When ad hoc help from an IT specialist is no longer enough for the company
Informal IT support may correspond to a simple business, but as your business grows, the importance of documentation, representation, security and agreed accountability increases. We show signals that justify changing the model.

The help of a trusted person may be a reasonable solution when the company has several devices, a simple way of working and accepts the lack of constant availability. The problem is not a private relationship with an IT specialist, but a model without a defined scope, documentation, replacement and security rules.
As the number of users and systems increases, the impact of failure affects more processes. Then it is worth replacing ad hoc interventions with a structured service or a formally defined internal role.
What is the ad hoc IT service model
Most often it means that help is ordered only after a problem occurs. The parties may not have agreed:
- availability hours and ticket priorities;
- response time and escalation method;
- responsibility for updates, copies and monitoring;
- locations for storing documentation and administrative accounts;
- replacement during absence;
- rules for access to data and termination of cooperation.
Such a model does not have to be wrong if both parties know the limitations and the company can accept the risk. However, it should not pretend to be full IT care.
Signals that the current model is too weak
It is worth considering a change when:
- employees don't know where to report problems;
- essential systems depend on the availability of one person;
- the company does not have its own administrative access or up-to-date documentation;
- it is not known whether copies are made and whether they can be restored;
- updates and termination of privileges of former employees happen haphazardly;
- downtime is already a significant cost, but there is no set escalation path;
- there are servers, multiple locations, remote work or customer security requirements.
There is no universal employee headcount threshold. A five-person company may have a mission-critical production system, while a larger team may work almost exclusively on simple cloud services.
How to calculate the cost of downtime
Instead of using general averages, it's worth calculating your own scenario:
- Determine the number of people who actually cannot work.
- Calculate their cost per hour or the margin generated by the stopped process.
- Estimate productivity loss; a crash doesn't always keep each person whole.
- Add possible additional costs, such as delayed shipping, replacement labour, and contract penalties.
- Multiply the result by the actual unavailability time.
The calculation is a scenario, not a forecast of guaranteed loss. However, it allows you to determine how much is worth spending on response time reduction, redundancy and recovery.
Downtime cost calculator helps sort out these assumptions.
Risk of knowledge concentrated in one person
One-person operation does not necessarily mean a lack of documentation, and a large supplier does not guarantee its quality. You need to check the facts. The company should control:
- owner and privileged accounts;
- safely stored recovery data;
- records of devices, licences and suppliers;
- network diagram and description of key configurations;
- backup schedule and recovery test results;
- procedure for receiving and transferring access.
Documentation should enable an authorized person to take over basic operations without guessing passwords and environment topology.
Personal data and confidentiality
The technical administrator may have access to systems containing personal data and confidential information. The organisation should establish roles, scope of authority, access logging rules and confidentiality obligations. If the service provider processes personal data on behalf of the company, a data processing agreement may be needed.
The conclusion of a contract does not transfer all responsibility for compliance to the supplier. The data controller still must select appropriate measures and supervise the processor to the extent required by law.
Possible target models
Formalized cooperation with the current person
If the IT specialist has appropriate competences and availability, the relationship can be structured: describe the scope, method of reporting, documentation, replacement, security and settlements. Change does not always require changing the person.
External assembly
The supplier can provide several specializations and substitutability. However, they must be confirmed in the offer and contract. Monitoring can detect some problems earlier, but it does not prevent every failure. The SLA should clearly distinguish between response, bypass, and service recovery.
Hybrid model
An internal person can know processes and handle tasks on-site, and an external partner can be responsible for agreed specialist areas. The prerequisite is a clear division of responsibility and common documentation.
How to change model without losing control
- Take inventory of devices, services, accounts and contracts.
- Secure owner accounts and emergency access.
- Determine where your data and backups are located.
- Describe critical processes, priorities, and required runtimes.
- Agree on the handover protocol with the current person.
- Change or revoke privileges only in accordance with the approved schedule.
- Verify documentation and test the selected recovery procedure.
Conclusion
The quality of service does not depend on whether the IT specialist is a friend, employee or external partner. Competence, availability, documentation, access control, representation and responsibility are decisive. If these elements are missing, the company should replenish them before a failure forces a change in a hurry.
Book a free IT reviewto identify gaps and prepare a safe scope for taking over administration.