Elevaire Systems
What Happens When the Only Person Who Knows Your Network Leaves
← Back to Insights
Infrastructureinfrastructure modernizationIT strategydocumentationkey person riskgrowth-stage companies

What Happens When the Only Person Who Knows Your Network Leaves

Elevaire Systems·

A 90-person company has one person who runs the network. They set up the firewall, they know which switch feeds the second floor, and they are the only one who remembers why the guest wifi shares a subnet with the accounting printers. On a Friday afternoon they give two weeks' notice. Nothing is broken yet, which is exactly the problem: the company has no way to tell how much it is about to lose.

This is key-person risk applied to infrastructure. The systems keep working because one person's memory keeps them working. When that memory walks out the door, the business finds out how much of its technology was never written down, never reviewed, and never owned by anyone but the person who is leaving.

Why the Knowledge Lives in One Head

Nobody plans this. A growing company hires one capable IT generalist, and that person solves problems faster than anyone could document them. Every fix teaches them something about the environment. Every month they become a little more essential and a little less replaceable.

The documentation stays in their head for ordinary reasons. Writing it down is never urgent. The person who knows the network is also the person who would have to find the time to describe it, and they are always busy fixing the thing that just broke. Leadership rarely asks for documentation because the network works, and a working network does not look like a risk.

Three conditions make the exposure worse:

  • Credentials with one holder. Admin logins for the firewall, domain registrar, wireless controller, and cloud console sit in one person's password manager, or in their head.
  • Configuration with no record. Firewall rules, VLAN assignments, and port forwards were added over years, each for a reason that nobody wrote down.
  • Vendor relationships through one contact. The internet provider, the phone carrier, and the software vendors all know one name. Account PINs and authorized-contact lists point to that person alone.

None of this reflects badly on the person doing the work. It reflects a company that grew faster than its technology leadership did.

What Actually Breaks When They Leave

The departure itself is rarely the crisis. The crisis arrives weeks or months later, when something that person quietly handled stops being handled.

Renewals and expirations lapse. Domain registrations, SSL certificates, firewall subscriptions, and software licenses renew on schedules that one person tracked mentally. When a certificate expires, the customer portal throws a security warning at 8 a.m. on a Monday, and nobody knows where the certificate was issued.

Locked doors nobody can open. Admin accounts tied to the departing employee's personal email or phone number cannot be reset by anyone else. Recovering a firewall, a registrar account, or a cloud tenant without the original holder can take days of identity verification with the vendor, and some accounts cannot be recovered at all.

Troubleshooting turns into archaeology. The next person to touch the network has to reverse-engineer it. A change that would take ten minutes with a diagram takes a day without one, and each guess risks taking something else down.

Security gaps open quietly. Access that should have been revoked stays active. Shared accounts keep working for someone who no longer works there. Nobody knows which firewall rules are intentional and which are leftovers, so nobody dares remove any of them.

Recovery plans fail on contact. A backup or failover process that only the departed person understood has never been tested by anyone else. The company discovers whether it works during the outage it was meant to prevent.

What an Outage Costs, in Your Own Numbers

Published downtime figures vary widely by industry and company size, so the most useful number is the one you calculate yourself. Take annual revenue, divide by roughly 2,000 working hours, and you have revenue per working hour. A $20 million company generates about $10,000 an hour. Add the payroll of every employee who cannot work during an outage: 90 people at an average loaded cost of $45 an hour is another $4,050 an hour. A single business day of disruption in that company costs more than $100,000 before anyone counts lost customer trust or overtime spent recovering.

Now multiply by the number of days an undocumented network takes to diagnose when something fails and the one person who understood it is gone. A two-day recovery that should have been a two-hour fix is a six-figure event for a company that size. That is the real price of keeping the knowledge in one place.

How to Tell If You Are Exposed Today

You do not have to wait for a resignation to learn how fragile your setup is. Ask the person who runs your network, and your leadership team, these questions:

  1. If this person were unreachable for two weeks, who could handle a firewall failure?
  2. Is there a current network diagram, and when was it last updated?
  3. Who can log in to the firewall, the domain registrar, and the cloud admin console right now?
  4. Are admin accounts tied to individual personal emails or phone numbers?
  5. When does each domain, certificate, and critical subscription expire, and who gets the reminder?
  6. Has anyone other than this person ever restored a system from backup?
  7. Which vendor contacts and account PINs exist only in one person's inbox?

Two or more honest answers of "nobody" or "I don't know" mean the company is carrying key-person risk that has not been priced or planned for.

A Checklist to Close the Gap

The goal is not to produce a binder of documentation that goes stale in a month. The goal is to make the environment legible to someone who did not build it, and to keep it that way with light, regular upkeep. Work through these steps in order.

