Your continuity plan is one person
Every company of forty people has a risk register, and none of them has the actual risk on it. The actual risk is that one person knows the admin passwords, which supplier does what, why that server in the corner exists, and what breaks if the certificate on the VPN is not renewed in March.
That person is competent, loyal and completely undocumented. Nobody planned this. It happened one urgent fix at a time.
How it forms
Somebody stepped up. Usually not a hire — a person who was good with computers when the company was twelve people, and who kept being the person as it grew.
Documentation was always next quarter. Genuinely, and for a good reason: there was always something broken, and writing down how you fixed the last thing loses to fixing the next one.
Access narrowed for good reasons. Fewer admins is better security advice, and it is correct right up to the point where fewer means one.
Suppliers learned who to call. Now the relationship, the account history and the informal context all live in the same head as the passwords.
Six months of that and the company has a dependency it did not choose, on a person who did not ask for it and mostly does not enjoy it.
What it actually costs
Holidays are not holidays. The person takes their laptop, and everybody knows they will answer. This is the first symptom and the one that gets normalised fastest.
Change slows down. Every project needs the same person, so the queue is one deep regardless of budget.
Security gets worse, not better. A single admin who cannot be covered means credentials get shared informally during an emergency, and the informal sharing is never undone.
They cannot be promoted. The most reliable way to lose this person is to make it impossible for them to do anything except be the single point of failure.
And then the real cost: they leave, and the company discovers what was in their head by finding out which parts of it were load-bearing.
What fixes it, in order
A written estate. What exists, where, why, who supplies it, when it renews, and what happens if it stops. Boring, unglamorous, and the single highest-value document in a mid-sized company.
Credentials in a system, not a person. A password manager with defined access, a documented break-glass procedure, and recovery that does not depend on one phone.
A second pair of hands with real access. Internal or external, but with genuine permissions and enough context to be useful during an incident rather than after it.
Supplier relationships on company accounts. Contracts, portals and support entitlements registered to the company, with more than one named contact.
Rehearsal. Once a year, the person goes away for a week and somebody else runs it. Whatever breaks is the documentation gap, found cheaply.
The uncomfortable conversation
The person in this position often resists fixing it, and the reason is rarely job security. It is that fixing it means admitting how much is undocumented, and that feels like an accusation about their work.
It is worth being explicit that it is not. The situation is a predictable consequence of a company growing faster than its documentation, and it is the company’s failure rather than theirs. Framed that way the conversation usually goes well, because the person carrying it has almost always wanted to put it down.
- key person risk
- documentation
- continuity
- IT management