Your only IT person quits. Within hours, routine technology tasks become business risks.
No one knows where the administrative credentials are stored. Backups may be running, or may have failed months ago. Critical vendor relationships may exist only in one person’s inbox. A server problem that used to take 20 minutes to fix can now stop operations for a full day.
This is key-person risk. For small and mid-size businesses, it is one of the most overlooked continuity problems.
The issue is not that one employee leaves. The issue is that your IT environment leaves with them.
WHAT BREAKS IN THE FIRST 30 DAYS
The first month usually exposes problems that were invisible while the IT person was still available.
DAYS 1–3: ACCESS BECOMES THE EMERGENCY
Your first problem is often not a system failure. It is proving that your company still controls its systems.
You may need access to:
- Microsoft 365 or Google Workspace
- Domain registration and DNS
- Cloud hosting accounts
- Firewall and VPN administration
- File servers and network storage
- Backup platforms
- Endpoint security tools
- Accounting, payroll, CRM, and ERP systems
- Website hosting and source code repositories
- Telecommunications and internet provider portals
If those accounts use a former employee’s email address, phone number, or authenticator app, password recovery can become slow and complicated.
You may also discover that “the admin password” was stored in a personal password manager, a local spreadsheet, or nowhere at all.
Your immediate priorities are simple:
- Identify every critical account.
- Confirm who owns the account.
- Recover or reset administrative access.
- Move access to company-controlled identities.
- Require multi-factor authentication.
- Record recovery contacts and escalation procedures.
Do not wait until the next outage to discover that no one can log in.

DAYS 4–10: BACKUPS AND VENDORS COME INTO QUESTION
The next problem is uncertainty.
You may know that “we have backups.” That is not enough. You need to know:
- What is being backed up?
- Where are the backups stored?
- When did the last successful backup run?
- Who receives failure alerts?
- How long are backups retained?
- Can you restore a file, mailbox, database, or full system?
- Is there an off-site or immutable copy?
- Who can authorize a restore?
A backup that has never been tested is an assumption, not a recovery plan.
Vendor relationships create another exposure. Your former IT employee may have been the only person who knew the account number, support tier, contract terms, renewal date, or escalation contact for key providers.
That can affect internet service, cloud platforms, cybersecurity tools, phone systems, software licensing, and hardware warranties.
A central vendor register should include:
- Vendor name and service
- Account number
- Contract and renewal dates
- Support portal URL
- Primary and backup contacts
- Service-level commitments
- Authorized company contacts
- Emergency escalation process

