Secure password sharing for Dutch MSPs
Managed service providers are the quiet backbone of the Dutch digital economy. They run the IT infrastructure of small and mid-sized businesses, keep an eye on servers and endpoints, and support clients with everything that touches their digital environment. Exchanging passwords and credentials is a daily reality in that work — and at the same time one of the biggest security risks in the sector.
What makes MSPs vulnerable?
An MSP typically manages dozens to hundreds of client environments. That means an enormous volume of credentials: admin passwords for servers, firewall logins, RDP credentials, API keys for monitoring tools, and access to cloud platforms such as Microsoft 365 and Google Workspace.
Those credentials are shared regularly:
- With new colleagues during onboarding
- With external engineers on temporary assignments
- With clients when management is handed over
- With suppliers during hardware replacement or a software migration
And then there is the reality of MSP work: it is busy, something is always urgent, and speed often wins over procedure. That is understandable, but it is exactly the environment in which security mistakes get made.
The Dutch MSP market and NIS2
The European NIS2 directive, implemented in the Netherlands through the Cyberbeveiligingswet, has direct consequences for MSPs. Dutch MSPs are explicitly designated as "managed security service providers" and in some cases therefore fall under the directive's obligations. One of its core requirements is taking appropriate technical measures for access management.
Even without a NIS2 obligation, though, clients set ever higher expectations for their IT provider's security. More and more Dutch SMBs ask for an ISAE 3402 report or ISO 27001 certification from their MSP during procurement. A careful approach to password management is a visible signal of maturity.
Common mistakes at MSPs
Passwords in the ticketing system Many MSPs use PSA tools such as Autotask, ConnectWise Manage or TOPdesk. Staff sometimes drop passwords straight into a ticket note, which makes them visible to everyone with access to the ticket — sometimes including the client reading along through the customer portal.
Shared password managers without access control Tools like Bitwarden or 1Password are excellent for password management, but at many MSPs every employee has access to every shared vault. When someone leaves the company, rotating passwords by hand becomes a major project.
Passwords in onboarding emails At the start of a new client contract, or when a new employee joins, credentials are often sent by email. That email stays in the sent items forever.
A better approach for Dutch MSPs
PassTransfer fits an MSP's way of working without a complete overhaul of existing processes:
Temporary access for external engineers Create a one-time link with a short expiry — four hours, say. The external engineer opens the link, gets the credentials, and after use — or once the time limit passes — the link is invalid. No lasting trace in the ticketing system or in email.
Client handovers When handing management to a client or another MSP, send secure links per category (hosting, firewall, cloud platform). The recipient opens each link once and stores the details in their own system.
Onboarding new employees Instead of a spreadsheet full of credentials, send new colleagues a series of one-time links. That removes the spreadsheet you would otherwise have to maintain, and no password ever sits in an onboarding email.
PassTransfer Pro for MSPs
With PassTransfer Pro an MSP can offer a branded experience. Clients receive secure links from a subdomain matching your company name, complete with your logo and house colours. That strengthens trust and reduces the risk of clients mistaking a legitimate link for phishing.
Dutch MSPs that want to professionalise their security practice will find PassTransfer a simple, effective tool that delivers value straight away — without months of implementation.