One person knowing everything isn't an IT problem

Most businesses have someone who knows how everything fits together. Sometimes it’s an employee. Sometimes it’s someone at the IT provider. Sometimes it’s the owner, quietly holding it all in their head.

Nobody plans for this to happen. It just does — one person picks things up, becomes the one who knows where everything is, and over time the business ends up depending on them more than anyone realised.

Why it's not obvious

The reason this risk stays invisible is simple: it doesn’t cause problems while the person is still there.

Everything works. Questions get answered. Issues get fixed, usually quickly, usually by the same person. There’s no reason to notice a dependency that never gets tested.

What happens when they're not there

It’s rarely anything dramatic. More often, it’s ordinary:

A holiday. A period of sickness. Retirement. A resignation. A change of IT provider.

Whatever the reason, the pattern’s usually the same. Nobody knows where things are documented, how systems connect, why certain decisions were made, or who has access to what.

Need to grant access to a new starter? Nobody’s quite sure where to begin. Need to change a supplier? Nobody knows which account owns the contract. Need to recover a password or licence? The answer used to be one phone call away.

Nothing necessarily breaks. But everything that used to be quick suddenly takes longer.

How it actually happens

It’s rarely one bad decision. More often it’s a few ordinary ones, stacked up over time.

A business grows faster than its IT setup does, and whoever’s closest to it just absorbs more responsibility. Or the same person’s been there since the early days, and nobody’s replaced the informal knowledge they built up with anything written down. Or IT was handed to a sole freelancer or a single contact at a provider, because that was simpler at the time, and it never got revisited.

None of these are mistakes. They’re just how businesses actually grow — a series of reasonable decisions that add up to a single point of failure nobody chose on purpose.

A simple test

If your main IT contact — internal or external — was unavailable tomorrow, would anyone else be able to answer:

  • How your systems are actually configured?
  • Which suppliers or vendors are involved, and for what?
  • What’s properly documented, and what only exists in someone’s head?
  • Who has administrative access, and to what?

No scoring system, no checklist to fill in. Just questions worth sitting with for a minute.

What it looks like when this isn't a problem

It’s not that the business needs a bigger IT team, or more people involved. It’s a lower bar than that. Usually it just means: more than one person could answer the questions above. Access isn’t tied to a single login nobody else has. The basics are written down somewhere that isn’t one person’s head.

Most businesses without this problem didn’t set out to solve it — they just never let it build up in the first place.

The thing about this risk

Businesses rarely discover whether they have it. They discover how much of it they have — usually the day they need an answer and there’s nobody left to ask.