DAYS 11–30: UNDOCUMENTED KNOWLEDGE SURFACES
By the second and third weeks, your business starts finding the work that lived in your IT person’s memory.
That may include:
- How new employees are provisioned
- Which systems require manual updates
- How to restart a critical service
- Which firewall rules are safe to change
- How applications connect to databases
- Which alerts require immediate attention
- How to restore files or email
- Why a system was configured a certain way
- Which vendors should be contacted first
- Which workarounds keep operations running
This is where many businesses realize they do not have an IT function. They have an individual who remembers how everything works.
HOW TO ASSESS YOUR EXPOSURE
You do not need a complex risk framework to identify your largest gaps. Start with these five questions.
- If our IT person disappeared tomorrow, who could access every critical system?
- Which business processes would stop within four hours, one day, or one week?
- Which passwords, recovery methods, or accounts are tied to one individual?
- Which systems have backups that we have successfully restored?
- Who could make an informed IT decision during an outage or security incident?
For each critical system, score three factors:
- Business impact: What happens if this system is unavailable?
- Time to failure: How quickly would the problem affect revenue, customers, or compliance?
- Replaceability: Could another employee or outside provider take over without extensive investigation?
Prioritize systems that have high impact, fail quickly, and are difficult to replace.
Your highest-risk areas are usually email, identity management, financial systems, file storage, customer data, internet connectivity, cybersecurity tools, and backups.
BUILD A 30-DAY IT CONTINUITY PLAN
A continuity plan does not need to be a 100-page binder. It needs to help another qualified person take action.
PHASE 1: SECURE ACCESS AND INVENTORY SYSTEMS
Create a current list of hardware, software, cloud platforms, vendors, and administrative accounts.
Store it in a company-controlled system with appropriate access controls. Do not keep the only copy on a local computer or in a personal email account.
Every critical system should have:
- A company-owned administrator account
- At least two authorized administrators
- Multi-factor authentication
- Documented recovery methods
- A named internal owner
- A backup owner or outside support contact
Use a secure password manager designed for business access. Avoid shared spreadsheets containing plain-text passwords.
PHASE 2: WRITE RUNBOOKS FOR THE TOP FIVE PROCESSES
You do not need to document everything at once. Start with the five processes that would cause the most damage if no one could perform them.
Common examples include:
- Employee onboarding and offboarding
- Backup verification and file restoration
- Email administration
- Incident response
- Vendor escalation
- Firewall and VPN changes
- Critical application restart procedures
Each runbook should explain:
- What triggers the process
- What successful completion looks like
- The required access
- The steps to follow
- Common exceptions
- When to escalate
- Which vendor to contact
- How to verify the result
Plain-English documentation is better than technical documentation that only one specialist can understand.
PHASE 3: TEST THE PLAN
Assign a backup person. Then have that person perform routine tasks without the primary IT person’s help.
Test whether they can:
- Create and disable a user
- Find the latest backup status
- Restore a test file
- Open a vendor support case
- Locate network and firewall documentation
- Escalate an outage
- Find emergency contacts
A three- to five-day absence simulation can expose more gaps than another planning meeting.
CO-MANAGED IT OR OUTSOURCED IT?
You do not necessarily need to replace one full-time employee with another full-time employee.
A co-managed IT model can work well when you have an internal employee or department that understands the business but needs technical depth, after-hours coverage, documentation, or specialized expertise.
Outsourced IT services may be a better fit when your business does not need a full-time internal IT role. A provider can manage daily support, monitoring, patching, cybersecurity, backups, infrastructure, and vendor coordination.
The right model depends on your risk, size, complexity, and internal capabilities.
CO-MANAGED IT MAY FIT IF:
- You have an internal technology coordinator
- Your team wants to retain day-to-day business context
- You need help with infrastructure or security
- You need coverage during vacations, leave, or turnover
- You want an outside escalation path
OUTSOURCED IT MAY FIT IF:
- No employee owns IT operations today
- Your systems are becoming too complex to manage informally
- You need predictable support coverage
- You need stronger documentation and monitoring
- You want access to a broader technical team
At Five 9, we can support a defined project, provide IT consulting services, or help establish an ongoing operating model. Our approach includes knowledge transfer. We document what we do, explain why we did it, and help your team remain capable after the engagement.
That distinction matters. You should not trade one single point of failure for another.

QUESTIONS TO ASK BEFORE YOU NEED HELP
Before selecting a provider for managed IT services for small business, ask:
- What happens during an emergency outside normal business hours?
- How quickly does someone assess a critical outage?
- Will we have named contacts or only a ticket queue?
- How do you document our environment?
- How do you handle administrative credentials?
- Will you test our backups or only monitor backup software?
- What work is included in the monthly service?
- What work is billed separately?
- Can you support our existing internal employee?
- How do you transfer knowledge back to our team?
- What happens if we end the relationship?
- Can you provide references from companies similar to ours?
Ask for clear service scopes, response targets, exclusions, and pricing.
As a planning guide, IT continuity work may include:
- Emergency access and risk assessment: 1–3 business days
- Environment documentation and credential cleanup: 1–3 weeks
- Backup validation and recovery testing: 1–2 weeks
- Full continuity and knowledge-transfer program: 30–60 days
- Ongoing managed or co-managed support: monthly service agreement
Pricing should be based on your number of users, locations, systems, security requirements, and desired coverage. We will provide a specific range after understanding your environment rather than pretending one flat price fits every business.
MAKE YOUR IT FUNCTION SURVIVE THE PERSON
Your IT person may be excellent. That is not the problem.
The problem is allowing critical access, decisions, relationships, and knowledge to exist with only one person.
Reliable IT infrastructure management services create visibility, redundancy, documentation, and accountability. They give your business a way to keep operating when someone leaves, takes a vacation, or becomes unavailable during a crisis.
You do not need to solve everything this week. Start with access, backups, vendors, and the five processes your business cannot afford to lose.
If you want an objective view of your exposure, Five 9 offers IT consulting services and infrastructure assessments built around your actual environment. We can also help with infrastructure management and continuity planning.
Reach out through our contact page for an honest conversation. We will ask questions, explain what we see, and tell you directly whether we are the right fit. No pressure. Just a practical next step toward making your business less dependent on one person.
