Frontrow Technology

Free tool · 5 minutes · Internal IT

INTERNAL IT CAPACITY —
GAP CHECK.

In most Australian small and medium businesses, IT is one person. Score whether the arrangement can actually carry what the business now depends on, across coverage, capability, workload, security ownership and escalation, in five minutes.

20 questions · 5 domains

Internal IT Capacity Gap Check

Score whether your internal IT arrangement can actually carry what the business now depends on, across coverage, capability, workload, security ownership and escalation. Answer for how things really work today, not how they're supposed to work.

Domain 1

Coverage and continuity

What happens when your IT person is on leave, gets sick, or resigns — and whether more than one person can act on anything critical.

  • If your primary IT person took two weeks of leave with no contact, what would happen?

    Source: General IT service continuity practice

  • How well documented are the passwords, procedures and system configurations your IT person relies on?

    Source: General IT service management knowledge-management practice

  • How many people could take over core IT administration if your primary person resigned tomorrow?

    Source: General workforce key-person risk practice

  • Does your IT person actually take annual leave without being contacted about work issues?

    Source: General workforce sustainability practice

Domain 2

Depth of technical capability

Whether the person carrying IT has genuine depth in identity and security, networking and cloud administration, and time to keep that current.

  • How confident is the current arrangement in identity and access administration — conditional access, MFA, privileged roles?

    Source: ASD Essential Eight Strategy 2 — Multi-factor Authentication and Restrict Administrative Privileges

  • Who has genuine depth in networking — firewalls, VPN, multi-site connectivity — beyond basic troubleshooting?

    Source: General IT capability and staffing practice

  • How is Microsoft 365 and Azure tenant administration handled day to day?

    Source: Microsoft Learn administration and role-based access guidance

  • Does the person responsible for IT have dedicated time to keep their skills current with Microsoft's platform changes?

    Source: General workforce development practice

Domain 3

Demand and workload

The balance between reactive ticket load and planned work, whether a backlog is growing, and whether after-hours work has become the norm.

  • Roughly what share of your IT person's week goes to reactive tickets and firefighting versus planned work?

    Source: General IT service management capacity practice

  • Is there a backlog of IT projects or improvements that never get started because there's no time?

    Source: General IT service management capacity practice

  • How often does IT work spill into evenings, weekends or personal time?

    Source: General workforce sustainability and burnout-risk practice

  • When a project is scoped — a migration, a rollout, a system change — does it actually finish on the agreed timeline?

    Source: General IT service management capacity practice

Domain 4

Security ownership

Who owns patching, MFA enforcement, security alerts and incident response, and whether anyone is watching outside business hours.

  • Who owns patching across servers, workstations and cloud services, and how is it verified?

    Source: ASD Essential Eight Strategy 3 — Patch Applications and Patch Operating Systems

  • Is MFA enforced across all accounts, and does anyone actually watch security alerts when they fire?

    Source: ASD Essential Eight Strategy 2 — Multi-factor Authentication

  • Is there a documented plan for what happens in a suspected security incident, such as a compromised account or ransomware?

    Source: ASD Essential Eight; Notifiable Data Breaches scheme incident response expectations

  • If a security alert fires at 2am on a Saturday, does anyone see it before Monday morning?

    Source: General managed detection and response practice

Domain 5

Escalation and vendor management

Whether there is a defined path when something is beyond the internal team, and who owns licence, contract and vendor relationships.

  • When something is genuinely beyond your IT person's expertise, is there a defined next step?

    Source: General IT service management escalation practice

  • Does your organisation have a working relationship with the vendors it depends on, or does contact only happen during a crisis?

    Source: General vendor management practice

  • Who owns visibility over software licences and contract renewal dates?

    Source: General IT asset and licence management practice

  • If your IT person left tomorrow, would the business know which vendors, contracts and support agreements are in place?

    Source: General key-person risk and business continuity practice

This is an indicative self-assessment based on how the person completing it sees the current arrangement. It is not an audit of any individual's performance. For a verified view, Frontrow Technology offers a capacity and coverage review run alongside your existing IT person or team.

What the check covers

Five domains. One capacity picture.

Domain 1

Coverage and continuity

In most small and medium Australian businesses, IT is one person. That is often fine day to day. The risk shows up the moment that person is unavailable — planned leave, unplanned illness, or resignation — and nobody else can act on something urgent. Documented procedures and a genuine backup arrangement are what stand between a routine absence and a genuine outage.

