstahl von Zugangsdaten als primären Breach-Einstiegspunkt überholt hat (31 %). Zugangsdaten-Missbrauch liegt bei 13 % als initialer Zugangsvektor, aber diese Zahl betrachtet nur die erste Aktion. Der DBIR stellte fest, dass Zugangsdaten-Missbrauch in 39 % aller Breaches auftaucht, wenn er über die gesamte Angriffskette gemessen wird — damit ist er die am weitesten verbreitete Technik im Datensatz.

Länge ist die primäre Verteidigung. Eine 15-Zeichen-Passphrase aus zufälligen Wörtern ist um Größenordnungen stärker als eine 8-Zeichen-Zeichenkette aus Symbolen, und ein Mensch kann sie tatsächlich behalten.


Der neue Standard: NIST SP 800-63B Rev. 4 Richtlinien

NIST SP 800-63B Rev. 4 (2025) legt die aktuelle Baseline für Passwortsicherheit fest. Wenn ein Passwort der einzige Authentifizierungsfaktor ist, müssen Systeme ein Minimum von 8 Zeichen verlangen und sollten mindestens 15 Zeichen verlangen. Verpflichtende Komplexitätsregeln (erzwungene Symbole, Zahlen, Groß-/Kleinschreibung) werden ausdrücklich gestrichen, ebenso der 90-Tage-Ablaufzyklus. Die Überprüfung neuer Passwörter gegen bekannte Breach-Zugangsdatenlisten ist jetzt erforderlich, nicht optional.

Die vollständige Richtlinienänderung sieht so aus:

Regel Alte Richtlinie (Rev. 3) Neue Richtlinie (Rev. 4)
Mindestlänge 8 Zeichen 8 Zeichen erforderlich; 15 empfohlen
Komplexitätsanforderungen Verpflichtend (Symbole, Zahlen, Großbuchstaben) Gestrichen, nicht mehr erforderlich
Passwortablauf Alle 90 Tage Nur bei Verdacht auf Kompromittierung
Passworthinweise Erlaubt Verboten
Wissensbasierte Authentifizierung Erlaubt Verboten
Prüfung gegen Breach-Listen Optional Erforderlich

Die Logik hinter dem Streichen der Komplexität ist gut dokumentiert. NISTs eigene Forschung ergab, dass Komplexitätsanforderungen Benutzer zu vorhersehbaren Mustern drängen und die Supportkosten erhöhen, ohne die Widerstandsfähigkeit gegen automatisierte Angriffe wesentlich zu verbessern. Länge hat eine direkte mathematische Beziehung zur Cracking-Schwierigkeit: Jedes zusätzliche Zeichen multipliziert den Suchraum exponentiell.

Für IT-Administratoren ist die praktische Implikation klar: Aktualisieren Sie Ihre Passwortrichtlinien, um 15+ Zeichen zu verlangen, entfernen Sie willkürliche Komplexitätsvorgaben und implementieren Sie Prüfungen gegen bekannte Breach-Passwortlisten wie den Have I Been Pwned-Datensatz, auf den NIST ausdrücklich verweist. Hören Sie auf, Rotationen nach einem Kalenderplan zu erzwingen.

Die Verwaltung von Passwortrichtlinien über Hunderte von Benutzern hinweg ist der Punkt, an dem die Durchsetzung zusammenbricht. Passwork gibt IT-Teams zentrale Kontrolle über Zugangsdaten-Tresore, rollenbasierten Zugriff und Audit-Logs — ohne die Komplexität auf Endbenutzer abzuwälzen. So funktioniert Passwork

Passwörter vs. Passphrasen

Eine Passphrase ist eine Sequenz zufälliger, nicht zusammenhängender Wörter, die als einzelnes Zugangsdatum verwendet wird. Wörter sind leichter zu behalten als zufällige Zeichen, und allein die Länge treibt die Entropie weit über das hinaus, was die meisten zeichenbasierten Passwörter erreichen. Vier Wörter übertreffen bereits eine typische 10-Zeichen-Zeichenkette mit Groß-/Kleinschreibung.

Passwort-Entropie misst, wie unvorhersehbar ein Zugangsdatum ist, ausgedrückt in Bit. Höhere Entropie bedeutet mehr mögliche Kombinationen, die ein Angreifer ausprobieren muss.

Tr0ub4dor&3 sieht komplex aus. Aber es ist ein Wörterbuchwort mit vorhersehbaren Ersetzungen, einem Großbuchstaben am Anfang und einem Symbol und einer Zahl am Ende — ein Muster, das Cracking-Tools explizit modellieren. Seine effektive Entropie ist weit niedriger, als es erscheint.

correct horse battery staple illustriert die Mathematik direkt. Vier zufällig aus dieser Liste gewählte Wörter ergeben ungefähr 44 Bit Entropie (log₂ von 2.000⁴). Sechs zufällige Wörter aus der Diceware-Liste (7.776 Wörter) erzeugen etwa 77 Bit — genug, um Brute-Force-Angriffen bei aktuellen Rechengeschwindigkeiten jahrzehntelang zu widerstehen.

Das kritische Wort ist zufällig. „Ich liebe meinen Hund Keks" ist eine Passphrase, aber sie ist nicht zufällig. Sie spiegelt persönliche Informationen und eine natürliche Satzstruktur wider, die Cracking-Tools modellieren können. Eine Passphrase, die Sie erfunden haben, ist nicht zufällig, weil Sie sie erfunden haben. Echte Zufälligkeit erfordert eine Methode, die die menschliche Wahl vollständig aus der Gleichung entfernt.

Quelle: xkcd.com

So erstellen Sie ein starkes Passwort, das Sie nicht vergessen

Die folgenden Techniken lösen ein spezifisches Problem: wie man eine einzelne Master-Passphrase erstellt und sich merkt. Diese Passphrase hat eine Aufgabe — Ihren Passwort-Manager zu entsperren. Für alle anderen Zugangsdaten, die Sie besitzen, ist die Antwort ein zufällig generiertes Passwort, das in diesem Manager gespeichert wird, keine Passphrase, die Sie konstruiert und auswendig gelernt haben.

Die Diceware-Methode

Die Diceware-Methode generiert kryptografisch zufällige Passphrasen unter Verwendung physischer Würfel und einer standardisierten Wortliste. Da die Zufälligkeit von Würfelwürfen stammt und nicht von menschlicher Wahl, hat die resultierende Passphrase nachweisbare Entropie und umgeht das Merkbarkeits-Paradoxon vollständig.

  1. Laden Sie die EFF Large Wordlist herunter, die 7.776 Wörter enthält, die durch fünfstellige Würfelcodes indiziert sind (z. B. 16132 = cleft).
  2. Würfeln Sie fünf sechsseitige Würfel (oder einen Würfel fünfmal). Notieren Sie das Ergebnis, zum Beispiel 2-4-1-3-6.
  3. Suchen Sie das entsprechende Wort in der EFF-Liste. 24136 entspricht dragster.
  4. Wiederholen Sie die Schritte 2-3 fünf weitere Male, um eine Sechs-Wort-Passphrase zu generieren.
  5. Ihr Ergebnis könnte lauten: dragster cleft robin usage stomp anvil. Schreiben Sie es vorübergehend auf.

Sechs Wörter aus der EFF-Liste ergeben ungefähr 77,5 Bit Entropie. Das ist das Ziel. Fünf Wörter (64,6 Bit) sind für die meisten Anwendungsfälle akzeptabel; vier Wörter sind das absolute Minimum für ein Masterpasswort.

Keine Würfel? Verwenden Sie einen Generator

Wenn keine physischen Würfel verfügbar sind, wendet Passworks kostenloser Passphrasen-Generator dieselbe Logik in einem Browser an. Er läuft vollständig lokal — nichts wird gespeichert oder übertragen. Sie können die Wortanzahl, Trennzeichen und Großschreibung an Ihre Anforderungen anpassen. Die Ausgabe ist dasselbe nachweisbar zufällige Ergebnis wie bei Diceware, ohne das Nachschlagen in der Wortliste.

Die Satz-Methode

Die Satz-Methode eignet sich besser für Personen, die schnell ein starkes Masterpasswort erstellen müssen, ohne Würfel. Nehmen Sie einen Satz, der persönlich bedeutsam, aber nicht öffentlich bekannt ist, und leiten Sie ein Passwort aus seiner Struktur ab.

  • Beispielsatz: „Mein erstes Auto war ein 1998er Honda und ich fuhr damit zur Uni."
  • Abgeleitetes Passwort: MeAwe1998HuifdU

Dies erzeugt eine 15-Zeichen-Zeichenkette mit Groß-/Kleinschreibung und Zahlen, die keine Wörterbuchbeziehung hat. Der Satz selbst ist die Eselsbrücke: Sie merken sich den Satz, nicht das Passwort.

Die Einschränkung: Diese Methode erzeugt weniger Entropie als Diceware, weil Menschen merkbare Sätze wählen und merkbare Sätze vorhersehbaren grammatikalischen Mustern folgen. Verwenden Sie sie nur für das Masterpasswort, wenn Diceware nicht praktikabel ist. Für alles andere verwenden Sie einen Manager.

Die Gedächtnispalast-Technik

Der Gedächtnispalast (Loci-Methode) ist eine mnemonische Technik zum Behalten der Master-Passphrase, die Sie mit Diceware generiert haben. Sie funktioniert, indem jedes Wort mit einem bestimmten physischen Ort in einem vertrauten Raum verknüpft wird: Ihr Zuhause, Ihr Arbeitsweg, ein Gebäude, das Sie gut kennen.

Um sich dragster cleft robin usage stomp anvil zu merken:

  1. Wählen Sie eine vertraute Route durch einen Raum, den Sie gut kennen: Ihre Haustür, Flur, Küche, Wohnzimmer, Treppe, Schlafzimmer.
  2. Ordnen Sie jedem Ort ein Wort zu. Machen Sie das Bild lebendig und ungewöhnlich: ein Dragster, der durch Ihre Haustür rast, ein Spalt (cleft) im Felsen, der Ihren Flurboden teilt, ein Rotkehlchen (robin), das auf Ihrer Küchentheke sitzt.
  3. Gehen Sie die Route mehrmals gedanklich durch, der Reihe nach. Je seltsamer das Bild, desto zuverlässiger bleibt es haften.
  4. Nach 24 Stunden testen Sie das Erinnern, ohne auf die geschriebene Passphrase zu schauen. Die meisten Menschen können sich nach drei oder vier gedanklichen Durchgängen an alle sechs Wörter erinnern.

Der Gedächtnispalast funktioniert, weil das Gehirn räumliche und visuelle Informationen zuverlässiger kodiert als abstrakte Zeichenketten. Sie merken sich nicht dragster cleft robin usage stomp anvil. Sie merken sich einen Gang durch Ihr Haus.

Sobald die Passphrase auswendig gelernt ist, vernichten Sie die schriftliche Kopie.

Zu wissen, wie man eine Master-Passphrase konstruiert und behält, ist eine nützliche Fähigkeit. Aber Merkbarkeit ist eine Einschränkung, und Einschränkungen erzeugen Kompromisse. Ein Passwort-Manager entfernt diese Einschränkung vollständig: Er generiert Zugangsdaten mit voller Entropie, speichert sie verschlüsselt und ruft sie ab, ohne Sie zu bitten, sich an irgendetwas außer einer Passphrase zu erinnern. Die obigen Techniken existieren, um diese eine Passphrase zu schützen. Alles andere sollte generiert, nicht erfunden werden.


Der einzige Standard: Eine Passphrase, alles andere im Passwort-Manager

Das Merkbarkeits-Paradoxon hat eine einzige strukturelle Lösung. Sie merken sich eine zufällig generierte Master-Passphrase. Ein Passwort-Manager generiert und speichert alles andere und erzeugt vollständig zufällige, einzigartige Zugangsdaten für jedes Konto, die Sie nie sehen, eingeben oder sich merken müssen. Diese Struktur gilt, ob Sie fünf Konten oder fünfhundert haben.

In der Praxis bedeutet das:

  • Keine Passwortwiederverwendung über Konten hinweg — jedes Zugangsdatum ist einzigartig und zufällig generiert.
  • Eine Sache zum Merken — die Master-Passphrase, die Sie mit Diceware erstellt haben.
  • Keine Sicherheitsentscheidungen beim Login — der Manager übernimmt Generierung, Speicherung und Autofill.

Passwork ist für diese Architektur gebaut. Es ist als selbstgehostete Bereitstellung oder als Cloud-Service verfügbar. Beide Optionen verwenden AES-256-Client-seitige Verschlüsselung: Zugangsdaten werden verschlüsselt, bevor sie Ihr Gerät verlassen, und Passwork sieht niemals Klartext-Passwörter.

Die beiden Bereitstellungsmodelle unterscheiden sich in einer Dimension:

  • Die selbstgehostete Option behält alle Daten in Ihrer eigenen Infrastruktur.
  • Die Cloud-Option entfernt den operativen Aufwand des Betriebs einer eigenen Instanz, ohne das Verschlüsselungsmodell zu ändern.

Rollenbasierte Zugriffskontrolle ermöglicht es Administratoren, Tresorberechtigungen an Teams statt an Einzelpersonen zuzuweisen — relevant, wenn Sie Zugangsdaten für ein Team verwalten und nicht nur für sich selbst. Ein neuer Ingenieur erbt ab dem ersten Tag Zugriff auf die richtigen Tresore und verliert ihn in dem Moment, in dem er geht, ohne dass manuelle Bereinigung erforderlich ist.

Für Teams mit Compliance-Anforderungen bieten Passworks Audit-Logs einen vollständigen Nachweis darüber, wer wann auf welches Zugangsdatum zugegriffen hat — die Art von Dokumentation, die SOC 2 CC6.1 und ISO 27001:2022 Annex A 5.15-Kontrollen erfordern. Die technischen Anleitungen behandeln AD/LDAP-Integration, SAML SSO und REST API-Zugriff für Teams, die Zugangsdatenverwaltung in bestehende Workflows einbetten müssen.


