Skip to content

The Accidental IT Person: What to Do When You’re Stuck Managing Tech

Somebody at your company has become the IT person. Maybe that’s you. You didn’t apply for the job, you didn’t train for it, and most days you’re guessing your way through it between everything else you’re actually supposed to be doing. Start with three things this week: get your backups actually verified, get every password out of people’s heads and into one secure place, and set a real date for when you’ll bring in outside help. The rest of this comes down to how you get there.

Nearly half of small businesses have no one on staff dedicated to cybersecurity or IT, according to a 2026 small business cybersecurity roundup. If that’s you, you’re not the exception. You’re the norm, which doesn’t make the risk any smaller.

1. How did you end up running IT anyway?

It’s rarely a decision. Somebody was comfortable with computers, or the last person who touched IT left, or the business grew faster than anyone planned for. Now you’re the one who gets pulled in when the printer won’t connect, when an employee forgets their password, when a laptop dies the week before a big client deadline.

None of that makes you unqualified. It makes you busy, and it puts your business one bad week away from a problem you don’t have the tools to fix.

What should you fix first, this week?

You don’t need a full IT overhaul to reduce your risk right now. Four things matter more than everything else on the list.

Confirm your backups actually restore something. A backup that runs every night but has never been tested is not a backup. It’s a hope. Pick one file or one folder and try restoring it from your backup system this week. If you can’t, you have your answer.

Get passwords out of sticky notes and shared documents. If your team is emailing logins to each other or keeping them in a spreadsheet, that’s the easiest way into your systems for anyone who shouldn’t have access. A password manager takes an afternoon to set up.

Write down every vendor and login that matters. Domain registrar, email provider, accounting software, payroll. If you left tomorrow, could someone else find and access all of it? If the answer is no, that’s a bigger risk than most of what’s on your plate right now.

Turn on multi-factor authentication everywhere it’s offered. Email first, then anything with financial or customer data. It’s the single highest-impact thing you can do in an afternoon.

How do you know if your backups are actually working, not just running?

A green checkmark that says “backup complete” tells you the process ran. It doesn’t tell you the data is recoverable, that the backup covers everything you’d need in a real recovery, or that it would come back fast enough to matter. Testing a restore, on a schedule, is the only way to know for sure. Our guide on backup and recovery plans walks through what a real plan covers, including how often to test it.

What about passwords scattered across half the team’s inboxes?

This is the one that keeps growing quietly until it’s unmanageable. New hires get whatever login worked for the last person. Old employees’ access never gets revoked. Passwords get reused across five different tools because remembering unique ones for each is exhausting. Our guide to strong passwords and authentication covers what actually makes a password hard to crack and where multi-factor authentication fits in.

When does this stop being a side project and become a real risk?

A few signs it’s outgrown what one person can handle on the side: you’re adding new employees or locations faster than you can document your own systems, a client or industry requirement now demands specific security practices you can’t confirm you meet, or you’ve had a close call, a phishing email that almost got clicked, a laptop that almost walked out the door, that made you realize how much you don’t actually know. Small businesses across every industry we work with hit this point eventually. Our small business IT page covers what managed support actually looks like day to day, without the jargon.

What if you’re the employee, not the owner, and leadership won’t budge on bringing in help?

Track your time for two weeks. Every ticket, every troubleshooting call, every hour spent researching a problem instead of doing your actual job. Bring that number to leadership, not a pitch about technology, just the cost of the current setup in hours and what those hours are worth. Framing it as a business cost rather than a tech upgrade tends to land better with owners who are focused on the bottom line.

You shouldn’t have to be the safety net for your company’s entire IT setup. Tell us where it hurts. We’ll take it from here.


Frequently Asked Questions

What should I do first if I got stuck managing IT with no training?

Start with three things this week: verify your backups actually restore, get passwords out of sticky notes and into a password manager, and turn on multi-factor authentication everywhere it’s offered. Those three cover the highest-risk gaps fastest.

How do I know if my backups are actually working?

A “backup complete” message only tells you the job ran, not that the data is recoverable. Test an actual restore of one file or folder on a schedule. That’s the only way to know for sure.

When should a small business bring in outside IT help instead of managing it internally?

When you’re growing faster than you can document your own systems, when a client or industry requirement demands security practices you can’t confirm you meet, or after a close call that reveals how much you don’t actually know.

How do I convince my employer to invest in IT support if I’m the one stuck managing it?

Track your hours spent on IT tasks for two weeks and bring leadership the actual cost, not a pitch about technology. Framing it as a business cost tends to land better than framing it as an upgrade.