Fig. 1From tangle to order. That is the whole job — and it happens on paper first.
01The situation
Fixing things and being in charge are two different jobs.
Most businesses between ten and a couple hundred people have the first job covered. Somebody resets passwords, swaps out the dead laptop, calls the internet company when the line drops. The computers work.
What they usually do not have is the second job: one accountable person who knows what the company pays for, who can get in, and what is at risk.
That second job is the one I take. I do not resell hardware, software, or anybody's managed service, so there is nothing to steer you toward. I make money paying attention.
Fig. 2Same desk, two conditions. Only one of them can be handed to the next person.
The part that isn't fractional is the accountability.
Kris Ostopchuck, Fractional IT LLC
02Self-check
Is anyone in charge of your IT?
Four questions. Yes or no.
Q1Does someone read your vendor contracts before they renew?YesNo
Q2Can anyone name every piece of software you pay for?YesNo
Q3Was access shut off the last time someone left?YesNo
Q4Could someone answer your insurer's security questionnaire from documentation?YesNo
03What you actually receive
Advice evaporates. Documents don't.
Depending on how we work together, you receive some or all of four things you can hold, hand to your board, or give to the next provider. Here is what each one looks like — reduced, but real in shape. The samples below are illustrative, not taken from any client.
Deliverable A
The written baseline
A fixed-scope document of what exists, who can get into it, what is at risk, and what to do next — in priority order. You keep it whether or not we continue.
2Who has accessAdmin rights, shared passwords, former staff, outside providers9
3What is at riskRanked, with likelihood, impact and rough cost to address14
4What to do nextA prioritized roadmap with options, not a shopping list21
AAppendix — inventory & renewal calendar27
Deliverable B
The decision log
Every recommendation carries a rationale, a cost, and the alternative that was considered — and how to reverse it. That is what makes a decision defensible a year later.
Decision LogIllustrative entry · D-014
Decision
Retire the aging on-site file server; move shared files into the Microsoft 365 subscription the company already pays for.
Rationale
The server is past vendor support, sits on a single disk, and its backup has never been test-restored. The licensing for the replacement is already in place and unused.
Cost
No new licensing. Roughly two working days of migration and staff walkthrough, plus one month of running both side by side.
Alternative considered
Replace the server hardware like-for-like. Rejected: it recreates a single point of failure and adds a second backup to babysit.
How to reverse
Copy the files back to the old server. Steps are written up; the old server stays powered off, not wiped, for ninety days.
Approved · Owner
Deliverable C
The ranked risk register
A living list, ranked, each line with an owner, a status, and a rough cost. It is the agenda for every report that follows, so there are never surprise findings.
Risk RegisterIllustrative · ranked by exposure
Illustrative risk register, ranked by exposure
#
Risk
Likelihood
Impact
Owner
Status
R-01
Backups have never been test-restoredRough cost: time only — one restore drill
Likely
High
IT Director
In progress
R-02
Accounts for former staff still enabledRough cost: time only — plus a written offboarding step
Likely
High
Office Manager
Open
R-03
Company web domain registered to one person's private accountRough cost: low — registrar transfer and a shared record
Possible
High
Owner
Scheduled
R-04
One shared admin password on the firewallRough cost: low — named accounts, password vault
Possible
High
IT Director
Closed
Scroll sideways for the full table →
Deliverable D
The monthly owner's report
Written for an owner or CFO, not for another technician. What changed, why, what is next, and what needs a decision from you. Quarterly, the roadmap and budget get the same treatment.
Monthly Owner's ReportIllustrative · prepared for an owner & CFO
What changed this month
Restore drill completed; files came back from backup on the first attempt (R-01).
Former-staff accounts disabled and their licenses released (R-02).
Firewall now uses named admin accounts; the shared password is retired (R-04, closed).
What is coming
Domain transfer to the company registrar account (R-03), scheduled for the second week.
File-server migration begins per decision D-014; staff walkthrough on a Friday.
Vendor renewal calendar published; first sixty-day notices go out.
