Digital Checkmark Business Security

Your IT Provider Vanished. Who Owns Your Network Now?

Keys with a blank tag left on an office desk, network switches behind and a person leaving through the door

A field report from a one day recovery, and how to tell whether the same thing could happen to you.

The equipment was theirs. Every switch, every camera, the firewall in the rack, all of it bought and paid for by the business. The invoices were in the filing cabinet.

And none of it was under their control.

Their technology provider had gone quiet. Calls unanswered, email bouncing, the company apparently no longer trading. That alone is an inconvenience. What made it a problem was what the provider had left behind, which was nothing, and what they had taken with them, which was ownership.

We were asked to take the system back. This is what that involved, and what we found on the way in.

“You own the hardware” is not the same as “you control it”

Modern network equipment does not work like a filing cabinet with a key. The switches, the wireless access points, the cameras and the door readers are all managed through a central console, and that console is claimed by a single account when the system is first set up.

Whoever holds that account is the owner. They can add and remove administrators, reach the network from anywhere in the world, and lock everyone else out. The business whose name is on the invoice has no special standing at all.

In this case the owner account belonged to the departed provider. The business had access in the sense that a guest has access to a house: they were let in, and the person holding the deed had walked off with it.

There is no support ticket that fixes this. Manufacturers will not transfer ownership on request, and for good reason, since the same mechanism that would help an abandoned client would also be a gift to anyone impersonating one. The only route back is to reset the equipment to factory condition and claim it properly.

Which means the entire configuration has to be recovered first, or it is gone.

What we found before touching anything

Our first job was not to fix anything. It was to write down everything that existed, because once the reset begins there is no going back to look something up.

That inventory took a few hours and it surfaced more than we expected.

No documentation existed. Not a network diagram, not a password list, not an inventory of what had been installed. If a device had failed that week, there would have been nothing to rebuild from except guesswork.

The backups had never run. The system was set to back itself up once a month, keeping no history, and storing the result on the very equipment it was protecting. In practice not a single backup file existed. Had the hardware failed, the backup would have failed with it.

Intrusion detection was installed and switched off. The firewall included a threat detection engine with tens of thousands of signatures. It had been left disabled since installation. The business believed it was protected. It was not.

The door access system had never finished installing. It had been failing quietly for months, blocked by a software fault in the manufacturer’s own installer. Nobody had chased it down, so the doors ran without central management.

Two remote access services were switched on with nobody using them. Both were open doors into the network that served no purpose, left behind from work that was started and never finished.

None of this was visible from the outside. The wireless worked, the cameras recorded, the lights on the rack were green. A network can look entirely healthy while quietly holding none of the protections its owner assumes are there.

The recovery

With the configuration captured and verified, the rest was mechanics, done in an order that kept the business running.

The firewall was reset and claimed under an account belonging to the business. The switches and access points followed, each one re-adopted into the clean console, one at a time, so that the network never went down entirely. Wireless networks were recreated with their original names and passwords so that no staff device needed reconfiguring.

Printers, the video recorder and one workstation had been holding their network addresses by habit rather than by design, an arrangement that works right up until something restarts. Those were pinned down properly. We tested scanning afterwards to confirm nothing had moved.

The camera system came back with all thirteen cameras confirmed recording, checked individually rather than taken on trust from a dashboard. The door system was diagnosed, the installer fault worked around, and four doors brought under the business’s control for the first time.

Then the things that had been silently absent. Threat detection switched on and left in a mode that alerts without interrupting legitimate traffic. Backups moved from monthly to weekly, with ten copies retained and a second copy stored away from the building. Unused remote access closed.

By the end of the day the network was operational, documented, backed up in three separate places, and owned by the people who had paid for it.

The part that surprises people

One detail is worth singling out, because it catches experienced people off guard.

The staff records in the door access system, the list of who is allowed through which door, do not live on the equipment. They live in the manufacturer’s cloud, tied to the organization rather than to the hardware.

Which means they are not in the backup. You can hold a perfect, verified configuration backup and still lose every person in your access system, because they were never in the file to begin with. They have to be recreated by invitation, one at a time.

We only knew to check because we went looking in the database rather than trusting the backup to be complete. It is the sort of thing you find once and never forget.

How to tell whether this applies to you

You do not need technical knowledge to check the important part. Three questions, and you can put them to whoever manages your systems today.

Who is the owner account on our systems? Not who has access, who is the owner. If the answer is a person at your provider rather than a person at your company, you are in the same position this business was in. Ask for it to be transferred, and note that a reasonable provider will do this without hesitation.

Show me our last backup. Not the setting that says backups are enabled. The actual file, with a date on it. We have now twice found systems where the setting said yes and the folder was empty.

What would happen if you disappeared tomorrow? A good provider has an answer to this, and the answer involves documentation you already hold. If the honest answer is that nobody else could pick it up, that is a business risk sitting quietly in your rack.

Why this matters more than it used to

Networks used to be dumb equipment in a cupboard. If your provider vanished, the next one plugged in a laptop and read the configuration off the box.

That is no longer how any of it works. Cloud managed systems are genuinely better, more secure, easier to run, more capable, but they moved the keys from the equipment to an account. Ownership became something you have to actively hold rather than something that follows the invoice.

Most businesses have never been told this. They assume that paying for hardware means controlling it, which was true for thirty years and quietly stopped being true.

If you are not certain who holds the keys to your network, that is worth an hour of somebody’s time to find out. Finding out on the day you need them is considerably more expensive.

Digital Checkmark LLC provides managed and co-managed IT for businesses that would rather somebody owned their technology and answered when it broke. This recovery was carried out with LenStar LLC, who handle cabling, surveillance and access control.

If you would like us to run the three questions above against your own systems, get in touch.