Alex Muntyan

Alex Muntyan

CEO · Enterprise password security

Under Alex's leadership, Passwork has been driven by a straightforward premise: enterprise-grade security should not require enterprise-grade complexity. Over the years, the company has grown from a startup into a trusted European password management platform serving thousands of organizations across the EU, the US, and beyond — fully bootstrapped, founder-owned, and independent.

He writes about the practical side of information security: how organizations actually manage credentials under real-world constraints, where compliance frameworks meet daily operations, and why most security tools fail before they're ever deployed. His perspective is shaped by years of building a product that security teams choose to use.

Articles by Alex Muntyan

Latest Jun 4, 2026
Employees are using AI tools you didn't approve, on accounts you can't monitor, with data you can't recover. Here's...

Shadow IT vs Shadow AI: Why AI is the bigger threat

Employees are using AI tools you didn't approve, on accounts you can't monitor, with data you can't recover. Here's what the risk actually looks like and what governance needs to address.

Shadow IT vs Shadow AI: Why AI is the bigger threat
Jun 3, 2026 14 min read
Bulgaria's NIS2 grace period ended on 1 June 2026 — board members now face full personal fines, not the discounted 50%...

NIS2 latest news: May 2026 enforcement and implementation update

Bulgaria's NIS2 grace period ended on 1 June 2026 — board members now face full personal fines, not the discounted 50% rate that applied through May. Luxembourg's NIS2 Directive transposition law entered into force on 10 May 2026, leaving four member states still without implementing legislation....

NIS2 latest news: May 2026 enforcement and implementation update
May 31, 2026 21 min read
VaultJacking targets the Google Password Manager PIN to unlock your entire vault. One captured PIN exposes every saved...

VaultJacking: How one PIN exposes the Google password manager vault

VaultJacking targets the Google Password Manager PIN to unlock your entire vault. One captured PIN exposes every saved password and passkey. Learn how the attack works, who's at risk, and what to do if you've been phished.

VaultJacking: How one PIN exposes the Google password manager vault
May 28, 2026 11 min read
NIS2 is mandatory. Regulators demand proof: who accessed what, when, and why. A password manager with RBAC, MFA, and...

NIS2 compliance made easy: How a password manager saves you money and time

NIS2 is mandatory. Regulators demand proof: who accessed what, when, and why. A password manager with RBAC, MFA, and immutable audit trails is the technical foundation for compliance. Benefit: €210k annual IT savings plus protection from €10 million fines.

NIS2 compliance made easy: How a password manager saves you money and time
May 28, 2026 17 min read
Stolen credentials dominate breaches in 2026. NIS2 Article 21 mandates 10 security measures to eliminate...

NIS2 compliance: The complete access management roadmap for 2026

Stolen credentials dominate breaches in 2026. NIS2 Article 21 mandates 10 security measures to eliminate credential-based attack vectors. This guide covers technical requirements, the 24-hour incident reporting obligation, ENISA's MFA tiers, and a 5-phase roadmap to audit-ready compliance.

NIS2 compliance: The complete access management roadmap for 2026
May 28, 2026 15 min read
Every IT admin who runs KeePass for a team tells the same story. It starts with one shared .kdbx file on a network...

Password and access management for SMBs: Is KeePass enough?

Every IT admin who runs KeePass for a team tells the same story. It starts with one shared .kdbx file on a network drive. Then someone can't open it because a colleague has it locked. Then a junior sysadmin saves over a change someone else made an hour ago. Then an employee leaves, and nobody's...

Password and access management for SMBs: Is KeePass enough?
May 28, 2026 3 min read
Passwork has been named a Top Performer Spring 2026 by SourceForge, ranking in the top 10% of 100,000+ solutions. The...

Passwork wins Top Performer Spring 2026 on SourceForge

Passwork has been named a Top Performer Spring 2026 by SourceForge, ranking in the top 10% of 100,000+ solutions. The badge is based entirely on verified reviews — 4.8 stars overall, with a perfect 5.0 for support.

Passwork wins Top Performer Spring 2026 on SourceForge
May 20, 2026 16 min read
Hardcoded secrets are credentials written directly into code instead of injected at runtime. They survive in Git...

What are hardcoded secrets and why are they so risky?

Hardcoded secrets are credentials written directly into code instead of injected at runtime. They survive in Git history, CI/CD logs, and forks long after the "fix" commit. This guide covers how they spread, how to detect them, and how to eliminate them.

What are hardcoded secrets and why are they so risky?
May 20, 2026 22 min read
Secret rotation fails when it's treated as a scheduled task rather than a lifecycle. This guide covers all seven stages...

Secrets rotation lifecycle: From creation to revocation

Secret rotation fails when it's treated as a scheduled task rather than a lifecycle. This guide covers all seven stages — from creation and ownership to safe rotation, emergency revocation, and audit evidence.

Secrets rotation lifecycle: From creation to revocation
May 15, 2026 27 min read
28.65 million secrets leaked on public GitHub in 2025. AI is accelerating the problem. Internal repos are 6× more...

The state of secrets sprawl in 2026: Key findings from GitGuardian's report

28.65 million secrets leaked on public GitHub in 2025. AI is accelerating the problem. Internal repos are 6× more exposed than public ones. And 64% of secrets from 2022 are still valid today. Here is what the data means for your security posture.

The state of secrets sprawl in 2026: Key findings from GitGuardian's report