Alex Muntyan

Alex Muntyan

CEO · Enterprise password security

Under Alex's leadership, Passwork has been driven by a straightforward premise: enterprise-grade security should not require enterprise-grade complexity. Over the years, the company has grown from a startup into a trusted European password management platform serving thousands of organizations across the EU, the US, and beyond — fully bootstrapped, founder-owned, and independent.

He writes about the practical side of information security: how organizations actually manage credentials under real-world constraints, where compliance frameworks meet daily operations, and why most security tools fail before they're ever deployed. His perspective is shaped by years of building a product that security teams choose to use.

Articles by Alex Muntyan

Latest Jan 1, 1970
Credentials move between people every day. A developer gets a database credential via Slack. A contractor receives an...

Insecure password sharing: 2026 threats, impacts, and secure solutions

Credentials move between people every day. A developer gets a database credential via Slack. A contractor receives an admin account through email. Finance keeps the payroll system login in a shared spreadsheet. Each handoff is a breach waiting to happen—and in 2026, waiting is measured in...

Insecure password sharing: 2026 threats, impacts, and secure solutions
Jan 1, 1970 NaN min read

Employee offboarding: Guide to secure access revocation in 2026

Jan 1, 1970 8 min read
NIS2 compliance for EU businesses requires a documented, technically enforced password policy under Article 21 of...

Simple NIS2 password policy checklist for EU businesses

NIS2 compliance for EU businesses requires a documented, technically enforced password policy under Article 21 of Directive (EU) 2022/2555. Compromised credentials remain the leading initial access vector across European organizations, and national competent authorities are actively scrutinizing...

Jan 1, 1970 9 min read
Introduction 160,000+ organizations across the EU are now subject to NIS2. 21 of 27 member states have transposed the...

NIS2 compliance made easy: How a password manager saves you money and time

Introduction 160,000+ organizations across the EU are now subject to NIS2. 21 of 27 member states have transposed the directive into national law — and under Article 32 of Directive (EU) 2022/2555, management bodies can be held personally liable for non-compliance. Fines reach €10 million or 2% of...

NIS2 compliance made easy: How a password manager saves you money and time
Mar 6, 2025 7 min read
Digital security demands the highest possible protection for passwords due to modern advances in digital presence. For...

Password security: Understanding salting and peppering

Digital security demands the highest possible protection for passwords due to modern advances in digital presence. For effective password security people need to understand that cybercriminals have developed intricate ways to break passwords. The lack of password security foundation has resulted in...

Password security: Understanding salting and peppering
Apr 1, 2025 8 min read
Businesses that ignore cybersecurity risks face breaches and financial losses. A single flaw can expose millions of...

What is a cybersecurity risk assessment?

Businesses that ignore cybersecurity risks face breaches and financial losses. A single flaw can expose millions of records. A cybersecurity risk assessment helps identify weak points, ensuring compliance and data protection. Learn how to conduct one and safeguard your organization.

What is a cybersecurity risk assessment?
Jan 1, 1970 1 min read
What Are Secrets? Secrets are sensitive digital credentials that grant access to critical systems and resources,...

Secrets management

What Are Secrets? Secrets are sensitive digital credentials that grant access to critical systems and resources, including: * Passwords and passphrases * API keys and access tokens * SSH keys and encryption keys * Digital certificates * Database credentials * Cloud service credentials Key...

Jun 4, 2026 19 min read
Employees are using AI tools you didn't approve, on accounts you can't monitor, with data you can't recover. Here's...

Shadow IT vs Shadow AI: Why AI is the bigger threat

Employees are using AI tools you didn't approve, on accounts you can't monitor, with data you can't recover. Here's what the risk actually looks like and what governance needs to address.

Shadow IT vs Shadow AI: Why AI is the bigger threat
Jun 3, 2026 14 min read
Bulgaria's NIS2 grace period ended on 1 June 2026 — board members now face full personal fines, not the discounted 50%...

NIS2 latest news: May 2026 enforcement and implementation update

Bulgaria's NIS2 grace period ended on 1 June 2026 — board members now face full personal fines, not the discounted 50% rate that applied through May. Luxembourg's NIS2 Directive transposition law entered into force on 10 May 2026, leaving four member states still without implementing legislation....

NIS2 latest news: May 2026 enforcement and implementation update
May 31, 2026 21 min read
VaultJacking targets the Google Password Manager PIN to unlock your entire vault. One captured PIN exposes every saved...

VaultJacking: How one PIN exposes the Google password manager vault

VaultJacking targets the Google Password Manager PIN to unlock your entire vault. One captured PIN exposes every saved password and passkey. Learn how the attack works, who's at risk, and what to do if you've been phished.

VaultJacking: How one PIN exposes the Google password manager vault