When Your Only IT Person Leaves: The Risk Most Australian SMBs Carry

Josh Boniface

|

17.07.26

The out-of-office reply reads 'Currently on leave, back Monday' for six days. The Customer Relationship Management (CRM) system has started throwing an error that no one in the office recognises. The domain renewal notice arrived on Tuesday, and nobody is quite sure whose card is on file. The one person who could answer any of this in under a minute is also the one person nobody has a backup contact for.

For small to medium-sized businesses (SMB), none of this would matter in an ordinary week. It only becomes visible on the day an ordinary week quietly goes wrong, because the entire plan was for one person to stay reachable.

Every Small Business Runs on One Person's Memory

Ask most SMB owners who manage their IT, and the answer is a name, not a team. Sometimes it is a dedicated staff member. More often, in a lean business, it is what the sector quietly calls an accidental IT admin: someone who was simply comfortable with computers, picked up more responsibility over the years, and became the default answer to 'who do we call?' Just as often, it is a long-standing external contractor who has been reliable for so long that nobody has thought to ask what would happen if they were not available.

This shows up most sharply in security-focused businesses across Australia: those already partway through a move to Microsoft 365 or Entra ID, aware they carry some exposure, but who have not yet formalised who is actually accountable if the person managing the migration is unreachable. Being aware of the risk and having a plan for it are two different things, and most businesses in this position have only the first.

However low staff turnover looks on paper, the average was never the risk. It says nothing about what happens when the one departure that does occur is the person who holds every password, every vendor relationship, and every undocumented workaround the business depends on. IT staff turnover risk was never about the sector average. It is about what leaves the building with the one person who does.

Why 'They've Never Let Us Down' Feels Like a Safe Bet

Leaders who have not addressed this are not being careless. The person in question has usually earned the trust. They answer the phone. They fix things quickly. They know the systems better than anyone else in the building, and for years, that has been exactly true. Formalising a backup plan can feel like an insult to someone who has never given the business a reason to doubt them, or an unnecessary cost against a risk that has never materialised.

The trust is well placed. The exposure was never about the person. It is about what has been allowed to depend on them by default.

The NSW Small Business Commissioner's own research into small business preparedness found the majority had no formal business continuity plan in place, which is precisely why business continuity for small businesses rarely gets treated as an IT problem until it already is one. Separately, research from Beyond Identity found that 83% of former employees retained some form of access to their previous employer's systems after leaving, not always with malice, simply because no one closed the loop. Put those together, and the picture is plain: even businesses that part ways well are routinely left with accounts nobody has revoked and knowledge nobody wrote down. Reliability while someone is there says nothing about what remains once they are gone.

What Actually Happens the Day They Leave

The difference is not between a good IT person and a bad one. It is between a business with a single point of failure in IT and one whose IT depends on a model that does not care who is on leave this week.

Access and credentials

In a single-person model, admin logins for the website, the CRM, and the domain registrar often go under one name, sometimes tied to a personal email address and a personal phone number for multi-factor authentication (MFA). In a team-backed model, the business owns its own accounts, credentials live in a shared, access-controlled vault, and offboarding one team member never means offboarding the system itself.

IT documentation and handover

In a single-person model, what needs backing up, how the CRM talks to the finance system, and why a particular workaround exists all live in one head. In a team-backed model, configurations and dependencies are documented as a condition of how the team works: an ongoing IT knowledge transfer, not squeezed into a two-week handover on the way out the door.

Support continuity

In a single-person model, when that person is on leave, at a conference, or simply asleep, support is unavailable. Something breaks, and it waits. In a team-backed model, tickets are logged, triaged and actioned by whoever is rostered on, so continuity never depends on one person's calendar. 

This is the practical meaning behind Next Step's own service philosophy: The phone doesn't ring because someone has already caught the problem before it becomes one.

Governance and reporting

In a single-person model, leadership has no independent view of its own IT risk, because the person managing it is also the one who informally reports on it when asked. In a team-backed model, reporting and reviews follow a schedule that exists regardless of who is available that week, including how the business sits against recognised frameworks like the Essential Eight and whether MFA is enforced business-wide, giving leadership something it can actually manage.

Why Next Step Treats This as a Continuity Problem, Not a Staffing Problem

This is why Next Step does not open this conversation by suggesting a business replace someone it trusts. Outsourced IT support for a small business is not about removing the accidental admin or the long-standing contractor from the picture. Managed IT services built this way do not replace people; they remove the single point of failure sitting behind them, wrapping a documented, team-backed model around what that person already does, so the knowledge stops living in one head and starts living in a system the whole business can rely on.

The Question That Changes the Conversation

The question most leadership asks is whether their IT person is good at their job. That is usually not in doubt, and it is the wrong question regardless. The one that matters is this: if that person resigned tomorrow with two weeks' notice, could the business keep functioning on day 15? Could someone else log in, find the answer, or fix the problem without waiting for a phone call that might not come? IT continuity for small businesses is not a reflection on any individual's competence. It is a measure of how much the business would survive without them.

A Five Minute Exposure Check

A business owner or operations lead can answer these honestly without any IT background at all:

  1. Could someone other than your IT person log in to your website, CRM, and finance system today?
  2. Is there a current, written list of every system, licence, and vendor the business depends on?
  3. If your IT person gave two weeks' notice tomorrow, would that be enough time to hand over everything they know?
  4. Are your admin accounts and the MFA tied to them registered to the business or to an individual's email and phone?
  5. Who would you call at 9 am the day after they left, and how confident are you that they could actually help?

If more than one of these is uncomfortable to answer, the exposure is not hypothetical. It already exists. It has not been tested yet.

The Bottom Line

A single, trusted IT person is not the risk. A business with no model for what happens without them is. The gap between those two things rarely shows up until the worst possible moment, when the person who could have closed it is already gone.

Next Step runs a free IT Health Check for security-focused Australian businesses that want to understand this exposure honestly, framed around one specific question: what would actually happen if your IT person left tomorrow? No jargon, no pressure to replace anyone, and no assumption that the answer is a new hire. 

For most small businesses, the answer is not more staff. It is a documented, team-backed support model that means no single departure can ever again take the business's institutional knowledge with it. If this is a risk your leadership team has never quite named, talk to Next Step before you have to test it in real life.

About the author

Josh Boniface

Josh Boniface , CEO

With over a decade of experience in managed IT and business development, I work with Australian associations, NFPs and peak bodies to make technology more predictable, secure and easier to manage.

At Next Step Infrastructure Services, my focus is helping leaders strengthen their IT environment without adding complexity. This includes proactive managed services, cybersecurity and Essential Eight compliance, cloud modernisation, Microsoft 365, Entra ID, SharePoint, Intune, and practical IT strategy for boards and executive teams.

I’m especially interested in supporting organisations where technology decisions often sit with CEOs or Operations Managers who need clear advice, reliable support and confidence that their IT is working in the background.