Beispiele für starke Passwörter: Wie gute Passwörter 2026 aussehen

Zugangsdaten-Typ Beispiel Entropie (ca.) Merkbar? Empfohlene Verwendung
8-Zeichen komplex Tr0ub4dor&3 ~28 Bit effektiv Nein Vermeiden
12-Zeichen zufällig k9#Lm2@pQr7! ~78 Bit Nein Akzeptabel für risikoarme Konten
4-Wort Diceware dragster cleft robin usage ~51 Bit Ja Sekundäre Konten
6-Wort Diceware dragster cleft robin usage stomp anvil ~77 Bit Ja (mit Gedächtnispalast) Nur Masterpasswort
Satz-abgeleitet MfcWa1998HaIdItC ~52 Bit Ja (über Satz) Nur Masterpasswort
Maschinell generiert k9#Lm2@pQr7!xN3$ ~105 Bit Nein — im Manager gespeichert Alle anderen Konten
Maschinell generiertes Secret eyJhbGciOiJIUzI1... 256 Bit N/A API-Keys, Tokens: Secrets-Manager verwenden

Die Spalte „Empfohlene Verwendung" ist der Punkt. Diceware- und satzabgeleitete Passwörter erscheinen einmal in Ihrem Leben, als Master-Zugangsdatum. Jedes andere Konto erhält ein maschinell generiertes Passwort, das Sie nie sehen, nie eingeben und nie merken müssen.


In die Praxis umsetzen

In die Praxis umsetzen

Das Merkbarkeits-Paradoxon hat keinen Workaround — es hat eine Lösung. Merken Sie sich eine Sache, zufällig generiert, mit einer Methode, die Ihr Gehirn aus dem Prozess entfernt. Verwenden Sie diese, um einen Passwort-Manager zu entsperren, der alle anderen Zugangsdaten mit maschinell generierter Zufälligkeit verwaltet, über die Sie nie nachdenken müssen.

Generieren Sie eine 6-Wort-Diceware-Passphrase. Kodieren Sie sie mit einem Gedächtnispalast. Legen Sie alles andere in einen Tresor.

Sobald Ihre Master-Passphrase festgelegt ist, übernimmt Passwork den Rest: gespeicherte Zugangsdaten, Team-Zugriffskontrollen und ein vollständiges Audit-Protokoll. Verfügbar als selbstgehostete Bereitstellung oder in der Cloud. Passwork kostenlos testen

Häufig gestellte Fragen

Häufig gestellte Fragen

Wie lang sollte ein starkes Passwort 2026 sein?

NIST SP 800-63B Rev. 4 (2025) legt das absolute Minimum auf 8 Zeichen fest, empfiehlt aber mindestens 15 Zeichen, wenn ein Passwort der einzige Authentifizierungsfaktor ist. Für Masterpasswörter, die einen Passwort-Tresor oder privilegierte Konten schützen, ist eine 6-Wort-Diceware-Passphrase (etwa 25-35 Zeichen) die aktuelle Best Practice. Länge ist der primäre Treiber der Cracking-Resistenz.

Was ist Passwort-Entropie und warum ist sie wichtig?

Passwort-Entropie misst, wie unvorhersehbar ein Passwort ist, ausgedrückt in Bit. Sie wird als log₂ der Anzahl möglicher Kombinationen berechnet. Eine 6-Wort-Diceware-Passphrase aus der EFF-Liste hat ungefähr 77,5 Bit Entropie. Höhere Entropie bedeutet, dass ein Angreifer mehr Kombinationen ausprobieren muss, um das Passwort per Brute-Force zu knacken. Komplexitätsregeln fügen weniger Entropie hinzu, als es den Anschein hat; Länge fügt Entropie direkt und vorhersehbar hinzu.

Ist eine Passphrase sicherer als ein komplexes Passwort?

Ja, in den meisten Fällen. Eine zufällige 6-Wort-Passphrase hat eine höhere Entropie als ein typisches 10-Zeichen-„komplexes" Passwort, und sie ist weitaus resistenter gegen die Mustererkennung, die KI-Cracking-Tools verwenden. Das Schlüsselwort ist zufällig. Eine Passphrase, die aus persönlich bedeutsamen Wörtern aufgebaut ist, ist schwächer als sie erscheint, weil menschliche Entscheidungen vorhersehbaren Mustern folgen.

Was ist die Diceware-Methode?

Diceware ist eine Technik zur Generierung zufälliger Passphrasen durch Würfeln mit physischen Würfeln und Zuordnung der Ergebnisse zu Wörtern auf einer standardisierten Liste. Die EFF Large Wordlist enthält 7.776 Wörter, die durch fünfstellige Würfelcodes indiziert sind. Einmal fünf Würfel zu werfen ergibt ein Wort; sechs Würfe ergeben eine Sechs-Wort-Passphrase mit ungefähr 77,5 Bit Entropie. Da die Zufälligkeit von Würfeln stammt und nicht von menschlicher Wahl, ist das Ergebnis nachweislich unvorhersehbar.

Sollte ich trotzdem einen Passwort-Manager verwenden, wenn ich eine starke Passphrase habe?

Ja. Eine starke Passphrase löst das Master-Zugangsdaten-Problem: das eine Passwort, das Sie sich merken, um alles andere zu entsperren. Sie löst nicht das Problem der Verwaltung von Dutzenden separater Zugangsdaten über verschiedene Systeme hinweg. Ein Passwort-Manager generiert vollständig zufällige, einzigartige Passwörter für jedes Konto und speichert sie sicher. Die Passphrase ist der Schlüssel zum Tresor. Der Tresor erledigt den Rest.

Wie merke ich mir eine lange Passphrase?

Die Gedächtnispalast-Technik (Loci-Methode) ist für die meisten Menschen die zuverlässigste Methode. Ordnen Sie jedes Wort in Ihrer Passphrase einem bestimmten Ort entlang einer vertrauten Route zu (Ihr Zuhause, Ihr Arbeitsweg) und erstellen Sie für jedes Wort ein lebhaftes mentales Bild. Gehen Sie die Route über 24-48 Stunden mehrmals gedanklich durch. Die meisten Menschen können sich nach vier oder fünf Übungsdurchgängen zuverlässig an eine Sechs-Wort-Passphrase erinnern.

Was hat sich in den NIST-Passwortrichtlinien geändert?

NIST SP 800-63B Rev. 4 hat mehrere bedeutende Änderungen vorgenommen. Es strich verpflichtende Komplexitätsanforderungen (erzwungene Symbole, Zahlen, Groß-/Kleinschreibung). Es eliminierte kalenderbasiertes Passwortablaufen und empfiehlt Zurücksetzungen nur bei Verdacht auf Kompromittierung. Es verbot Passworthinweise und wissensbasierte Authentifizierungsfragen. Es verlangt jetzt die Prüfung neuer Passwörter gegen bekannte Breach-Zugangsdatenlisten. Die Mindestlänge bleibt bei 8 Zeichen, mit 15 Zeichen als empfohlenem Standard für Einzelfaktor-Authentifizierung.

Warum kann ich nicht einfach merkbare Passwörter ohne Manager erstellen?

Weil Merkbarkeit und Sicherheit in direkter Spannung zueinander stehen. Das menschliche Gehirn kodiert Informationen durch Muster und Assoziationen. Jedes Passwort, das sich merkbar anfühlt, ist per Definition gemustert — und Muster sind das, worauf Cracking-Algorithmen trainiert sind. Der einzige Ausweg aus diesem Paradoxon ist, sich eine starke Master-Passphrase zu merken und alles andere an ein Tool zu delegieren, das echte Zufälligkeit generiert.

Passwortverwaltung für Teams: Die Lösung, die jedes KMU braucht
Das Speichern von Passwörtern in Slack und Browsern setzt Ihr Unternehmen Breaches aus. Erfahren Sie, warum persönliche Tools für Teams versagen, wie Sie ausscheidende Mitarbeiter mit einem Klick sicher offboarden und warum die neuesten NIST-Richtlinien von erzwungener Passwortrotation abraten.
11 Risiken der Passwortwiederverwendung und wie Sie sie vermeiden
Ein Passwort wiederzuverwenden fühlt sich harmlos an. Ist es aber nicht. Hier erfahren Sie, warum ein geleaktes Zugangsdatum die gesamte Sicherheit Ihrer Organisation gefährden kann — und wie Sie das verhindern.
Passwort-Chaos: Warum es ein Geschäftsproblem ist und wie Sie es beheben
Ein vergessenes Passwort kostet 70 $. Ein Breach kostet 4,44 Millionen $. Beides beginnt gleich — Zugangsdaten, die über Slack geteilt, in Tabellen gespeichert und nie rotiert werden. Hier erfahren Sie, was Passwort-Chaos tatsächlich kostet und wie Sie es eliminieren.

So erstellen Sie ein starkes Passwort, das Sie nicht vergessen (Leitfaden 2026)

Komplexitätsregeln sind gescheitert. Ein @ zum Namen Ihres Hundes hinzuzufügen macht ein Passwort nicht sicher — es macht es vorhersehbar. Dieser Leitfaden erklärt, was NIST SP 800-63B tatsächlich fordert, warum Diceware jede Komplexitätsregel übertrifft und wie das Ein-Passphrase-System alles löst.

Jul 3, 2026 — 17 min read
Ilustración de un experimento de laboratorio sobre fondo azul. Un matraz Erlenmeyer con líquido azul se calienta sobre una pequeña llama y está conectado mediante un tubo a un tubo de ensayo que contiene pastillas blancas. Sobre cada recipiente hay un campo de contraseña con asteriscos — el matraz muestra asteriscos azules y el tubo de ensayo muestra asteriscos verdes — sugiriendo transformación de contraseñas, cifrado o procesamiento de seguridad.

Durante décadas, la respuesta a «¿cómo creo una contraseña segura?» fue: añada una mayúscula, ponga un símbolo al final, agregue un número. El problema es que los humanos bajo reglas son predecibles. La mayúscula va al principio. El símbolo y el número van al final. Las herramientas de descifrado lo saben, porque fueron entrenadas con miles de millones de contraseñas reales de personas que siguieron exactamente el mismo instinto.

Tanto la memoria humana como los algoritmos de descifrado funcionan con patrones. Ese es el conflicto, y no desaparece añadiendo @ al final del nombre de su mascota. Esta guía explica la mecánica, la única excepción y cómo es realmente un sistema de credenciales sostenible.


Puntos clave

  • Cuanto más fácil es recordar una contraseña, más fácil es descifrarla. La memorabilidad y la seguridad tiran en direcciones opuestas. Esa tensión es estructural: proviene de cómo funciona la memoria humana.
  • Las sustituciones de símbolos y las reglas de complejidad no aumentan significativamente la seguridad. Los algoritmos modernos de descifrado de contraseñas están entrenados específicamente en estos patrones humanos predecibles, lo que permite a los atacantes eludirlos con ataques de fuerza bruta optimizados.
  • Las últimas directrices NIST SP 800-63B eliminan oficialmente las reglas de complejidad obligatorias y las rotaciones de 90 días, estableciendo un nuevo mínimo recomendado de 15 caracteres.
  • El único tipo de contraseña que es memorable y criptográficamente fuerte es una frase de contraseña Diceware: palabras aleatorias elegidas por dados, no por usted.
  • Solo necesita memorizar una contraseña: la frase de contraseña maestra que desbloquea su gestor de contraseñas. Todas las demás credenciales deben generarse aleatoriamente y almacenarse en la bóveda.

Qué es una contraseña segura

Una contraseña segura es una credencial que resiste tanto los intentos automatizados como los ataques dirigidos. NIST SP 800-63B establece el mínimo en 8 caracteres, recomienda que los sistemas acepten hasta 64 caracteres y elimina por completo las reglas de complejidad obligatorias en favor de la longitud y la unicidad. La base práctica de trabajo para la mayoría de los equipos de seguridad es de 12-16 caracteres generados aleatoriamente, con una entropía superior a 75 bits.

Cuatro parámetros definen si una contraseña cumple esa base:

  • Longitud. La variable más efectiva. Cada carácter adicional multiplica el espacio de búsqueda exponencialmente. Con 12 caracteres, una cadena alfanumérica completamente aleatoria requiere miles de millones de años para descifrar por fuerza bruta a las velocidades de hardware actuales. Con 8, esa ventana se reduce a horas.
  • Aleatoriedad. Las contraseñas elegidas por humanos se agrupan en torno a patrones predecibles: nombres, fechas, palabras de diccionario con sustituciones. Un generador de contraseñas elimina esa agrupación por completo. Si usted la eligió, probablemente sea más débil de lo que parece.
  • Unicidad. Una credencial por cuenta. Una sola contraseña comprometida otorga acceso a cada sistema donde aparece. La reutilización transforma una brecha aislada en una oportunidad de movimiento lateral.
  • Sin caducidad sin causa. NIST SP 800-63B desaconseja explícitamente la rotación periódica obligatoria. La rotación forzada produce incrementos predecibles (Password1 → Password2) y entrena a los usuarios a elegir contraseñas base más débiles. Cambie una credencial cuando haya evidencia de compromiso.

La paradoja de la memorabilidad: Por qué su cerebro es una vulnerabilidad

Cualquier propiedad que hace que una contraseña sea más fácil de recordar también la hace más fácil de adivinar. La memoria humana codifica información a través de patrones, asociaciones y significado. Una contraseña que permanece en su mente lo hace porque se conecta con algo que ya conoce: una palabra, una fecha, un nombre, una forma de teclado. Esas mismas conexiones son exactamente lo que explotan las herramientas de descifrado.

PassGAN (Red Generativa Adversarial para descifrado de contraseñas) y herramientas similares están entrenadas con miles de millones de credenciales filtradas. No prueban aaaaaaa antes de p@ssword. Prueban las cosas que los humanos realmente eligen, en el orden en que los humanos realmente las eligen. Sustituir @ por a en password le da p@ssword, que PassGAN genera dentro de los primeros miles de intentos en menos de una fracción de segundo. Poner mayúscula en la primera letra y añadir 1 al final son patrones que el modelo ha visto millones de veces.

