When your password manager isn't available
Consolidating every credential into one vault is the right move, and it creates one concentrated failure: if you can't open the vault, you can't open anything. Most people never think about this until the morning it happens. A break-glass kit takes an afternoon to build and is the difference between an inconvenience and a very bad week.
The ways it actually fails
Worth separating, because they need different answers:
- Provider outage. Rare and usually brief. Most managers cache an encrypted local copy, so you often still have read access — but not always on a device you haven't opened recently.
- You lose the master password. With end-to-end encryption, nobody can recover it for you. That's the trade you accepted for the provider not being able to read your data.
- You lose the vault's second factor. More common than forgetting the password. The phone was the only authenticator, and the recovery codes were saved in the vault it's protecting.
- Device loss with nothing else set up. One phone, one laptop, both in the same bag.
- Account lockout or suspension. Billing failure, a policy action, an account tied to a work identity you no longer hold.
- You're unavailable. Illness, an accident, leaving a job abruptly. Everything works fine — nobody else can get in. This is the failure people plan for least and organisations feel most.
Notice how many are circular: the recovery material for the vault stored inside the vault, or on the single device that just disappeared. Breaking those loops is most of the work.
What goes in the kit
The goal isn't a second copy of everything — that's a second thing to steal. It's the minimum set that lets you rebuild access to the accounts that recover all the others. In practice, that's your Tier 1 list from the inventory: registrar, DNS, primary email, cloud root, the password manager itself.
Include:
- The vault's recovery material — emergency kit, recovery code, or account key. Whatever your provider issues, printed.
- Backup codes for Tier 1 accounts, labelled with the service and the identity that signs in.
- The primary email password, if reaching it depends on the vault.
- A short account list — which services are Tier 1 and which identity each uses. Not passwords; just the map. Without it, someone reconstructing your setup doesn't know where to start.
- A spare hardware key, registered in advance, stored separately.
- Instructions. A page explaining what this is and the order to use it in. Written for someone who isn't you.
Deliberately excluded: the ninety Tier 3 passwords. Those are recoverable through normal password resets once you control the email account, and copying them multiplies your exposure for no benefit.
Could you rebuild access to everything using only the kit, from a borrowed computer, with no phone? If yes, it's complete. If a step depends on something you'd have lost, it isn't.
Where to keep it
Paper, in a physically secure place — a home safe, a locked drawer at a different location, a safe deposit box. Paper is immune to every remote attack, which is exactly why it suits the material you need when everything digital has failed.
The requirements are simple. It must not be in the same place as the devices it recovers, or a single burglary or fire takes both. It must be somewhere you can reach without the credentials it contains. And it needs a date on it, because a kit you can't tell the age of is a kit you won't trust.
If paper genuinely won't work for you, an encrypted file on offline media — a USB drive in a safe — is a reasonable second choice. Encrypt it with a passphrase you've memorised and never used elsewhere. But be honest: an encrypted drive whose passphrase is in the vault is not a backup, and offline media degrades and its connectors go obsolete. Check it annually.
Not cloud storage, a photo in your camera roll, a notes app, or an email to yourself. These are online, syncing, and reachable by anyone who compromises the account they live in — which may well be the account you're trying to recover.
Someone else needs to be able to get in
If you're the only person who can reach anything, your organisation has a single point of failure wearing a lanyard. Three mechanisms, in rough order of preference:
Emergency access built into the manager. Many offer a designated contact who can request access, with a waiting period during which you can deny it. This is the cleanest option: no credential changes hands in advance, and the delay protects against a contact acting improperly. Set it up now and confirm your contact knows they're listed.
A shared organisational vault. Business credentials belong in a shared collection rather than one person's personal vault — even when only one person uses them day to day. This solves the bus factor by default and costs nothing.
A sealed physical envelope. Low-tech and effective for a small team. The kit goes in a signed, sealed envelope in a safe that a second person can access. Tampering is visible, and opening it is a deliberate act rather than a quiet one. Re-seal and re-date whenever it changes.
Whatever you choose, tell the person. A break-glass plan nobody knows exists isn't a plan.
Reduce what needs recovering
Some architecture choices shrink the problem before you build the kit:
Register two hardware keys and keep the second somewhere else. This is the highest-value item here — a spare key registered in advance turns "lost my Tier 1 access" into "used the other key". It's also the most-skipped step in every hardware key setup.
Keep more than one device enrolled. A vault that opens on both your laptop and your phone survives losing either.
Break the circular dependencies. Your primary email's second factor should not live only on the phone whose replacement requires email access. Trace each Tier 1 recovery path and check it doesn't route through something you'd have lost.
Use role addresses for business accounts. An account registered to ops@ rather than an individual can be recovered by whoever holds that mailbox — which is the organisation, not a person.
Test it once a year
An untested plan is a guess. Once a year, half an hour:
- Get the kit out. If you can't find it in five minutes, that's finding number one.
- Check the contents against your current Tier 1 list. Accounts change; kits go stale.
- Try one backup code on a low-risk account to confirm the codes are real and current. Regenerate the set afterwards.
- Verify the spare hardware key still works and is still registered where you think.
- Confirm your emergency contact is still the right person and still knows.
- Re-date the kit and re-seal it.
Update it out of cycle whenever you change the master password, add or remove a Tier 1 account, replace a hardware key, or change who your emergency contact is.
If it happens today
Order matters. Work outward from the accounts that recover the others:
- Stay calm and don't start guessing. Repeated failed attempts trigger rate limits and lockouts, which makes everything slower.
- Get the kit.
- Recover the vault first if you can. If that works, you're done — everything else follows.
- Otherwise, recover the primary email. It's the recovery path for most other accounts, so it's the highest-leverage single account.
- Then the registrar and DNS. These control your domains, and losing them is the hardest thing to undo.
- Work down by tier. Most Tier 3 accounts recover through email password resets once you control the mailbox.
- Afterwards, rotate what you used. Consumed backup codes get regenerated. Anything the kit exposed gets changed.
- Write down what didn't work and fix those gaps while it's fresh. This is the most valuable half hour of the whole episode.
The last step is what turns a bad day into a setup that won't fail the same way twice.