WebBased All articles
Digital Services

One Person Knows Everything: The Silent Risk Hiding Inside Your Web Infrastructure

WebBased
One Person Knows Everything: The Silent Risk Hiding Inside Your Web Infrastructure

Somewhere in Britain today, a business owner is discovering that the person who built and maintained their website — perhaps a trusted employee, a long-standing freelancer, or an agency that quietly became indispensable — is no longer available. The server needs a critical update. The SSL certificate has expired. The e-commerce integration has stopped passing orders through. And nobody else knows where to begin.

This is not a rare scenario. It plays out with uncomfortable regularity across organisations of every size, and the cost — measured in downtime, emergency contractor fees, and lost trading — can be severe. What makes it particularly frustrating is that the risk is entirely foreseeable and almost entirely preventable.

How Knowledge Silos Form

Web infrastructure knowledge tends to concentrate in a single individual not through any deliberate decision but through accumulated convenience. The developer who set up the hosting account becomes the natural first call when something needs changing. The IT manager who configured the domain settings is the only person who knows the registrar login. The freelancer who built the original site in 2019 still holds the master credentials because nobody ever got around to transferring them.

Over time, these individual threads of knowledge weave themselves into a system that the wider organisation cannot read, access, or maintain independently. The person at the centre of this arrangement is often entirely unaware of how dependent the business has become upon them. They are simply doing their job.

The problem surfaces only when they stop.

The Specific Risks to UK Businesses

For businesses operating under UK GDPR obligations, the knowledge silo problem carries regulatory as well as operational implications. If the individual who understands your data processing configurations, cookie consent framework, or third-party integrations becomes unavailable, your ability to demonstrate compliance — or to respond to a subject access request within the statutory timeframe — may be materially compromised.

For e-commerce operators, the stakes are more immediately financial. A website that cannot accept orders for forty-eight hours during a peak trading period represents a concrete and calculable loss. A checkout integration that breaks and cannot be diagnosed because the original developer is unreachable translates directly into abandoned baskets and diverted revenue.

For professional services firms, the reputational dimension is equally significant. A law practice, an accountancy firm, or a financial services provider whose website goes dark — even briefly — sends a message to existing and prospective clients that no amount of subsequent explanation fully neutralises.

What Good Documentation Actually Looks Like

The solution to knowledge concentration is documentation, but the word is often interpreted too narrowly. A list of usernames and passwords stored in a shared spreadsheet is not documentation — it is a credential inventory. Genuine infrastructure documentation captures not just what exists but why it exists, how it connects to everything else, and what to do when it fails.

A complete web infrastructure record for a typical UK business should include the following:

Hosting and domain management. The registrar holding your domain, the renewal date, the nameserver configuration, and the hosting provider account details. These should be accessible to at least two named individuals within the organisation, not stored solely in a personal email account.

Content management credentials. Administrator access to your website's CMS, along with a record of which plugins or extensions are installed, what each one does, and when licences require renewal.

Third-party integrations. A map of every external service connected to your website — payment gateways, CRM systems, email marketing platforms, analytics tools — including the account holder details and the nature of each connection.

Deployment and update procedures. A written record of how the website is updated, who is authorised to make changes, and what the rollback procedure is if an update causes a problem.

Incident history. A log of past technical issues, how they were diagnosed, and how they were resolved. This is frequently overlooked but proves invaluable when a similar issue recurs.

Building a Handover Protocol Before You Need One

The most effective organisations treat knowledge transfer not as an emergency measure but as a standard operational discipline. The test is simple: if the person who currently manages your website gave notice tomorrow, how long would it take a competent replacement to get to grips with the system?

If the honest answer is "weeks" or "we genuinely don't know," the risk is present and it needs addressing.

A practical starting point is to commission what some practitioners call a technical discovery exercise — a structured process in which your current developer or agency documents the full architecture of your web infrastructure in a format that a different technical professional could follow. This is distinct from a handover document prepared under the pressure of departure; it should be a living record, reviewed and updated at regular intervals.

Some organisations build this into their maintenance agreements, requiring that documentation be updated as a condition of any change to the system. This approach ensures that the record remains accurate rather than drifting out of date as the platform evolves.

The Human Dimension

It is worth acknowledging that knowledge concentration is not always accidental. In some cases, individuals — whether internal staff members or external contractors — have an interest in remaining indispensable. This is rarely malicious; it is a natural feature of the employment relationship. But it does mean that requests for comprehensive documentation may occasionally meet with subtle resistance.

The appropriate response is to frame documentation not as a vote of no confidence but as a professional standard. Well-run organisations document their systems. It protects the individual as much as the business — a developer who has properly handed over their work is far less likely to receive a distressed phone call at ten o'clock on a Sunday evening.

Starting the Conversation

If your business has never formally addressed web infrastructure documentation, the time to begin is before a crisis makes it urgent. A conversation with your current web partner — or an independent technical consultant — about what a complete infrastructure record should contain is a low-cost, high-value exercise.

The businesses that weather technical disruption most effectively are not those with the most sophisticated systems. They are those whose systems are most thoroughly understood by more than one person.

All Articles

Related Articles

Sold a Demolition When You Needed Renovation: The Website Rebuild Myth Costing British Businesses Tens of Thousands

Sold a Demolition When You Needed Renovation: The Website Rebuild Myth Costing British Businesses Tens of Thousands

When Your Competitor Relaunches: The Uncomfortable Mirror a Better Website Holds Up to Your Business

When Your Competitor Relaunches: The Uncomfortable Mirror a Better Website Holds Up to Your Business

What Your Server Bill Doesn't Show You: The True Cost of a Website Built on Shortcuts

What Your Server Bill Doesn't Show You: The True Cost of a Website Built on Shortcuts