Will your company survive the departure of its IT admin?

A checklist of the ten areas your company must own — not one person. Control questions, verification cadences and a free 5-minute IT continuity check.

In a single summer, two companies called us with the same sentence: our IT admin is in hospital, heart attack. The first call came from the owner of a mid-sized company, the second from the operations director of a large one. In both cases, the first concern was a colleague's health — and right after that, operations. Servers were running and mail kept flowing, but nobody knew where the passwords were or what could safely be restarted.

Both companies discovered the same thing: they didn't know how much only their IT admin knew.

Seven ways a company loses its IT

A heart attack is just one scenario. In practice you'll meet seven:

  1. Resignation or retirement — even with a two-month notice period, knowledge of the environment leaves with the person; a successor spends weeks mapping the network from scratch.
  2. Sudden death or incapacity — the passwords might turn up, but the second login factor (MFA) is tied to their phone. MFA dies with the device.
  3. Long illness — the admin is alive but can't work for six months. The company chooses between bothering a sick person and waiting.
  4. Conflict — the admin refuses to hand over passwords. You'll win in court eventually, but that takes years. The outage is happening now.
  5. Your IT provider goes bankrupt — access to your data can vanish within hours.
  6. Your IT provider gets sold — after an acquisition, experienced technicians leave and response times stretch.
  7. Ransomware at your provider — an extortion attack encrypts your data through the very tool your provider manages you with. The mistake wasn't yours.

The common denominator: the bus factor — how many people would have to disappear for operations to stop. "One" means critical risk — for an employee and for an external provider alike. More in our article on when IT outsourcing pays off — and when it doesn't.

Three situations from our own practice

A domain registered to the IT guy. While taking over one company's IT, we found its domain was registered to the IT admin as a private person — right at a time when the relationship had gone sour. Yet the domain carries the website, e-mail, and logins to services. The company didn't legally own the address its entire business stood on.

Backups green, data three years old. Backups were running and monitoring glowed green. An inspection showed the system was dutifully backing up three-year-old accounting data — the current data lived elsewhere. And nobody knew the password to decrypt the backups. A green light doesn't say you're safe. It only says a job is running.

A missing emergency account in Microsoft 365. It happened in our own practice: the emergency global administrator account (a "break-glass" account — break the glass in case of emergency) simply didn't exist. Nothing was lost. But steps that should have taken minutes took days — escalations and waiting all the way. Yes, we're speaking against ourselves here — and it still belongs in this article: today it's the first thing we set up at every takeover.

More cases: Danish hosting provider CloudNordic lost all customer data in a 2023 ransomware attack — backups included. The 2021 attack on the Kaseya tool hit up to 1,500 end companies through their management providers. Terry Childs refused to hand over passwords in 2008 — San Francisco spent 12 days without administrative control of its own network; the network ran, but nobody could manage it. After the founder of crypto exchange QuadrigaCX died in December 2018, roughly 190 million dollars belonging to 115,000 clients stayed locked — only he knew the passwords. (Later investigation revealed much of it was fraud; but the collapse was triggered by the death of the single person holding the keys.)

The checklist: ten areas the company must own — not one person

Most guides tell you what you should have. We ask differently: when did you last verify that you have it? That's why every area comes with a control question and a test you can run without your IT admin.

1. Domains and DNS

The domain carries your website, mail, and logins to most services; DNS is the set of records telling the domain where to route what. The holder must be the company (company ID, not a person's name), the registrar account must be corporate, the contact a role address like [email protected]. Control question: who is the holder of our domain? Test: once a year, pull a WHOIS extract (the public registry of domain holders) and log in to the registrar without your IT admin. Your e-mail deliverability stands on the domain too.

2. Tenant and licence ownership

Microsoft 365 licences are often bought through a partner (CSP — Cloud Solution Provider, partner-channel licensing). Transferring existing subscriptions to a new partner requires the old one's approval (with no response, the request expires after 30 days) — without their consent, subscriptions run out their term with them. But the tenant — your Microsoft 365 environment — and the data stay yours: delegated access (GDAP) can be revoked unilaterally at any time, and new licences can be bought elsewhere immediately. The trap is in money and commitment, not in data. Control question: can a company director log in to the admin portal without the provider? Test: once a year + an extract of the partner's permissions.

3. Systems documentation

Not an encyclopedia — the minimum: an inventory of systems, a network diagram, a list of admin accounts and owners, supplier contacts, a step-by-step recovery procedure. The yardstick: an outside technician could take over operations with it within 48 hours. Control question: could they? Test: review twice a year; keep a copy outside the systems it describes. More in our article on technical debt.

4. Emergency admin accounts

A break-glass account — "break the glass in case of emergency" — is an emergency global administrator. Microsoft's cookbook: at least two, cloud-only, sign-in with a FIDO2 hardware key, keys in two vaults at separate locations, an exception from Conditional Access policies, and an alert on every sign-in. Control question: can we get into Microsoft 365 if the admin doesn't show up tomorrow? Test: every 90 days and after every personnel change in IT.

5. Backups you can reach yourself

Your IT runs the backups and of course has access to them — that's what you have them for. The point is that you can reach them too: the company must be able to open its own backups on the very day IT is unavailable. The foundation is the 3-2-1 rule — three copies, two media, one off-site — plus one immutable copy on top: this one isn't about access but about deletion — nobody can erase it, not even with an admin password. CloudNordic lost its backups because they were reachable from the same management plane as production. Control question for your provider: when did you last run a test restore, and can I see the record? Test: monthly a sample of files, quarterly a whole application, yearly everything. Why an undeletable backup is the last insurance policy, we've written up separately.

