What happens when your only IT person leaves.

Alex Macklin, CEO at InterIntra
Alex MacklinAugust 2026 · InterIntra

Every business owner I speak to has a version of the same quiet worry. There is one person who knows how the technology works, and everyone else knows to ask them. It is a comfortable arrangement right up until the morning a resignation email arrives, and then it becomes the most urgent problem in the business.

This is key person risk, and IT is where it hides best. Nobody notices a single point of failure while that point is turning up every day and doing an excellent job.

This is not a criticism of your IT person

Worth saying plainly, because the topic gets misread as a trust issue. Good internal IT staff accumulate context far faster than they can write it down, because they are spending their days keeping the business running rather than describing how they do it. The exposure is a by-product of one capable person carrying a workload designed for a team. It is a structural problem, and it belongs to the business to solve, not to them.

What actually walks out the door

The passwords are the easy part, and they are the part most handovers concentrate on. What genuinely hurts is everything sitting one layer underneath:

None of that appears on an asset register. All of it costs money to rediscover.

The two-week handover is mostly a myth

A notice period sounds like a safety net. In practice the departing person spends it finishing business-as-usual work, wrapping up projects and having farewell coffees, and produces a handover document in whatever hours are left. It will be accurate and it will be thin, because they are documenting the answers to questions you have not thought to ask yet.

The real handover happens over the following six months, in the form of phone calls to someone who no longer works for you. That works for a while, out of goodwill, and then it stops.

A quiet test you can run this week

You do not need an audit to size this up. Ask yourself whether, if that person were unreachable tomorrow, someone else in the business could:

Every answer of "we would have to ask them" is a real, measurable exposure rather than a hypothetical one. Most businesses that run this exercise honestly find three or four.

Fixing it does not mean replacing anyone

The instinct is to hire a second IT person. For most small and medium businesses that is hard to justify, and two people can still share the same blind spots. The cheaper and more durable fixes are structural:

Two of those three cost almost nothing. They are administrative decisions, not technology purchases.

The version nobody plans for

Resignations at least come with notice. Illness, injury, a family emergency or a well-earned month of long service leave arrive with far less, and they create exactly the same gap. If your continuity planning covers fire, flood and ransomware but not one person being unavailable for six weeks, it has a hole in the middle of it. It is the same discipline as any other business continuity risk assessment, applied to people rather than systems.

The bottom line

The knowledge should belong to the business, not to a person.

Your IT person leaving should be a resourcing problem, not an emergency. Own your tenancy and your vendor accounts, keep documentation current as a habit rather than a project, and make sure at least one other party understands the environment. Do it while they are still here and the handover becomes routine.

If that quiet test turned up more gaps than you were expecting, the fastest way to close them is an independent look at the environment. Our ICT audits document what you actually have and where the single points of failure sit, and IT staff placements and co-managed support give your internal person backup rather than a replacement. Either way, the goal is the same: the business keeps the knowledge.

Alex Macklin is the CEO of InterIntra, an Adelaide-based ISO 27001 certified managed service provider working alongside internal IT teams across South Australia. Meet the team →

Frequently Asked Questions

Key person risk is when the continuity of a business function depends on one individual. In IT it usually means one person holds the administrative access, the vendor relationships and the undocumented reasoning behind how the environment is configured. If they become unavailable for any reason, the business cannot make changes safely or recover quickly.

No. Key person risk is structural, not personal. Capable internal IT staff accumulate context far faster than they can document it, because they are busy keeping the business running. The exposure is a by-product of them doing the job well without a second set of eyes, and addressing it is the business's responsibility rather than theirs.

A useful baseline covering identity, backups, network, licensing and vendor ownership is usually a matter of weeks rather than months, provided it is scoped as a discovery exercise rather than an open-ended documentation project. The bigger gain comes afterwards, from making documentation part of how changes get made so the record stays current.

For many small and medium businesses a second full-time hire is hard to justify, and two people can still share the same blind spots. A co-managed arrangement, where your internal person keeps ownership and an external team provides documentation discipline, escalation and cover for leave, usually addresses the risk at lower cost.

Secure control before you gather knowledge. Confirm the business owns its Microsoft 365 tenancy, domain registrar and key vendor accounts, establish a break-glass administrator account held by the business, and move credentials into a business-owned password manager. Then spend the notice period on context and decisions rather than on password lists.

Talk to the team

Does your IT rest on one person?

Book a discovery call and we'll map where your single points of failure sit, what the business owns, and how to close the gaps without replacing anyone. No obligation, no pressure.

Book a Discovery Call More Articles