Straits of IT: Why Most IT Organizations Never Escape Reactive Mode

Page content

Navigating the Digital Straits

Narrow constrained channels are not necessarily a problem. The Strait of Hormuz is a high capacity corridor that provides a far more efficient route for Gulf products to world markets than other realistic alternatives. The same geography that makes the passage strategically sensitive also makes it economically valuable. If it were not the shortest or most useful route, so much trade would not depend on it.

đź§  Narrow Isn’t The Problem

Narrow channels, scarce resources, constraints and potential chokepoints are not the issue - chaos is the issue. A laser derives power precisely by being narrowly focused. Considerable engineering—and considerable energy—goes into creating and maintaining that narrow coherence. Its constraint is not a defect; it is what makes the system useful.

The key qualification is that the advantage is conditional: the corridor creates immense global value when navigation remains sufficiently predictable. IT departments create immense value for their organizations when navigation remains sufficiently predictable.

The difference between a high-value corridor and a dangerous chokepoint, then, isn’t simply capacity. It is coherence. How early does information arrive? How well is demand communicated? Can competing priorities be seen before they collide? Are dependencies understood before commitments are made? Does everyone navigating the channel share enough of the same picture to coordinate their movement?

đź“– The Reactive/Proactive Pendulum

Referring back to article one in this series, The Strait of Hormuz maintains value more often in recent history than not because of rigorous organization of all traffic into it. Well-defined shipping lanes and routing rules were established in 1968, creating defined lanes, directions, and separation between opposing traffic. Those structures have helped high-value traffic move through the constrained corridor for decades. Even amid periods of significant regional tension, value continues to flow through the Strait. The constraint remained. What changed was the coordination of movement through it.

Now for a fun experiment: chart what happens to oil prices with each news story about escalation or de-escalation in the region. You may find yourself experiencing a bit of whiplash.

This is what happens in many organizations - the IT department gets very good at managing from crisis to crisis while the overall organization does not mature in a way that reduces crisis. This may look like an IT organization solidly into the proactive operating mode when in reality the IT department matures and makes inroads into proactivity in between crisis, but the crisis force them back into reactivity, at a potentially high cost.

The area of cybersecurity is particularly impacted by this chaos. A Sophos report of 5000 cybersecurity professionals across 17 countries reported 76% of respondents felt fatigue or burnout constantly, frequently, or occasionally ( https://www.sophos.com/en-us/blog/report-addressing-cybersecurity-burnout-in-2025) Compare that to the AMA (https://www.ama-assn.org/practice-management/physician-health/national-physician-burnout-survey) report among physicians where 45.2% reported burnout. I am not going to pretend that these are universal numbers, or even that they are equateable, but the juxtaposition should cause you to pause and have some concern - burnout has a tangible impact on your organizations reputation, hiring ability, and bottom line.

That number matters, but not simply because cybersecurity is stressful. Cybersecurity teams operate at the intersection of nearly every organizational communication failure. A business unit introduces a new application. A vendor gets access. An employee changes roles. Infrastructure changes. A vulnerability is discovered. A merger adds an unfamiliar environment. A project makes a deadline commitment before security is consulted. Individually, none of those necessarily represents chaos. When information about them reaches the narrow channel late, incomplete, or all at once, the organization converts potentially manageable work into reactive demand.

The cybersecurity team responds. The incident closes. The vulnerability gets patched. The exception gets approved. Everyone moves on.

Until the next ship arrives at the strait. And on and on the pendulum swings from reactive to proactive and back. The IT organization often improves measurably and matures with each iteration – Crisis → Response → Stabilization → Proactive Improvement → Uncoordinated Change → New Crisis – BUT do the surrounding communication channels?

You may even have asked yourself

“We’ve invested millions in IT. We hired good people. We implemented ITIL. We added security tooling. Why are we still fighting fires?”

The answer too often is you let the tail wag the dog. When local commitments repeatedly dictate enterprise architecture, the tail is wagging the dog. A deadline becomes an architecture decision. A vendor selection becomes an integration requirement. A departmental preference becomes an enterprise dependency. By the time IT sees the traffic, much of the route has already been decided.

