You Don’t Have an IT Problem. You Have a Gap Problem.

A CFO told me last month that IT was handled. They had a guy. He’d been there nine years, knew everything, never complained.

So I started asking questions. Who handles the cyber insurance questionnaire? “The broker fills that out.”

Who runs the backups? “There’s a company that does that.”

Who patches the laptops? “Our guy does.”

Who keeps things running when “the guy” is on vacation? Long pause.

They didn’t have IT handled.

They had some of the jobs handled internally, several more farmed out to vendors nobody was really managing, and the rest sitting in gaps nobody had looked at in years.

That’s not unusual. That’s what I see in a lot of companies with 50 to 500 employees.

“IT” Is 36 Different Jobs

The problem starts with the word IT. We use one word to describe dozens of jobs that require different skills, different tools, different levels of attention, and sometimes entirely different people.

Infrastructure and Operations

  1. Service desk and end user support
  2. Endpoint management and patching
  3. Firewalls and network security
  4. Switching, wireless and remote sites
  5. Servers and virtualization
  6. Cloud and tenant administration
  7. Backup
  8. Disaster recovery and testing
  9. Phone systems and collaboration tools
  10. Conference rooms, AV and printing
  11. Cabling, closets, cameras and badge access
  12. Hardware procurement and lifecycle

Identity and Security

13. Access management, including who gets added and removed

14. Email security

15. Endpoint detection and response

16. Security monitoring, including nights and weekends

17. Vulnerability management

18. Incident response

19. Security awareness and phishing testing

20. Penetration testing

21. Knowing what files have been shared outside the organization

Governance and Business

22. Policy, frameworks and compliance work

23. Customer security questionnaires

24. Cyber insurance attestations

25. Vendor and third-party risk

26. IT budget, roadmap and strategy

27. Software licensing and renewals

28. Project management

29. Documentation and change control

Applications and Data

30. ERP administration

31. Line-of-business application support

32. Integrations between systems

33. Reporting and analytics

34. Data governance

35. Website and anything customer-facing

36. Automation and AI

And that’s before adding the things specific to your business. If you’re a manufacturer, add plant-floor technology and OT. If you’re in healthcare, defense or another highly regulated industry, compliance can become a job of its own.

Now Map What’s Handled, Who Handles It and Where the Gaps Are

Take the list and put one letter beside every job:

H: Handled in house P: Partly handled, or split across people V: A vendor has it N: No one has it ?: You’re not sure, or you’re not even sure what it is

Don’t skip the question marks. They’re important. In fact, the biggest surprise for many companies isn’t how many Ns they have. It’s how many Ps and question marks show up once somebody actually goes through the exercise.

A job that is partly handled can be more dangerous than one everyone knows is unassigned. Two people each think the other person owns the other half. Then something breaks.

The internal IT person calls the software vendor. The software vendor blames the network. The network vendor says it’s an application problem. Meanwhile, the business is down and nobody actually owns the outcome.

That’s the seam. And seams are where a lot of expensive problems live.

Your One IT Person Isn’t Covering 36 Jobs

Now count your H column. Realistically, one strong generalist can cover six to eight of these areas well. Two people might cover a dozen.

If you’re checking H beside 20 or 25 items because “Bob takes care of all that,” I’d look again. There is a difference between touching something and owning it.

That’s not a criticism of Bob. It’s math.

No one person is simultaneously a help desk technician, network engineer, cloud administrator, security analyst, incident responder, compliance specialist, ERP administrator, project manager, data governance expert and IT strategist. Yet a surprising number of growing companies have built their IT operation around the assumption that one person somehow is.

You’re Probably Already Outsourcing IT

This is why I think the usual debate about “in-house versus outsourced IT” misses the point.

If you’re a 50-to-500-person company, you’re probably already outsourcing. You just may not think of it that way.

Look at the V column. Maybe there’s a break-fix shop for desktops. A phone vendor. The ERP reseller. A company managing backups. Someone who configured the firewall. A copier company that somehow ended up connected to the network. A web developer nobody has talked to since 2022. Whoever installed the cameras.