💡
Según el análisis de IA de Home Security Heroes, la mayoría de las contraseñas comunes pueden descifrarse en segundos porque las herramientas de IA modelan la psicología humana a escala en lugar de adivinar aleatoriamente

La longitud y el conjunto de caracteres importan, pero no importan igual. La tabla de contraseñas de Hive Systems de 2025, probada contra 12 × RTX 5090 GPUs con bcrypt en factor de trabajo 10, muestra que una contraseña de 8 caracteres usando solo letras minúsculas cae en tres semanas. Añada mayúsculas, números y símbolos, y esa cifra alcanza 164 años contra el mismo hardware. Una contraseña de 12 caracteres con el mismo conjunto completo de caracteres mixtos lleva la tabla a siglos.

Tabla de descifrado de contraseñas de Hive Systems
Fuente: Hive Systems

La tabla se actualiza anualmente para reflejar el hardware GPU de consumo actual. El cambio de la edición de 2024 a 2025 refleja tanto hardware más rápido como suposiciones de fortaleza de hash más realistas extraídas de lo que Hive Systems observó en datos reales de brechas.


Por qué los consejos tradicionales sobre contraseñas están obsoletos

Las antiguas reglas de complejidad (ocho caracteres, una mayúscula, un número, un símbolo) fallaron porque estaban equivocadas sobre el comportamiento humano bajo restricciones. Mientras que la paradoja de la memorabilidad describe un fallo cognitivo, las reglas de complejidad obligatorias produjeron un fallo de política sobre él.

Durante años, el enfoque de descifrado dominante fueron los ataques de diccionario: herramientas automatizadas recorriendo palabras conocidas y sustituciones comunes. Los equipos de seguridad respondieron exigiendo complejidad. El problema es que los humanos bajo presión de complejidad son predecibles. Cuando se les dice que añadan un símbolo, la mayoría lo añade al final. Cuando se les dice que sustituyan una letra, la mayoría elige las mismas sustituciones. Las reglas diseñadas para aumentar la imprevisibilidad produjeron una nueva capa de comportamiento predecible.

💡
NIST reconoció esto en SP 800-63B: la guía eliminó explícitamente los restablecimientos periódicos obligatorios y las reglas de complejidad, citando exactamente este modo de fallo

El otro fallo de los consejos antiguos fue la política de rotación de 90 días. Los restablecimientos forzados producen Summer2025! seguido de Fall2025!. El DBIR de 2026 de Verizon, que analizó más de 22.000 brechas confirmadas en 145 países, encontró que la explotación de vulnerabilidades ha superado al robo de credenciales como principal punto de entrada de brechas (31%). El abuso de credenciales se sitúa en el 13% como vector de acceso inicial, pero esa cifra solo mira la primera acción. El DBIR encontró que el abuso de credenciales aparece en el 39% de todas las brechas cuando se mide a lo largo de toda la cadena de ataque, convirtiéndolo en la técnica más generalizada del conjunto de datos.

La longitud es la defensa principal. Una frase de contraseña de 15 caracteres construida con palabras aleatorias es órdenes de magnitud más fuerte que una cadena de símbolos de 8 caracteres, y un humano puede realmente recordarla.


El nuevo estándar: Directrices NIST SP 800-63B Rev. 4

NIST SP 800-63B Rev. 4 (2025) establece la base actual para la seguridad de contraseñas. Cuando una contraseña es el único factor de autenticación, los sistemas deben requerir un mínimo de 8 caracteres y deberían requerir al menos 15 caracteres. Las reglas de complejidad obligatorias (símbolos forzados, números, mayúsculas y minúsculas) se eliminan explícitamente, al igual que el ciclo de caducidad de 90 días. Verificar las nuevas contraseñas contra listas de credenciales conocidas filtradas es ahora obligatorio, no opcional.

El cambio completo en la política se ve así:

Regla Directriz anterior (Rev. 3) Nueva directriz (Rev. 4)
Longitud mínima 8 caracteres 8 caracteres obligatorios; 15 recomendados
Requisitos de complejidad Obligatorios (símbolos, números, mayúsculas) Eliminados, ya no requeridos
Caducidad de contraseña Cada 90 días Solo cuando se sospeche compromiso
Pistas de contraseña Permitidas Prohibidas
Autenticación basada en conocimiento Permitida Prohibida
Verificación contra listas de brechas Opcional Obligatoria

La lógica detrás de eliminar la complejidad está bien documentada. La propia investigación de NIST encontró que los requisitos de complejidad empujan a los usuarios hacia patrones predecibles y aumentan los costes de soporte sin mejorar significativamente la resistencia a ataques automatizados. La longitud tiene una relación matemática directa con la dificultad de descifrado: cada carácter adicional multiplica el espacio de búsqueda exponencialmente.

Para los administradores de TI, la implicación práctica es clara: actualice sus políticas de contraseñas para requerir más de 15 caracteres, elimine los mandatos de complejidad arbitrarios e implemente verificaciones contra listas de contraseñas filtradas conocidas como el conjunto de datos de Have I Been Pwned, al que NIST hace referencia explícitamente. Deje de forzar rotaciones en un calendario programado.

Gestionar políticas de contraseñas en cientos de usuarios es donde falla la aplicación. Passwork ofrece a los equipos de TI control centralizado sobre bóvedas de credenciales, acceso basado en roles y registros de auditoría, sin transferir la complejidad a los usuarios finales. Vea cómo funciona Passwork

Contraseñas vs. frases de contraseña

Una frase de contraseña es una secuencia de palabras aleatorias y no relacionadas usadas como una sola credencial. Las palabras son más fáciles de retener que los caracteres aleatorios, y la longitud por sí sola eleva la entropía muy por encima de lo que logran la mayoría de las contraseñas basadas en caracteres. Cuatro palabras ya superan a una cadena típica de 10 caracteres con mayúsculas y minúsculas.

La entropía de contraseña mide cuán impredecible es una credencial, expresada en bits. Mayor entropía significa más combinaciones posibles que un atacante debe probar.

Tr0ub4dor&3 parece compleja. Pero es una palabra de diccionario con sustituciones predecibles, una mayúscula al principio y un símbolo y número añadidos al final, un patrón que las herramientas de descifrado modelan explícitamente. Su entropía efectiva es mucho menor de lo que parece.

correct horse battery staple ilustra las matemáticas directamente. Cuatro palabras elegidas aleatoriamente de esa lista dan aproximadamente 44 bits de entropía (log₂ de 2.000⁴). Seis palabras aleatorias de la lista Diceware (7.776 palabras) producen alrededor de 77 bits, suficiente para resistir ataques de fuerza bruta durante décadas a las velocidades de computación actuales.

La palabra crítica es aleatorio. «Amo a mi perro Galleta» es una frase de contraseña, pero no es aleatoria. Refleja información personal y una estructura de oración natural que las herramientas de descifrado pueden modelar. Una frase de contraseña que usted inventó no es aleatoria, porque usted la inventó. La verdadera aleatoriedad requiere un método que elimine la elección humana de la ecuación por completo.

Fuente: xkcd.com

Cómo crear una contraseña segura que no olvidará

Las técnicas a continuación resuelven un problema específico: cómo crear y recordar una única frase de contraseña maestra. Esa frase de contraseña tiene un solo trabajo — desbloquear su gestor de contraseñas. Para todas las demás credenciales que posee, la respuesta es una contraseña generada aleatoriamente almacenada dentro de ese gestor, no una frase de contraseña que construyó y memorizó.

El método Diceware

El método Diceware genera frases de contraseña criptográficamente aleatorias usando dados físicos y una lista de palabras estandarizada. Debido a que la aleatoriedad proviene de tiradas de dados en lugar de elección humana, la frase de contraseña resultante tiene entropía demostrable y evita la paradoja de la memorabilidad por completo.

  1. Descargue la lista de palabras grande de EFF, que contiene 7.776 palabras indexadas por códigos de dados de cinco dígitos (p. ej., 16132 = cleft).
  2. Lance cinco dados de seis caras (o un dado cinco veces). Registre el resultado, por ejemplo, 2-4-1-3-6.
  3. Busque la palabra correspondiente en la lista de EFF. 24136 corresponde a dragster.
  4. Repita los pasos 2-3 cinco veces más para generar una frase de contraseña de seis palabras.
  5. Su resultado podría ser: dragster cleft robin usage stomp anvil. Escríbalo temporalmente.

Seis palabras de la lista de EFF dan aproximadamente 77,5 bits de entropía. Ese es el objetivo. Cinco palabras (64,6 bits) es aceptable para la mayoría de casos de uso; cuatro palabras es el mínimo absoluto para una contraseña maestra.

¿Sin dados? Use un generador

Si no hay dados físicos disponibles, el generador gratuito de frases de contraseña de Passwork aplica la misma lógica en un navegador. Se ejecuta completamente en local — nada se almacena ni transmite. Puede ajustar el número de palabras, separadores y capitalización según sus requisitos. El resultado es el mismo resultado demostrablemente aleatorio que Diceware, sin la búsqueda en la lista de palabras.

El método de la oración

El método de la oración es más adecuado para personas que necesitan crear una contraseña maestra segura rápidamente sin dados. Tome una oración que sea personalmente significativa pero no públicamente conocida, y derive una contraseña de su estructura.

  • Oración de ejemplo: «Mi primer coche fue un Honda de 1998 y lo conduje a la universidad.»
  • Contraseña derivada: MpcfuHd1998ylcalu

Esto produce una cadena de 17 caracteres con mayúsculas y minúsculas y números que no tiene relación con el diccionario. La oración misma es el mnemotécnico: recuerda la oración, no la contraseña.

La limitación: este método produce menos entropía que Diceware porque los humanos eligen oraciones memorables, y las oraciones memorables siguen patrones gramaticales predecibles. Úselo solo para la contraseña maestra cuando Diceware no sea práctico. Para todo lo demás, use un gestor.

La técnica del palacio de la memoria

El palacio de la memoria (Método de Loci) es una técnica mnemotécnica para retener la frase de contraseña maestra que generó con Diceware. Funciona asociando cada palabra con una ubicación física específica en un espacio familiar: su casa, su ruta de desplazamiento, un edificio que conoce bien.

Para memorizar dragster cleft robin usage stomp anvil:

  1. Elija una ruta familiar a través de un espacio que conoce bien: su puerta de entrada, pasillo, cocina, sala de estar, escaleras, dormitorio.
  2. Asigne una palabra a cada ubicación. Haga la imagen vívida e inusual: un dragster rugiendo a través de su puerta de entrada, una roca hendida partiendo el suelo de su pasillo, un petirrojo sentado en la encimera de su cocina.
  3. Recorra la ruta mentalmente, en orden, varias veces. Cuanto más extraña sea la imagen, más fiablemente permanece.
  4. Después de 24 horas, pruebe el recuerdo sin mirar la frase de contraseña escrita. La mayoría de las personas pueden recordar las seis palabras después de tres o cuatro recorridos mentales.

El palacio de la memoria funciona porque el cerebro codifica la información espacial y visual de manera más fiable que las cadenas abstractas. No está memorizando dragster cleft robin usage stomp anvil. Está memorizando un paseo por su casa.

Una vez memorizada la frase de contraseña, destruya la copia escrita.

Saber cómo construir y retener una frase de contraseña maestra es una habilidad útil. Pero la memorabilidad es una restricción, y las restricciones producen compromisos. Un gestor de contraseñas elimina esa restricción por completo: genera credenciales con entropía completa, las almacena cifradas y las recupera sin pedirle que recuerde nada más allá de una frase de contraseña. Las técnicas anteriores existen para proteger esa única frase de contraseña. Todo lo demás debe generarse, no inventarse.


El único estándar: Una frase de contraseña, todo lo demás en un gestor de contraseñas

La paradoja de la memorabilidad tiene una única solución estructural. Memoriza una frase de contraseña maestra generada aleatoriamente. Un gestor de contraseñas genera y almacena todo lo demás, produciendo credenciales completamente aleatorias y únicas para cada cuenta que nunca necesita ver, escribir ni recordar. Esa estructura se mantiene tanto si tiene cinco cuentas como quinientas.

En la práctica, esto significa:

  • Cero reutilización de contraseñas entre cuentas — cada credencial es única y generada aleatoriamente.
  • Una sola cosa que memorizar — la frase de contraseña maestra que creó con Diceware.
  • Sin decisiones de seguridad que tomar al iniciar sesión — el gestor maneja la generación, almacenamiento y autocompletado.

Passwork está diseñado para esta arquitectura. Está disponible como despliegue autoalojado o como servicio en la nube. Ambas opciones utilizan cifrado AES-256 del lado del cliente: las credenciales se cifran antes de salir de su dispositivo, y Passwork nunca ve las contraseñas en texto plano.

Los dos modelos de despliegue difieren en una dimensión:

  • La opción autoalojada mantiene todos los datos dentro de su propia infraestructura.
  • La opción en la nube elimina la carga operativa de ejecutar su propia instancia sin cambiar el modelo de cifrado.

El control de acceso basado en roles permite a los administradores asignar permisos de bóveda a equipos en lugar de a individuos — relevante si gestiona credenciales para un equipo en lugar de solo para usted mismo. Un nuevo ingeniero hereda acceso a las bóvedas correctas desde el primer día y lo pierde en el momento en que se va, sin necesidad de limpieza manual.

Para equipos con requisitos de cumplimiento, los registros de auditoría de Passwork proporcionan un registro completo de quién accedió a qué credencial y cuándo — el tipo de documentación que requieren los controles SOC 2 CC6.1 e ISO 27001:2022 Anexo A 5.15. Las guías técnicas cubren la integración con AD/LDAP, SAML SSO y acceso REST API para equipos que necesitan integrar la gestión de credenciales en flujos de trabajo existentes.