🔍 Big Organizations Still Get Stuck in the Strait

The problem is that the communication and decision pathways around IT often do not mature at the same rate. A new priority is announced. A vendor is selected before dependencies are understood. An executive commitment creates an immovable date. A “small” departmental change enters a shared platform, identity model, data flow, or integration channel without a common view of the traffic already there.

SSouthwest Airlines’ December 2022 disruption illustrates the difference. Severe winter weather triggered the event, but weather alone didn’t explain the difficulty recovering. As cancellations multiplied, the volume of scheduling work exceeded the processes designed to absorb it, forcing increasing amounts of manual intervention. Southwest’s own review also found that information and processes weren’t moving effectively across the operational groups trying to recover the network.

The airline ultimately reduced daily departures from roughly 4,000 to 1,500 for several days simply to reset the network. Its response included technical upgrades and additional surge capacity—but also changes intended to improve how planning, operations, and technology worked together.

That distinction matters. This wasn’t simply a technology problem or simply an operations problem. The failure emerged at the interfaces between them. Operational conditions changed faster than information, decisions, processes, and technology could remain aligned. Technology eventually became the visible constraint, but the conditions producing that constraint extended well beyond IT.

The U.S. Department of Transportation later cited 16,900 cancelled flights, more than two million stranded passengers, and a $140 million civil penalty—the largest such penalty in DOT history at that time. DOT also noted that Southwest had to provide more than $600 million to passengers.

Southwest didn’t suddenly become an unsophisticated organization in December 2022. Its technology didn’t suddenly become isolated from the rest of the enterprise, either. The storm created extraordinary traffic and exposed what happens when organizational demand and technical capacity lose coherence under load.

Google’s 2024 DORA research found that constantly shifting organizational priorities hurt both productivity and employee well-being. Perhaps more importantly, good leaders and solid documentation weren’t enough to cancel out the damage caused by that instability. This is because it suggests something uncomfortable: you cannot tool your way out of organizational incoherence. Culture and communication failures, unstable priorities, unclear decision rights, and fragmented visibility are not tooling problems

In other words, the technical organization can invest in ITIL, security tooling, new platforms, automation, and better incident response—yet still be repeatedly pulled back into reactive work if new demands enter without stable priorities, clear decision rights, or cross-functional visibility.

đź§  Why “Work Harder” Makes the Strait Worse

Effort does not equal effectiveness. Too often, busyness becomes a proxy for productivity. Some of the most awe-inspiring moments in sports—a Hail Mary dropping into a receiver’s hands or a step-back three hitting nothing but net—look almost effortless in the moment. What we don’t see are the years of disciplined practice that made the moment possible.

Effort should never be a proxy for efficacy.

The sad truth is the more effective IT becomes at heroic recovery, the easier it is for the enterprise to keep producing conditions that require heroics. There’s no grand capitalistic conspiracy behind that either - it is just plain human nature, the rescue is visible, while the work that would prevent the rescue—portfolio discipline, earlier intake, demand management, service mapping, capacity planning, architecture review, and cross-functional decision-making—is slower, less dramatic, and easier to postpone.

Think about your last major technology initiative. When did IT learn about it?

When the business problem was identified?

When possible solutions were being explored?

After the vendor was selected?

After the contract was signed?

Or when somebody needed an integration, firewall rule, identity connection, security review, data feed, or production date?

The later your answer, the more reactive your IT organization is being forced to become—regardless of how mature the IT department itself may be.

đź’¬ The Missing Harbor Master

If narrow isn’t the problem, widening the channel isn’t necessarily the answer. The Strait needs coordination before traffic arrives. IT does too.

That requires a place where business priorities, architecture, security, dependencies, capacity, and technology decisions meet before commitments become constraints.

Most large organizations already have—or have tried to have—something designed to do exactly that.

Unfortunately, it has earned a famously bad reputation.

Next: The Architecture Review Board—and why the thing everyone loves to hate may be the harbor master your Strait has been missing.

Sharpstone Notes

If this kind of thinking is useful, stay in the loop.