IT Person Quit? What to Secure in the First Week

Your IT Person Just Quit: What to Secure in the First Week

Start with access. In the first week, find out who holds the admin keys to your email, domain, firewall, backups and business apps, move those keys to someone you trust, and confirm your backups actually restore. Everything else can follow a checklist.

Whether your IT person retired, took a new job or left on less friendly terms, the risk is the same: much of how your business runs may live in one person's head and one person's password manager. Nobody is being accused here: changing credentials after a departure is standard practice, and a good IT person would tell you to do it. Here's a day-by-day plan for the first week.

Day 1: Find out who holds the keys

Make a list of every system where your former IT person had administrator access. Most offices find more than they expected. Check:

  • Microsoft 365 or Google Workspace admin center
  • Domain registrar (where your web address is registered)
  • DNS host (sometimes the same as the registrar, sometimes not)
  • Firewall and router
  • Wi-Fi controllers and access points
  • Backup system and any cloud backup accounts
  • Line-of-business applications (accounting, practice management, CRM, point of sale)
  • Vendor portals: internet provider, phone system, copier lease, software licensing
  • The company password manager, if you have one
  • Servers, NAS devices and remote access tools

If you don't know where something is managed, check old invoices and renewal emails. They usually reveal the vendor, and the vendor can tell you who the account contact is.

Days 1 to 2: Change passwords and remove admin rights

Do this respectfully and promptly, even if they left on great terms. A short, friendly note works: "We're updating credentials as part of the transition. Thanks for everything." Then:

  • Disable or remove their personal accounts and admin roles in Microsoft 365 or Google Workspace
  • Change every shared and admin password they knew, starting with email, the domain registrar and the firewall
  • Rotate Wi-Fi passwords, especially for the staff network
  • Remove their access to remote access tools and VPN
  • Revoke any API keys or app passwords they created, if you can identify them

Make sure at least two people at your company can reach the master admin accounts. One owner plus a trusted manager is a good start.

Day 2: Reset MFA and recovery details

Changing a password doesn't help if the account's multi-factor authentication still sends codes to your former IT person's phone. For every admin account:

  • Reset or re-register multi-factor authentication (MFA) to a device the company controls
  • Update recovery email addresses and phone numbers
  • Replace any personal email address used as an account login with a company address

This is the step people skip most often, and it matters as much as the passwords.

Day 3: Confirm domain, DNS, licenses and billing

Your domain name is how customers find you and how your email works. Confirm your business is the registered owner of the domain, not your former IT person or their company. Check the renewal date and make sure auto-renew charges a company card.

Then review billing accounts for Microsoft 365 or Google Workspace, backup services, security tools and software subscriptions. Move any that are billed to a personal card or personal account. Note renewal dates so nothing lapses quietly.

Day 4: Find the documentation

Ask where the documentation lives: network diagrams, passwords, vendor contacts, configuration notes, the list of who has which software. It might be a shared folder, a notebook or nowhere. Whatever you find, copy it to a location the company controls.

If your former IT person is willing to spend an hour on a handoff call, take it. Ask about anything unusual: custom scripts, workarounds and "don't touch that server" warnings.

Day 5: Test the backups

A backup report that says "success" is not the same as a backup you can restore. Confirm:

  • Which systems are backed up (servers, Microsoft 365 or Google data, key workstations)
  • Backups ran successfully in the last few days
  • A test file or folder can actually be restored
  • A copy is stored off-site or in the cloud

If you can't confirm all four, treat that as the top item for next week.

Day 6: Check contracts, warranties and scheduled tasks

Gather warranty and support contracts for servers, firewalls and other key equipment so you know who to call when hardware fails. Then look for scheduled tasks and scripts that may stop working once the departed person's account is disabled. Common culprits are backup jobs, file sync tasks and reports that run under a personal login. Expect something small to break; knowing where to look makes it a quick fix.

Day 7: Tell staff who to call now

Your team needs a clear answer to "my computer isn't working, who do I contact?" Send a short note with the new process, even if it's temporary. While you're at it, review how you handle new hires and departures going forward; our new employee IT security checklist covers the access steps.

When to bring in a Managed Service Provider

A departure is a natural point to ask whether one person should hold all of this at all. A Managed Service Provider (MSP) gives you a team rather than a single point of failure, with documentation that belongs to you. It's worth a conversation if:

  • You couldn't complete the checklist above without help
  • Nobody else in the office understands how the network is set up
  • You handle regulated data (financial, health or legal) and need evidence your controls are in place
  • Hiring a replacement would take months

Not sure where you stand? Read is my business ready for managed IT?

How NerdSquad handles a handoff

When a business comes to us after an IT person leaves, our managed IT onboarding process covers the same ground in a structured way:

  • Discovery and documentation: we inventory your systems, accounts, vendors and licenses and document how everything connects
  • Credential vault: admin credentials move into a secure, audited vault, with your company keeping owner-level access to its own accounts
  • Monitoring: automated monitoring runs around the clock on every plan, so failing backups or devices surface as tickets
  • Security baseline: MFA, endpoint protection and backups are checked and brought up to standard
  • A clear support path: your staff know exactly how to reach us by phone, email or the support portal

If you're a smaller business, our page on managed IT for small businesses explains what working with us looks like.


Talk to NerdSquad

Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.

Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.

Related: Managed IT services and plans