Decisions needed from you
Which two people should hold emergency admin access alongside the IT Director.
Whether the unused conferencing subscription is cancelled at renewal or kept for one more term.
Thirty minutes is enough to tell whether the written baseline is worth doing for your company.
04Services · index
Six areas. One person accountable for all of them.
Each area is written up the same way — what exists, what is at risk, what changed. The assessment is where most engagements begin.
1
Fractional IT Leadership
Executive IT direction without the full-time hire.
Budgeting. A 12-to-24-month roadmap. Vendor and MSP management — contracts, renewals, and accountability for what they promised. Leadership reporting a CFO or owner can act on without a translator.
2
Infrastructure Management
Infrastructure that is stable, documented, and manageable.
Windows Server and Active Directory. Microsoft 365 — Exchange, SharePoint, Teams. Intune device management. Cisco Meraki networking. Hybrid on-premises and cloud, kept in a state someone else could inherit.
3
Security & Risk Management
Practical security improvement, grounded in your actual risks.
A living risk register. Control validation — checking that the protections you pay for are actually on. Patch and vulnerability oversight, admin-access review, vendor risk. Insurance and client security questionnaires answered from documentation instead of memory.
4
Microsoft 365 Governance
Order and governance for Microsoft 365.
Licensing that matches what you actually use. Access control that reflects who works here today. Offboarding that genuinely shuts things off — mail, files, devices, and the logins nobody remembers.
5
Assessment
Know where you stand — and what to do next.
A fixed-scope, written baseline of what exists, what is at risk, and a prioritized roadmap. It is a useful document whether or not you continue with me, and it is where pricing for anything further is set out in writing. This is where most engagements begin.
Own your IT — the access, the documentation, and the plan.
Moving on from a previous provider: securing admin access, verifying the backups, documenting what exists so it belongs to the company and not to whoever set it up. Also incident response and recovery — ransomware, email compromise — handled as structured containment with a written log, by someone who has done it before.
05Approach · four chapters
The work happens in order, and it is written down as it happens.
Four phases, each with something on paper at the end of it. Nothing gets changed before it has been understood.
1Chapter one
Assess
Find out what exists, who can get into it, and what is genuinely at risk. Domains, accounts, devices, vendors, subscriptions, admin rights — all of it inventoried before anything is touched.
Yields: the written baseline and the first ranked risk register.
2Chapter two
Stabilize
Secure administrative access so it belongs to the company. Confirm that backups actually restore. Close the accounts that should have been closed. Catch the renewals and expirations already in motion.
Yields: a change log — what changed, why, and how to reverse it.
3Chapter three
Structure
Put order around the environment: licensing matched to use, access control that mirrors the org chart, an offboarding routine that shuts things off, vendors held to their contracts, a renewal calendar somebody reads.
Yields: the decision log and the first monthly owner's report.
4Chapter four
Improve
Work the risk register in priority order against a 12-to-24-month roadmap and a budget your CFO can defend. Monthly reports for owners; quarterly roadmap and budget review.
Yields: monthly reports, quarterly roadmap and budget, a register that gets shorter.
Documented def.
The environment, the decisions, and the risks are written down as we go — not reconstructed afterward. If I were hit by a bus tomorrow, the next person could pick up the binder and keep going.
Defensible def.
Every recommendation carries a rationale, a cost, and the alternative that was considered. It has to stand up to leadership, an auditor, an insurer, or a new provider reading it cold.
i.
No surprise findings. Anything new goes in the next report, ranked, with options — not sprung in a meeting.
ii.
No fear-based selling. Risks are described plainly, with likelihood and cost. You decide what to fund.
iii.
No dependency by design. Documentation is written so another provider could take over without calling me.
iv.
No jargon walls. Reports are written for the person signing the checks, in plain English.
06Engagement models
Three ways to work together. All of them end with a document.
Pricing is set out in the written assessment, where it can be tied to what you actually have — not on a web page.
