I want to start with a quick story. I once spoke to a business owner who had one person handle all his company’s technology. Now, this person wasn’t a technical person by trade, but got handed the role and did it for a long time. I asked a really simple question, out of curiosity, not fear. The question was: what if they get hit by a bus?
The business owner brushed it off and didn’t seem terribly worried. We had a good discussion after that, but you could tell they didn’t take these things seriously.
Months go by, and I get a phone call from that business owner. He called to tell me that this person had passed away. They were panicking because they didn’t have any of the information they should have: logins to systems, or even how to set up basic things like a new employee. Of course we offered to help, but they turned it down, and that’s where the story ends. Unfortunately, I don’t have anything more.
But it’s really, really important that I tell you that story. Because although it’s the extreme side, the ordinary version of this happens all the time. People quit. People get fired. Maybe they get sick, and they’re on sick leave. Or maybe they’re just sick of you, and they leave. The problem is that businesses find this out way too late. They find out there’s only one person who can log into a system, only one person who can make changes. And when that person leaves, they hold the keys to the kingdom.
Getting everything back can be somewhat destructive and will take weeks or months. Meaning if you needed to hire an employee and get them an email address spun up, you couldn’t for at least a couple of weeks.
Although this is framed as a technology problem, it’s really not a technical problem. It’s a who-holds-the-keys problem. Sometimes those keys are stuck in someone’s head, and whether they’re around to give them to you, or not willing to give them to you at all, is a moot point. The business owner needs to mitigate that risk altogether.
So let me give you a quick 20-minute check.
The 20-minute check
Let’s start with the really simple one. Your website domain, whatever yourcompany.com is. Who owns it, and who can log into it? Do you need two-factor authentication to access it?
Your email provider: Microsoft 365, Google, or somebody else. Who has the administrative access to that?
Then look at things like your website, accounting software, ERP or CRM, phone systems, network passwords, and server passwords. Who controls all of those?
On each account, whose email is on the recovery email or the recovery phone? In some cases, if you need to make a change, they require a second step of verification.
And the last question you should ask about every item: if this person vanished, do I have a way to get into it that doesn’t go through them?
What to fix today
You, as the owner or the person in charge of this crucial piece of the business, need access to everything. Or, if you have a contractual obligation with a tech firm not to have access to everything, they often have a sealed version of how to get in. What do I mean by that? A lot of IT people, and even IT companies, don’t want you to have admin credentials, for good reason. They don’t want people making changes to systems they don’t know about that could cause security problems or outages. But they’re happy to give you a sealed version. Once you break the seal and get in, whether through technology or other means, the IT person gets notified, or, in terms of a contractual obligation, there are clauses of liability and cost in case something breaks.
Another thing to think about is recovery contacts. Make sure the email and phone number point to a business system, not just a person. Set up a shared number through your phone service that can receive text messages, such as a Google Voice number, or even something as simple as a cell phone that sits in a drawer. As much as I don’t like that idea, it’s better than having it on someone’s personal cell phone that no one can access.
More than one person needs to know how things work. Even if it’s documented in a binder. If you want to print it because you’re old school, that’s fine. But document how everything works, and make sure more than one person knows it. The document should also include what’s where, how it connects, and how one system talks to another. That way, if something happens and you want to bring on another technical resource, you can hand them these pieces. It’s not a three-month discovery process of finding problems. It’s a one-day read, and business continues as normal.
The other thing to fix today: figure out what you’d actually tell a client if you couldn’t get into one of your systems. Or what you’d tell a new employee, or an existing one, if something happened and you couldn’t get in.
The other side
So that we’re not playing on fear, it’s not about trusting your people, because most of the time nothing happens. You can trust someone completely and still not want them to be the only key. If you have a spouse, they have the key to the house too.
It’s not about the business being afraid of someone doing something wrong. It’s about the business being one major event away from being locked out of everything it has.
Doing this will take you twenty minutes. But even if it took you an hour, that hour might save you weeks or months down the road.
In two weeks, I’ll get into the cyber insurance landscape. The questionnaires you get are more important than you think, and they’re getting tougher. If that sounds interesting, subscribe so we can send it to you.
If you’d rather talk about risk management and how to protect your business, that’s the kind of thing I like doing. You can grab some time with me here.

