What Happens When Your Only IT Person Leaves on Bad Terms? A Recovery Case Study

Walter’s Services Inc. ran on a single in-house IT employee for years - one person managing the network, the servers, and a custom sales application the business depended on across all seven of its locations. That arrangement worked fine, until the day it didn’t: that employee left abruptly and on bad terms, and on his way out, did everything he could to make sure Walter’s would struggle without him.

Quick answer: When Walter’s Services’ sole IT employee left on bad terms, he destroyed his laptop, locked the company out of its own network equipment, deleted the source code for a customer-facing app, and left backdoor access devices behind. Merit IT restored access, decompiled and rebuilt the app from its public Google Play Store build, and helped Walter’s move to a fully documented, multi-person security setup - turning a single point of failure into a resilient one.

What happened

Before he left, the departing employee destroyed his own work laptop, locked Walter’s out of its own networking equipment, and deleted the source code for a customer-facing sales app the company had published on the Google Play Store - along with the reporting tools built around it. He also left behind devices designed to let him regain network access after he was gone. Separately, the business discovered that data had been deleted from one of its databases as well.

How Merit IT regained control

Merit IT’s first job wasn’t a redesign - it was regaining basic access. We worked with Walter’s to replace the networking equipment across all seven locations (timed to align with a refresh that was already coming), sending technicians to every single site to get connectivity and access back under Walter’s control. Alongside that, we swept for and removed the access devices the departing employee had left behind, and went through the notes, documents, and email he’d left in place to reconstruct as much of the working environment and institutional knowledge as we could.

How do you recover a lost financial report and a deleted app?

Two different problems needed two different fixes. The most time-sensitive issue was a year-end financial report that, it turned out, had only ever been run from the departed employee’s now-destroyed laptop - recreating a working version of that report became an immediate priority so Walter’s leadership wasn’t flying blind on its own financials.

The sales app was a harder problem: with the source code gone, there was no repository to pull from. Merit IT’s development team decompiled the app’s public build from the Google Play Store and rebuilt both the application and its management dashboard from that decompiled code - effectively reconstructing a shipped product Walter’s had already lost the source for.

Merit IT also supported a digital forensics review of the incident, which Walter’s leadership ultimately reported to law enforcement given the scope of the data deletion and sabotage involved.

Where Walter’s stands now

Walter’s Services Inc. operates today with full IT documentation, modern network security, an in-house IT manager working alongside Merit IT, and security awareness training in place for its team - resilient rather than dependent on any single person’s knowledge or goodwill.

The lesson for any small business

This isn’t really a story about one bad departure. It’s a story about what a single-person IT department actually is: a single point of failure. Sometimes that risk shows up as a disgruntled exit. Just as often it shows up far less dramatically - a knowledge gap in a field that changes constantly, a sudden medical emergency, or simply one person who can’t keep up alone with how much there now is to secure and maintain. Either way, if your business’s entire technology knowledge lives in one person’s head, that’s not a personnel question. It’s a business continuity question, and it’s worth answering before something forces the issue.

Frequently asked questions

What should a business do if its only IT employee leaves without notice? Immediately change or lock down administrative credentials on every system that person had access to - network equipment, cloud accounts, email, and any custom applications - before anything else. Then inventory what documentation actually exists versus what only lived in that person’s head. If access has already been lost or equipment has been tampered with, an IT provider experienced in incident response should be brought in immediately rather than attempting recovery internally.

Can an application be rebuilt if its source code is lost or deleted? Sometimes. If the application was ever published publicly - like on the Google Play Store or Apple App Store - the compiled, public version can potentially be decompiled and used as the basis for reconstructing the application and rebuilding its functionality. This is technically demanding and doesn’t always recover code in a clean, original form, but it’s a viable recovery path when no other backup or repository exists.

Is having a single in-house IT person a security risk? It’s a structural business risk regardless of that person’s intentions. A single point of IT knowledge and access means the business is exposed if that person leaves abruptly, has a medical emergency, or simply can’t keep up alone with how quickly security threats and technology change. It’s not a judgment on any individual - it’s a business continuity gap worth closing before something forces the issue.

Should a business involve law enforcement after an IT sabotage incident? That depends on the scope and nature of what occurred, and is ultimately a decision for the business and its own legal counsel. In cases involving significant data deletion or deliberate sabotage, engaging a digital forensics team to document what happened is a reasonable first step, and their findings can inform whether a law enforcement referral makes sense.

Facing something similar, or want a second set of eyes on your current setup before it becomes a problem? Get a free technology assessment - or read more about how Merit IT approaches IT Support and Software & AI Development.

Have an IT Question Like This One?

No pressure, no long-term commitments — just honest technology advice from people who care.