Back to Blog

Advisory

Your Tech-Savvy Employee Is Probably Hurting Your Business

Every small business has one. The person who 'handles the tech stuff.' They're not malicious — they just don't know what they don't know. Here's what that actually costs you.

Greg DuffieUpdated 6 min read

TL;DR

  • The person who "handles the tech stuff" at most small businesses has surface-level competence — enough to solve immediate problems, not enough to set things up correctly for the long term
  • The gap shows up in domain ownership, admin account access, and email configuration — things that seem fine until someone leaves or something expires
  • These are not edge cases: domain lockouts, dead admin inboxes, and near-miss expirations are among the most common problems we're called in to fix
  • The fix isn't complicated — it's getting the right ownership and documentation in place before a crisis forces the issue

Every small business has one.

The person who swapped out the RAM a few years ago. Who set up the Wi-Fi. Who "handles the tech stuff." Who you call when something stops working.

They are not malicious. They are helpful, willing, and usually faster than anyone else on the team when it comes to clicking through a settings panel.

The problem is that they don't know what they don't know.

And the gap between what they confidently handle and what they actually understand is where businesses get hurt.


What this looks like in practice

These are not hypothetical scenarios. They are patterns we have seen play out more than once.

The domain that nobody controls anymore

Your tech-savvy employee bought the domain years ago. They used their personal Gmail account because it was the fastest path at the time. Nobody thought to document it.

Then they left.

You text them. They call back eventually. They lost access to that Gmail account months ago. The password manager they used was personal. The recovery phone number was their old cell. The backup email was something they do not remember.

You contact the registrar. The registrar does not care who your developer is. They do not care that you are the business owner. They care about the account holder — and that account holder is gone, locked out, and not very motivated to spend their weekend on this.

So now you have a domain that is technically yours in spirit and completely inaccessible in practice. At some point, you are having a conversation you never wanted to have: what alternative domain names might work for your business?

That is why getting this right at the beginning matters — domain registered under a company-owned account, with recovery options tied to the business, not any individual.

The Microsoft 365 account nobody is reading

Your tech person set up the main company email. They used a distribution list as the Microsoft 365 admin contact. It made sense at the time.

The problem: they only added themselves to that distribution list. They were the only one receiving billing notices, security alerts, and Microsoft communications.

They left. The mailbox got deleted or abandoned. Nobody noticed — because nothing seemed broken on the surface.

But for months, lead inquiries to that address had been bouncing silently, or landing in a dead inbox. You spent money on an SEO campaign. Leads came in. Nobody followed up because the inbox did not exist anymore.

You find out six months later when a prospective client calls instead of emailing and mentions they tried to reach you a few times.

You were losing business and had no way to know.

The domain expiration notice that turned out to be real

You received an email that looked like spam — urgent action required, your domain is expiring. You ignored it because you get a dozen of these a month.

Then someone mentioned it again and you looked more carefully. The expiration date matched your actual domain. You pulled up the registrar. The domain was expiring in less than 24 hours.

You have no admin access. You are not qualified to navigate a domain rescue under time pressure. The registrar's support queue is not designed for this kind of urgency. Your website is about to go dark, and your email with it.

That is where we come in — but ideally, you never reach that point.


Why this keeps happening

The tech-savvy employee did not do anything malicious. They did what helpful, technically-inclined people do: they solved the immediate problem with whatever was convenient. They did not think about transition planning, documentation, or account ownership because those are not the kinds of things someone learns from swapping RAM or clicking around in antivirus software.

Formal IT training and experience on production systems covers this. Helpful intuition does not.

The gap is not knowledge of computers. It is knowledge of what can go wrong — and what "correctly set up" actually means from a business continuity standpoint.


What correctly set up looks like

Getting this right is not complicated. It just requires thinking ahead:

  • Domain registered under a company-owned account, with recovery options tied to the business — not any individual's personal email or phone
  • Admin contacts pointing to active mailboxes the business controls — distribution lists with multiple recipients, not a single person
  • Microsoft 365 or Google Workspace accounts owned at the business level, not personal accounts
  • Billing tied to a card the company controls, with renewal notifications going somewhere they'll actually be read
  • Someone responsible for reviewing expiration dates and account access at least once a year
  • Documentation that lives with the business, not in one person's head

None of this is complex. It is just not something most businesses think to do until something breaks.


Frequently Asked Questions

What accounts should always be under the company name, not an employee's? At minimum: domain registrar accounts, DNS management, website hosting, business email admin (Microsoft 365 or Google Workspace), and any platform where billing or access control lives. If a single person leaving could lock you out of something critical, it needs to be owned at the business level.

How do I find out who actually controls our domains? Run a WHOIS lookup on your domain at lookup.icann.org — it shows the registrant name, organization, and contact email on file. If those point to a personal account or someone who no longer works for you, that's the problem to fix first.

What does it cost to recover a locked domain? It depends on how locked out you are. If the previous account holder is cooperative and reachable, an hour or two of their time plus a support ticket with the registrar. If they're unreachable and the domain has lapsed into a grace or redemption period, registrar recovery fees run $100–$300 and can take days. If it expires completely and gets picked up by a domain squatter, recovery is expensive and not guaranteed.

What should admin notification email addresses point to? A distribution list that delivers to at least two active people — ideally the business owner and one other. The key is that the list should be company-controlled, with multiple recipients, so that no single person's departure silences it.

Can Google Workspace or Microsoft 365 be transferred if it's under an employee's account? Technically yes, but it typically requires working with Microsoft or Google support, proving business ownership, and the process can be slow and painful. It is much easier to set it up correctly at the start than to recover it later.

How often should we audit account access and ownership? At minimum, annually. Also whenever someone with technical access leaves the company. A 30-minute review of who controls what — domain registrars, hosting, DNS, email admin, billing accounts — is cheap insurance against the scenarios above.


If you recognize any of these scenarios, get in touch. We can tell you what we find before it becomes a crisis.

Tagged:OperationsBusiness RiskDomain ManagementEmailIT Strategy

Greg Duffie

Owner of 37SOLUTIONS. Senior software engineer with 20+ years of production experience across healthcare, legal, eDiscovery, and financial services — including eight years as senior technical lead on a large-scale healthcare data platform. LinkedIn

Need Senior Technical Judgment on Your Side?

37SOLUTIONS helps small and mid-sized businesses make better technology decisions — without the overhead of a full-time CTO.

Get in Touch