Sentry CTO

FAQ

Our I.T. Person Quit: What to Do in the First Week

4 min read
An empty office desk with two dark monitors and a vacant chair.

The person who ran your technology is gone. Maybe they retired. Maybe they resigned. Maybe the departure was not friendly. Either way, you now own systems you have never logged into, protected by passwords you do not have, documented nowhere.

Here is the reassuring part. Your systems will mostly keep running this week exactly as they ran last week. Panic is unnecessary. What you need is a short, ordered checklist, because a few of the risks in front of you are quiet and genuinely urgent. Most of the rest only look urgent.

This is the order we walk new clients through when their I.T. person quits.

Day One: Secure Access First

The one genuinely urgent item

If the departure was anything other than friendly, disable the person's accounts and change shared administrative passwords today. This is standard practice, not an accusation. An unwatched account with the keys to everything is now your single largest risk.

Even in the friendliest departure, do these three things on day one:

  • List every administrator account you know about. Include Microsoft 365 or Google Workspace, your firewall, your backup system, your accounting software, and your website.
  • Change the passwords you can change. Store the new ones in a business password manager rather than a spreadsheet. Setup takes about an hour.
  • Check the departed person’s mailbox for forwarding rules. Then decide deliberately who receives their email now.

Day Two: Find Out What You Cannot Get Into

The list of accounts you cannot access is your real exposure, written down. It tells you more than the list you can access. Work through these four:

  • Your domain name. Where is it registered, and can you log in? A lost domain is one of the few unrecoverable disasters in business technology. If it was registered under a personal email address, fixing that outranks nearly everything else this week.
  • Your Microsoft 365 or Google Workspace admin account. Confirm someone can still create accounts, reset passwords, and remove users.
  • Your firewall and network equipment. These were often installed years ago, with the password known to exactly one person. That person no longer works for you.
  • Your backup system. The question is whether anyone still employed can log into it.

If you are locked out of something, do not guess passwords until the account locks. Vendors have recovery processes for business owners. Those processes take days, which is why you start them now.

Day Three: Test One Backup

Skip the full backup audit this week. Instead, restore one real file and open it. That single test tells you whether backups run, whether they are usable, and whether anyone left can operate them. If nobody can figure out how, you have found a serious gap during a calm week instead of during a ransomware incident. Our backup testing guide covers the full process when you are ready.

Day Four: Write Down What You Do Not Know

Take an hour and write out every question you cannot answer. Where are our files actually stored? What is the wifi admin password? What software renews next month, and on which card? Who hosts the website?

Every unanswered question is a finding. This list will tell your next I.T. provider more about your environment than any interview. It costs nothing to produce.

Also worth an hour this week

Check what was on autopay. I.T. people frequently put licenses, domains, and services on personal cards for convenience. A subscription that quietly fails to renew in month three is how businesses lose their website, their email filter, or their domain.

Day Five: Avoid the Two Tempting Mistakes

Mistake one: hiring the fastest available replacement. The pressure to make the problem go away is real, and it produces decisions you will live with for years. Running unattended for two or three weeks while you choose carefully is a smaller risk than three years with the wrong provider.

Mistake two: asking the departed person to “stay available.” This feels like a safety net. In practice, the knowledge stays in their head, the documentation never gets written, and the favor has a shelf life. If they are willing to help, spend that goodwill on a structured handover of passwords and documentation instead of informal on-call support.

What This Week Should Teach You

The useful lesson has nothing to do with the person who left. Your business depended on a single human being with no documentation, and it will again unless the next arrangement is structurally different. The next one needs written documentation, more than one set of eyes, and access that belongs to the business rather than to a person.

Hold every replacement candidate to that standard, whether you hire an employee, a managed I.T. provider, or some combination of the two. Ask each one three questions. Where does the documentation live? Who covers when you are away? What happens when you leave?

Want a structured picture of where you stand before you talk to anyone? The three-minute self-assessment covers the nine areas that matter and shows your score on screen, no email required. If you would rather have help working the checklist above, book fifteen minutes with us. It costs nothing and carries no obligation.

Next step

Reading about it is a good start. Knowing where you stand is better.

The self-assessment takes about three minutes and covers the same nine areas as our paid assessment. You get a score and a breakdown immediately, no email, no follow-up unless you ask.

No pitch on the first call. If we are not a fit, we will say so and point you somewhere better.