Every IT Team Has a Joe | Ep 195
Show notes
Interested in a pen test? Visit securit360.com.
Every organization has a Joe. He is the long tenured engineer or admin who built half the environment, maintains the other half, and keeps most of it in his head. Everybody depends on him and nobody wants to challenge him.
Spencer and Tyler break down key man risk in IT, drawing on hundreds of internal pen tests across law firms, banks, credit unions, manufacturing, municipalities, and SaaS organizations.
In this episode:
- Why tribal knowledge is a security risk, not just an operations problem
- How word of mouth process handoffs turn into a game of telephone
- The reason remediations stall for an extra 30 days
- Shadow IT that originates inside the IT team
- Privilege creep and the single account that owns the environment
- When Joe's resistance to change is the correct call
- Cross training that does not add more work to Joe's plate
- Incentives, clear ownership, and update deadlines that actually stick
- Separating fact gathering from decision making so seniority does not win by default
This is not a knock on senior admins. It is a look at the risk that accumulates when one person carries everything, and what IT leaders can do about it.
All of our content can be found at Offsec.blog. Interested in a pen test? Visit securit360.com.
Blog: https://offsec.blog/
Youtube: https://www.youtube.com/@cyberthreatpov
Twitter: https://x.com/cyberthreatpov
Follow Spencer on social ⬇
Spencer's Links: https://spenceralessi.com
Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.