For Volunteer-Supported Organizations

Nothing has broken. That isn't the same as being covered.

Most organizations don't think they have an IT problem. They think it's handled — by a volunteer, a board member's son, or whoever on staff is good with computers. Usually that person is capable and well-intentioned. The gap is somewhere else entirely.

The gap is rarely skill

It's that nobody is watching the things that don't announce themselves.

A capable volunteer fixes what's in front of them, and fixes it well. Printers work. The Wi-Fi reaches the back office. Email gets sorted out. From the outside, that looks like coverage.

What it isn't is continuous accountability. Nobody is checking whether the backup that runs every night can actually be restored. Nobody noticed that an administrator account still belongs to someone who left in 2022. Nobody would see a compromise for weeks, because nobody is looking.

That gap can't be closed by the volunteer being more capable. It requires someone whose job it is to watch — which was never part of the arrangement, and was never fair to expect.

What usually goes unwatched

Backups that run successfully every night and have never once been tested by an actual restore.

Accounts belonging to former employees, volunteers, and vendors that were never disabled.

Firmware and software running years behind on firewalls, switches, and servers.

Subscriptions and licenses still billing monthly for things nobody uses.

Contracts auto-renewing because the termination window passed unnoticed.

No documentation of how anything is configured, and no plan if the volunteer becomes unavailable.

Nobody has to be replaced

The hardest part of changing this is usually not technical.

If someone has been handling technology for years — a parishioner, a board member, the office manager who has been proud to manage it — changing the arrangement is a social decision before it is a business one. Nobody wants to be the person who pushed out someone who helped for free.

They usually stay. They keep doing the part they're good at, with someone accountable above them, documentation behind them, and no obligation to carry risk they were never equipped to carry. What ends is the arrangement, not the relationship.

The same is true of vendors. If you'd rather keep the firm that installed your phone system or the contractor a board member recommends, keep them.

We'll scope the work, review the quote, hold them to it, and verify what was delivered. We don't need to be the ones doing it. Someone needs to be accountable for whether it was done right.

What professional coverage actually costs

The usual assumption is that the only alternative to a volunteer is hiring someone. It isn't.

Organizations that decide the volunteer arrangement has run its course usually conclude they need to hire. That's a real number: a network, security, or infrastructure specialist in this market is a six-figure salary before benefits — and for most organizations that ends the conversation before it starts.

There's a third option. The same function, contracted rather than salaried, at a fixed monthly rate of $500–$2,100 depending on the size of the organization.

For most of the organizations we work with, that is less than the copier. Less than phone service for a handful of employees. Less than one after-hours emergency when a server fails on a Friday night and nobody has a current backup.

  • A fixed monthly rate that doesn't change when you add devices or locations
  • Monitoring, patching, and lifecycle management running on a schedule
  • Backups verified by restore, not by a green checkmark
  • Documented environments that survive any one person's absence
  • One accountable person who knows your systems and sits in your budget conversations
  • No hardware sales, no commissions, no manufacturer agreements

Worth asking, whoever handles your technology

These questions aren't a test of the person. They're a test of the arrangement.

  • When was our backup last verified by an actual restore — not by a successful job report?
  • Which accounts still have access that shouldn't?
  • Who would notice if someone were inside our systems, and how long would it take?
  • What are we paying for monthly that nobody uses?
  • If the person handling our technology were unavailable for a month, what would we do?
  • Is there documentation of how anything is set up, or does it live in one person's memory?
  • Which of our contracts auto-renew, and when do the termination windows close?
  • Who is accountable if we're breached? Not who fixes it — who owns it.
  • If someone is injured helping us with technology on our property, whose insurance responds?

If the answers are good, that's genuinely worth knowing — and you can stop reading here. If they're hard to get, that's worth knowing too. See how the common options compare →

Find out where things actually stand

Most conversations start with a structured review of your current environment — what's running, what's exposed, and what's being paid for. Findings first, before anyone talks about an engagement.

See how the review works