Is this tool trying to say my IT person isn't good enough?
No. This scores the arrangement, not the person's competence. The person carrying IT is very often the one filling this out, and the most common honest result is that they are doing a genuinely good job day to day, with no backup behind them anywhere else. That's a resourcing gap, not a skills gap. The tool is built to give evidence for a conversation about support, not a case against anyone.
What's the difference between IT being understaffed and IT being a single point of failure?
Understaffed means there's too much work for the hours available. Single point of failure means that if one specific person is unavailable, for any reason, critical functions stop. A business can be adequately staffed for day-to-day demand and still have a severe single-point-of-failure risk, because nobody else can act on security incidents, vendor escalations or anything outside routine tickets. The two problems need different fixes, so it's worth knowing which one you actually have.
Doesn't this just mean I need to hire another IT person?
Not necessarily. Hiring is one option. A co-managed arrangement, where a partner backs up specific gaps such as after-hours monitoring, specialist escalation or a second set of administrative hands, closes most of the same risk without adding a full-time role. Which option makes sense depends on which domains score lowest and how much of the business depends on them, not on a general instinct that 'we need more IT'.
What does 'co-managed IT' actually mean?
Co-managed IT means an external partner works alongside your existing internal person or team rather than replacing them. Typically that covers the gaps an individual can't reasonably cover alone: after-hours security monitoring, escalation for specialist work like networking or identity, a second administrator with full access, and vendor relationship management. The internal person keeps day-to-day ownership and local knowledge; the partner fills in around them.
How is this different from a technical configuration audit?
A configuration audit checks whether specific settings, such as backup policy or conditional access rules, are correctly configured. This tool checks something upstream of that: whether the human arrangement responsible for maintaining those settings has the coverage, depth, time and escalation path to do it reliably, especially when something goes wrong or someone is unavailable. Both matter; they answer different questions.
My IT person handles everything fine day to day. Why would this matter?
Day-to-day competence and resilience under stress are different things. The gap usually isn't visible until the person is on leave, resigns, or a problem lands that's genuinely outside their depth, such as a security incident at 2am. By then it's too late to build the coverage that would have caught it. The value of scoring this now is finding the gap before an absence or an incident finds it for you.
Should I show my results to my IT person or to the business owner?
Either, or both. If you're the business owner, the results give you a structured, non-accusatory way to talk about resourcing with your IT person. If you're the IT person, the results give you evidence to take to the business about where you're exposed and what support would actually close the gap, rather than a vague request for 'more help'. It's designed to start a conversation, not settle one unilaterally.
What's the most common gap Frontrow sees in Australian small and medium businesses?
Two patterns show up repeatedly: nobody is watching security alerts outside business hours, and there is no documented, tested backup arrangement for when the primary IT person is unavailable. Both are cheap to fix relative to the risk they carry, and both are the kind of gap that stays invisible right up until the exact week it matters most, and by then it's a crisis rather than a fix.
How is this self-assessment validated?
Each scoring threshold reflects general IT service management and business continuity practice, with ASD Essential Eight cited where a specific control, such as MFA or patching, is directly relevant. The methodology is authored by Graeme Lodge (Managing Director), Daniel Brown (5x Microsoft MVP), and Sam Williams (Investor & Executive Consultant), drawing on Frontrow's experience co-managing internal IT teams across regional and multi-site Australian businesses.