Ejemplos de contraseñas seguras: Cómo luce una buena contraseña en 2026

Tipo de credencial Ejemplo Entropía (aprox.) ¿Memorable? Uso recomendado
8 caracteres complejos Tr0ub4dor&3 ~28 bits efectivos No Evitar
12 caracteres aleatorios k9#Lm2@pQr7! ~78 bits No Aceptable para cuentas de bajo riesgo
4 palabras Diceware dragster cleft robin usage ~51 bits Cuentas secundarias
6 palabras Diceware dragster cleft robin usage stomp anvil ~77 bits Sí (con palacio de la memoria) Solo contraseña maestra
Derivada de oración MfcWa1998HaIdItC ~52 bits Sí (mediante oración) Solo contraseña maestra
Generada por máquina k9#Lm2@pQr7!xN3$ ~105 bits No — almacenada en el gestor Todas las demás cuentas
Secreto generado por máquina eyJhbGciOiJIUzI1... 256 bits N/A Claves API, tokens: use un gestor de secretos

La columna de «uso recomendado» es el punto. Las contraseñas Diceware y derivadas de oraciones aparecen una vez en su vida, como la credencial maestra. Todas las demás cuentas obtienen una contraseña generada por máquina que nunca ve, nunca escribe y nunca necesita recordar.


Poniéndolo en práctica

Poniéndolo en práctica

La paradoja de la memorabilidad no tiene un rodeo — tiene una solución. Memorice una cosa, generada aleatoriamente, usando un método que elimine su cerebro del proceso. Use eso para desbloquear un gestor de contraseñas que maneje todas las demás credenciales con aleatoriedad generada por máquina en la que nunca tiene que pensar.

Genere una frase de contraseña Diceware de 6 palabras. Codifíquela con un palacio de la memoria. Ponga todo lo demás en una bóveda.

Una vez establecida su frase de contraseña maestra, Passwork se encarga del resto: credenciales en bóveda, controles de acceso de equipo y un registro de auditoría completo. Disponible como despliegue autoalojado o en la nube. Pruebe Passwork gratis

Preguntas frecuentes

Preguntas frecuentes

¿Qué longitud debe tener una contraseña segura en 2026?

NIST SP 800-63B Rev. 4 (2025) establece el mínimo absoluto en 8 caracteres pero recomienda al menos 15 caracteres cuando una contraseña es el único factor de autenticación. Para contraseñas maestras que protegen una bóveda de contraseñas o cuentas privilegiadas, una frase de contraseña Diceware de 6 palabras (aproximadamente 25-35 caracteres) es la mejor práctica actual. La longitud es el principal impulsor de la resistencia al descifrado.

¿Qué es la entropía de contraseña y por qué importa?

La entropía de contraseña mide cuán impredecible es una contraseña, expresada en bits. Se calcula como log₂ del número de combinaciones posibles. Una frase de contraseña Diceware de 6 palabras extraída de la lista de EFF tiene aproximadamente 77,5 bits de entropía. Mayor entropía significa que un atacante debe probar más combinaciones para descifrar la contraseña por fuerza bruta. Las reglas de complejidad añaden menos entropía de lo que aparentan; la longitud añade entropía directa y predeciblemente.

¿Es una frase de contraseña más segura que una contraseña compleja?

Sí, en la mayoría de los casos. Una frase de contraseña aleatoria de 6 palabras tiene mayor entropía que una contraseña «compleja» típica de 10 caracteres, y es mucho más resistente al reconocimiento de patrones que usan las herramientas de descifrado con IA. La palabra clave es aleatoria. Una frase de contraseña construida con palabras personalmente significativas es más débil de lo que parece porque las elecciones humanas siguen patrones predecibles.

¿Qué es el método Diceware?

Diceware es una técnica para generar frases de contraseña aleatorias lanzando dados físicos y mapeando los resultados a palabras en una lista estandarizada. La lista de palabras grande de EFF contiene 7.776 palabras indexadas por códigos de dados de cinco dígitos. Lanzar cinco dados una vez produce una palabra; seis lanzamientos producen una frase de contraseña de seis palabras con aproximadamente 77,5 bits de entropía. Debido a que la aleatoriedad proviene de dados en lugar de elección humana, el resultado es demostrablemente impredecible.

¿Debo seguir usando un gestor de contraseñas si tengo una frase de contraseña segura?

Sí. Una frase de contraseña segura resuelve el problema de la credencial maestra: la única contraseña que memoriza para desbloquear todo lo demás. No resuelve el problema de gestionar docenas de credenciales separadas en diferentes sistemas. Un gestor de contraseñas genera contraseñas completamente aleatorias y únicas para cada cuenta y las almacena de forma segura. La frase de contraseña es la llave de la bóveda. La bóveda hace el resto.

¿Cómo recuerdo una frase de contraseña larga?

La técnica del palacio de la memoria (Método de Loci) es el método más fiable para la mayoría de las personas. Asigne cada palabra de su frase de contraseña a una ubicación específica a lo largo de una ruta familiar (su casa, su desplazamiento) y cree una imagen mental vívida para cada palabra. Recorra la ruta mentalmente varias veces durante 24-48 horas. La mayoría de las personas pueden recordar de manera fiable una frase de contraseña de seis palabras después de cuatro o cinco prácticas.

¿Qué cambió en las directrices de contraseñas de NIST?

NIST SP 800-63B Rev. 4 realizó varios cambios significativos. Eliminó los requisitos de complejidad obligatorios (símbolos forzados, números, mayúsculas y minúsculas). Eliminó la caducidad de contraseñas basada en calendario, recomendando restablecimientos solo cuando se sospeche compromiso. Prohibió las pistas de contraseña y las preguntas de autenticación basadas en conocimiento. Ahora requiere verificar las nuevas contraseñas contra listas de credenciales filtradas conocidas. La longitud mínima sigue siendo 8 caracteres, con 15 caracteres como estándar recomendado para autenticación de factor único.

¿Por qué no puedo simplemente crear contraseñas memorables sin un gestor?

Porque la memorabilidad y la seguridad están en tensión directa. El cerebro humano codifica información a través de patrones y asociaciones. Cualquier contraseña que se sienta memorable es, por definición, con patrón — y los patrones son lo que los algoritmos de descifrado están entrenados para encontrar. La única salida de esta paradoja es memorizar una frase de contraseña maestra segura y delegar todo lo demás a una herramienta que genera verdadera aleatoriedad.

Gestión de contraseñas para equipos: La solución que toda pyme necesita
Almacenar contraseñas en Slack y navegadores expone su negocio a brechas. Descubra por qué las herramientas personales fallan para los equipos, cómo dar de baja de forma segura a empleados que se van con un clic, y por qué las últimas directrices NIST recomiendan no forzar la rotación de contraseñas.
11 riesgos de reutilización de contraseñas y cómo evitarlos
Reutilizar una contraseña parece inofensivo. No lo es. Aquí le explicamos por qué una sola credencial filtrada puede desmoronar toda la seguridad de su organización — y cómo evitar que suceda.
Caos de contraseñas: Por qué es un problema empresarial y cómo solucionarlo
Una contraseña olvidada cuesta $70. Una brecha cuesta $4,44 millones. Ambas empiezan igual — credenciales compartidas por Slack, almacenadas en hojas de cálculo, nunca rotadas. Esto es lo que realmente cuesta el caos de contraseñas y cómo eliminarlo.

Cómo crear una contraseña segura que no olvidará (guía 2026)

Las reglas de complejidad fracasaron. Añadir @ al nombre de su mascota no hace segura una contraseña — la hace predecible. Esta guía cubre lo que NIST SP 800-63B realmente exige, por qué Diceware supera cualquier regla de complejidad y el sistema de una frase que resuelve todo lo demás.

Jul 3, 2026 — 15 min read
llustration of a laboratory experiment on a blue background. An Erlenmeyer flask containing blue liquid is heated over a small flame and connected by tubing to a test tube holding white tablets. Above each vessel is a password field with asterisks—the flask shows blue asterisks and the test tube shows green asterisks—suggesting password transformation, encryption, or security processing.

For decades, the answer to "how do I make a strong password?" was: add a capital letter, throw a symbol at the end, append a number. The problem is that humans under rules are predictable. The capital goes at the front. The symbol and number go at the back. Cracking tools know this, because they were trained on billions of real passwords from people who followed exactly the same instinct.

Both human memory and cracking algorithms run on patterns. That's the conflict, and it doesn't go away by adding @ to the end of your dog's name. This guide explains the mechanics, the one exception, and what a sustainable credential system actually looks like.


Key takeaways

  • The easier a password is to remember, the easier it is to crack. Memorability and security pull in opposite directions. That tension is structural: it comes from how human memory works.
  • Symbol substitutions and complexity rules do not meaningfully increase security. Modern password-cracking algorithms are trained specifically on these predictable human patterns, allowing attackers to bypass them with optimized brute-force attacks.
  • The latest NIST SP 800-63B guidelines officially drop mandatory complexity rules and 90-day rotations, establishing a new recommended minimum of 15 characters.
  • The only password type that is both memorable and cryptographically strong is a Diceware passphrase: random words chosen by dice, not by you.
  • You need to memorize exactly one password: the master passphrase that unlocks your password manager. Every other credential should be randomly generated and stored in the vault.

What is a strong password

A strong password is a credential that resists both automated guessing and targeted attacks.  NIST SP 800-63B sets the minimum at 8 characters, recommends systems accept up to 64 characters, and drops mandatory complexity rules entirely in favor of length and uniqueness. The practical working baseline for most security teams is 12-16 randomly generated characters, with entropy above 75 bits.

Four parameters define whether a password meets that baseline:

  • Length. The single most effective variable. Each additional character multiplies the search space exponentially. At 12 characters, a fully random alphanumeric string requires billions of years to brute-force at current hardware speeds. At 8, that window collapses to hours. 
  • Randomness. Human-chosen passwords cluster around predictable patterns: names, dates, dictionary words with substitutions. A password generator removes that clustering entirely. If you chose it, it is probably weaker than it looks.
  • Uniqueness. One credential per account. A single compromised password grants access to every system where it appears. Reuse transforms an isolated breach into a lateral movement opportunity.
  • No expiration without cause. NIST SP 800-63B explicitly deprecates mandatory periodic rotation. Forced rotation produces predictable increments (Password1 → Password2) and trains users to choose weaker base passwords. Change a credential when there is evidence of compromise.

The memorability paradox: Why your brain is a liability

Any property that makes a password easier to remember also makes it easier to guess. Human memory encodes information through patterns, associations, and meaning. A password that sticks in your mind does so because it connects to something you already know: a word, a date, a name, a keyboard shape. Those same connections are exactly what cracking tools exploit.

PassGAN (Generative Adversarial Network for password cracking) and similar tools are trained on billions of leaked credentials. They do not try aaaaaaa before p@ssword. They try the things humans actually choose, in the order humans actually choose them. Substituting @ for a in password gives you p@ssword, which PassGAN generates within the first few thousand guesses in less than a fraction of a second. Capitalising the first letter and adding 1 at the end are patterns the model has seen millions of times.

💡
According to the Home Security Heroes AI analysis, most common passwords can be cracked in seconds because AI tools model human psychology at scale instead of guessing randomly

Length and character set both matter, but they don't matter equally. Hive Systems' 2025 password table, tested against 12 × RTX 5090 GPUs with bcrypt at work factor 10, shows that an 8-character password using only lowercase letters falls in three weeks. Add uppercase, numbers, and symbols, and that figure reaches 164 years against the same hardware. A 12-character password with the same full mixed-character set takes the table into centuries.

Hive Systems's cracking password table
Source: Hive Systems

The table is updated annually to reflect current consumer GPU hardware. The shift from the 2024 edition to 2025 reflects both faster hardware and more realistic hash strength assumptions drawn from what Hive Systems observed in actual breach data.


Why traditional password advice is dead

The old complexity rules (eight characters, one uppercase, one number, one symbol) failed, because they were wrong about human behaviour under constraints. Where the memorability paradox describes a cognitive failure, mandatory complexity rules produced a policy failure on top of it.

For years, the dominant cracking approach was dictionary attacks: automated tools cycling through known words and common substitutions. Security teams responded by mandating complexity. The problem is that humans under complexity pressure are predictable. When told to add a symbol, most people add it at the end. When told to substitute a letter, most choose the same substitutions. The rules designed to increase unpredictability produced a new layer of predictable behaviour.

💡
NIST recognised this in SP 800-63B: the guidance explicitly dropped mandatory periodic resets and complexity rules, citing exactly this failure mode

The other failure of old advice was the 90-day rotation policy. Forced resets produce Summer2025! followed by Fall2025!. Verizon's 2026 DBIR, which analyzed over 22,000 confirmed breaches across 145 countries, found that vulnerability exploitation has now overtaken credential theft as the primary breach entry point (31%). Credential abuse sits at 13% as an initial access vector, but that figure looks at only the first action. The DBIR found that credential abuse appears in 39% of all breaches when measured across the full attack chain making it the single most pervasive technique in the dataset.

Length is the primary defense. A 15-character passphrase built from random words is orders of magnitude stronger than an 8-character string of symbols, and a human can actually remember it.


The new standard: NIST SP 800-63B Rev. 4 guidelines

NIST SP 800-63B Rev. 4 (2025) sets the current baseline for password security. When a password is the only authentication factor, systems must require a minimum of 8 characters and should require at least 15 characters. Mandatory complexity rules (forced symbols, numbers, mixed case) are explicitly dropped, as is the 90-day expiration cycle. Checking new passwords against known-breached credential lists is now required, not optional.

The full shift in policy looks like this:

Rule Old guidance (Rev. 3) New guidance (Rev. 4)
Minimum length 8 characters 8 characters required; 15 recommended
Complexity requirements Mandatory (symbols, numbers, uppercase) Dropped, no longer required
Password expiration Every 90 days Only when compromise is suspected
Password hints Allowed Prohibited
Knowledge-based authentication Allowed Prohibited
Checking against breached lists Optional Required

The logic behind dropping complexity is well-documented. NIST's own research found that complexity requirements push users toward predictable patterns and increase support costs without meaningfully improving resistance to automated attacks. Length has a direct mathematical relationship with cracking difficulty: each additional character multiplies the search space exponentially.

For IT administrators, the practical implication is clear: update your password policies to require 15+ characters, remove arbitrary complexity mandates, and implement checks against known-breached password lists such as the Have I Been Pwned dataset, which NIST explicitly references. Stop forcing rotations on a calendar schedule.

