Secure password sharing for Dutch hosting companies
The Netherlands has a strong and varied hosting landscape. From large players such as TransIP, Antagonist and Byte to hundreds of smaller managed hosting providers and resellers — Dutch hosting companies run the digital infrastructure of a large part of the Dutch SMB market. And with every new client account, every server migration and every environment handover, the same question comes up: how do you share the credentials safely?
The daily reality at a hosting company
A typical hosting company exchanges dozens of logins every day:
- New accounts: SFTP details, cPanel logins, database passwords on account activation
- Server migrations: temporarily handing root access or sudo rights to a migration specialist
- Support escalations: passing details to a colleague or an external party for troubleshooting
- Client handovers: transferring all credentials properly when a service ends
At most hosting companies this still runs through a mix of email, ticketing systems such as WHMCS or Freshdesk, and sometimes even WhatsApp or SMS. Every one of those channels leaves a trail.
Risks specific to the hosting sector
Hosting companies carry a particular responsibility: they manage not only their own data but that of all their clients. A single compromised root password can open up dozens or hundreds of client environments. That makes the sector an attractive target.
Concrete risks of sharing passwords insecurely:
- Phishing through tickets: attackers pose as clients and request credentials through a support ticket
- Unmanaged email archives: departed employees who still have access to their old mailbox
- Shared Slack channels with clients: a password in a shared channel is visible to everyone in it
- Ticketing systems with weak access control: not every employee needs to be able to see every password
Dutch hosting companies and GDPR compliance
Under the GDPR, hosting companies are usually processors: they process data on behalf of their clients. At the same time they are controllers for their own customers' data (name, address, payment details). The credentials they manage grant indirect access to third parties' personal data, which calls for extra care.
The Dutch Data Protection Authority has made clear in its enforcement practice that technical service providers can also be held liable when the security of credentials falls short.
A better way of working for hosting teams
On account activation: Send new clients their credentials through a one-time secure link instead of by email. The client opens the link, notes the details, and the link expires automatically. No password ever sits in your sent items.
On support escalations: When a colleague or external engineer needs temporary access, create a link with a short expiry — four or eight hours is usually enough. Afterwards the link has already expired, even if the recipient wanted to forward it.
On client handovers: Instead of one long document with every login sent by email, send a series of secure links that each work once. The client opens them, saves the details in their own password manager, and the handover is done.
Fitting into existing workflows
Creating a link takes seconds and needs no account, so the step fits into the account activation procedure you already have. Note it in the runbook next to the moment the credentials are generated, and paste the link into the welcome email instead of the password itself. That way the safe method becomes the default without staff having to think about it separately.
For Dutch hosting companies looking to professionalise their service and get their GDPR compliance in order, PassTransfer is a low-threshold first step in the right direction.