There is a very specific way IT departments are created at large companies. There are job descriptions, interviews, certifications, budgets and people with titles like Director of Infrastructure and Security.
At a small company or nonprofit, the process is considerably more streamlined: “Hey, you’re pretty good with computers, right?”
And just like that, you’re in IT.
Maybe you helped connect a laptop to the conference room screen. Maybe you knew how to reset the Wi-Fi router. Maybe you once mentioned that you built your own PC. It doesn’t matter. You have demonstrated technical competence, and there will be consequences.
Meet the Accidental IT Person
The Accidental IT Person thrives in startups, nonprofits and small organizations where everyone already has three jobs. Officially, they may be the office manager, operations director, finance person or communications manager. Unofficially, they’re responsible for questions like: “Why can’t I get into my email?” “Can you add Sarah to SharePoint?” “Is this email from Microsoft real?” And the particularly ominous: “I clicked something. Can you come over here?”
It usually begins innocently. Someone needs a Microsoft 365 account, and the Accidental IT Person figures it out. Then someone needs access to a shared folder. Then a new employee needs “all the same stuff Jennifer has.”
Before long, our hero has administrative access to the company’s entire technology environment and is making decisions about cybersecurity, licensing, data access and backups while simultaneously ordering toner.
Being Good with Computers Is No Longer Enough
The problem isn’t that Accidental IT People are bad at technology. Quite often, they’re surprisingly good at it. That’s how they got into this mess.
The problem is that modern IT has become enormously complicated. Even a 15-person organization may have Microsoft 365 or Google Workspace, cloud storage, laptops, mobile devices, SaaS applications, multifactor authentication, cybersecurity tools and dozens of user accounts.
Someone has to decide who gets access to what, remove that access when employees leave, make sure backups work and configure security policies. Now they also have to figure out whether that shiny new AI tool someone just signed up for is quietly uploading confidential organizational information somewhere it shouldn’t.
That’s a lot to put on the person who got the job because they successfully connected the CEO’s AirPods.
The Password Spreadsheet of Doom
Every Accidental IT Person eventually discovers something that makes them question the decisions of everyone who came before them. It might be a spreadsheet called Passwords.xls, an administrator account belonging to an employee who left in 2022, or a mysterious monthly software charge nobody can explain.
Or perhaps they ask, “Who manages our domain?”
“I think Dave set that up.”
Where’s Dave?
“Dave left six years ago.”
Excellent.
Small organizations accumulate technology organically. Finance adds an accounting platform. Development gets a CRM. Someone introduces Slack. Someone else signs up for ChatGPT. Individually, every decision makes sense. Collectively, you may have accidentally constructed a technology ecosystem that nobody fully understands.
Then Cybersecurity Shows Up
This is where the Accidental IT Person’s job stops being quite so amusing. Cybercriminals don’t give nonprofits and startups a pass because they lack dedicated IT departments. In fact, smaller organizations can be attractive precisely because attackers know security resources may be limited.
Suddenly, the Accidental IT Person may be responsible for multifactor authentication, phishing protection, endpoint security, cyber insurance requirements, data privacy and incident response. AI adds another layer: which tools are approved, what information employees can put into them, and what organizational data those systems can access.
That’s a dramatic escalation from “Can you see why the printer isn’t working?”
You Probably Don’t Need a Full-Time IT Department
Fortunately, discovering Sharon from Operations probably shouldn’t be solely responsible for cybersecurity doesn’t mean you need to hire a CIO, three engineers and someone named Viktor who lives in the server room.
Small organizations often don’t need a traditional IT department. What they need is professional IT expertise in the right places.
Your Accidental IT Person may be perfectly capable of routine administration. They know the organization, the people and the technology. They also know that when Bob says “the Internet is broken,” there’s a decent chance Bob has accidentally turned off Wi-Fi.
But they should have someone to call when the issue involves security, backups, compliance, Microsoft 365 administration, data governance or AI policies — anything where “I Googled it and this Reddit post looks promising” probably shouldn’t be the official technology strategy.
Give the Accidental IT Person Some Backup
The answer isn’t necessarily to replace your Accidental IT Person or outsource everything. Small organizations can bring in professional help only where they need it: cybersecurity, Microsoft 365 or Google administration, backups, onboarding and offboarding, compliance, or simply experienced advice when a bigger question comes up.
That’s the thinking behind CGNET’s new Custom Service Provider model. Organizations keep handling the routine things they’re comfortable managing internally and bring in CGNET for the more specialized pieces. You don’t have to completely outsource your IT just because you need help with IT.
And that may be the best thing you can do for your Accidental IT Person. Let them reset Bob’s password if they want to. Just don’t make them personally responsible for ransomware, disaster recovery and your cyber insurance requirements because three years ago they made the conference room projector work.
I mean, haven’t they suffered enough already?
For over forty-three years, CGNET has provided state-of-the-art IT services to organizations of all sizes, across the globe. We’ve done it all, from IT and cybersecurity assessments to cloud services management to generative AI user training. Want to learn more about who we are and how we might be able to help you? If so, check out our website or send us a message!




0 Comments