Itwerx is a service-disabled veteran-owned managed IT provider serving Seattle-area businesses, founded in 2005, and one of the more sensitive situations we get called in for is helping a client safely remove someone who holds privileged access and might not take the news well.
If you are the CEO, this could be a CIO or CTO. If you are a newly installed CIO or CTO yourself, it could be someone who has been with the organization a long time and has grown hostile to a change in direction. Either way, there are five main steps, and the order matters.
The emergency half: steps one and two
- Map every system and service the person has access to, official or unofficial. You cannot lock down what you have not inventoried.
- Have an emergency lockdown plan ready in advance, accepting the possibility of some service interruption, in case the person finds out early and things move faster than planned.
These two have to be executed as quickly and quietly as possible, in days rather than weeks, because they are the difference between a controlled transition and an incident. The people who need to be removed in these circumstances frequently avoid documenting their own access, whether deliberately or simply as a byproduct of how they worked, which is exactly why the mapping step cannot be skipped or rushed.
The mitigation half: steps three through five
- Gather the admin account information for every system and service identified in step one.
- Prepare a plan to block all external access for that person without causing a service interruption.
- Watch and search for anything that might have been missed over the following weeks and months.
These three are more about limiting ongoing impact than preventing an immediate crisis, and in most environments they do not take as long as people fear. A smaller IT team usually means a less complex environment, which makes gathering the needed information faster. A larger team usually has access-management systems already in place, and no single person, even the most senior, typically holds every credential alone.
What this looked like in practice
The case that shows why the first two steps matter most involved a company in acquisition talks whose own CTO was sabotaging systems, apparently to reduce the company’s valuation. Management suspected it but had no proof, and brought Itwerx in to confirm what was happening and prepare a contingency plan. Before that plan was finished, management found hard evidence another way, and the CTO was escorted out the same day. That left under an hour to lock down access held by the person who had built much of the environment. It worked. He was caught on camera that night, probing the company’s wifi from the parking lot.
The lesson generalizes past that one case: the mapping and the lockdown plan have to exist before the confrontation, not after, because there is no guarantee you get to choose the timeline.
Itwerx Corp is a service-disabled veteran-owned small business providing IT services across Seattle, Bellevue, Everett and Snohomish County. This is the kind of thing our hardware lifecycle work deals with – talk to us about yours.

