Every business owner I speak to has a version of the same quiet worry. There is one person who knows how the technology works, and everyone else knows to ask them. It is a comfortable arrangement right up until the morning a resignation email arrives, and then it becomes the most urgent problem in the business.
This is key person risk, and IT is where it hides best. Nobody notices a single point of failure while that point is turning up every day and doing an excellent job.
This is not a criticism of your IT person
Worth saying plainly, because the topic gets misread as a trust issue. Good internal IT staff accumulate context far faster than they can write it down, because they are spending their days keeping the business running rather than describing how they do it. The exposure is a by-product of one capable person carrying a workload designed for a team. It is a structural problem, and it belongs to the business to solve, not to them.
What actually walks out the door
The passwords are the easy part, and they are the part most handovers concentrate on. What genuinely hurts is everything sitting one layer underneath:
- The reasoning. Why the file server is configured that way, why that firewall rule exists, why one legacy application has to stay on an old version. Decisions with a good reason behind them look like mistakes to whoever inherits them.
- Vendor relationships. Who to call at the ISP, which reseller holds your licensing, which account has your name on it and which quietly has theirs.
- Administrative control. Global admin on the Microsoft 365 tenancy, the domain registrar login, multi-factor prompts arriving on a phone that is about to leave with its owner.
- The unwritten roadmap. Which switch is out of warranty, when the hardware lease ends, which system has been limping for eighteen months and was next on the list.
- The workarounds. The manual step someone does every Tuesday that keeps a critical process working, which nobody has ever written down because it lives in muscle memory.
None of that appears on an asset register. All of it costs money to rediscover.
The two-week handover is mostly a myth
A notice period sounds like a safety net. In practice the departing person spends it finishing business-as-usual work, wrapping up projects and having farewell coffees, and produces a handover document in whatever hours are left. It will be accurate and it will be thin, because they are documenting the answers to questions you have not thought to ask yet.
The real handover happens over the following six months, in the form of phone calls to someone who no longer works for you. That works for a while, out of goodwill, and then it stops.
A quiet test you can run this week
You do not need an audit to size this up. Ask yourself whether, if that person were unreachable tomorrow, someone else in the business could:
- Sign in as a global administrator to your Microsoft 365 tenancy.
- Find the current backup configuration, and say when a restore was last tested.
- Name every software vendor you pay, and who the account holder is on each one.
- Produce a network diagram and an asset register that match reality.
- Be recognised as an authorised contact by your ISP and telephony provider.
- List which systems are past end of support.
Every answer of "we would have to ask them" is a real, measurable exposure rather than a hypothetical one. Most businesses that run this exercise honestly find three or four.
Fixing it does not mean replacing anyone
The instinct is to hire a second IT person. For most small and medium businesses that is hard to justify, and two people can still share the same blind spots. The cheaper and more durable fixes are structural:
- Take ownership of the essentials. The Microsoft 365 tenancy, the domain registration and the primary vendor accounts should be held in the business's name, with a break-glass administrator account the business controls and credentials stored in a business-owned password manager rather than a personal one.
- Make documentation a standing task, not a project. Documentation written in one heroic push is out of date within a quarter. Written as part of how changes get made, it stays current on its own.
- Put a second set of eyes on the environment. This is what a co-managed arrangement is for. Your internal person keeps ownership and local knowledge, and an external team carries the documentation discipline, the after-hours escalation and the cover when they take leave.
Two of those three cost almost nothing. They are administrative decisions, not technology purchases.
The version nobody plans for
Resignations at least come with notice. Illness, injury, a family emergency or a well-earned month of long service leave arrive with far less, and they create exactly the same gap. If your continuity planning covers fire, flood and ransomware but not one person being unavailable for six weeks, it has a hole in the middle of it. It is the same discipline as any other business continuity risk assessment, applied to people rather than systems.
The knowledge should belong to the business, not to a person.
Your IT person leaving should be a resourcing problem, not an emergency. Own your tenancy and your vendor accounts, keep documentation current as a habit rather than a project, and make sure at least one other party understands the environment. Do it while they are still here and the handover becomes routine.
If that quiet test turned up more gaps than you were expecting, the fastest way to close them is an independent look at the environment. Our ICT audits document what you actually have and where the single points of failure sit, and IT staff placements and co-managed support give your internal person backup rather than a replacement. Either way, the goal is the same: the business keeps the knowledge.
