A CFO told me last month that IT was handled. They had a guy. He’d been there nine years, knew everything, never complained.
So I started asking questions. Who handles the cyber insurance questionnaire? “The broker fills that out.”
Who runs the backups? “There’s a company that does that.”
Who patches the laptops? “Our guy does.”
Who keeps things running when “the guy” is on vacation? Long pause.
They didn’t have IT handled.
They had some of the jobs handled internally, several more farmed out to vendors nobody was really managing, and the rest sitting in gaps nobody had looked at in years.
That’s not unusual. That’s what I see in a lot of companies with 50 to 500 employees.
“IT” Is 36 Different Jobs
The problem starts with the word IT. We use one word to describe dozens of jobs that require different skills, different tools, different levels of attention, and sometimes entirely different people.
Infrastructure and Operations
- Service desk and end user support
- Endpoint management and patching
- Firewalls and network security
- Switching, wireless and remote sites
- Servers and virtualization
- Cloud and tenant administration
- Backup
- Disaster recovery and testing
- Phone systems and collaboration tools
- Conference rooms, AV and printing
- Cabling, closets, cameras and badge access
- Hardware procurement and lifecycle
Identity and Security
13. Access management, including who gets added and removed
14. Email security
15. Endpoint detection and response
16. Security monitoring, including nights and weekends
17. Vulnerability management
18. Incident response
19. Security awareness and phishing testing
20. Penetration testing
21. Knowing what files have been shared outside the organization
Governance and Business
22. Policy, frameworks and compliance work
23. Customer security questionnaires
24. Cyber insurance attestations
25. Vendor and third-party risk
26. IT budget, roadmap and strategy
27. Software licensing and renewals
28. Project management
29. Documentation and change control
Applications and Data
30. ERP administration
31. Line-of-business application support
32. Integrations between systems
33. Reporting and analytics
34. Data governance
35. Website and anything customer-facing
36. Automation and AI
And that’s before adding the things specific to your business. If you’re a manufacturer, add plant-floor technology and OT. If you’re in healthcare, defense or another highly regulated industry, compliance can become a job of its own.
Now Map What’s Handled, Who Handles It and Where the Gaps Are
Take the list and put one letter beside every job:
H: Handled in house P: Partly handled, or split across people V: A vendor has it N: No one has it ?: You’re not sure, or you’re not even sure what it is
Don’t skip the question marks. They’re important. In fact, the biggest surprise for many companies isn’t how many Ns they have. It’s how many Ps and question marks show up once somebody actually goes through the exercise.
A job that is partly handled can be more dangerous than one everyone knows is unassigned. Two people each think the other person owns the other half. Then something breaks.
The internal IT person calls the software vendor. The software vendor blames the network. The network vendor says it’s an application problem. Meanwhile, the business is down and nobody actually owns the outcome.
That’s the seam. And seams are where a lot of expensive problems live.
Your One IT Person Isn’t Covering 36 Jobs
Now count your H column. Realistically, one strong generalist can cover six to eight of these areas well. Two people might cover a dozen.
If you’re checking H beside 20 or 25 items because “Bob takes care of all that,” I’d look again. There is a difference between touching something and owning it.
That’s not a criticism of Bob. It’s math.
No one person is simultaneously a help desk technician, network engineer, cloud administrator, security analyst, incident responder, compliance specialist, ERP administrator, project manager, data governance expert and IT strategist. Yet a surprising number of growing companies have built their IT operation around the assumption that one person somehow is.
You’re Probably Already Outsourcing IT
This is why I think the usual debate about “in-house versus outsourced IT” misses the point.
If you’re a 50-to-500-person company, you’re probably already outsourcing. You just may not think of it that way.
Look at the V column. Maybe there’s a break-fix shop for desktops. A phone vendor. The ERP reseller. A company managing backups. Someone who configured the firewall. A copier company that somehow ended up connected to the network. A web developer nobody has talked to since 2022. Whoever installed the cameras.
Maybe there are eight or ten relationships, each holding one piece of your technology environment. None of them talk to each other. And every one of them can legitimately say: “That’s on somebody else’s side.”
The question was never really whether you should outsource IT. You settled that years ago, probably without realizing it. The better question is: Who is managing the seams?
Some Things Should Be Outside. Some Should Stay Inside.
Not every one of these 36 jobs belongs in the same column. Some things should probably never be entirely in house.
Penetration testing is an obvious example. Having the people who built or maintain the environment independently test their own work defeats much of the purpose.
Twenty-four-hour security monitoring is another. Three people cannot sustainably cover a 24-hour clock. You don’t solve that staffing problem by asking people to keep their phones beside the bed.
Other responsibilities should never completely leave the business.
- Someone inside your company needs to know what the business is trying to accomplish next year.
- Someone has to decide what gets funded.
- Someone has to own the vendor relationships and understand the contracts.
- Someone has to connect technology decisions to business decisions.
That person doesn’t necessarily need “IT” in their title. It might be the CFO spending four hours a month on it.
But somebody has to own it. A lot of the middle is a legitimate business decision.
- Should this function be internal or external?
- What’s the fully loaded cost?
- What happens when the person who owns it is on vacation, sick or leaves the company?
- How specialized is the work?
- How often do you actually need that expertise?
- How much management attention does it require?
- Those aren’t technology questions.
- They’re business questions.
Four Questions I’d Ask After You Finish the List
Once you’ve marked all 36, don’t just count the columns.
Look at them differently.
For every P, ask: Who owns the half nobody claimed?
For every V, ask: Who inside our company owns that relationship, and when did somebody last read the contract?
For every H, ask: How many of these depend on one specific person being available?
And then find the worst N or ? on the entire page and ask: If this fails at 4 p.m. on Friday, what do we actually do?
If nobody has a good answer, you just found something worth fixing.
This Isn’t a Crisis. It’s Visibility.
If you go through the exercise and discover you’ve got eight jobs handled internally, twelve spread across vendors, and another group that are partly handled, unowned or simply unknown, don’t panic.
That’s not evidence that your company is a mess. It’s usually evidence that your company grew. The technology setup that worked when you had 30 employees kept accumulating pieces as you became a 75-person company, then a 150-person company, then a 300-person company.
Another vendor got added. Another application got purchased. Another responsibility landed on someone’s desk. Nobody ever stopped and redesigned the whole thing.
That’s normal.
What’s dangerous is continuing to make those decisions by default instead of on purpose.
So count the jobs. Mark the columns. Find the seams.
Because the question isn’t whether you have someone “handling IT.”
The question is whether all the things hiding inside those two letters actually have an owner.
I’ve shortened the list into a survey that takes 2 minutes and doesn’t attribute any sensitive information to your company. Take it, and if you want to talk, reach out: https://itsurvey.itauditlabs.com/
Common Questions Asked
An IT gap analysis is the process of mapping every function IT actually covers — infrastructure, security, governance, applications — against who currently owns each one, so you can see what’s handled, what’s split between people, what’s outsourced, and what nobody owns at all.
This post breaks IT into 36 distinct jobs across four categories: infrastructure and operations, identity and security, governance and business, and applications and data. Regulated or specialized industries often add more, like OT for manufacturers or compliance work for healthcare and defense.
No. A strong generalist can typically own six to eight of these functions well; two people might cover a dozen. A single person credited with 20 or more is usually touching those areas, not truly owning them, which creates hidden risk.
Almost certainly, yes. Most 50-to-500-employee companies already rely on multiple vendors — for backups, phones, ERP, firewalls, cameras, and more — even if no one has framed it as “outsourcing.” The real question isn’t whether to outsource, it’s who manages the relationships and the gaps between them.