Managing password policies across hundreds of users is where enforcement breaks down. Passwork gives IT teams centralized control over credential vaults, role-based access, and audit logs, without pushing complexity onto end users. See how Passwork works

Passwords vs. passphrases

A passphrase is a sequence of random, unrelated words used as a single credential. Words are easier to retain than random characters, and length alone pushes entropy well above what most character-based passwords achieve. Four words already outperform a typical 10-character mixed-case string .

Password entropy measures how unpredictable a credential is, expressed in bits. Higher entropy means more possible combinations an attacker must try.

Tr0ub4dor&3 looks complex. But it is a dictionary word with predictable substitutions, a capital at the start, and a symbol and number appended at the end, a pattern that cracking tools model explicitly. Its effective entropy is far lower than it appears.

correct horse battery staple illustrates the math directly. Four words chosen randomly from that list gives approximately 44 bits of entropy (log₂ of 2,000⁴). Six random words from the Diceware list (7,776 words) produces around 77 bits, enough to resist brute-force attacks for decades at current computing speeds.

The critical word is random. "I love my dog Biscuit" is a passphrase, but it is not random. It reflects personal information and a natural sentence structure that cracking tools can model. A passphrase you invented is not random, because you invented it. True randomness requires a method that removes human choice from the equation entirely.

Source: xkcd.com

How to create a strong password you won't forget

The techniques below solve one specific problem: how to create and remember a single master passphrase. That passphrase has one job — unlocking your password manager. For every other credential you own, the answer is a randomly generated password stored inside that manager, not a passphrase you constructed and memorized. 

The Diceware method

The Diceware method generates cryptographically random passphrases using physical dice and a standardized word list. Because the randomness comes from dice rolls rather than human choice, the resulting passphrase has provable entropy and sidesteps the memorability paradox entirely.

  1. Download the EFF Large Wordlist, which contains 7,776 words indexed by five-digit dice codes (e.g., 16132 = cleft).
  2. Roll five six-sided dice (or one die five times). Record the result, for example, 2-4-1-3-6.
  3. Look up the corresponding word in the EFF list. 24136 maps to dragster.
  4. Repeat steps 2-3 five more times to generate a six-word passphrase.
  5. Your result might be: dragster cleft robin usage stomp anvil. Write it down temporarily. 

Six words from the EFF list gives approximately 77.5 bits of entropy. That is the target. Five words (64.6 bits) is acceptable for most use cases; four words is the absolute minimum for a master password.

No dice? Use a generator

If physical dice aren't available, Passwork's free passphrase generator applies the same logic in a browser. It runs entirely locally — nothing is stored or transmitted. You can adjust word count, separators, and capitalization to match your requirements. The output is the same provably random result as Diceware, without the wordlist lookup.

The sentence method

The sentence method is better suited for people who need to create a strong master password quickly without dice. Take a sentence that is personally meaningful but not publicly known, and derive a password from its structure.

  • Example sentence: "My first car was a 1998 Honda and I drove it to college."
  • Derived password: MfcWa1998HaIdItC

This produces a 16-character string with mixed case and numbers that has no dictionary relationship. The sentence itself is the mnemonic: you remember the sentence, not the password.

The limitation: this method produces less entropy than Diceware because humans choose memorable sentences, and memorable sentences follow predictable grammatical patterns. Use it only for the master password when Diceware is not practical. For everything else, use a manager.

The memory palace technique

The memory palace (Method of Loci) is a mnemonic technique for retaining the master passphrase you generated with Diceware. It works by associating each word with a specific physical location in a familiar space: your home, your commute route, a building you know well.

To memorize dragster cleft robin usage stomp anvil:

  1. Choose a familiar route through a space you know well: your front door, hallway, kitchen, living room, stairs, bedroom.
  2. Assign one word to each location. Make the image vivid and unusual: a dragster roaring through your front door, a cleft rock splitting your hallway floor, a robin sitting on your kitchen counter.
  3. Walk the route mentally, in order, several times. The stranger the image, the more reliably it sticks.
  4. After 24 hours, test recall without looking at the written passphrase. Most people can recall all six words after three or four mental walkthroughs.

The memory palace works because the brain encodes spatial and visual information more reliably than abstract strings. You are not memorizing dragster cleft robin usage stomp anvil. You are memorizing a walk through your house.

Once the passphrase is memorized, destroy the written copy.

Knowing how to construct and retain a master passphrase is a useful skill. But memorability is a constraint, and constraints produce compromises. A password manager removes that constraint entirely: it generates credentials with full entropy, stores them encrypted, and retrieves them without asking you to remember anything beyond one passphrase. The techniques above exist to protect that one passphrase. Everything else should be generated, not invented.


The only standard: One passphrase, everything else in a password manager

The memorability paradox has a single structural solution. You memorize one randomly generated master passphrase. A password manager generates and stores everything else, producing fully random, unique credentials for every account that you never need to see, type, or remember. That structure holds whether you have five accounts or five hundred.

In practice, this means:

  • Zero password reuse across accounts — every credential is unique and randomly generated.
  • One thing to memorize — the master passphrase you created with Diceware.
  • No security decisions to make at login — the manager handles generation, storage, and autofill.

Passwork is built for this architecture. It is available as a self-hosted deployment or as a cloud service. Both options use AES-256 client-side encryption: credentials are encrypted before they leave your device, and Passwork never sees plaintext passwords.

The two deployment models differ in one dimension:

  • The self-hosted option keeps all data within your own infrastructure.
  • The cloud option removes the operational overhead of running your own instance without changing the encryption model.

Role-based access control lets administrators assign vault permissions to teams rather than individuals — relevant if you are managing credentials for a team rather than just yourself. A new engineer inherits access to the right vaults on day one and loses it the moment they leave, with no manual cleanup required.

For teams with compliance requirements, Passwork's audit logs provide a full record of who accessed which credential and when — the kind of documentation that SOC 2 CC6.1 and ISO 27001:2022 Annex A 5.15 controls require. The technical guides cover AD/LDAP integration, SAML SSO, and REST API access for teams that need to embed credential management into existing workflows.


Strong password examples: What good looks like in 2026

Credential type Example Entropy (approx.) Memorable? Recommended use
8-char complex Tr0ub4dor&3 ~28 bits effective No Avoid
12-char random k9#Lm2@pQr7! ~78 bits No Acceptable for low-risk accounts
4-word Diceware dragster cleft robin usage ~51 bits Yes Secondary accounts
6-word Diceware dragster cleft robin usage stomp anvil ~77 bits Yes (with memory palace) Master password only
Sentence-derived MfcWa1998HaIdItC ~52 bits Yes (via sentence) Master password only
Machine-generated k9#Lm2@pQr7!xN3$ ~105 bits No — stored in manager All other accounts
Machine-generated secret eyJhbGciOiJIUzI1... 256 bits N/A API keys, tokens: use a secrets manager

The "recommended use" column is the point. Diceware and sentence-derived passwords appear once in your life, as the master credential. Every other account gets a machine-generated password that you never see, never type, and never need to remember.


Putting it into practice

Putting it into practice

The memorability paradox does not have a workaround — it has a solution. Memorize one thing, generated randomly, using a method that removes your brain from the process. Use that to unlock a password manager that handles every other credential with machine-generated randomness you never have to think about.

Generate a 6-word Diceware passphrase. Encode it with a memory palace. Put everything else in a vault.

Once your master passphrase is set, Passwork handles the rest: vaulted credentials, team access controls, and a full audit trail. Available as a self-hosted deployment or in the cloud. Try Passwork free

Frequently asked questions

Frequently asked questions

How long should a strong password be in 2026?

NIST SP 800-63B Rev. 4 (2025) sets the absolute minimum at 8 characters but recommends at least 15 characters when a password is the sole authentication factor. For master passwords protecting a password vault or privileged accounts, a 6-word Diceware passphrase (roughly 25-35 characters) is the current best practice. Length is the primary driver of cracking resistance.

What is password entropy and why does it matter?

Password entropy measures how unpredictable a password is, expressed in bits. It is calculated as log₂ of the number of possible combinations. A 6-word Diceware passphrase drawn from the EFF list has approximately 77.5 bits of entropy. Higher entropy means an attacker must try more combinations to crack the password by brute force. Complexity rules add less entropy than they appear to; length adds entropy directly and predictably.

Is a passphrase more secure than a complex password?

Yes, in most cases. A 6-word random passphrase has higher entropy than a typical 10-character "complex" password, and it is far more resistant to the pattern-matching that AI cracking tools use. The key word is random. A passphrase built from personally meaningful words is weaker than it appears because human choices follow predictable patterns.

What is the Diceware method?

Diceware is a technique for generating random passphrases by rolling physical dice and mapping the results to words on a standardized list. The EFF Large Wordlist contains 7,776 words indexed by five-digit dice codes. Rolling five dice once produces one word; six rolls produce a six-word passphrase with approximately 77.5 bits of entropy. Because the randomness comes from dice rather than human choice, the result is provably unpredictable.

Should I still use a password manager if I have a strong passphrase?

Yes. A strong passphrase solves the master credential problem: the one password you memorize to unlock everything else. It does not solve the problem of managing dozens of separate credentials across different systems. A password manager generates fully random, unique passwords for every account and stores them securely. The passphrase is the key to the vault. The vault does the rest.

How do I remember a long passphrase?

The memory palace technique (Method of Loci) is the most reliable method for most people. Assign each word in your passphrase to a specific location along a familiar route (your home, your commute) and create a vivid mental image for each word. Walk the route mentally several times over 24-48 hours. Most people can reliably recall a six-word passphrase after four or five practice runs.

What changed in NIST's password guidelines?

NIST SP 800-63B Rev. 4 made several significant changes. It dropped mandatory complexity requirements (forced symbols, numbers, mixed case). It eliminated calendar-based password expiration, recommending resets only when compromise is suspected. It prohibited password hints and knowledge-based authentication questions. It now requires checking new passwords against known-breached credential lists. The minimum length remains 8 characters, with 15 characters as the recommended standard for single-factor authentication.

Why can't I just create memorable passwords without a manager?

Because memorability and security are in direct tension. The human brain encodes information through patterns and associations. Any password that feels memorable is, by definition, patterned — and patterns are what cracking algorithms are trained to find. The only exit from this paradox is to memorize one strong master passphrase and delegate everything else to a tool that generates true randomness.

Password management for teams: The fix every SMB needs
Storing passwords in Slack and browsers exposes your business to breaches. Discover why personal tools fail teams, how to securely offboard departing employees in one click, and why the latest NIST guidelines recommend against forced password rotation.
11 password reuse risks and how to avoid them
Reusing a password feels harmless. It isn’t. Here’s why one leaked credential can unravel your entire organization’s security — and how to stop it from happening.
Password chaos: Why it’s a business problem and how to fix it
A forgotten password costs $70. A breach costs $4.44 million. Both start the same way — credentials shared over Slack, stored in spreadsheets, never rotated. Here’s what password chaos actually costs and how to eliminate it.

How to create a strong password you won't forget (2026 guide)

Complexity rules failed. Adding @ to your dog's name doesn't make a password strong — it makes it predictable. This guide covers what NIST SP 800-63B actually requires, why Diceware beats every complexity rule, and the one-passphrase system that solves the rest.

Jun 26, 2026 — 30 min read
Shadow IT en 2026: riesgos, detección y cómo gestionarlo

El shadow IT en 2026 no se parece en nada al de hace cinco años. El problema ahora son los agentes de IA con tokens OAuth persistentes, las sesiones de LLM que procesan código fuente propietario en silencio y las cuentas SaaS huérfanas que nadie recuerda haber aprovisionado. Cada uno de estos elementos extiende la superficie de ataque corporativa mucho más allá de lo que cualquier perímetro de red tradicional fue diseñado para manejar.

Según el informe State of Shadow AI de UpGuard, más del 80% de los empleados utilizan herramientas de IA no aprobadas. Una encuesta de Gartner a 302 líderes de ciberseguridad (marzo-mayo de 2025) reveló que el 69% de las organizaciones sospechaban o habían confirmado que sus empleados utilizaban herramientas públicas de GenAI prohibidas. Gartner predice que para 2030, más del 40% de las empresas experimentará un incidente de seguridad o cumplimiento relacionado con shadow AI no autorizado.

El informe Cost of Insider Risks 2026 de DTEX/Ponemon cifra el coste anual de la negligencia interna impulsada principalmente por el shadow AI en 10,3 millones de dólares por organización. Esa cifra cubre incidentes donde no hubo intención maliciosa: solo empleados usando herramientas que TI nunca aprobó, y presupuestos financiando silenciosamente infraestructura que nadie puede ver ni proteger.


Puntos clave

  • El shadow IT en 2026 es tanto un problema de IA como de SaaS. Los agentes de IA con tokens OAuth persistentes, las sesiones de LLM que procesan código fuente propietario y las cuentas SaaS huérfanas que sobreviven a sus propietarios son ahora los riesgos de mayor gravedad.
  • El shadow AI es categóricamente diferente del shadow IT tradicional. Las herramientas SaaS no autorizadas almacenan datos en el lugar equivocado. Las herramientas de IA no autorizadas los procesan, analizan y actúan sobre ellos.
  • La exposición financiera está cuantificada. El informe Cost of a Data Breach 2025 de IBM encontró que la participación del shadow AI añade 670.000 dólares al coste promedio de una brecha de 4,44 millones de dólares. El informe Cost of Insider Risks 2026 de DTEX/Ponemon cifra el coste anual de la negligencia interna impulsada por IA en 10,3 millones de dólares por organización.
  • La detección requiere al menos cinco fuentes de datos trabajando en paralelo. CASB, análisis de logs DNS, EDR, revisión de datos de gastos y escaneo de integraciones de correo electrónico cubren cada uno una porción diferente del entorno. Ningún método único ve simultáneamente los dispositivos personales, las cuentas de nivel gratuito y los endpoints gestionados.
  • Las organizaciones europeas enfrentan una exposición regulatoria por capas. Las herramientas SaaS no autorizadas violan el Artículo 28 del GDPR en el momento en que procesan datos personales sin un DPA firmado. El Artículo 21 de NIS2 trata las herramientas de terceros no verificadas como riesgo de la cadena de suministro. El Artículo 28 de DORA exige a las entidades financieras registrar cada proveedor de TIC — sea shadow o no.
  • Bloquear sin habilitar alternativas falla consistentemente. Casi la mitad de los empleados continúan usando cuentas personales de IA después de una prohibición organizacional. La respuesta efectiva es hacer que el camino aprobado sea más rápido que el atajo: un flujo de aprobación ligero, gestión centralizada de credenciales y un programa de concienciación de seguridad que haga tangible el riesgo.
  • El Marco de Gobernanza de Shadow IT de 6 pasos — descubrir y clasificar, centralizar credenciales, establecer políticas, agilizar aprobaciones, automatizar el offboarding, construir concienciación de seguridad — aborda tanto el lado técnico como el conductual del problema. Las herramientas manejan la detección. El marco cambia la estructura de incentivos que impulsa la adopción del shadow IT en primer lugar.

