Subnet Blog

How Much of Your Council Depends on One IT Person?

Written by Ben Luks | 20 August 2026, 06:44:36 Z

Every organisation has people it relies upon. In a council IT environment, however, that reliance can sometimes become surprisingly concentrated.

There may be one person who understands why a particular system was configured a certain way, who knows which supplier to call when something fails, or who understands the network across every council location. The same person might know how the backups work, where the documentation lives, which projects are coming up and what needs to happen when something goes wrong.

Often, that person is exceptionally valuable precisely because they've accumulated years of knowledge about the council. But there's an important question for both IT teams and council leaders:

How much of your council's ability to operate depends on that knowledge being available when you need it?

Key-person dependency isn't a criticism of the person carrying the responsibility. Quite the opposite. It's a question of whether the organisation has put enough documentation, processes, capacity and expertise around them to ensure they don't have to carry it alone.

1. Small IT team doesn't necessarily mean small IT responsibility

The size of a council's technology environment isn't always proportional to the size of its IT team.

Even a relatively small council may depend on Microsoft 365 and cloud services, networks and connectivity, cybersecurity controls, backup and disaster recovery, finance and ERP platforms, records-management systems, asset and planning applications, end-user devices, mobile and field technology, and community-facing digital services.

Then there are projects, procurement, licensing, budgeting, user support and the constant work involved in keeping everything secure and current.

As we explored in The Top 7 IT Challenges Facing Australian Local Councils in 2026, skills shortages are already creating pressure for council IT teams, with IT managers often required to cover infrastructure, security, governance and procurement simultaneously.

The problem isn't that a small team can't manage an effective IT environment. Many do. The problem arises when too many critical responsibilities have nowhere else to go.

2. What happens when your key IT person isn't available?

It's a simple question, but a useful one.

Imagine your most knowledgeable IT person is unavailable tomorrow. Perhaps they're on annual leave or sick. Perhaps they've moved to another organisation. Or perhaps a major incident is occurring and they're already occupied dealing with one critical problem while three others require attention.

Could somebody else quickly determine which systems are most important, how the network is configured, where administrator credentials are managed and who the critical technology vendors are?

Would they know which backups exist and how to restore them? What projects and renewals are approaching? How to escalate a cybersecurity incident? Which systems have unusual configurations or dependencies? Who needs to be contacted when something fails?

If the answer to many of those questions is: "We'd need to ask [person's name]" then the council may have a key-person dependency worth addressing.

3. The real risk is often knowledge that lives in someone's head

Experienced IT people develop enormous amounts of organisational knowledge, and not all of it makes its way into documentation. There's the formal environment: network diagrams, asset registers, passwords and privileged access, vendor details, backup procedures, licensing and configuration records.

Then there's the informal knowledge: that application has to be restarted in a particular order; call this person at the vendor because they'll know what we're talking about; that switch is labelled incorrectly; we tried upgrading that system two years ago and here's why it didn't work.

There's also the knowledge that sits at the intersection of IT and the wider organisation: don't change that setting without speaking to Finance first. That knowledge can be incredibly valuable. It can also become a risk if the organisation has no way of accessing it when the person isn't there.

Good documentation isn't about replacing experience. It's about making organisational knowledge belong to the organisation.

4. Cybersecurity makes key-person dependency more serious

The problem becomes particularly acute during a cybersecurity incident.

A compromised account, ransomware event or suspicious device doesn't necessarily occur during normal business hours — or when every member of the IT team happens to be available. During an incident, councils may need to make important decisions quickly.

Which systems should be isolated? Who has authority to take them offline? Who contacts the cyber insurer or engages external specialists? Where are the emergency contact details? How do you access systems if normal credentials have been compromised? Who communicates with leadership?

Our article Is Your Council Actually Ready for a Cyber Incident? explores this broader preparedness challenge, including incident-response plans, tested backups, escalation responsibilities and tabletop exercises.

But key-person dependency adds another question: Would your incident-response capability still work if the person who knows your environment best wasn't available?

That's worth testing before an actual incident provides the answer.

5. Specialist IT knowledge is becoming harder for one person to maintain

There's another dimension to the problem: IT has become increasingly specialised.

