Congratulations. You’re the IT Department Now.

Microsoft 365
Jackie Bilodeau

Written by Jackie Bilodeau

I am the Communications Director for CGNET, having returned to CGNET in 2018 after a 10-year stint in the 1990's. I enjoy hiking, music, dance, writing, cheering on Bay Area sports teams, and traveling near and far as much as I can. Read more about my work at CGNET here.

August 27, 2026

There is a very specific way IT departments are created at large companies. There are job descriptions, interviews, certifications, budgets and people with titles like Director of Infrastructure and Security.

At a small company or nonprofit, the process is considerably more streamlined: “Hey, you’re pretty good with computers, right?”

And just like that, you’re in IT.

Maybe you helped connect a laptop to the conference room screen. Maybe you knew how to reset the Wi-Fi router. Maybe you once mentioned that you built your own PC. It doesn’t matter. You have demonstrated technical competence, and there will be consequences.

Meet the Accidental IT Person

The Accidental IT Person thrives in startups, nonprofits and small organizations where everyone already has three jobs. Officially, they may be the office manager, operations director, finance person or communications manager. Unofficially, they’re responsible for questions like: “Why can’t I get into my email?” “Can you add Sarah to SharePoint?” “Is this email from Microsoft real?” And the particularly ominous: “I clicked something. Can you come over here?”

It usually begins innocently. Someone needs a Microsoft 365 account, and the Accidental IT Person figures it out. Then someone needs access to a shared folder. Then a new employee needs “all the same stuff Jennifer has.”

Before long, our hero has administrative access to the company’s entire technology environment and is making decisions about cybersecurity, licensing, data access and backups while simultaneously ordering toner.

Being Good with Computers Is No Longer Enough

The problem isn’t that Accidental IT People are bad at technology. Quite often, they’re surprisingly good at it. That’s how they got into this mess.

The problem is that modern IT has become enormously complicated. Even a 15-person organization may have Microsoft 365 or Google Workspace, cloud storage, laptops, mobile devices, SaaS applications, multifactor authentication, cybersecurity tools and dozens of user accounts.

Someone has to decide who gets access to what, remove that access when employees leave, make sure backups work and configure security policies. Now they also have to figure out whether that shiny new AI tool someone just signed up for is quietly uploading confidential organizational information somewhere it shouldn’t.

That’s a lot to put on the person who got the job because they successfully connected the CEO’s AirPods.

The Password Spreadsheet of Doom

Every Accidental IT Person eventually discovers something that makes them question the decisions of everyone who came before them. It might be a spreadsheet called Passwords.xls, an administrator account belonging to an employee who left in 2022, or a mysterious monthly software charge nobody can explain.

Or perhaps they ask, “Who manages our domain?”

“I think Dave set that up.”

Where’s Dave?

“Dave left six years ago.”

Excellent.

Small organizations accumulate technology organically. Finance adds an accounting platform. Development gets a CRM. Someone introduces Slack. Someone else signs up for ChatGPT. Individually, every decision makes sense. Collectively, you may have accidentally constructed a technology ecosystem that nobody fully understands.

Then Cybersecurity Shows Up

This is where the Accidental IT Person’s job stops being quite so amusing. Cybercriminals don’t give nonprofits and startups a pass because they lack dedicated IT departments. In fact, smaller organizations can be attractive precisely because attackers know security resources may be limited.

Suddenly, the Accidental IT Person may be responsible for multifactor authentication, phishing protection, endpoint security, cyber insurance requirements, data privacy and incident response. AI adds another layer: which tools are approved, what information employees can put into them, and what organizational data those systems can access.

That’s a dramatic escalation from “Can you see why the printer isn’t working?”

You Probably Don’t Need a Full-Time IT Department

Fortunately, discovering Sharon from Operations probably shouldn’t be solely responsible for cybersecurity doesn’t mean you need to hire a CIO, three engineers and someone named Viktor who lives in the server room.

Small organizations often don’t need a traditional IT department. What they need is professional IT expertise in the right places.

Your Accidental IT Person may be perfectly capable of routine administration. They know the organization, the people and the technology. They also know that when Bob says “the Internet is broken,” there’s a decent chance Bob has accidentally turned off Wi-Fi.

But they should have someone to call when the issue involves security, backups, compliance, Microsoft 365 administration, data governance or AI policies — anything where “I Googled it and this Reddit post looks promising” probably shouldn’t be the official technology strategy.

Give the Accidental IT Person Some Backup

The answer isn’t necessarily to replace your Accidental IT Person or outsource everything. Small organizations can bring in professional help only where they need it: cybersecurity, Microsoft 365 or Google administration, backups, onboarding and offboarding, compliance, or simply experienced advice when a bigger question comes up.

That’s the thinking behind CGNET’s new Custom Service Provider model. Organizations keep handling the routine things they’re comfortable managing internally and bring in CGNET for the more specialized pieces. You don’t have to completely outsource your IT just because you need help with IT.

And that may be the best thing you can do for your Accidental IT Person. Let them reset Bob’s password if they want to. Just don’t make them personally responsible for ransomware, disaster recovery and your cyber insurance requirements because three years ago they made the conference room projector work.

I mean, haven’t they suffered enough already?

 

 

For over forty-three years, CGNET has provided state-of-the-art IT services to organizations of all sizes, across the globe. We’ve done it all, from IT and cybersecurity assessments to cloud services management to generative AI user training. Want to learn more about who we are and how we might be able to help you? If so, check out our website or send us a message!

 

You May Also Like…

The MSP Model: A Dying Dinosaur

The MSP Model: A Dying Dinosaur

One Size Fits All Doesn’t Survive the Age of AI For twenty years, the managed service provider model was built on a...

You May Also Like…

The MSP Model: A Dying Dinosaur

The MSP Model: A Dying Dinosaur

One Size Fits All Doesn’t Survive the Age of AI For twenty years, the managed service provider model was built on a...

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *

Translate »
Share This
Subscribe
CGNET
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.