¿Qué es el shadow IT?

Shadow IT es cualquier tecnología (software, servicio en la nube, herramienta de IA o hardware) que los empleados utilizan para trabajar sin el conocimiento o la aprobación formal de TI. Abarca desde una carpeta personal de Dropbox usada para compartir archivos de proyectos, hasta un asistente de codificación de IA con acceso OAuth a repositorios de producción. El hilo común: sin revisión de seguridad, sin registro de adquisición, sin pista de auditoría.

El shadow IT no es un problema marginal. Gartner sitúa la proporción del gasto de TI consumido por herramientas no autorizadas entre el 30-40% en grandes empresas. El análisis de Harmonic Security de 22,4 millones de prompts empresariales de IA identificó 665 herramientas distintas de IA generativa ejecutándose en entornos empresariales — sin embargo, solo el 40% de esas organizaciones había adquirido una suscripción oficial de IA. El tráfico de GenAI aumentó más del 890% solo en 2024.

Shadow IT vs. shadow AI: Cómo se comparan los riesgos

Dimensión Shadow IT Shadow AI
Qué es Aplicaciones, dispositivos o servicios en la nube no autorizados que funcionan fuera de la visibilidad de TI Herramientas y modelos de IA no autorizados que procesan datos empresariales sin supervisión de seguridad
Punto de entrada típico Un empleado se registra en una herramienta SaaS con su correo laboral Un empleado pega un documento, fragmento de código o credencial en un chat de IA público
Qué se expone Archivos y datos almacenados en un servicio no aprobado Datos leídos, resumidos y potencialmente retenidos activamente por un modelo de terceros
Riesgo de credenciales Contraseñas guardadas en aplicaciones o navegadores no aprobados Claves API, tokens y cadenas de conexión a bases de datos pegados directamente en los prompts
¿Deja rastro? Normalmente sí — logs de red, alertas CASB, consultas DNS A menudo no — las sesiones basadas en navegador y los modelos locales no producen huella de red
Quién lo detecta primero El equipo de TI o seguridad, mediante herramientas Nadie — hasta que ocurre una brecha o una auditoría de cumplimiento
Exposición de cumplimiento Residencia de datos, Artículo 32 del GDPR, brechas en el control de acceso Ley de IA de la UE, NIS2, consentimiento para entrenamiento de datos, responsabilidad sobre los outputs
Qué tan rápido se propaga Herramienta por herramienta, a lo largo de meses En todo un equipo en días — las funciones de IA vienen integradas en herramientas que la gente ya usa
Estado de gobernanza Maduro — existen políticas, CASB y herramientas DLP Inmaduro — la mayoría de las organizaciones no tienen un inventario de uso de IA contra el cual aplicar políticas
Cómo abordarlo Bloquear servicios no autorizados, imponer alternativas aprobadas Auditar qué herramientas de IA están en uso, clasificar la sensibilidad de los datos, establecer políticas de higiene de prompts

¿Qué impulsa a los empleados a usar shadow IT?

Los empleados recurren a herramientas no autorizadas cuando las alternativas aprobadas son demasiado lentas, demasiado limitadas o simplemente aún no existen. La fricción es la causa: un desarrollador que espera tres semanas por un asistente de IA con licencia encontrará uno gratuito antes de que termine el día.

Tres patrones se repiten en organizaciones de todos los tamaños:

  • Velocidad sobre proceso. Los empleados recurren a lo que sea que haga el trabajo más rápido. Cuando las herramientas aprobadas no igualan lo que está disponible gratuitamente fuera de la empresa, la elección es obvia: usar lo que funciona.
  • Retraso en adquisiciones. Los ciclos de software empresarial funcionan por trimestres. Las herramientas de IA se lanzan por semanas. Para cuando TI evalúa y aprueba una herramienta, los empleados ya han construido flujos de trabajo alrededor de su equivalente de nivel gratuito.
  • Brechas funcionales. Las herramientas aprobadas a menudo no cubren casos de uso específicos. Un analista de datos que necesita un entorno Python rápido, o un diseñador que necesita un generador de imágenes específico, recurrirá a lo que funcione, no a lo que esté en la lista aprobada.
  • Sin ciclo de retroalimentación. Los empleados rara vez reportan las herramientas que están usando porque no hay un canal fácil para hacerlo. TI no sabe qué gobernar. Seguridad no sabe qué auditar. La brecha entre el uso real de herramientas y el inventario aprobado se amplía silenciosamente.
  • Las prohibiciones no se sostienen. Casi la mitad de los empleados continúan usando cuentas personales de IA después de una prohibición organizacional. La prohibición no elimina el shadow IT. Solo lo empuja fuera de la vista, haciendo la detección más difícil y la respuesta más lenta.

Estos patrones son una respuesta predecible a estructuras de gobernanza que no han seguido el ritmo de la velocidad con que evoluciona el ecosistema de herramientas. Esa brecha es exactamente lo que convierte al shadow IT en un riesgo sistémico en lugar de un problema de disciplina.


La evolución del shadow IT en 2026

El shadow IT en 2026 ha ido mucho más allá del almacenamiento en la nube no gestionado. Ahora abarca herramientas de IA, agentes autónomos y ecosistemas SaaS completos que TI nunca aprobó, nunca inventarió y no puede monitorear. La empresa promedio ejecuta 305 aplicaciones SaaS, gasta 55,7 millones de dólares en SaaS anualmente, y ha visto el gasto en aplicaciones nativas de IA aumentar un 108% interanual — la mayor parte de ese crecimiento ocurriendo más rápido de lo que los equipos de gobernanza pueden rastrear.

De la proliferación de SaaS al shadow AI

La cifra de 305 aplicaciones proviene del Zylo 2026 SaaS Management Index, que se basa en datos de gasto reales de miles de organizaciones. Una proporción significativa de esas aplicaciones nunca fueron aprobadas formalmente. Los empleados adoptan herramientas de forma independiente y TI se entera meses después, si es que se entera.

El shadow AI acelera esta dinámica. Asistentes de IA gratuitos, generadores de código y agentes autónomos se volvieron ampliamente disponibles más rápido de lo que los ciclos de adquisición podían responder. El informe Check Point 2026 Cloud Security Report encontró que el 78-80% de los trabajadores usan herramientas de IA personales en el trabajo. La mayoría de esas sesiones ocurren a través de cuentas personales, fuera de SSO, fuera de DLP, y sin pista de auditoría.

La distinción vale la pena precisarla: 

  • El shadow IT tradicional crea residencia de datos no gestionada: archivos almacenados en un servicio no autorizado. 
  • El shadow AI crea procesamiento de datos no gestionado: información propietaria siendo analizada, resumida y utilizada por sistemas que su equipo de seguridad nunca ha revisado.

Por qué la superficie de ataque sigue expandiéndose

Tres fuerzas estructurales impulsan esto:

  • El trabajo remoto e híbrido eliminó el perímetro de red como punto de control natural. Los empleados que trabajan desde casa adoptan herramientas sin canalizar las solicitudes a través de TI.
  • Los niveles gratuitos están en todas partes. La mayoría de las herramientas SaaS ofrecen un punto de entrada sin coste. Sin orden de compra, sin ticket de aprobación, sin visibilidad.
  • La proliferación de agentes de IA cambió las apuestas. Los agentes operan a través de permisos OAuth delegados — leyendo datos, activando flujos de trabajo y modificando registros de forma autónoma. Un desarrollador que conecta un asistente de codificación de IA a su cuenta de GitHub puede haber otorgado a ese agente acceso de lectura/escritura a los repositorios. Cuando el desarrollador se va, el permiso OAuth permanece.

Gartner proyecta que para 2027, el 75% de los empleados adquirirá, modificará o creará tecnología fuera de la visibilidad de TI — frente al 41% en 2022. La dirección es inequívoca.


Los riesgos ocultos del shadow IT (la realidad de 2026)

El shadow IT en 2026 no es solo un problema de fuga de datos. Las herramientas no gestionadas crean acceso no autorizado persistente, exponen credenciales, desencadenan violaciones regulatorias, y cada vez más alimentan datos empresariales en modelos de IA que ningún equipo de seguridad ha aprobado o puede monitorear.

El multiplicador de riesgo del shadow AI: Procesamiento de datos vs. almacenamiento de datos

El shadow IT tradicional almacena datos en el lugar equivocado. El shadow AI hace cosas con ellos. Pegar un contrato de cliente en un LLM público envía esos datos a al menos tres lugares: un pipeline de entrenamiento, un sistema de logging, y potencialmente un modelo que otros usuarios pueden consultar.

El informe Cost of a Data Breach 2025 de IBM pone un número a esto: las brechas que involucraban altos niveles de shadow AI añadieron un promedio de 670.000 dólares al coste total de la brecha, llevando el promedio de brechas relacionadas con shadow AI a aproximadamente 5,11 millones de dólares contra una línea base global de 4,44 millones. El mismo informe encontró que el 97% de los incidentes de seguridad relacionados con IA involucraban sistemas sin controles de acceso adecuados.

Passwork proporciona a los equipos de seguridad una bóveda centralizada con acceso basado en roles y un registro de auditoría completo, para que las credenciales conectadas a herramientas de IA y aplicaciones SaaS permanezcan visibles y controladas. Vea cómo funciona

Exposición de credenciales y reutilización de contraseñas

El shadow IT es, en su raíz, un problema de identidad. Cada aplicación no autorizada es una nueva cuenta. Cada nueva cuenta es una credencial. Y la mayoría de esas credenciales se reutilizan.

Según el informe Data Breach Investigations Report 2026 de Verizon, las credenciales robadas aparecieron en el 39% de todas las brechas confirmadas, no solo como el vector de acceso inicial, sino a lo largo del movimiento lateral y la persistencia. Cuando un empleado reutiliza su contraseña corporativa en una herramienta SaaS gratuita que posteriormente sufre una brecha, los atacantes no necesitan romper nada. Simplemente inician sesión.

Los infostealers empeoran esto. En 2025, Recorded Future indexó 1.950 millones de exposiciones de credenciales procedentes de malware, de las cuales el 31% incluía cookies de sesión activas que evitan completamente el MFA. Las cuentas de shadow IT, no monitoreadas, a menudo sin MFA configurado, son exactamente el tipo de objetivo para el que están diseñados los infostealers.

El riesgo de reutilización de contraseñas es un patrón de ataque documentado, automatizado y a escala industrial.

La pesadilla del offboarding: Cuentas huérfanas

Cuando un empleado se va, sus cuentas gestionadas se desaprovisionan. Sus cuentas de shadow IT no. Nadie sabe que existen.

El espacio de trabajo de Figma de ese antiguo desarrollador, la prueba personal de HubSpot del representante de ventas con datos exportados del CRM, la página de Notion del contratista con notas de arquitectura interna: todo esto persiste indefinidamente después de que la persona sale por la puerta.

Las consecuencias pueden ser graves. En un caso documentado, un antiguo empleado de Cisco accedió a una infraestructura de máquinas virtuales alojada en AWS cinco meses después de su despido y eliminó 456 máquinas virtuales, dejando fuera de servicio más de 16.000 cuentas de WebEx Teams durante casi dos semanas.

El Departamento de Justicia de EE. UU. confirmó que el incidente le costó a Cisco aproximadamente 2,4 millones de dólares en remediación y reembolsos a clientes, y el antiguo empleado fue sentenciado a 24 meses en una prisión federal (United States v. Sudhish Kasaba Ramesh, Caso N.º 5:20-cr-00102). Ese era un sistema gestionado. Las cuentas de shadow IT huérfanas son más difíciles de encontrar y tardan más en cerrarse — si es que se cierran alguna vez.

Agentes de IA y permisos OAuth no gestionados

Esta es la amenaza que la mayoría de las organizaciones aún no están rastreando. Los agentes de IA operan a través de permisos OAuth delegados: un usuario otorga al agente acceso a Google Drive, GitHub o Slack, y el agente puede leer, escribir y actuar sobre ese acceso de forma continua — no solo durante la sesión.

Cuando el usuario cierra sesión, el permiso OAuth permanece. Cuando el usuario deja la empresa, el permiso OAuth permanece. El agente puede seguir teniendo acceso a repositorios corporativos, hilos de correo electrónico y unidades compartidas semanas o meses después de que la persona que lo autorizó se haya ido.

El informe AI Agents at Work 2026 de Okta encontró que el 58% de las organizaciones sufrieron un incidente de seguridad relacionado con IA en el último año, sin embargo, el 90% de los ejecutivos reportaron carecer de visibilidad completa sobre qué agentes de IA están operando dentro de su organización. La brecha entre adopción y gobernanza es donde reside el riesgo.

Violaciones de cumplimiento y multas regulatorias

Las aplicaciones no autorizadas no cumplen con el requisito del Artículo 32 del GDPR de «medidas técnicas y organizativas apropiadas» para proteger los datos personales. No satisfacen los requisitos de salvaguardas técnicas de HIPAA bajo 45 CFR § 164.312. No cumplen con el Requisito 12.8 de PCI-DSS para la gestión de proveedores de servicios externos.

La Ley de IA de la UE añade otra capa. Los sistemas de IA de alto riesgo utilizados sin una gobernanza adecuada conllevan penalizaciones de hasta 15 millones de euros o el 3% de la facturación anual global según el Artículo 99(4).

