Here's a question most owners never ask: what happens if your IT person disappears tomorrow? Not quits. Disappears. Hospital. A lottery win. A flight that lands somewhere without wifi and they never come back.
Could you get into your own systems? For most mid-market companies, the honest answer is no. One person knows the admin passwords. One person knows where the backups live and whether anyone actually checks them. One person knows which vendors are real and which ones are just a monthly charge nobody remembers approving.
That's not an IT department. That's a hostage situation with dental benefits.
The vacation test
There is a simple test. If your go-to IT person took a real two-week vacation tomorrow, no laptop, no "just text me if something blows up," what breaks first? If the answer is everything, you have your answer. You built a business that runs on one person's memory.
I see this constantly in companies that otherwise have their act together. Good revenue, good customers, real growth. And underneath it, one person holds all the keys, because at some point it was easier to just let them handle it. It always starts that way. It never stays convenient.
It's not just passwords
The password problem is the visible part. The deeper problem is documentation, or the lack of it. Where is the network diagram? Nobody has drawn one since 2019. Which account pays for the domain registration? Nobody remembers, until the renewal email goes to someone who left in 2022 and the website goes dark on a Tuesday.
Then vendors. Ask who your MSP answers to. Ask who can approve a change to the firewall rules. If the answer to every question is one name, your IT governance is that name. People retire.
What good looks like
This is fixable, and it does not require hiring anyone. It requires writing things down and spreading the keys around.
Start with a password manager the company owns, not a personal one on somebody's phone. Admin credentials live in a shared vault, and at least two people have access. Not ten. Two is fine. Two beats one by a lot.
Then document the basics. Not a 90-page binder nobody opens. A short list: the critical systems, who owns each one, where the credentials live, who the vendor contacts are. Five pages covers most shops. Update it twice a year, or after anything big changes.
Give somebody else admin rights. Pick a second person and train them just enough to reset a password and find the vendor list. They do not need to run IT. They need to be the backup key.
And do the uncomfortable exercise. Once a year, sit down and ask: if our IT person walked out tomorrow, what couldn't we do by Friday? Write down the answers. Fix the top three. Repeat next year.
The point
None of this is about distrusting your IT person. Most of the time they did not design it this way. It just accumulated, one shortcut at a time, because the company kept growing and nobody built the boring infrastructure underneath.
But a business that can't survive the absence of one person doesn't really own its technology. It rents it from an employee. The fix is a weekend of documentation and a password manager, not a hiring round.
Don't wait for the lottery ticket.
Not sure where your IT really stands? Start with a Clarity Audit: a focused assessment of your backups, security, vendors, and AI readiness. It's the first step in every engagement I take on.
About the author: Chris McGlasson is a fractional CIO and the founder of ClearStack Advisory, where he helps mid-market companies build AI governance, IT strategy, and technology roadmaps without the overhead of a full-time CIO. He previously built and sold LANPRO Systems, an IT services firm serving 350+ enterprise clients.
