Your IT manager hands in their notice on a Friday afternoon. Or your sole tech person goes off sick with no return date in sight. Either way, you’re now facing a question that most businesses haven’t prepared for: what actually lives inside their head, and what happens to your systems when they’re gone?
For businesses in Manchester and Sale, this isn’t a theoretical problem. The IT handover problem is one of the most common crises we deal with at PC Express IT. It’s real, it’s expensive, and in most cases it’s entirely avoidable.
What Actually Gets Lost During an IT Handover
Most business owners assume that when an IT person leaves, they take their login and not much else. In reality, what departs with them is often far more damaging.
- Passwords and credentials for systems, routers, firewalls, cloud accounts, and third-party tools that nobody else knows
- Licensing keys for software your business depends on daily
- Vendor contacts and account numbers that took years to build up
- Network configurations: IP schemes, VPN setups, firewall rules
- Undocumented workarounds for known bugs or quirks in your systems
- Renewal dates for subscriptions, warranties, and contracts
- Admin access to Microsoft 365, cloud services, or on-premises servers
When all of this leaves with one person, you’re not just down an employee. You’re potentially locked out of your own business infrastructure.
The Security Risks Nobody Talks About
The immediate operational headache is obvious. But the security implications run deeper and are far more serious.
If a departing IT person remains an admin on your Microsoft 365 tenant, they can access emails, files, and Teams conversations after they’ve left. In most cases this isn’t malicious, but the access is there. If the departure was acrimonious, the risk escalates significantly.
Beyond deliberate misuse, there’s the passive risk. A former employee’s credentials sitting active in your systems become a target for attackers. If those credentials are breached elsewhere, through a phishing attack on the ex-employee for instance, an attacker inherits admin-level access to your business.
According to IBM’s Cost of a Data Breach report, the average breach caused by compromised credentials costs millions of pounds globally. For Manchester SMEs, even a fraction of that figure is catastrophic. This is why proper IT offboarding is not just good HR practice, it’s a cybersecurity necessity.
Admin Accounts: The Hidden Time Bomb in Every IT Handover
The most common scenario we encounter is a business where a former employee or contractor is still listed as a Global Administrator on Microsoft 365, months or even years after they left. Getting that access back, and making sure no damage has been done, requires careful forensic work.
Changing admin accounts without proper knowledge of the configuration can break email flows, knock out multi-factor authentication, or disrupt Azure Active Directory synchronisation across your whole organisation. The same applies to on-premises systems. If your departing IT person was the only one who knew the local admin password for your servers, you may face a lengthy and expensive recovery process.
Licences, Subscriptions, and Renewals
Your IT person was probably the one managing all the renewals. Software licences, antivirus subscriptions, SSL certificates, domain registrations, and Microsoft 365 billing often sit in a single person’s inbox or personal account. When they leave, those renewal reminders stop reaching anyone who can act on them.
We’ve seen businesses in the Sale and Trafford areas lose their primary domain because nobody spotted the renewal notice, or have critical security tools lapse because billing was tied to a now-defunct email address. It’s a quiet failure, until it isn’t.
How to Protect Your Business Before They Leave
If you have an IT person in post right now, this is the time to act. You don’t need to anticipate conflict or plan for the worst. You simply need to treat IT documentation and access as a business asset, not a personal one.
Build a Living IT Documentation File
This should include: network topology, all admin credentials stored in a business password manager, software licences and renewal dates, vendor contacts and account numbers, and any non-standard configurations or known workarounds. Review and update it quarterly.
Use a Business Password Manager
Tools like 1Password Teams, Bitwarden for Business, or Microsoft’s built-in capabilities mean credentials are shared with the organisation, not a single person. When someone leaves, you remove them from the vault. The credentials stay with the business.
Separate Personal and Service Accounts
Every admin account should be tied to a business email address, not a personal Gmail or the IT person’s own Microsoft account. Subscriptions, renewals, and vendor accounts should flow to a shared mailbox that the business controls, not the individual.
Run a Quarterly Access Audit
Review who has admin access to your Microsoft 365 tenant, cloud services, and on-premises systems every quarter. Remove anyone who shouldn’t still have it. This takes 30 minutes and eliminates significant risk.
What If Your IT Person Has Already Left?
If you’re reading this because the departure has already happened, don’t panic, but do act quickly. Start by listing every system you know is in use, then contact vendors directly to verify account ownership and reset credentials where possible. For Microsoft 365, you can regain access through Microsoft’s account recovery process if you have the billing account details.
If you’re struggling to gain access or aren’t sure what’s exposed, bring in an external IT support team immediately. Attempting to manually reset admin credentials on unfamiliar systems without guidance can cause more problems than it solves.
Why Manchester Businesses Need a Managed IT Partner
The root cause of the IT handover problem is almost always the same: too much knowledge locked in one person’s head, and no formal process for maintaining IT as a business asset rather than a personal one.
A managed IT support partner changes this by design. Everything is documented centrally. Admin credentials are held by the support organisation, not individual engineers. Renewals are tracked. Configurations are recorded. When a member of the IT partner’s team moves on, it has no effect on your business.
For Manchester and Sale businesses that have been relying on a single internal IT person, or a contractor who “just sorts things”, moving to a managed service model is often the most significant risk reduction you can make. At PC Express IT, based in Sale, we work with businesses across Manchester, Trafford, and Altrincham to ensure your IT doesn’t depend on any single person. If you’re concerned about your current exposure, get in touch for a no-obligation review.
Frequently Asked Questions
What should I do immediately when my IT person hands in their notice?
Start an account audit right away. List every system they have access to and begin resetting credentials and transferring ownership before their last day. Disable all accounts on the day they leave, not after. Treat the notice period as your window for a structured IT handover.
Can a former IT employee still access our systems after they have left?
Yes, if their accounts have not been disabled. Former employees who held admin roles on Microsoft 365, cloud platforms, or on-premises servers retain that access until it is explicitly revoked. This is one of the most common oversights we see in Manchester and Sale businesses.
What is an IT knowledge base and does my business need one?
An IT knowledge base is a documented record of your systems, configurations, credentials, licences, and processes. Every business with more than a handful of staff should have one. It does not need to be complex; even a well-maintained spreadsheet in a secure shared location is better than nothing.
How do I regain admin access to Microsoft 365 if my IT person has already left?
Microsoft has an account recovery process for Global Admin access. You will need to verify ownership of the billing account or domain. If the billing email is inaccessible, contact Microsoft support directly. An IT partner familiar with Microsoft 365 can guide you through this process quickly and safely.
Is it a GDPR issue if a former employee still has access to our systems?
Potentially yes. Under GDPR, access to personal data must be granted on a need-to-know basis. A former employee who retains access to customer records, emails, or HR systems after leaving represents a data breach risk. You should document your offboarding procedures as part of your data security policy.
How often should we audit IT access and user accounts?
At minimum, quarterly. In practice, access audits should also be triggered by any staff change, not just IT roles. Anyone who leaves the business should have all system access removed on their last day, without exception.
Can a managed IT support company prevent the IT handover problem entirely?
Yes, and this is one of the primary benefits of managed IT. A managed IT partner holds all credentials, documentation, and configurations centrally. If one of their engineers moves on, it has no impact on your service. Your business knowledge never leaves with any individual person.