El sector de servicios financieros ya ha visto cómo es la aplicación regulatoria en la práctica. En septiembre de 2022, la SEC y la CFTC multaron a 16 firmas de Wall Street con un total combinado de 1.800 millones de dólares por empleados que usaban WhatsApp y otras aplicaciones de mensajería no aprobadas para comunicaciones comerciales — una violación típica de shadow IT que los reguladores trataron como un fallo de mantenimiento de registros. El comunicado de prensa de la SEC deja claro que el uso «generalizado y prolongado» de comunicaciones fuera del canal oficial no es un factor atenuante; es uno agravante.


Exposición regulatoria europea: GDPR, NIS2 y DORA

Para las organizaciones que operan en la UE, el shadow IT crea una exposición regulatoria por capas a través de tres marcos distintos. Cada uno apunta a una dimensión diferente del problema, y juntos dejan muy poco espacio para «no lo sabíamos».

GDPR: Procesadores no autorizados y transferencias transfronterizas

El Artículo 32 del GDPR es la disposición que más citan las organizaciones. Pero el Artículo 28 es el que el shadow IT viola primero. Toda herramienta SaaS no autorizada que procese datos personales es, en términos del GDPR, un encargado del tratamiento. El Artículo 28 requiere un acuerdo de procesamiento de datos (DPA) por escrito con cada encargado antes de que comience el procesamiento. Un empleado que se registra en una herramienta de IA gratuita usando su correo corporativo y le introduce datos de clientes ha creado una relación de encargado no autorizada — sin DPA, sin diligencia debida y sin registro.

Los Artículos 44 a 49 agravan la exposición. Muchas herramientas SaaS y de IA con sede en EE. UU. transfieren datos personales fuera del Espacio Económico Europeo. Sin un mecanismo de transferencia válido (Cláusulas Contractuales Tipo, una decisión de adecuación o Normas Corporativas Vinculantes), esa transferencia viola el GDPR independientemente de cómo se haya adoptado la herramienta. Los empleados que eligen herramientas de forma independiente no tienen visibilidad sobre dónde se procesan o almacenan los datos.

Las autoridades europeas de protección de datos han aplicado ambas disposiciones. En 2023, la Comisión de Protección de Datos de Irlanda multó a Meta con 1.200 millones de euros bajo el Artículo 46 por transferencias ilegales de datos a EE. UU. — la mayor multa del GDPR hasta la fecha. Aunque ese caso involucraba a un operador de plataforma y no a un usuario empresarial final, el principio subyacente se aplica: la ausencia de un mecanismo de transferencia válido es una violación, independientemente de la intención.

NIS2: Control de acceso y obligaciones de la cadena de suministro

La Directiva NIS2 (Directiva UE 2022/2555), aplicable a entidades esenciales e importantes en toda la UE desde octubre de 2024, aborda directamente las condiciones que crea el shadow IT. El Artículo 21(2) establece diez medidas mínimas de gestión de riesgos de ciberseguridad. Tres están directamente implicadas por el shadow IT:

  • Artículo 21(2)(d): Seguridad de la cadena de suministro, incluyendo aspectos de seguridad relativos a las relaciones entre cada entidad y sus proveedores directos o prestadores de servicios. Toda herramienta SaaS no autorizada es, en efecto, una relación de proveedor no verificada.
  • Artículo 21(2)(i): Políticas y procedimientos relativos al uso de criptografía y, cuando proceda, cifrado.
  • Artículo 21(2)(j): Seguridad de recursos humanos, políticas de control de acceso y gestión de activos.

Las penalizaciones de NIS2 alcanzan los 10 millones de euros o el 2% de la facturación anual global para entidades esenciales, y 7 millones de euros o el 1,4% para otras. La transposición por parte de los Estados miembros varía, pero el marco ya está activo en toda la UE.

La página de cumplimiento NIS2 de Passwork cubre en detalle cómo la gestión centralizada de credenciales se alinea con los requisitos del Artículo 21 de NIS2.

DORA: Riesgo de terceros TIC para entidades financieras

El Reglamento de Resiliencia Operativa Digital (DORA, Reglamento UE 2022/2554) está en vigor desde enero de 2025 para las entidades financieras que operan en la UE: bancos, aseguradoras, empresas de inversión, procesadores de pagos y sus proveedores críticos de TIC. El Artículo 28 requiere que las entidades financieras mantengan un registro de todos los proveedores de servicios TIC de terceros y realicen la diligencia debida precontractual antes de incorporar a cualquier nuevo proveedor.

El shadow SaaS está directamente dentro del ámbito de aplicación. Un empleado de un banco que adopta una herramienta de gestión de proyectos o un asistente de IA no autorizado ha creado una relación con un tercero TIC no registrada. Bajo DORA, eso no es un problema de gobernanza de TI; es una infracción regulatoria. Las Autoridades Europeas de Supervisión (EBA, ESMA, EIOPA) tienen autoridad supervisora para investigar y sancionar. En las jurisdicciones donde la transposición nacional lo prevé, también puede aplicarse responsabilidad penal a nivel directivo.

Para los equipos de TI y cumplimiento del sector financiero, el descubrimiento de shadow IT ya no es una buena práctica. Bajo DORA, es una obligación legal.

Regulación Artículo clave Implicación del shadow IT Penalización máxima
GDPR Art. 28 (contratos con encargados), Art. 32 (medidas de seguridad), Art. 44-49 (transferencias a terceros países) Toda herramienta SaaS no autorizada que procese datos personales es un encargado del tratamiento no registrado. Sin DPA vigente = violación directa del Art. 28. La sincronización de datos transfronteriza a servidores fuera del EEE activa los Art. 44-49. 20 millones de euros o 4% de la facturación anual global, lo que sea mayor (Art. 83(4-5))
NIS2 Art. 21 (gestión de riesgos de ciberseguridad), Art. 23 (notificación de incidentes) Las herramientas de terceros no gestionadas amplían la superficie de ataque sin pasar por el proceso de gestión de riesgos de la organización. Los incidentes de shadow IT pueden activar obligaciones de notificación obligatoria bajo el Art. 23. Entidades esenciales: 10 millones de euros o 2% de la facturación global. Entidades importantes: 7 millones de euros o 1,4% de la facturación global (Art. 34)
DORA Art. 28 (riesgo de terceros TIC), Art. 30 (disposiciones contractuales) Las entidades financieras deben registrar y evaluar a todos los proveedores de TIC de terceros. Las herramientas de shadow IT utilizadas por el personal evitan por completo este requisito, creando dependencias TIC no registradas y riesgo de concentración. Pagos periódicos de penalización de hasta el 1% de la facturación diaria mundial promedio; responsabilidad penal para la dirección donde la transposición nacional lo prevea
Ley de IA de la UE Art. 6-7 (clasificación de IA de alto riesgo), Art. 52 (obligaciones de transparencia), Art. 99 (penalizaciones) Los empleados que utilizan herramientas de IA no autorizadas para decisiones de RRHH, calificación crediticia o gestión de infraestructuras críticas pueden constituir un despliegue no registrado de sistemas de IA de alto riesgo según el Anexo III. 35 millones de euros o 7% de la facturación anual global para prácticas de IA prohibidas (Art. 99(3)); 15 millones de euros o 3% para incumplimiento de IA de alto riesgo (Art. 99(4))


El impacto financiero: Cuantificando el coste del shadow IT

El shadow IT conlleva dos costes financieros distintos: exposición a brechas y gasto desperdiciado. El informe Cost of a Data Breach 2025 de IBM encontró que la participación del shadow AI añade 670.000 dólares al coste promedio de una brecha de 4,44 millones de dólares. En el lado del gasto, el SaaS Management Index 2026 de Zylo cifra el gasto promedio desperdiciado en licencias en 21 millones de dólares por año — impulsado por herramientas redundantes, puestos sin usar y compras de las que TI nunca tuvo conocimiento.

Datos de IBM 2025: La penalización de 670.000 $ del shadow AI

El informe Cost of a Data Breach de IBM de 2025 es el punto de referencia más autorizado disponible para entender las consecuencias financieras de la IA no gestionada. Los números principales:

  • Coste promedio global de una brecha: 4,44 millones de dólares
  • La participación del shadow AI añade 670.000 dólares a ese promedio, llevando la cifra con shadow AI involucrado a aproximadamente 5,11 millones de dólares
  • El 97% de los incidentes relacionados con IA involucraban sistemas sin controles de acceso adecuados
  • El 20% de las organizaciones reportaron un incidente de seguridad directamente vinculado al shadow AI en 2025

El incremento de 670.000 dólares es el coste adicional de investigación, contención, notificación y remediación cuando están involucrados sistemas de IA que los equipos de seguridad desconocían.

Gasto de TI desperdiciado y licencias redundantes

Las organizaciones pagan por herramientas aprobadas mientras los empleados adoptan silenciosamente alternativas gratuitas o más baratas. El resultado: funcionalidad duplicada, licencias abandonadas y gasto que nadie gestiona.

Según el SaaS Management Index 2026 de Zylo, la organización promedio desperdicia 21 millones de dólares al año solo en licencias SaaS sin usar — y la tasa de utilización promedio en las carteras SaaS empresariales se sitúa en apenas el 47%. Para empresas medianas con 500 o menos empleados, esa cifra aún alcanza los 4,2 millones de dólares anuales en gasto desperdiciado en licencias.

El patrón es predecible: las compras descentralizadas significan que los equipos se registran en herramientas de forma independiente, a menudo sin saber que ya existe un contrato empresarial para la misma categoría. Cuando ocurre un incidente de seguridad además de eso, los costes de remediación agravan el desperdicio base en una exposición financiera material.


Cómo detectar el shadow IT y el shadow AI

Detectar el shadow IT en 2026 requiere combinar al menos cinco fuentes de datos: despliegue de CASB (Cloud Access Security Broker), análisis de logs DNS, EDR (Endpoint Detection and Response), revisión de datos de gastos y escaneo de integraciones de correo electrónico. Cada método cubre una porción diferente del entorno. Ninguno lo cubre todo. Los puntos ciegos son estructurales, no incidentales — ninguna herramienta única ve simultáneamente los dispositivos personales, las cuentas de nivel gratuito y los endpoints gestionados.

Monitoreo de endpoints y extensiones de navegador

Las herramientas EDR y las auditorías de extensiones de navegador pueden revelar el uso de SaaS no autorizado directamente en el dispositivo. El análisis del historial del navegador, los inventarios de extensiones y el monitoreo basado en agentes detectan actividad que nunca toca la red corporativa.

La limitación: los entornos BYOD (Bring Your Own Device) y los dispositivos personales usados para trabajar son en gran medida invisibles para las herramientas de endpoint a menos que la organización haya desplegado MDM (Mobile Device Management) con el alcance apropiado.

Análisis de red: Logs DNS y de proxy

Los logs de consultas DNS y los datos de proxy web revelan a qué dominios están accediendo los empleados. Los picos de tráfico a dominios SaaS desconocidos, servicios de IA o plataformas de intercambio de archivos aparecen claramente en los logs DNS incluso cuando el contenido está cifrado.

Este método funciona bien para el tráfico de red corporativa. No detecta nada de lo que ocurre sobre conexiones móviles, redes domésticas o VPNs que enrutan fuera del proxy corporativo. DNS-over-HTTPS (DoH) y DNS-over-TLS (DoT) cifran las consultas de extremo a extremo, evitando por completo la inspección DNS tradicional sin una política de firewall adicional para bloquearlos.

CASB: Fortalezas y limitaciones

Un CASB (Cloud Access Security Broker) se sitúa entre los usuarios y los servicios en la nube, proporcionando visibilidad, aplicación de políticas y prevención de pérdida de datos para aplicaciones autorizadas y no autorizadas. Los CASB son la herramienta más específicamente diseñada para la detección de shadow IT y pueden identificar miles de servicios en la nube en uso en una organización.

La limitación práctica es la cobertura. Los CASB funcionan mejor cuando el tráfico se enruta a través de ellos — son más efectivos para dispositivos gestionados en redes corporativas. Los empleados que usan cuentas personales en dispositivos personales, o herramientas de IA accedidas a través del navegador sin SSO, pueden no ser visibles. Las funciones de shadow AI integradas dentro de herramientas SaaS ya autorizadas tampoco se detectan normalmente, ya que el dominio padre ya está aprobado.

Método Cobertura Puntos ciegos Complejidad de despliegue
CASB Aplicaciones en la nube autorizadas y no autorizadas enrutadas a través de proxy o conector API; identifica permisos OAuth y movimiento de datos entre aplicaciones Dispositivos personales no inscritos en MDM; tráfico TLS 1.3 con SNI cifrado sin descifrado SSL completo; funciones de shadow AI dentro de herramientas SaaS autorizadas Alta — requiere encadenamiento de proxy o integración API por cada tenant SaaS
Monitoreo DNS Identifica dominios consultados por endpoints gestionados; detecta el primer contacto con nuevas herramientas SaaS antes de que se establezca una sesión DoH y DoT cifran las consultas de extremo a extremo; los puntos de acceso personales enrutan fuera del DNS corporativo; sin visibilidad sobre los datos transferidos Baja a media — desplegar un resolver DNS o reenviar logs al SIEM; el bloqueo de DoH requiere política de firewall adicional
Endpoint EDR Visibilidad profunda de la ejecución de procesos, escrituras de archivos, conexiones de red y actividad del navegador en dispositivos gestionados Los dispositivos personales y BYOD no tienen agente; los portátiles de contratistas fuera del alcance de MDM; las herramientas SaaS basadas en navegador dejan una huella de proceso mínima Media — el despliegue de agentes en la flota gestionada es sencillo; BYOD requiere política de inscripción MDM
Análisis de gastos Detecta suscripciones SaaS en tarjetas corporativas o presentadas como gastos; revela herramientas que evitaron TI a través de presupuestos departamentales Las herramientas de nivel gratuito no generan registro financiero; las compras con tarjeta personal nunca aparecen en los sistemas corporativos Baja — sin despliegue técnico; requiere colaboración entre finanzas y TI
Escaneo de integraciones de correo electrónico Escanea bandejas de entrada en busca de correos de bienvenida y confirmaciones de prueba de SaaS; identifica cuentas registradas con correo corporativo en plataformas no autorizadas Las herramientas registradas con correo personal son invisibles; el acceso otorgado mediante OAuth no deja rastro en la bandeja de entrada Baja — acceso API de solo lectura a la plataforma de correo; se necesita revisión de la política de privacidad antes del despliegue

Un marco de 6 pasos para gestionar el shadow IT

El Marco de Gobernanza de Shadow IT es un proceso de seis pasos: descubrir y clasificar, centralizar credenciales, establecer políticas, agilizar aprobaciones, automatizar el offboarding y construir un programa de concienciación de seguridad. Aborda tanto las dimensiones técnicas como las conductuales del problema. Bloquear herramientas no autorizadas sin habilitar alternativas aprobadas más rápidas falla consistentemente.