Cybersecurity alone can encompass identity protection, endpoint detection, vulnerability management, Microsoft 365 security, incident response, backup protection and continuous monitoring. Then there is networking, cloud, Microsoft platforms, infrastructure, business continuity, compliance, AI, vendor management and project delivery.

The expectation that one internal IT Manager should maintain deep expertise across every one of those areas is becoming increasingly unrealistic.

That doesn't mean the internal IT Manager is under-skilled. It means the technology industry has become too broad for almost anyone to be an expert in everything.

This is particularly relevant for councils operating with lean teams and constrained budgets. Your internal people may know your council better than any external provider ever could. The question is whether they have access to additional specialist capability when they need it.

6. More technology means more responsibility

The pressure isn't likely to reduce. Council technology environments continue to evolve. Community expectations for digital services are increasing, cybersecurity threats continue to develop, cloud platforms keep changing and new compliance requirements emerge.

Then technologies such as generative AI create entirely new governance questions. As we've explored in Building Trust in AI: A Guide for SA Local Government IT Teams, councils need to consider not only the opportunities presented by AI but also issues around governance, information security and responsible adoption.

That means the IT team's responsibilities don't remain static. They accumulate. For councils already operating with lean internal teams, every new technology decision can create another capability the team is expected to understand, secure, govern and support.

That's one reason workforce sustainability deserves to be treated as an IT risk-management issue, not simply an HR problem.

7. The answer isn't necessarily a bigger internal IT department

The obvious response to a capacity problem might seem to be hiring more people. Sometimes that's exactly the right answer, but it isn't the only one.

A council might instead ask two questions: Which capabilities genuinely need to live internally? And where would access to external expertise make the internal team stronger?

An internal IT Manager brings invaluable organisational context. They understand the council's people, priorities, history, systems, constraints and upcoming projects.

An external technology partner can provide something different: depth and breadth of capability.

That might include additional service-desk capacity, specialist engineering, cybersecurity expertise, proactive monitoring, project resources, backup and recovery capability or escalation support.

The two don't have to compete. In a co-managed model, they can complement each other. The objective isn't to replace the person your council depends upon. It's to make the council less dependent on them having to do everything.

What can this look like in practice?

A real council example is particularly useful because it moves the discussion away from the false choice between "we manage IT ourselves" and "we outsource everything."

Subnet works with the District Council of Yankalilla, providing an example of how an external technology partner can work alongside a local council and support its technology environment.

See how Subnet works with the District Council of Yankalilla →

For another council, the right balance may look completely different. The useful starting point is understanding where knowledge, capability and responsibility currently sit — and where the organisation would be exposed if those resources suddenly weren't available.

8. Five questions council leaders and IT teams should ask

Key-person risk doesn't require an elaborate assessment to start thinking about. Five questions can reveal quite a lot:

  1. If our most knowledgeable IT person left tomorrow, what would we struggle to understand?
  2. Are critical systems, configurations, credentials, vendors and procedures properly documented?
  3. Can somebody else respond to a serious IT or cybersecurity incident if our primary IT person isn't available?
  4. Are we expecting one person or small team to maintain specialist expertise across too many technology disciplines?
  5. Does our IT team have somewhere to escalate when a problem exceeds its internal capacity or expertise?

If the answers reveal gaps, that doesn't mean the council needs to completely redesign its IT operating model. It simply identifies where resilience could be improved.

Strong IT people shouldn't become single points of failure

The most knowledgeable person in your IT environment may be one of the council's most valuable employees. They've accumulated organisational knowledge, built relationships with employees and vendors, solved problems nobody else remembers and developed an understanding of the environment that can't simply be captured in a network diagram.

The goal shouldn't be to diminish that value. It should be to protect it.

Document what can be documented. Build processes that don't depend on memory. Make sure somebody else can step in when required. Give internal people access to specialist expertise, and ensure there is enough capacity around them that taking annual leave doesn't require keeping one eye on the phone.

Because a resilient IT environment isn't one where nobody is indispensable. It's one where valuable people can do their best work without becoming a single point of failure.

Give your IT team a bigger bench

If your council has a lean internal IT team, the question doesn't have to be whether you should outsource it. A better question may be:

What could your existing team accomplish if it had more capability around it?

See how Subnet works with the District Council of Yankalilla, or talk to us about where additional support, specialist expertise or co-managed IT could strengthen your existing environment.

Read the District Council of Yankalilla case study →