I'm a recent Computer Science graduate who started my career in desktop support at a large multinational manufacturer. That role gave me experience with Windows troubleshooting, hardware, basic networking, print servers, ticket management, network-management tools, and limited Active Directory administration. The company had mature infrastructure and dedicated teams, so I understood the basics but had not yet managed servers, VLANs, cloud systems, or security independently.
After six months, I accepted a similarly paid job at a smaller manufacturing company closer to home. The company operates two manufacturing sites and a main office, but its IT environment is in very poor condition. The sites use an unreliable mixture of unmanaged switches, hubs, old routers, and improvised connections. Many computers are outdated, underpowered, and improperly licensed. The ERP database is running on a desktop with an evaluation copy of Windows, and the company has already experienced multiple security incidents.
There also appear to be separate ERP databases at different sites that are synchronized manually. The website is hosted in the same general environment, several ports are exposed, and the firewall rules do not appear to follow a coherent security design. There is no clear backup, disaster-recovery, segmentation, monitoring, documentation, or access-control strategy.
I explained to the CEO that this is far beyond ordinary desktop support and that the company needs an experienced infrastructure consultant or managed service provider to assess the environment and create a proper plan. Instead, he told me to take responsibility, ask former coworkers for advice, and make sure no data is lost. He suggested using the same local computer shop that has been supporting the company so far.
I'm willing to learn server administration, networking, Active Directory, security, and cloud technologies, but I'm concerned about being held responsible for systems I'm not qualified to design or secure. I'm also expected to handle user support, old hardware, the ERP, networking, and security as the only IT employee.
What would you do in this situation? Would you document the risks and insist on outside help, stay and treat it as a major learning opportunity, or start looking for another job immediately?
3 Answers
Document everything immediately: current diagrams, equipment, software versions, licenses, open ports, known incidents, missing backups, and the risks associated with each issue. Put recommendations and warnings in writing, preferably as a short business-focused report. Make it clear that you can help coordinate the work, but you cannot personally guarantee data integrity or security without the authority, budget, and expertise to address the problems.
Ask management to fund an external assessment or managed service provider. A third party can produce a prioritized plan and give you support while you learn. Do not make major changes to production systems alone, and do not promise that the environment is secure simply because you made a few improvements.
I would start a confidential job search now. You can still do responsible work while you are there, but the CEO has already indicated that he wants you to carry responsibility without providing appropriate resources. If the company suffers another breach or loses its ERP data, being the only IT person makes you an obvious scapegoat.
You do not need to wait for a disaster to prove that leaving is justified. Look for a proper help-desk or junior infrastructure role with senior staff, documented processes, and a team. That will build your skills much more safely than being thrown into an unsupported production environment.
That is my main concern. I’m not afraid of difficult work, but I don’t want to be blamed for risks that I have already reported and that management refuses to address.
This is not a normal junior support role. You are being asked to function as a systems administrator, network engineer, security engineer, disaster-recovery planner, and possibly an IT manager, all at once. A junior can absolutely learn in a small company, but only when there is supervision, a budget, and management that accepts realistic limits.
Do not rebuild the whole environment by yourself. Stabilize the basics first if you have approval: reliable backups with tested restores, patching, endpoint protection, removal of unnecessary internet exposure, strong individual accounts, and a documented recovery procedure. Get experienced help before touching the ERP database, firewall architecture, or site connectivity.

Frame it in terms of business impact rather than technical vocabulary: production downtime, lost orders, ransomware recovery costs, licensing exposure, and the inability to restore the ERP. That is more likely to get management’s attention.