Subnet Blog

When a Small IT Team Carries a Firm-Sized Security Burden

Written by Ben Luks | 22 September 2026, 04:23:50 Z

Professional services firms depend heavily on technology. Client documents, financial information, emails, project records and intellectual property may all be stored across cloud platforms and business applications. Employees need reliable access to this information wherever they work, while clients increasingly expect their data to be protected.

Behind all of this is often a surprisingly small IT team. In some firms, responsibility may rest with one internal IT manager. In others, a small team supports the entire organisation while also managing cybersecurity, Microsoft 365, business applications, vendors, projects and strategic planning.

These teams can be highly capable. The challenge is that the size and complexity of their responsibilities may have grown faster than the resources available to manage them. When a small IT team is expected to carry a firm-sized security burden, even excellent people can struggle to give every risk the attention it deserves.

The responsibilities of IT have expanded

There was a time when an internal IT team could focus primarily on devices, software, connectivity and user support. Those responsibilities have not disappeared. However, they now sit alongside a much broader range of security and governance requirements. A typical IT function within a professional services firm may be expected to:

  • Support employees working across offices, homes and client locations.
  • Manage Microsoft 365 accounts, permissions and security settings.
  • Protect client information across email, document libraries and collaboration platforms.
  • Monitor cyber threats and respond to suspicious activity.
  • Maintain backups and recovery processes.
  • Review new applications and cloud services.
  • Manage external technology providers.
  • Support compliance, insurance and client assurance requirements.
  • Deliver technology projects and improvements.
  • Help the business evaluate artificial intelligence and other emerging tools.

Each responsibility may be manageable in isolation. The pressure comes from managing all of them simultaneously—often while responding to a constant flow of support requests and operational issues. Security work can then become something the team fits around its immediate responsibilities, rather than a continuous and properly resourced function.

The problem is capacity, not capability

When discussing the pressure on small IT teams, it is important to distinguish between capability and capacity. An experienced IT manager may understand exactly what the firm needs to improve. They may already know that permissions should be reviewed, security settings need strengthening or recovery procedures require further testing.

Knowing what needs to happen does not create the time required to complete it. Urgent operational work will usually take priority. If an employee cannot access a system, a client-facing application stops working or a senior leader needs immediate assistance, the IT team must respond.

Strategic and preventative work is easier to defer because the consequences are less visible—at least until something goes wrong. Over time, this can create a growing backlog of important work:

  • Security recommendations remain partially implemented.
  • Microsoft 365 settings are not regularly reviewed.
  • Old accounts, external guests and shared links remain active.
  • Recovery procedures exist but are not fully tested.
  • Technology documentation becomes outdated.
  • Vulnerabilities and software updates compete with operational demands.
  • Important projects depend heavily on one person’s availability.

This does not necessarily indicate poor performance. It may simply mean that the workload has exceeded the team’s practical capacity.

Cybersecurity is no longer a part-time responsibility

Cybersecurity requires ongoing attention. Threats change. New vulnerabilities emerge. Employees join, leave and change roles. Applications are introduced. Information moves between systems. Security settings are altered during projects and may never be revisited.

A one-off security project cannot account for all these changes. Professional services firms also face risks that require different areas of expertise. Protecting identity systems, securing Microsoft 365, monitoring threats, testing recovery processes and responding to an incident are related disciplines—but they are not identical.

It can be difficult for a small internal team to maintain specialist knowledge across every area while continuing to run the firm’s day-to-day technology environment.

The concern is not that the team lacks technical ability. It is that the organisation may be depending on a limited number of people to cover an unusually broad security landscape.

Key-person dependency creates another layer of risk

In many firms, one person holds a significant amount of knowledge about the technology environment. They understand how critical systems are configured, which suppliers to contact, where documentation is located and how previous problems were resolved.

That knowledge is extremely valuable. It can also become a business risk if it is not shared. What happens if that person is unavailable during a serious outage or cyber incident? Could someone else access the required systems, documentation and supplier information? Would the firm know which services should be restored first?