Maybe there are eight or ten relationships, each holding one piece of your technology environment. None of them talk to each other. And every one of them can legitimately say: “That’s on somebody else’s side.”

The question was never really whether you should outsource IT. You settled that years ago, probably without realizing it. The better question is: Who is managing the seams?

Some Things Should Be Outside. Some Should Stay Inside.

Not every one of these 36 jobs belongs in the same column. Some things should probably never be entirely in house.

Penetration testing is an obvious example. Having the people who built or maintain the environment independently test their own work defeats much of the purpose.

Twenty-four-hour security monitoring is another. Three people cannot sustainably cover a 24-hour clock. You don’t solve that staffing problem by asking people to keep their phones beside the bed.

Other responsibilities should never completely leave the business.

  • Someone inside your company needs to know what the business is trying to accomplish next year.
  • Someone has to decide what gets funded.
  • Someone has to own the vendor relationships and understand the contracts.
  • Someone has to connect technology decisions to business decisions.

That person doesn’t necessarily need “IT” in their title. It might be the CFO spending four hours a month on it.

But somebody has to own it. A lot of the middle is a legitimate business decision.

  • Should this function be internal or external?
  • What’s the fully loaded cost?
  • What happens when the person who owns it is on vacation, sick or leaves the company?
  • How specialized is the work?
  • How often do you actually need that expertise?
  • How much management attention does it require?
  • Those aren’t technology questions.
  • They’re business questions.

Four Questions I’d Ask After You Finish the List

Once you’ve marked all 36, don’t just count the columns.

Look at them differently.

For every P, ask: Who owns the half nobody claimed?

For every V, ask: Who inside our company owns that relationship, and when did somebody last read the contract?

For every H, ask: How many of these depend on one specific person being available?

And then find the worst N or ? on the entire page and ask: If this fails at 4 p.m. on Friday, what do we actually do?

If nobody has a good answer, you just found something worth fixing.

This Isn’t a Crisis. It’s Visibility.

If you go through the exercise and discover you’ve got eight jobs handled internally, twelve spread across vendors, and another group that are partly handled, unowned or simply unknown, don’t panic.

That’s not evidence that your company is a mess. It’s usually evidence that your company grew. The technology setup that worked when you had 30 employees kept accumulating pieces as you became a 75-person company, then a 150-person company, then a 300-person company.

Another vendor got added. Another application got purchased. Another responsibility landed on someone’s desk. Nobody ever stopped and redesigned the whole thing.

That’s normal.

What’s dangerous is continuing to make those decisions by default instead of on purpose.

So count the jobs. Mark the columns. Find the seams.

Because the question isn’t whether you have someone “handling IT.”

The question is whether all the things hiding inside those two letters actually have an owner.

I’ve shortened the list into a survey that takes 2 minutes and doesn’t attribute any sensitive information to your company.  Take it, and if you want to talk, reach out: https://itsurvey.itauditlabs.com/

Common Questions Asked

What is an IT gap analysis?

An IT gap analysis is the process of mapping every function IT actually covers — infrastructure, security, governance, applications — against who currently owns each one, so you can see what’s handled, what’s split between people, what’s outsourced, and what nobody owns at all.

How many IT functions does a typical business actually need to cover?

This post breaks IT into 36 distinct jobs across four categories: infrastructure and operations, identity and security, governance and business, and applications and data. Regulated or specialized industries often add more, like OT for manufacturers or compliance work for healthcare and defense.

Can one IT person realistically cover all of a company’s IT needs?

No. A strong generalist can typically own six to eight of these functions well; two people might cover a dozen. A single person credited with 20 or more is usually touching those areas, not truly owning them, which creates hidden risk.

Is my company already outsourcing IT even if we have an internal person?

Almost certainly, yes. Most 50-to-500-employee companies already rely on multiple vendors — for backups, phones, ERP, firewalls, cameras, and more — even if no one has framed it as “outsourcing.” The real question isn’t whether to outsource, it’s who manages the relationships and the gaps between them.

Share the Post:

Related Posts

Join Our Live Podcast | FRIDAY @ 2pm CT