woman with hand under chin looking worried

Does your organisation have a single point of failure?

Someone set up the website, the domain name and the email system years ago, whether that was a staff member, a volunteer or an external developer, and it worked, so nobody revisited it. The person who understood how it all connected either moved on, or is still there but is now the only one who knows. Either way, that’s a single point of failure sitting inside your organisation’s infrastructure.

The gap doesn’t show up until you need it to

Most organisations can tell you who manages day-to-day IT. Fewer can tell you who’s accountable for the domain name registration, who holds the login for the hosting account, or what happens if that person is unavailable, has left, or becomes difficult to deal with.

This rarely causes a problem while everything’s working. It surfaces when something changes, such as a staff transition, a dispute with a developer, an organisation wanting to move providers or a routine renewal that nobody has the login details for. At that point, what looked like a minor administrative gap becomes leverage someone else holds over your organisation.

Why it happens even in well-run organisations

Well-run organisations end up here too. It’s a sign of technology decisions made incrementally, by different people, at different times, without anyone stepping back to decide who should hold ultimate control. A website, a domain and an email system typically get set up separately, by whoever was handling each one at the time, and the documentation that would tie it all together never quite gets written.

The result is an organisation that’s quietly dependent on a single person, system or vendor, without that dependency ever having been a deliberate decision.

What proper oversight looks like

Closing this gap doesn’t require a large project. It requires knowing the answers to a short set of questions, and making sure the answers live somewhere other than one person’s memory.

Who is the domain name registered to, and who can access that account? Who holds the primary login for hosting, and is there a documented backup contact? If your current web developer or IT provider became unavailable tomorrow, could someone else pick up where they left off without starting again? Is any of this dependent on a personal email address rather than an organisational one?

None of these questions require deep technical knowledge to ask, and the answers are usually easy enough to find once someone takes responsibility for finding them.

Where this fits in a broader review

Access control and single points of failure are one part of what we look at in a Technology Governance review, alongside the wider question of whether your organisation’s technology decisions are connected to its goals. For organisations wanting a fuller picture, an IT Current State Assessment covers this alongside six other areas, from infrastructure to data management.

The organisations that handle this well aren’t the ones with the most technical staff. They’re the ones that treated ownership and access as something to document deliberately, rather than something to sort out later.

Get in touch if you’d like a hand finding these gaps in your own organisation.