EO Advisor

The Single IT Person Problem:

What Happens to Your School When the Only Tech Person Leaves
Kids on Smartphones

There is a risk sitting inside most small K-12 schools in Western North Carolina that does not appear on any risk register and rarely comes up in board meetings until the moment it becomes a crisis.

It is not a cyberattack. It is not a compliance failure. It is a resignation letter.

When the person who manages all of a school’s technology—the network, the student information system, the devices, the vendor relationships, the passwords, the documentation, the institutional memory of a decade of IT decisions—submits two weeks’ notice, what happens next depends almost entirely on what that person chose to write down. In most small schools, the honest answer is: not very much.

The Single Point of Failure Hidden in Plain Sight

The single IT person model is not a failure of school leadership. It is a rational response to real budget constraints. Technology coordinators in small WNC schools are often extraordinarily capable individuals who manage workloads that would require three or four staff members in a comparable private-sector organization. They are also, by the nature of the role, the sole repository of critical operational knowledge that the school cannot function without.

This creates a structural vulnerability that becomes visible only when triggered. Consider what a school actually depends on its technology coordinator to know and manage:

The network infrastructure—where the servers are physically located, how the network is segmented, what firewall rules are in place, what the wireless controller configuration looks like, which VLANs carry which traffic.

The credentials—administrator passwords for every system, vendor portal logins, E-Rate account credentials, emergency recovery keys.

The vendor relationships—who to call when the internet is down, which account manages the school’s Microsoft licenses, who supports the student information system, what the escalation path is for each vendor.

The undocumented decisions—why the network is configured the way it is, which systems cannot be updated without breaking something else, which devices are grandfathered exceptions to the patch management process.

When that knowledge leaves the building, the school has a gap that cannot be filled by the next person who takes the role — not quickly, and not without significant risk during the transition.

What Actually Happens During the Gap

The period between a technology coordinator’s departure and a new hire reaching full competency is the most dangerous window in a school’s technology operations. During that period:

Security patching stops or slows significantly. Patches require someone who knows which systems they apply to, how to test them before deployment, and how to respond if something breaks. Without that expertise readily available, patches accumulate while vulnerabilities remain open.

Monitoring goes dark. Most small schools rely on their technology coordinator to notice when something is wrong. Without that person—or their replacement—watching the environment, the school learns about problems when end users report them. In a security context, that means the school learns about an intrusion when the ransomware launches, not when the attacker first established a foothold.

Vendor escalations stall. When an urgent vendor issue requires someone with the right credentials and account access to call the right number and say the right things, a school in transition may not have that person readily available.

Projects stop. The network refresh, the backup system modernization, the Microsoft 365 migration—whatever was in progress or planned gets indefinitely deferred while the school is in reactive mode.

And the new technology coordinator, when they are eventually hired, arrives into an undocumented environment with no institutional context and a backlog of deferred work that the previous person also never fully caught up on.

The Compounding Risk: Security During Transition

Attackers are aware of this pattern. Ransomware groups and phishing campaigns against K-12 schools are not random. They monitor for signals of organizational weakness, including the kind of reduced vigilance that naturally accompanies staff transitions.

82% of K-12 schools experienced a cyber incident between July 2023 and December 2024. The schools most likely to appear in that statistic share a common characteristic: they were operating without consistent, continuous security monitoring at the time of the incident. A staff transition is precisely the period when that monitoring is most likely to lapse — and it is precisely the period when the school is most vulnerable.

The PowerSchool breach, which compromised the personal information of approximately 62 million students and 9.5 million teachers, traced to a single missing security control — multi-factor authentication on a vendor portal that went unaddressed because vendor security review at that level requires someone whose job it is to think about these things systematically. When IT oversight is concentrated in a single person who is managing dozens of other priorities, systematic security review is what slips first.

What a Managed Services Model Eliminates

The structural risk of the single IT person model is not eliminated by hiring a better technology coordinator. It is eliminated by building a model in which the school’s technology operations do not depend on any single individual’s presence, health, or continued employment.

Electronic Office’s managed services model provides this structural resilience through several mechanisms.

Complete documentation. Every aspect of a school’s managed environment is documented—network architecture, system configurations, vendor relationships, recovery procedures, and change history. That documentation belongs to the school and is accessible regardless of any staffing change.

Continuous monitoring. Security monitoring runs 24 hours a day, seven days a week, regardless of whether the school’s in-house technology staff is available. Alerts are handled by EO’s team, not deferred until a coordinator is back at their desk.

Team depth behind every client relationship. When a WNC school works with Electronic Office, they have access to a team that includes network engineers, security specialists, project managers, and help desk support—not a single person. The school’s relationship with that expertise does not change when any individual on our team changes.

Project management capability. The projects a single IT coordinator cannot prioritize because they are managing daily operational demands get managed by EO’s project team — planned, staffed, executed, and documented.

The Conversation Worth Having at Your Next Board Meeting

The single IT person problem is one of the easiest risks for a school board to understand once it is framed clearly, because it requires no technical expertise to evaluate. The question is simply this: If our technology coordinator were not here tomorrow—for any reason—what would we not be able to do, and how long would it take to recover?

If the answer is uncomfortable, that discomfort is useful information.

Electronic Office works with K-12 schools across Western North Carolina to build technology and security operations that are structurally resilient — that do not depend on any single person’s knowledge, availability, or tenure. We would welcome the opportunity to show your school what that looks like.

Like this article? Read more news about , .