A one-man IT shop puts every password, every vendor relationship, and every undocumented fix inside one person’s head. When that person leaves, gets sick, or retires, a small business loses its entire IT department in one day.
Last spring an owner in Valley Cottage called me. Eighteen employees, light manufacturing, and the same IT guy for eleven years. That morning he’d walked into her office and given his two weeks. She wasn’t calling to replace him yet. She was calling because somewhere between his desk and hers, she’d realized she didn’t know the password to a single system her company runs on.
Not the Microsoft 365 admin account. Not the firewall. Not the backup box she’d been paying for since 2019. Him. He was the password.
I’ve taken a version of that call every year since we started VJNetworks in 2004. The company changes. The sentence in the middle doesn’t. “I couldn’t even tell you what we own.”
Before we go further, the disclosure. We sell the alternative. VJNetworks has run managed IT services for Tri-State small businesses out of Rockland for over 20 years, which means I benefit if this post worries you, and you should discount my conclusions by whatever amount feels fair. The math below doesn’t care either way.

Why Good Owners End Up With One IT Guy
A one-man IT shop is any arrangement where a single person holds all of a company’s technical knowledge and access. Sometimes that’s a full-time employee. Just as often it’s an outside consultant who built your network years ago and still answers when things break. Either way, one head holds everything.
And owners don’t land there by being careless. They land there by being reasonable. A dedicated hire or an IT company feels like overkill at ten employees. Your brother-in-law knows a guy, the guy is good, and for two or three years the arrangement works so well you stop thinking about it. That’s the trap. Not the failure. The comfort.
The one-man shop is cheaper on paper, and paper is where most IT budgets get decided. What never shows up on that paper is concentration risk, which is a finance term for a plain idea. Everything in one place burns in one fire.
The Risks You’re Carrying While He’s Still There
Most owners think the risk shows up on his last day. It moved in years ago. It’s been paying rent.
Start with coverage. Your server doesn’t check his calendar before it dies. One person means no nights he isn’t on call, no vacation that isn’t a coverage gap, and no flu that isn’t an outage risk, because emergencies famously refuse to check anyone’s availability before they happen. When our clients call, someone from my team responds within 15 minutes. When his clients call and he’s at his daughter’s wedding, they wait.
Then there’s the ceiling. Modern small-business IT is firewalls, Microsoft 365, backups, phones, Wi-Fi, printers, vendor contracts, and now a steady stream of cybersecurity work that barely existed fifteen years ago. No single human is good at that entire list. Not him. Not me. A solo operator triages what he’s best at and quietly defers the rest, and the deferred pile is invisible to you until something in it catches fire.
Security is the sharpest edge here. CISA, the federal cybersecurity agency, says the quiet part plainly. Small businesses get targeted because fewer people are watching. Their guidance for small businesses assumes somebody reviews the alerts, patches on a schedule, and rehearses an incident response plan, which is a reasonable set of assumptions right up until all three of those jobs belong to one man who also fixes the printers. One person can do some of that. One person cannot do it at 2am while also sleeping.
And there’s a quieter one. No second opinion. Every design decision your solo guy has made for a decade has gone unreviewed. Some of those decisions were smart. Some were whatever got the office back online by 5pm on the day the problem appeared. Which is which? Impossible to tell from the owner’s chair.
The Day the Notice Lands
Here’s the inventory of what walks out the door with him. I’ve watched owners work through this list in real time, and it’s longer than any of them expected.
- Every admin credential that was never written down. In most one-man shops, that’s all of them. Microsoft 365 global admin, firewall, router, backup console, domain registrar, the works.
- The vendor map. Which reseller holds your licenses, what the internet account number is, when the domain renews, who to call when the phone system acts up.
- The why. Why the warehouse Wi-Fi sits on its own network. Why one workstation was never allowed to update. Configurations make sense to the person who made them and to nobody else.
- Eleven years of muscle memory. He knows the server gets cranky after a power blip and exactly which service to restart, and your new person will learn every one of those quirks the hard way, at a price you will pay in downtime.