Paso 1. Descubrir y clasificar

No se puede gobernar lo que no se puede ver. Comience con un barrido de descubrimiento completo utilizando una combinación de análisis de logs DNS, despliegue de CASB, monitoreo de endpoints y revisión de datos de gastos. El resultado debe ser un inventario clasificado: autorizado, tolerado (conocido pero no aprobado formalmente) y no autorizado.

Clasifique cada aplicación por sensibilidad de datos. Un corrector gramatical gratuito que accede a borradores de correo electrónico tiene un perfil de riesgo diferente a un asistente de codificación de IA con acceso a repositorios.

Paso 2. Implementar una gestión segura de credenciales

Cada cuenta de shadow IT es una credencial no gestionada. La solución no es prohibir las cuentas; es poner las credenciales bajo control centralizado.

Una bóveda centralizada con control de acceso basado en roles (RBAC) proporciona a los empleados un lugar seguro y conveniente para almacenar y compartir credenciales tanto para herramientas aprobadas como para las recién aprobadas. Cuando el acceso está centralizado, el offboarding se vuelve determinístico: revoque el acceso a la bóveda, y el empleado pierde el acceso a todas las credenciales almacenadas allí.

Paso 2. Implementar una gestión segura de credenciales

Passwork está disponible como un despliegue autoalojado o en la nube, dando a los equipos la flexibilidad de elegir dónde residen los datos de credenciales. El modelo autoalojado mantiene todo dentro de su propia infraestructura sin dependencia de servicios en la nube de terceros; la opción en la nube le permite comenzar a funcionar sin gestionar su propia infraestructura de servidores. En cualquier caso, los administradores obtienen visibilidad completa de quién tiene acceso a qué y un registro de auditoría completo de cada operación con credenciales. Consulte las guías técnicas para obtener detalles sobre despliegue e integración.

Paso 3. Establecer políticas claras de IA y SaaS

Una prohibición general será ignorada incluso por las personas que la aplican. Una política que defina cómo obtener herramientas aprobadas, qué clasificaciones de datos están permitidas en las herramientas de IA, y qué sucede con los permisos OAuth cuando un empleado se va, es aplicable.

La política debe abordar específicamente:

  • Clasificaciones de datos prohibidas para la entrada en herramientas de IA (PII, código fuente, datos financieros, credenciales)
  • Ciclos de aprobación y revisión de permisos OAuth
  • Tiempo máximo de aprobación para nuevas solicitudes de SaaS (los procesos de aprobación lentos son la razón principal por la que los empleados evitan TI)
  • Consecuencias por violaciones de la política

Paso 4. Agilizar el proceso de aprobación

El shadow IT existe porque el camino aprobado es demasiado lento. Si un empleado necesita una herramienta hoy y el proceso de aprobación tarda tres semanas, usará la herramienta sin aprobación y pedirá perdón después, si es que lo pide.

Construya un flujo de aprobación ligero: un formulario de solicitud breve, un SLA de 48 horas para herramientas de bajo riesgo, y un marco de decisión claro basado en la sensibilidad de los datos y la postura de seguridad del proveedor. El objetivo es hacer que «pasar por TI» sea más rápido que «resolverlo por cuenta propia».

Paso 5. Automatizar los flujos de trabajo de offboarding

El offboarding manual es donde nacen las cuentas huérfanas. Cuando un empleado se va, TI normalmente desaprovisiona las cuentas que conoce. Las cuentas de shadow IT, por definición, no están en esa lista.

Los flujos de trabajo de offboarding automatizados, activados por eventos de baja en el HRIS, deben:

  • Revocar el acceso a SSO e IdP inmediatamente
  • Rotar o invalidar todas las credenciales almacenadas en la bóveda centralizada para ese usuario
  • Auditar y revocar los permisos OAuth asociados con la identidad corporativa del usuario
  • Transferir la propiedad de los recursos compartidos antes de que se corte el acceso

Las guías de usuario de Passwork cubren en detalle los flujos de trabajo de offboarding de la bóveda de credenciales, incluyendo cómo manejar contraseñas compartidas y credenciales de cuentas de servicio que necesitan rotarse, no solo revocarse.

El offboarding automatizado comienza por saber qué credenciales existen. La bóveda centralizada de Passwork proporciona ese inventario, y hace que rotar o revocar el acceso sea una sola operación. Explore las funciones de control de acceso de Passwork.

Paso 6. Construir un programa de concienciación de seguridad

Las políticas y herramientas por sí solas no cambian el comportamiento. Los empleados adoptan shadow IT porque no entienden el riesgo, no saben que existe la alternativa aprobada, o encuentran el camino aprobado demasiado lento. Un programa de concienciación de seguridad aborda directamente los dos primeros.

  • Haga el riesgo tangible: mostrar a los empleados un ejemplo real de cómo funciona un ataque de reutilización de credenciales tiene más impacto que una diapositiva sobre «protección de datos». Publicite el conjunto de herramientas aprobadas; los empleados que conocen una alternativa rápida y autorizada tienen menos probabilidades de recurrir a una no aprobada. 
  • Cree una cultura de reporte: los empleados deben sentirse cómodos señalando las herramientas que ya están usando sin temor a un castigo inmediato. El descubrimiento a través del autorreporte es más rápido y más barato que el descubrimiento a través de una brecha.
  • La formación anual no es suficiente. Las sesiones de microformación trimestrales (10-15 minutos, basadas en escenarios) superan consistentemente a los módulos de cumplimiento anuales en estudios de retención. Las simulaciones de phishing que incluyen falsos formularios de registro de SaaS — no solo señuelos por correo electrónico — prueban exactamente el comportamiento que la gobernanza del shadow IT está tratando de cambiar.

Mida el efecto del programa en las tasas de descubrimiento de shadow IT, no solo en los porcentajes de finalización de la formación. La finalización es una métrica de entrada. La reducción en la adopción de herramientas no autorizadas es el resultado que importa.

Conclusión: Haga que el camino aprobado sea más rápido que el atajo

Conclusión: Haga que el camino aprobado sea más rápido que el atajo

Las organizaciones que gestionan eficazmente el shadow IT son las que hicieron que el camino aprobado fuera más rápido que el atajo. No las que tienen las políticas de bloqueo más estrictas.

Eso significa un programa de descubrimiento que funcione continuamente. Una bóveda de credenciales que los empleados realmente quieran usar porque les ahorra tiempo. Un flujo de trabajo de offboarding que se active automáticamente en el momento en que se desencadena un evento de baja en el HRIS. Una política de IA que diga a los empleados lo que pueden hacer con las herramientas de IA, no solo lo que no pueden. Y un programa de concienciación de seguridad que haga el riesgo real en lugar de abstracto.

Para las organizaciones europeas, las apuestas son aún más altas. El Artículo 28 del GDPR, el Artículo 21 de NIS2 y el Artículo 28 de DORA no tratan el shadow IT como un inconveniente de gobernanza; lo tratan como un fallo de cumplimiento con penalizaciones cuantificadas asociadas. El incremento de coste de 670.000 dólares por shadow AI del informe de IBM de 2025 no es una abstracción. Es lo que sucede cuando la gobernanza va por detrás de la adopción. Cierre esa brecha antes de que la próxima brecha argumente el caso por usted.

Passwork es un gestor de contraseñas y secretos diseñado para equipos de TI que gestionan entornos de acceso complejos. Proporciona control centralizado de credenciales, permisos basados en roles y un registro de auditoría completo — disponible como despliegue autoalojado o en la nube. Pruebe Passwork en su infraestructura o explore la opción en la nube.

Preguntas frecuentes

Preguntas frecuentes

¿Qué es el shadow IT en 2026?

El shadow IT en 2026 se refiere a cualquier tecnología (software, aplicaciones SaaS, herramientas de IA o agentes autónomos) utilizada por los empleados sin el conocimiento o la aprobación de TI. Incluye aplicaciones no autorizadas tradicionales como intercambio de archivos y mensajería, y riesgos más nuevos como asistentes de IA que procesan datos sensibles y agentes de IA con acceso OAuth persistente a sistemas corporativos.

¿Cuál es la diferencia entre shadow IT y shadow AI?

El shadow IT es tecnología no gestionada que crea residencia de datos no controlada. El shadow AI es uso de IA no gestionado que crea procesamiento de datos no controlado: modelos que analizan información propietaria, generan outputs y toman acciones a través de permisos delegados. El shadow AI conlleva un mayor riesgo porque los datos no solo se almacenan en algún lugar no autorizado; están siendo procesados y utilizados activamente por sistemas fuera de su perímetro de gobernanza.

¿Cuánto cuesta el shadow IT a las organizaciones?

El informe Cost of a Data Breach 2025 de IBM encontró que la participación del shadow AI añade 670.000 dólares al coste promedio de una brecha de 4,44 millones de dólares, llevando las brechas con shadow AI involucrado a aproximadamente 5,11 millones de dólares. Por separado, la investigación de DataFence de 2026 estima que el incidente promedio de ciberataque por shadow IT cuesta 4,2 millones de dólares. Más allá de los costes de brechas, el shadow IT representa un estimado del 30-40% del gasto total de TI en grandes empresas a través de licencias redundantes y gasto desperdiciado.

¿Cómo se detecta el shadow IT?

La detección efectiva del shadow IT combina múltiples métodos: despliegue de CASB para visibilidad de servicios en la nube, análisis de logs DNS y de proxy para descubrimiento a nivel de red, monitoreo de endpoints para actividad a nivel de dispositivo, y revisión de datos de gastos para suscripciones de pago. Ningún método único proporciona cobertura completa. Las herramientas de integración de correo electrónico también pueden revelar cuentas SaaS creadas con direcciones de correo corporativas, incluyendo herramientas de nivel gratuito que no aparecen en los datos de gastos.

¿Cuál es el mayor riesgo de shadow IT en 2026?

El riesgo de mayor gravedad es la exposición de credenciales a través de cuentas huérfanas y reutilización de contraseñas. Cada aplicación no autorizada es una credencial no gestionada, a menudo protegida por una contraseña reutilizada y sin MFA. Cuando esas credenciales se comprometen (a través de una brecha en el proveedor SaaS, un infostealer o credential stuffing) los atacantes obtienen acceso a cuentas que los equipos de seguridad desconocen y no pueden monitorear.

¿Cómo crea el shadow IT exposición al GDPR?

Toda herramienta SaaS no autorizada que procese datos personales es un encargado del tratamiento no autorizado bajo el Artículo 28 del GDPR, que requiere un acuerdo de procesamiento de datos por escrito antes de que comience el procesamiento. Si esa herramienta tiene sede en EE. UU. y transfiere datos personales fuera del EEE sin Cláusulas Contractuales Tipo u otro mecanismo de transferencia válido, los Artículos 44-49 también se violan. Ambas exposiciones surgen en el momento en que un empleado se registra, independientemente de si TI lo sabe.

¿Cómo se relaciona el shadow AI con la Ley de IA de la UE?

La Ley de IA de la UE impone penalizaciones a las organizaciones que utilizan sistemas de IA de alto riesgo sin una gobernanza adecuada — hasta 15 millones de euros o el 3% de la facturación anual global según el Artículo 99(4). Los empleados que utilizan herramientas de IA no aprobadas que procesan datos personales o influyen en decisiones importantes pueden estar operando sistemas de IA de alto riesgo fuera del marco de cumplimiento de la organización, creando una exposición regulatoria directa sin que haya tenido lugar ninguna evaluación formal de riesgos.

¿Por qué falla bloquear el shadow IT?

La prohibición sin habilitación empuja al shadow IT a la clandestinidad en lugar de eliminarlo. Cuando los empleados no pueden obtener lo que necesitan a través de canales oficiales con suficiente rapidez, encuentran alternativas. La respuesta efectiva es la habilitación estructurada: procesos de aprobación rápidos, alternativas aprobadas y seguras, gestión centralizada de credenciales, y un programa de concienciación de seguridad que haga del camino conforme el camino conveniente.

10 fallos de seguridad en el trabajo remoto (y cómo solucionarlos)
10 fallos de seguridad en el trabajo remoto — y el principio único detrás de todos ellos: la seguridad se rompe donde el camino seguro tiene más fricción que el inseguro. Casos reales, soluciones realistas, una línea base de 5 capas contra la que su equipo puede auditar.
Shadow IT vs shadow AI: Por qué la IA es la mayor amenaza
Los empleados están usando herramientas de IA que usted no aprobó, en cuentas que no puede monitorear, con datos que no puede recuperar. Así es como realmente luce el riesgo y qué debe abordar la gobernanza.
Guía de seguridad de la cadena de suministro: Riesgos de proveedores, regulaciones, control de acceso en 2026
El 48% de las brechas ahora involucran a un tercero. Esta guía cubre los patrones de ataque detrás de SolarWinds, MOVEit y XZ Utils — y los controles de acceso, prácticas de gestión de credenciales y requisitos regulatorios que realmente los detienen.

Shadow IT en 2026: riesgos, detección y cómo gestionarlo

El Shadow IT en 2026 abarca agentes de IA, cuentas SaaS huérfanas y sesiones LLM sin supervisión — riesgos que la mayoría de las organizaciones no pueden ver. Descubra qué ha cambiado, cuánto cuesta y cómo un marco de gobernanza de 6 pasos cierra la brecha.