
At 8:15 on a Monday, your IT manager gives notice - or simply does not come back. The immediate question is what to do when IT manager leaves, but the real concern is bigger: who holds the keys to your email, backups, firewall, cloud accounts, phones, vendor portals, and security tools?
For a small or midsize business, one IT departure can expose years of undocumented decisions. That does not mean your business is doomed. It means the first few days need disciplined action, not a rushed search for someone who claims they can fix everything.
Treat the departure as an access and continuity event
An IT manager leaving is an HR event, but it is also a security and business-continuity event. Even a trusted employee may have personal admin accounts, saved credentials, recovery codes, vendor relationships, and knowledge that no one else has. A clean exit can still create real risk if the organization does not control its systems.
Bring together the people who can make decisions: leadership, HR, finance or operations, and any remaining technical staff. Assign one business owner to coordinate the response. Without a clear owner, tasks get scattered among people who assume someone else is handling them.
Your goal is simple for the first 24 hours: maintain control of systems, keep employees working, and avoid creating a new security problem while trying to solve the old one.
What to do when an IT manager leaves: first 24 hours
Start by determining whether the departure is planned, immediate, or potentially contentious. The access response should match the circumstances. If the person is departing on good terms and can support a transition, preserve that knowledge before accounts are changed. If access needs to end immediately, secure the environment first and document what you find afterward.
These actions should happen promptly:
- Disable or remove the departing employee’s access to email, VPN, remote-management tools, password vaults, cloud administration, financial systems, and physical access controls.
- Change shared administrator passwords and rotate credentials for firewalls, wireless networks, backup platforms, domain registrars, cloud tenants, phone systems, and critical vendor portals.
- Confirm who owns your Microsoft 365 or Google Workspace tenant, domain names, internet service account, cloud subscriptions, backup account, and cybersecurity tools.
- Preserve the employee’s email mailbox, files, documentation, tickets, and configuration records according to your HR, legal, and retention requirements.
- Check that backups are completing and that alerts are going to an active, monitored mailbox rather than the former manager’s inbox.
- Contact key technology vendors to update authorized contacts and prevent unauthorized account changes.
Do not assume disabling the employee’s primary email account is enough. Many organizations discover that their former IT manager used a personal email address for a software renewal, domain registration, cloud account, or emergency recovery contact. Those accounts can become a painful ownership dispute at the exact moment you need access.
If your organization handles protected health information, client legal files, donor data, payment information, or other sensitive records, document the access changes. You may need evidence for an insurer, client, audit, or compliance review later.
Stabilize the systems people rely on every day
Once access is controlled, look for the quiet failures that may be waiting in the background. An IT manager often handles work that nobody notices until it stops: approving software renewals, replacing failed equipment, reviewing security alerts, monitoring storage capacity, and chasing down an internet provider when service goes out.
Ask practical questions. Are endpoint protections active on every computer? Are operating-system patches being applied? Is anyone watching failed backup reports? When does the firewall license expire? Are there open help desk tickets, aging servers, or equipment orders in progress?
This is not the time to launch a complete technology makeover. You need enough visibility to prevent avoidable downtime while you build a fuller plan. A reliable outside IT team can quickly assess the environment, but be wary of anyone who starts by selling a major replacement project before they understand what you have.
For many Atlanta organizations, the immediate gap is help desk coverage. Staff still need password resets, printer help, new-user setup, laptop support, and someone to call when the internet drops. If those requests had been living in the IT manager’s personal inbox or cell phone, establish a visible support path right away. People should know where to get help and who is accountable for responding.
Capture knowledge before it walks out the door
If the departing manager is available and willing to help, schedule a structured handoff. A casual conversation is not enough. Ask for documentation, but also ask the questions that documentation usually misses.
Start with a map of the environment: internet circuits, firewalls, switches, wireless networks, servers, cloud services, line-of-business applications, VoIP phones, backup systems, and endpoint-security tools. Then identify the vendors, contract dates, renewal costs, support contacts, and any known problems.
Pay particular attention to exceptions. Every business has them: the workstation that runs specialized accounting software, the file share a department cannot lose, the copier scan-to-email setup, the employee with a remote-access exception, or the old application that only works on one server. Those exceptions are often where outages and security gaps begin.
A useful transition document should also identify who has administrator rights, where credentials are stored, how new employees are onboarded and offboarded, how backups are restored, and what happens after a suspected security incident. If the answer is that one person simply knows how to do it, you have found the real continuity problem.
Decide whether to replace, outsource, or build a hybrid model
The right answer depends on your organization, not on a generic headcount chart. Replacing the IT manager may make sense if you have a complex environment, a sizable technical team, or a full-time stream of projects and support work. But hiring takes time, and one replacement hire can recreate the same single-person dependency if documentation and oversight remain weak.
Outsourced IT management can be a better fit when you need immediate coverage across help desk support, cybersecurity, backup monitoring, patching, vendor management, and strategic planning. It gives leadership access to more than one skill set, which matters when a ransomware alert, a failed server, and a new-office move all arrive in the same month.
A hybrid approach is common as well. Keep an internal IT coordinator or technology-minded operations leader, then use a local managed services provider for monitoring, security, escalations, and specialized projects. This can work especially well for law firms, healthcare-adjacent practices, nonprofits, and congregations that need dependable support but do not need a large internal IT department.
The trade-off is control versus coverage. An internal hire may know your culture and workflows deeply. An outside partner should bring broader technical depth, documented processes, and coverage when one technician is unavailable. The best model makes responsibilities clear instead of leaving them in a gray area.
Get an independent assessment before making large commitments
Before signing a long contract or buying new infrastructure, get a clear picture of your risks. A good assessment should answer plain-English questions: Can you recover from a ransomware attack? Who controls your cloud accounts? Are backups actually recoverable? Which systems are unsupported? Where are former employees still active? What will break first if your server, internet connection, or phone system fails?
Ask for findings ranked by business risk, not a 40-page pile of jargon. Critical items might include missing multifactor authentication, unknown admin accounts, failed backups, unsupported firewalls, or no tested recovery plan. Lower-priority improvements can be scheduled around budget and operations.
This is where a local partner can be particularly useful. 404 Network Ninjas works with Metro Atlanta organizations that need a real person to assess the environment, document the gaps, and handle the work without enterprise-style runaround. The point is not to add another vendor. It is to make sure no single departure can leave your business without a map, a backup, or someone answering the phone.
Build the exit plan you should have had all along
After the immediate transition, turn the experience into a permanent operating practice. Every critical system should have organization-owned accounts, at least two authorized administrators, current documentation, and a defined support process. Passwords and recovery codes should live in a controlled business vault, not in someone’s browser, notebook, or personal phone.
Review access regularly, especially after staffing changes. Test backup restoration instead of trusting a green check mark. Keep an inventory of equipment and software renewals. Document your incident-response contacts, including who has authority to make decisions when a security event interrupts normal business.
The next IT departure should be inconvenient, not catastrophic. When the keys, knowledge, and accountability belong to the organization, a staffing change stays a staffing change - not the start of an outage.