Model A
Assessment
Fixed scope, fixed deliverable. The written baseline, the ranked risk register, and a prioritized roadmap. Yields Deliverables A and C.
Not sure which model fits? Thirty minutes will settle it, and the answer may be "none yet."
07About
Fig. 3Kris Ostopchuck, Fractional IT LLC. Philadelphia, PA.
A senior operator, not a slide deck.
I have spent my career doing the hands-on work rather than advising on it from a distance: building, securing, and running IT for small and midsize organizations, and leading recoveries from ransomware and email compromise when the phone rang at the wrong hour.
That matters for a fractional role because the job is not to produce recommendations. It is to make the change, write down what was done, and be the one who answers for it next month. I am on-site for the greater Philadelphia region and remote for everyone else.
Practical over impressive. The right fix is usually the boring one.
Written down, always. If it isn't in the binder, it didn't happen.
Calm under pressure. Incidents get a log and a plan, not a panic.
Honest about limits. See the fine print below — it's short and it's real.
Most engagements go wrong on the things nobody said out loud at the start. These are mine.
What I will and won't promiseFractional IT LLC · every engagement
§ 1.1
Not a 24/7 helpdesk. I am one senior person working a set number of hours. If something is genuinely on fire, call — I will get back to you as soon as I can and tell you what to do in the meantime. A printer at nine on a Saturday can wait until Monday. If you need round-the-clock desk coverage, I will help you choose and manage a provider for it.
§ 1.2
No guaranteed outcomes. I will never tell you a network cannot be broken into or that a risk has been eliminated. I will tell you what the risk is, what reduces it, what that costs, and what remains.
§ 1.3
No dependency by design. Documentation is written so that another provider could take over from it without my help. Access belongs to the company, not to me.
§ 1.4
Nothing is resold. No hardware margin, no software commission, no vendor referral fee. Recommendations are paid for by the hours it takes to make them. That keeps them honest.
These apply to every engagement, in writing, before work starts.
09Fair questions
Four things owners ask on the first call.
They come up often enough to deserve a written answer. Here they are — before the call rather than after it.
9.1
You say
"We already have an IT person."
Good. Keep them. This practice does not replace the person who fixes things; it adds the person that work answers to — the one who owns the plan, the contracts and the budget. In my experience the in-house technician is usually relieved when someone finally owns the contracts, the budget and the risk conversations — nobody had asked them to, and they never had the hours for it.
Fixing things and being in charge are two different jobs. Both of them still get done.
9.2
You say
"We're too small for an IT director."
Too small for a full-time one. But the insurer's questionnaire, the renewal notices, the admin passwords and the departures all arrive at a thirty-person company exactly as they do at a three-hundred-person one — there is simply nobody whose job it is to catch them. The arithmetic is in the engagement section above; the short version is that the role is needed, the headcount is not.
Small companies don't have smaller risks. They have fewer people watching them.
9.3
You say
"How much does it cost?"
It depends on what exists and what is at risk, and a number guessed at on a web page would be exactly the kind of number this practice avoids. Almost every engagement therefore starts with the written assessment: fixed scope, a document you keep, and a plain statement of what is worth doing and what it would roughly cost — before anything ongoing is agreed. The exceptions are the ones that can't wait, like a takeover from a departing provider or an active incident.
From there the options are a monthly retainer with a set number of hours, a defined project, or nothing further, because the document said enough.
"You're one person. What if you get hit by a bus?"
Then the next person picks up the binder and keeps going. The environment, the decisions, the access, the vendor list, the risk register — all written down, in the company's own systems, in plain language, so a new provider could read it cold on a Monday morning.
The point of having someone in charge of IT is that the company stops depending on any one person's memory. That includes mine.
Anything not answered here is a fair question for the thirty minutes.
10Contact
Start with a thirty-minute conversation.
No forms, no pitch deck. Tell me what you have and who currently looks after it, and I'll tell you honestly whether an assessment is worth your money.
On-site across the greater Philadelphia region. Remote for everyone else.