  1. Build an asset inventory. List every device, application, cloud service, and subscription the business depends on, with an owner, a location, and a renewal date. The NIST Cybersecurity Framework 2.0 Small Business Quick-Start Guide puts this first: its Identify function starts with maintaining an inventory of hardware, software, systems, and services. CISA reinforces the point in its asset inventory guidance, which treats an asset inventory as one of its Cybersecurity Performance Goals. That guide is written for operational technology, but its advice to prioritize assets by criticality and build the list out over time applies to any environment.
  2. Draw the network. A one-page diagram showing locations, internet connections, firewalls, switches, wireless, and the main segments is enough to start. Store it where leadership and a successor can find it, not on one laptop.
  3. Move credentials into a shared vault. Admin access belongs to the company, not an individual. Put privileged credentials in a business password manager with at least two named administrators, and tie critical accounts to role-based mailboxes such as it-admin@ rather than a person's address.
  4. Record the why behind firewall and network rules. Export the configuration, and annotate unusual rules with their purpose and the date added. Rules nobody can explain are the first candidates for review.
  5. Put every renewal on a shared calendar. Domains, certificates, security subscriptions, and licenses each get an expiration date and two people who receive the alert.
  6. Update vendor records. Make sure the internet provider, registrar, and carrier list at least two authorized contacts, and that the account PINs are stored in the vault.
  7. Test one recovery. Have someone other than the usual administrator restore a system from backup, using only the written procedure. Fix whatever the procedure forgot to say.
  8. Schedule a quarterly review. Thirty minutes each quarter to confirm the inventory, diagram, and access list still match reality is what keeps the work from decaying.

If a departure is already underway, compress the same list into the notice period. Prioritize credentials and admin access first, then the network diagram, then renewals. Ask the departing employee to walk a colleague, or an outside technology leader, through the environment while they are still available to answer questions. Many people are glad to leave things in order when they are asked early and directly.

Where Fractional IT Leadership Fits

Documentation fails when it has no owner. The IT generalist is too busy keeping things running to write it down, and the managed service provider does what the contract says, which usually means keeping the lights on rather than keeping a leadership-level record of how the whole environment fits together. Neither is a failure. It is a gap in who is accountable for the environment as a business asset.

Fractional IT leadership fills that gap without replacing anyone. A fractional CIO works alongside your internal IT person and your existing MSP, sets the documentation standard, owns the inventory and the renewal calendar, runs the quarterly review, and makes sure no single person, internal or external, is the only holder of critical knowledge. When your IT lead is in a meeting, on vacation, or gone, the business still has a clear picture of what it runs and who can touch it.

Done well, this also makes the IT person's job better. Their expertise is captured and credited instead of being locked in their head, and they get a successor-ready environment that lets them take a real vacation.

Frequently Asked Questions

How much does it cost to document our network?

For a company of 25 to 200 employees, the first pass is mostly staff time rather than software spend. Expect a few days of focused effort to build the inventory, diagram, and credential vault, then a small recurring commitment each quarter. The cost of not doing it is the multi-day recovery described above, which is far larger.

How does this work alongside our existing MSP or IT team?

It adds to them. Your MSP keeps doing what it does, your internal IT person keeps running day-to-day operations, and a fractional CIO sits above both to own the documentation standard, the renewal calendar, and the quarterly review. Your MSP also benefits, since clear documentation makes their work faster and their onboarding of new technicians smoother.

What should we do first if our IT person just gave notice?

Secure access before anything else. Inventory every admin account the person holds, move those credentials into a shared vault, and confirm at least two other people can log in to the firewall, registrar, and cloud console. Then capture a network diagram and the renewal list before their last day.

How often should network documentation be reviewed?

Quarterly is a workable default for most companies in this size range, with an extra review after any major change such as a new office, a new internet provider, or a migration to a cloud service. The aim is for the documentation to match reality closely enough that a stranger could use it.

Is a shared password manager really enough to protect admin access?

It solves the single-holder problem, but it needs to be configured well. Use at least two company-owned administrator accounts, require multi-factor authentication, and review who has access to which vaults on a regular schedule. The vault should belong to the business, not to the person who happened to set it up.

How do we get started without disrupting day-to-day work?

Start with the seven questions above and use the answers to find your largest single point of failure. Fix that one first, usually admin credentials or the renewal calendar, and add the rest in order. A fractional IT leader can run the process so your IT person is not asked to document everything on top of their normal workload.

About Elevaire Systems

Elevaire Systems provides fractional Chief Information Officer (CIO), Chief Technology Officer (CTO), and Chief Information Security Officer (CISO) leadership, along with infrastructure modernization, intelligent automation, and compliance strategy for growing organizations.

Ready to Put This Into Practice?

Schedule a free consultation and let's talk through what this means for your organization specifically.

Schedule a Free Consultation