What Happens When Your IT Provider Holds Your Network Hostage
Geek Heros War Stories
The Transition That Turned Hostile
Switching IT providers should be a professional process. Documentation is exchanged, credentials are handed over, knowledge transfer happens, and both parties move on. That's how it works when you're dealing with reputable organizations.
This was not one of those situations.
A professional services firm handling sensitive client data decided to transition away from their solo IT operator — a one-person shop who had managed their network for several years. The reasons were straightforward: slow response times, no documentation, no proactive maintenance, and growing concerns about security gaps. They engaged us to take over.
What followed was a masterclass in why vendor lock-in is one of the most underestimated risks in IT management.
Going Dark
When the firm notified their existing provider of the transition, communication stopped. Emails went unanswered. Calls weren't returned. Requests for network documentation, switch credentials, firewall configurations, and admin passwords were met with silence.
This is more common than most people realize. Solo IT operators and small shops sometimes treat client networks as personal territory. When they're asked to leave, they take the keys with them — sometimes out of spite, sometimes as leverage for unpaid invoices, and sometimes simply because they never documented anything in the first place.
We began the takeover process without cooperation. This meant mapping the network from scratch, identifying every device, tracing every cable, and working around credentials we didn't have. It's slower and more expensive, but it's a process we've been through before.
The Weekend Shutdown
Then things escalated. Over a weekend — when no one was in the office — the previous provider remotely accessed the network and deliberately shut down critical infrastructure. Monday morning, the firm arrived to find their systems offline. Email down. File shares inaccessible. Phone system unresponsive.
Our forensic analysis confirmed what happened. Remote access logs showed the previous provider's connection. Configuration changes were timestamped to Saturday evening. This wasn't a coincidence or a system failure — it was deliberate sabotage.
Recovery and Lockout
We responded immediately. Within hours, we had identified the access vector the previous provider used, locked it down, and began restoring services. We changed every credential on every device — switches, firewalls, servers, wireless access points, and cloud accounts. The previous provider was permanently locked out of the environment.
The firm was fully operational by Monday afternoon. But the damage extended beyond the downtime. Staff trust was shaken. The firm's leadership had to consider legal action. And the entire episode cost time, money, and productivity that could have been avoided with proper vendor management from the start.
What This Means for Your Firm
This story isn't unusual. IT vendor lock-in is a real and common risk, especially with solo operators and small shops. Here's how to protect yourself:
- You must own your credentials. Every admin password, every cloud account, every license — your firm should have independent access to all of them. If your IT provider is the only person who knows the passwords, you're locked in. - Demand documentation. Network diagrams, device inventories, configuration records, and vendor contacts should all be documented and stored where your firm can access them independently. - Use business-owned accounts. Your Microsoft 365 tenant, your domain registrar, your firewall management portal — all of these should be registered under your firm's name with your firm's email, not your IT provider's. - Include transition clauses in your contract. Your IT agreement should explicitly require cooperation during transitions, including credential handover, documentation transfer, and a defined transition period.
> 📋 Read the full case study → [View the Insider Threat Forensics case study](#case-studies)
The best time to address vendor lock-in is before you need to switch providers. The worst time is when you're already in a hostage situation.
Concerned about your current IT relationship? [Take our free site audit](#assessment) to identify vendor lock-in risks before they become crises.
Get Your Free Site Audit
Find out where your firm stands on security, compliance, and IT performance — at no cost.