Key-person dependency does not always mean someone is about to leave the organisation. Annual leave, illness or competing project demands may be enough to expose the problem.

The goal should not be to make an internal IT role less important. It should be to ensure that the firm’s resilience does not depend entirely on one person being available at the right moment.

Warning signs that your IT team may be carrying too much

Capacity pressure does not always appear as a major failure. More often, it shows up through small compromises and recurring delays. Some warning signs may include:

  • Preventative work is frequently postponed because operational issues take priority.
  • Security reviews occur mainly in response to an audit, client request or insurance renewal.
  • Important systems or processes depend on knowledge held by one person.
  • The team has limited time to investigate new threats or security recommendations.
  • Documentation is incomplete or difficult to keep current.
  • Recovery plans have been written but not recently tested.
  • IT staff are consistently working reactively.
  • Major projects stall because the same people are also responsible for daily support.
  • Leadership lacks a clear view of unresolved technology risks.
  • The organisation would struggle to maintain coverage during leave or an incident.

None of these signs automatically means the firm is insecure. They do suggest that the operating model may need additional support.

What co-managed IT support should look like

Bringing in external support does not need to mean replacing the internal IT team. A co-managed approach allows an organisation to retain its internal knowledge and relationships while adding capacity, tools and specialist expertise where required.

The internal team remains close to the firm. They understand its people, clients, priorities and business applications. An external technology partner can complement that knowledge by assisting with areas such as:

  • Security monitoring and incident response.
  • Microsoft 365 security and configuration reviews.
  • Backup and recovery testing.
  • Vulnerability management.
  • Escalation support for complex technical issues.
  • Project delivery.
  • Documentation and technology planning.
  • After-hours or leave coverage.
  • Access to specialists who may not be required as permanent employees.

This model can also give an internal IT manager more time to focus on work that requires a detailed understanding of the business, rather than spending every available hour responding to operational demands.

The most effective arrangement should feel like an extension of the existing team. Responsibilities should be clear, communication should be direct and the internal team should retain visibility and control.

A shared-responsibility model strengthens security

Technology risk cannot be delegated entirely to one person, one department or one external provider. Internal IT teams manage the environment, but business leaders determine priorities and provide the resources needed to address risk. Practice and project leaders understand who should have access to client information. Employees influence security through the tools they use and the decisions they make.

External specialists can contribute expertise and capacity, but they also need input from people who understand the firm. A stronger model therefore distributes responsibility:

  • Leadership sets expectations and treats technology risk as a business issue.
  • Internal IT provides organisational knowledge and day-to-day oversight.
  • Business leaders help define access and operational requirements.
  • Employees follow agreed processes and raise concerns.
  • External specialists provide additional capability, coverage and independent insight.

This shared approach reduces the likelihood that the entire security burden will fall on a small internal team.

Questions professional services firms should ask

Leaders do not need to understand every technical detail to determine whether their IT function has sufficient support. A useful starting point is to ask:

  • Which security and technology tasks are being deferred because the team lacks time?
  • Where do we depend heavily on one person’s knowledge or availability?
  • Can we maintain appropriate coverage during leave, major projects or an incident?
  • When did we last test our recovery procedures?
  • Does our IT team have access to specialists when a complex issue arises?
  • Are responsibilities clearly divided between internal staff and external providers?
  • Is the team spending most of its time preventing problems or reacting to them?
  • What additional capacity would allow the team to focus on higher-value priorities?

These questions can help reveal whether the current model remains appropriate for the size, complexity and risk profile of the firm.

Give capable people the support to succeed

Small internal IT teams often achieve a great deal with limited resources. They keep employees productive, solve problems, support projects and protect systems that are essential to client service. But commitment and expertise cannot create unlimited capacity.

As technology environments become more complex—and the consequences of disruption or data exposure become more serious—professional services firms need to ensure their IT teams are not carrying the burden alone.

Providing additional capacity and specialist support does not diminish the role of internal IT. It gives capable people the time, coverage and expertise they need to protect the firm more effectively.

The question is not simply whether your IT team is capable. It is whether the organisation has given them enough support to manage everything now expected of them.