Two weeks of notice does not transfer eleven years of context. It can’t. A good tech leaving on good terms will write down maybe a tenth of what he knows, and that is the friendly version of the story, the one where nobody’s angry and the handoff happens over coffee instead of through a lawyer. Departures aren’t always friendly. I’ve seen an owner negotiate for the firewall password after the relationship went sour, and there is no worse position to bargain from.

The Replacement Math
Say you decide to replace him with another full-time hire. Here’s what the market says it costs.
The Bureau of Labor Statistics puts the median wage for a network and computer systems administrator at $96,800 as of May 2024. Add benefits, employer taxes, and equipment, and the loaded number clears $120,000 before he fixes a single printer. Recruiting isn’t free either. SHRM’s benchmarking report measured the average cost of making one hire at $4,129, and that figure is from 2016, a full decade of wage inflation ago.
The pipeline is thinning too. BLS projects the sysadmin occupation will shrink about 4 percent through 2034 as cloud platforms absorb the generalist work, with roughly 14,300 openings a year nationwide, most of them backfilling retirements. You’ll be bidding for a shrinking pool against companies with deeper pockets than yours.
Then the part nobody budgets. Ramp time. Your new hire spends the first three months learning where things are, not fixing them. Figure six months before he’s as useful as the guy who left, and that assumes you found him quickly, assumes he’s good, and assumes he stays, which is three separate bets in a market where each one fails all the time. One bet goes wrong and the meter restarts.
Call it a year, all in, to get back to where you were the day before the resignation. And where you were was one resignation away from doing it again.
Three Ways Out of the Trap
Nobody has to get fired here. There are three honest paths out, and the right one depends on your size, your person, and your appetite for repeating this exercise someday.
| Hire another solo tech | Co-managed IT | Managed IT team | |
|---|---|---|---|
| Cost shape | $96,800 median salary plus benefits (BLS, May 2024) | Your person’s salary plus a monthly fee | Flat monthly fee. Ours starts at $995/month. |
| Coverage when someone’s out | None. Same trap, new face. | A team backfills vacations and sick days | Team coverage year-round |
| Documentation | Depends entirely on the individual | Shared ticket history and runbooks | Contractual. Documentation is part of the product. |
| When a person leaves | Start this article over from the top | The team keeps the knowledge | You never notice |
A word on the middle column, because most owners have never heard of it. Co-managed IT means your person stays, keeps doing what they’re great at, and a provider’s team plugs in behind them with monitoring, backup coverage, documentation, and depth on the specialties no single human covers. It’s the option for owners who like their IT guy and would like him to survive a vacation. It deserves its own post. One is coming.
Keeping the One-Man Shop? Do These Five Things This Month
Maybe none of the three paths fits right now. That’s fair. Then buy down the risk you’re holding. In this order.
- Get every credential into a password manager your company owns. BitWarden is our recommended system. The recovery key sits with you, the owner, not with him.
- Ask for a one-page map of the network. What runs where, which box does what, the internet account number, the domain registrar, the license list.
- Watch a backup restore happen with your own eyes. A backup that’s never been restored is a rumor, not a plan.
- Build a renewal calendar. Domains, SSL certificates, software licenses, warranties. Missed renewals are how companies discover their website is down on a Saturday.
- Get an outside set of eyes on the whole thing once a year. Not to replace anyone. To review what one smart person built alone, because everything built alone has blind spots.
If your current person pushes back on items one and two, that tells you something too, because good techs love documentation requests, and it’s only the shaky ones who treat a password vault like a hostage negotiation.
The Part Where Owners Push Back
Our IT guy is excellent. Doesn’t that make this less urgent?
How long does replacing a solo IT admin take?
What is co-managed IT, in plain English?
How do we bring this up without insulting him?
We’re 12 people. Is a whole IT team overkill?
One more thing, and then I’ll let you go run payroll or whatever fire is next on your list. If any paragraph in this post made your stomach drop, the fix costs you an hour.
A free IT assessment inventories what you have, what’s documented, and what you’d lose. The assessment reads the same whether you ever hire us or not. You keep the report either way.
Over 20 years in the Tri-State area · 97% client retention · a real person responds within 15 minutes
