For a lot of Australian small businesses, IT support began as "the person who knows about computers": a handy employee, a once-a-week contractor, or a friend who set up the network years ago and still answers the phone when it breaks. It's an arrangement that works right up until the day it doesn't, and that day tends to arrive without warning.
What happens when your IT person is unavailable?
Key-person dependency is the core risk. If one individual holds the knowledge of your network configuration, licences, email routing, backups and security settings, your business continuity rests on their availability and goodwill. A holiday means a fortnight without cover. An illness means hoping it's brief. A falling-out, or a departure without a handover, can mean rebuilding your IT knowledge from scratch, assuming anything was ever written down.
Who else holds your admin credentials?
This is the sharpest version of the risk and the first question to answer honestly. If a single person holds sole administrator access to your email tenancy, file storage, accounting platform and domain registration, they can lock you out of your own business, deliberately or simply by becoming unreachable. Before you change anything else, get a second set of admin credentials into the hands of an owner or director, and record where every account, licence and renewal lives. That step costs nothing and defuses the worst scenario.
Reactive hours versus proactive systems
A part-time IT person spends their limited hours reacting: the printer, the slow laptop, the folder someone can't reach. What never gets done is the preventative work that stops incidents happening, patching, testing that backups actually restore, reviewing who has access to what when roles change, and watching for unusual activity. A managed IT service inverts this. Monitoring, patching and backup verification run continuously as a system rather than depending on someone remembering, and support comes from a team, so coverage doesn't evaporate when one person is away.
The security dimension matters more each year. A capable managed provider will structure your environment against a recognised framework such as the ASD Essential Eight, which gives you a defensible, auditable baseline rather than one person's accumulated habits. Insurers and larger customers increasingly ask about exactly this.
Making the transition without burning the relationship
The switch is often delayed for personal reasons: the current IT person is loyal, liked, maybe a mate. Handle it as a structural change, not a judgement of them. The honest framing is that the business has outgrown a single-person model, which is true regardless of how good that person is. Practically, the transition looks like this:
- Document first. Ask for (or commission) a written record of the network, accounts, licences, vendors and passwords before any change is announced. This is easiest to obtain while the relationship is intact.
- Transfer control of identities. Admin access, the Microsoft or Google tenancy, and domain ownership should sit with the business, with providers granted access rather than owning it.
- Overlap deliberately. A handover period where the incoming provider audits the environment while the outgoing person is still contactable saves weeks of archaeology.
- Keep the person if it fits. Some businesses retain their original IT contact for on-site tasks while a managed service handles infrastructure, security and after-hours cover.
What to ask a managed IT provider before signing
Not all managed services are equal, and the label gets applied loosely. Useful questions: What exactly is included versus billed separately? What are your response commitments, and how do you handle after-hours emergencies? How do you verify backups restore, and how often? Which security framework do you align to, and can you show evidence? Who owns our documentation and credentials if we leave you? A provider who answers the last question awkwardly is telling you they plan to recreate the dependency you're escaping, just at company scale.
The deeper point is that this is one instance of a broader pattern: any function resting on a single irreplaceable person is a fragility, whether that person is your IT contact or you. It's the same logic that drives systemising a business generally, knowledge in systems, not just in heads. IT happens to be the domain where the failure mode is fastest and most visible.
About the author
Andrew Northcott
Founder & Chairman, Valont
Andrew is the founder and chairman of Valont and the parent group Wattlestone. He has spent two decades building and running Australian SMEs, and writes about the realities of ownership — cash, people, systems, and the decisions that compound.
LinkedIn →