Skip to content

Cybersecurity accidental custodian

The Accidental Custodian

If you are the person keeping the technology running while doing your actual job - thank you. You are the reason the business kept running. Now I need to tell you something hard: you should not be doing this job. And the longer you do, the more risk you are quietly building into the company you have worked so hard to protect.

Illustration for the article: The Accidental Custodian
If you are the person keeping the technology running while doing your actual job - thank you. You are the reason the business kept running. Now I need to tell you something hard: you should not be doing this job. And the longer you do, the more risk you are quietly building into the company you have worked so hard to protect.

If this is you – the person keeping the technology running at your company while doing your actual job at the same time – I want to say something before anything else.

Thank you.

Thank you for the hours nobody sees. Thank you for being the one people call when something breaks, when the Wi-Fi goes down, when the printer stops working twenty minutes before a deadline. Thank you for figuring it out, every time, without a manual, without training, and usually without anyone asking how long it took. You are the reason the business kept running. You are a real hero of this company and you deserve a vacation and a raise.

Now I need to tell you something hard.

You should not be doing this job. And the longer you do, the more risk you are quietly building into the company you have worked so hard to protect.

Hear me out.

How the Accidental Custodian Is Born

Nobody sets out to become the de facto IT manager of a growing business. It happens gradually, in the way that most organizational problems happen – one small decision at a time, each one reasonable on its own.

Someone was good with computers. They helped set up the office Wi-Fi when the company was small. They figured out how to get the printers talking to each other. They were the one who did not panic when something broke. So when a question came up, people asked them. When something needed to be set up, they got the call. And somewhere along the way, without a title change or a job description or a pay adjustment, they became the person responsible for the technology that runs the entire operation.

That is the Accidental Custodian. Not a bad employee. Not a careless one. A capable, committed person who got handed a responsibility that was never part of their training – and said yes because that is what they do.

What It Actually Looks Like

The most common version I walk into looks like this.

There is a folder on someone’s desktop. A Windows PC – usually the person who has been there the longest, or the one who set things up in the early days. That folder is shared across the network. Everyone in the company drops files into it, pulls files out of it, and depends on it to do their work.

When I look at the permissions on that folder, it is set to Workgroup. All users. Full access. No restrictions, no audit trail, no visibility into who has accessed what or when.

That desktop – that one person’s computer – is the company’s file server. It is the place where customer records live, where financial documents are stored, where contracts and proposals and operational data sit. And it is configured with the same level of security as a shared folder at a public library.

This is not unusual. This is the most common thing I find. And it is not the Accidental Custodian’s fault – they set it up at a time when it worked, when the company was smaller, when the risk was lower. The problem is that the company grew and the infrastructure did not grow with it.

The Gap Between Getting Here and Getting There

Just because the lights turn on does not mean the wiring is safe.

I can follow directions. I can watch a video and wire an outlet and the light will come on. That does not mean I have any business wiring a commercial building. There is a gap between making something work and making something work safely, reliably, and at scale – and that gap is filled by years of specialized training, real-world experience, and the kind of knowledge you only get from doing it professionally.

The Accidental Custodian got the company here. That is not a small thing. But the company is now ten times bigger than it was when they started. The data is more sensitive. The regulatory exposure is real. The attack surface is larger. And the informal, improvised infrastructure that worked at twenty employees is quietly becoming a liability at two hundred.

As we talked about in What Is a vCISO, a business owner has no business rebuilding a transmission – not because they cannot follow instructions, but because there is so much more to it than following instructions. People spend years learning that work so that it holds up from day one to mile one hundred thousand. Security is the same. The person who built the shared folder on their desktop did not go to school for this. They were not trained for this. They were just willing – and willing is not the same as equipped.

Stay Ahead of Technology Risk

Practical, no-jargon insights on cybersecurity, resilience, and IT strategy - built for business leaders, not engineers.

What the Accidental Custodian Cannot Do

There is another layer to this that goes beyond technical skill.

Even if the Accidental Custodian knows exactly what needs to change – and often they do, because they are sharp and they have been paying attention – they cannot enforce it. Not because they lack authority on paper, but because they lack the organizational standing that makes a policy stick.

Imagine them walking into a team meeting and saying: starting Monday, everyone logs into their computer with a unique username and password, MFA is required on every account, and the shared folder on my desktop is being replaced with a proper file server with role-based access controls.

What happens? People push back. Someone says it is too complicated. Someone else says it was fine the way it was. And because the Accidental Custodian is still the person everyone calls when the printer breaks – not the person leadership has formally designated as the security authority – the policy stalls before it starts.

This is not a technology problem. It is an authority problem. And it cannot be solved by the person who inherited the responsibility informally. It requires leadership to acknowledge that a problem exists, designate someone with the standing to address it, and back that person when the friction comes – because the friction always comes.

The Conversation in the Room

When I have this conversation with a business owner, the Accidental Custodian is usually in the room. And they always take it hard.

Not because they are defensive. Because they tried. They gave everything they had to keeping things running and they know, somewhere underneath it all, that they have been doing their best with tools and knowledge that were never designed for the scale the company has reached.

My job in that moment is to make sure they hear what I actually mean.

You did not do anything wrong. You got this company here. That matters more than most people will ever say out loud. But the company you work for now is not the company you started with. It is bigger, more complex, more exposed, and more valuable – and it deserves to be protected like the serious operation it has become.

The big companies – the ones that have been doing this for decades – they do not run their infrastructure off a shared desktop folder. They have policies and access controls and dedicated security leadership and documented systems. And here is the truth: your company may be just as big as they are now, or bigger. It is time to start operating like it.

The handoff is not a demotion. It is a recognition that what you built is worth protecting at the next level.

What Comes Next

The first step is the hardest one: acknowledging that the informal arrangement that got you here is not the arrangement that will protect you going forward.

That means documenting what exists. Auditing who has access to what. Moving critical data off personal computers and onto infrastructure that was designed to hold it. Establishing policies that have teeth. And putting someone in the security seat who has the training, the tools, and the organizational authority to enforce them.

The Accidental Custodian does not have to disappear. In many cases, they become one of the most valuable people in the transition – because they know where everything is, how it was built, and why decisions were made the way they were. That institutional knowledge is irreplaceable.

But the security program cannot rest on their shoulders alone. Not anymore.

Kelly Hansen is the author of The IT Dilemma: Why Good Businesses Fail During Cyberattacks, Outages, and Technology Disasters – and How to Prevent It. Have a question about your own environment? Reach out: Contact, or connect with me on LinkedIn.

Key Takeaways

  • The Accidental Custodian is not a bad employee — they are a capable committed person who got handed a responsibility that was never part of their training
  • The shared desktop folder set to Workgroup all users full access is the most common infrastructure failure I find
  • Willing is not the same as equipped
  • This is not a technology problem — it is an authority problem
  • The handoff is not a demotion — it is a recognition that what you built is worth protecting at the next level