Domain 2

Depth of technical capability

Microsoft's platform changes constantly. Identity, security and cloud administration are specialist areas in their own right, and a generalist carrying all of them, with no time set aside to keep current, will fall behind quietly, usually without anyone noticing until something goes wrong.

Domain 3

Demand and workload

An internal IT function that spends all its time firefighting never gets to the planned work that would reduce the firefighting. The busier reactive work gets, the less capacity there is to fix the causes, and the backlog compounds.

Domain 4

Security ownership

Security ownership needs to be explicit, not implied. 'The IT person handles security' usually means patching happens when there is time, alerts pile up unread, and nobody is watching at 2am on a Saturday. Attackers do not work business hours.

Domain 5

Escalation and vendor management

Every internal IT arrangement eventually hits something beyond its expertise — a compromised account, a niche system, a specialist project. What matters is whether there is already a defined next step, or whether the business is inventing an escalation path for the first time under pressure.

Frequently asked questions

What owners and internal IT people actually ask.

Is this tool trying to say my IT person isn't good enough?

No. This scores the arrangement, not the person's competence. The person carrying IT is very often the one filling this out, and the most common honest result is that they are doing a genuinely good job day to day, with no backup behind them anywhere else. That's a resourcing gap, not a skills gap. The tool is built to give evidence for a conversation about support, not a case against anyone.

What's the difference between IT being understaffed and IT being a single point of failure?

Understaffed means there's too much work for the hours available. Single point of failure means that if one specific person is unavailable, for any reason, critical functions stop. A business can be adequately staffed for day-to-day demand and still have a severe single-point-of-failure risk, because nobody else can act on security incidents, vendor escalations or anything outside routine tickets. The two problems need different fixes, so it's worth knowing which one you actually have.

Doesn't this just mean I need to hire another IT person?

Not necessarily. Hiring is one option. A co-managed arrangement, where a partner backs up specific gaps such as after-hours monitoring, specialist escalation or a second set of administrative hands, closes most of the same risk without adding a full-time role. Which option makes sense depends on which domains score lowest and how much of the business depends on them, not on a general instinct that 'we need more IT'.

What does 'co-managed IT' actually mean?

Co-managed IT means an external partner works alongside your existing internal person or team rather than replacing them. Typically that covers the gaps an individual can't reasonably cover alone: after-hours security monitoring, escalation for specialist work like networking or identity, a second administrator with full access, and vendor relationship management. The internal person keeps day-to-day ownership and local knowledge; the partner fills in around them.

How is this different from a technical configuration audit?

A configuration audit checks whether specific settings, such as backup policy or conditional access rules, are correctly configured. This tool checks something upstream of that: whether the human arrangement responsible for maintaining those settings has the coverage, depth, time and escalation path to do it reliably, especially when something goes wrong or someone is unavailable. Both matter; they answer different questions.

My IT person handles everything fine day to day. Why would this matter?

Day-to-day competence and resilience under stress are different things. The gap usually isn't visible until the person is on leave, resigns, or a problem lands that's genuinely outside their depth, such as a security incident at 2am. By then it's too late to build the coverage that would have caught it. The value of scoring this now is finding the gap before an absence or an incident finds it for you.

Should I show my results to my IT person or to the business owner?

Either, or both. If you're the business owner, the results give you a structured, non-accusatory way to talk about resourcing with your IT person. If you're the IT person, the results give you evidence to take to the business about where you're exposed and what support would actually close the gap, rather than a vague request for 'more help'. It's designed to start a conversation, not settle one unilaterally.

What's the most common gap Frontrow sees in Australian small and medium businesses?

Two patterns show up repeatedly: nobody is watching security alerts outside business hours, and there is no documented, tested backup arrangement for when the primary IT person is unavailable. Both are cheap to fix relative to the risk they carry, and both are the kind of gap that stays invisible right up until the exact week it matters most, and by then it's a crisis rather than a fix.

How is this self-assessment validated?

Each scoring threshold reflects general IT service management and business continuity practice, with ASD Essential Eight cited where a specific control, such as MFA or patching, is directly relevant. The methodology is authored by Graeme Lodge (Managing Director), Daniel Brown (5x Microsoft MVP), and Sam Williams (Investor & Executive Consultant), drawing on Frontrow's experience co-managing internal IT teams across regional and multi-site Australian businesses.