6. Disaster recovery plan

A written recovery plan (DR — who restores what, in what order, with contacts), available even during an IT outage: printed, a copy outside the company, known to at least two people. Control question: where is it, and who read it when? Test: once a year, a tabletop exercise — our admin had a heart attack this morning — what do we do in the next 24 hours?

7. Password management and access escrow

A corporate password manager with vaults owned by the company, not in one person's head. On top of that, an emergency mechanism: a sealed envelope in a safe (a new one after every password change), Bitwarden Emergency Access (a trusted person requests access; unless you reject it within the set period, access opens), or third-party escrow. Control question: who can reach the passwords when their holder can't? Test: a trial request every quarter. The basics are in our article on passwords.

8. The contract with your IT provider

Continuity is negotiated while the relationship is good. The contract must state: data, backups, documentation, and admin access belong to the client — explicitly; 30–90 days of exit cooperation at fixed rates; access handed over continuously, not at the break-up. Control question for your provider: what happens if I want to leave? Test: once a year, take over the current documentation and spot-check the access. We've written up the red flags in seven questions to ask an IT company.

9. Payment continuity

Domains, certificates, hosting, key services: what renews, when, from whose card, and where the reminders go. Everything on a corporate card and a role e-mail. Expirations don't hurt — until the day a certificate lapses: a single one cut off mobile data for roughly 32 million Britons in 2018. Control question: which critical service hangs on a personal card or e-mail? Test: twice a year, a payment listing and an expiration calendar.

10. Offboarding and secret rotation

At every departure from IT: revoke privileged access within an hour; rotate shared passwords, API keys (the keys systems use to authenticate to other systems), and service accounts. Out of 262 companies in our audit, 151 had at least one serious finding — accounts left behind by former employees are among the most common. Control question: who left last, and what stayed active after them? Test: at every departure, follow a written procedure — more in our article on what IT management does when nothing breaks.

How often to verify what

A checklist filled in once is a photograph; continuity is a film. The cadence we recommend:

AreaHow oftenThe proof you want to see
Domains and DNS1× a year + at provider changeWHOIS extract with the company as holder
Tenant and licences1× a yeardirector's login; extract of partner permissions
Documentation2× a year + after every changereview record, outside-technician test
Emergency accountsevery 90 days + after personnel changestest record + alert firing
Backupsmonthly a sample · quarterly an application · yearly everythingtest-restore record (what, when, how long)
Recovery plan1× a year, an exerciseexercise record, updated plan
Passwords and escrowquarterlysuccessful trial request, envelope rotation date
Contract1× a yearcurrent documentation handed over, working access
Payments2× a yearoverview of services with cards and expirations
Offboardingat every departureprotocol: what was revoked, what rotated, when

The new Czech Cybersecurity Act (Act No. 264/2025 Coll., the Czech transposition of the NIS2 directive) allows fines for the most serious offences under the higher-obligations regime of up to CZK 250 million (≈ €10 million), or 2% of the company's worldwide turnover — whichever is higher.

You can secure all of this yourself, for free

None of the ten areas requires us or any other provider. Microsoft publishes its emergency-account guide openly, a test restore is an afternoon's work, a WHOIS extract is free. A company that has these in order doesn't need to buy anything from us — and we know it. You start needing us when someone should watch it for you: every quarter, every departure, every expiration. That's our entire business interest.

Find out where you stand in five minutes

You don't have to take our word for anything. Take the IT Continuity Check — 10 questions, one per area, answers yes / no / don't know. You immediately get, free and on screen: an overall score, a traffic light for the ten areas, and three steps for tomorrow morning. If you ask for the report by e-mail, we add an action plan for every area, a "forward this to your IT admin" page with questions and proofs, a fillable Critical Access Register template — and if you want, we'll remind you every 90 days to test your emergency account. We don't see your answers; when you request the report, we store only your e-mail and the overall score.

Want the outside view too? Take the free on-line security audit — 13 checks, 5 minutes, no meeting. The checklist maps the inside. The audit measures the outside. IT without surprises.

Frequently asked questions

We have an external IT company — does this apply to us?

Yes — possibly more than to companies with an in-house admin. CloudNordic and Kaseya are both cases where the failure originated at the provider — and the customers paid for it. The checklist applies the same way, just substitute "provider" for "IT admin": your own copy of the backups, your own access, an exit clause in the contract.

Is this the same as your on-line audit?

No. The audit is a passive scan from the outside — 13 checks of what's publicly visible from your domain. The Continuity Check maps the inside: who owns what, who knows what, and when you last tested it. They complement each other; neither replaces the other.

Isn't this a sign of distrust towards our IT admin?

The opposite — it protects them most of all. As long as everything lives in their head, they can't take a calm holiday, let alone sick leave. A good admin welcomes the sealed envelope and a second emergency account — and nervousness at these questions is an answer in itself.

Where do we start if we have none of this?

With the three critical areas: an emergency account for Microsoft 365, a test restore of a backup, and a check of who your domain is registered to. These are the places where the whole company stops. You can verify all three within a week.