Straits of It: Hidden Chokepoints and Whiplash IT

🌊 The Chokepoint We Don’t See
The Strait of Hormuz is a name you have been hearing frequently over the last few months, but not one that you likely heard a lot about before the current conflict started between the United States and Iran. It is geographically a very small body of water that controls a very large portion of the flow of global energy, roughly one-fifth of global oil in 2024. When that narrow passage is disrupted, the effects do not remain local. They ripple through energy prices, financial markets, supply chains, and household budgets.
I just finished the book Chokepoints by Edward Fishman, and it opened my eyes to a recurring pattern, enormous volumes of value pass through a small number of shared channels - when the channels are open they are mostly invisible in our daily lives - but when they are constrained they become chokepoints. Every organization has them and they shape how well vision becomes strategy, how efficiently strategy becomes action, and further how efficient that action is in returning value on investment. In most organizations many of those channels flow through IT.
🚢 Every Organization Has a Strait
The issue comes down to visibility. When you want to ship oil through the strait from the sponsoring department’s perspective two things may seem well-defined - where the oil is coming from and where it needs to be. But determining how it gets there requires the people who understand the Strait—its weather, channel depths, traffic patterns, capacity, and changing risks. Inside an enterprise, marketing may identify a need to present existing customers with relevant products and opportunities based on their history.
This seems like a pretty straightforward use case - however, there are straits or chokepoints that no matter the organization the value will have to flow through. Consider the work of the Identity and Access Management team, which is often brought in as a final step in the process, and a variation of “can’t you just give them access” is not all that uncommon. In reality, while Marketing may define the cargo and destination, that value must travel through shared enterprise channels—including identity, data, integration, security, architecture, and vendor governance. Identity determines who may enter the enterprise environment, what they may do, what sensitive data they may see, which actions require stronger verification, and how quickly access can be removed when a person, contractor, role, or vendor relationship changes. In other words there are a lot of moving parts, and a lot of potential chokepoints. These are beginning-of-process questions that should be answered before a solution is selected. However, a lot of times in business a solution is committed to, before any thought of what channels, or chokepoints need to be passed has occurred, and you end up with ripple effects throughout the enterprise.
⚠️ Whiplash IT
Imagine for a moment if you airdropped a cargo-laden ship into the middle of the Strait of Hormuz, expecting that this new ship would not disrupt any of the other ships, would be allowed to pass through without any issues, and that you would be able to guarantee a delivery date. This would be complete chaos risking the safety and schedules of the air-dropped ship and every other ship in the lane. When a solution is chosen and dropped onto IT’s plate this is exactly what happens - I call it “Whiplash IT” where everyone has no choice but to manage chaos, or react to it. The difference is subtle but important: “We need this platform or tool” is air-dropping a ship. “We need to solve X because of Y by Z—what is the best way to move it through the channels?” allows the teams who know those channels best to take control of transport and delivery.
đź§ From Chaos to Anticipatory
A former CIO I worked with stated that every IT organization has four possible levels of maturity. Chaotic, the level in which it’s every person for themselves, little to no prioritization, and almost no guarantee of success. This is peak air-dropped ship into the middle of the strait. Reactive is the second level and things are not a lot better, but most IT organizations get to this level and not much further, there is still lots of whiplash IT and shadow IT with reactive levels - ships are still being air-dropped into the strait but now at least there’s some form of early warning, or the battle-hardened crew has just gotten very good at managing the chaos. Teams often deliver real value but they don’t have time to monitor the shipping lanes, watch the weather, double-check maintenance records, make sure tankers aren’t overloaded, or that politics prevent a path, meaning they get caught in a nearly inescapable loop from chaotic to reactive.
The third level is proactive, and IT needs help with getting there. To effectively leave reactive and avoid loops back into reactive and chaos, enterprise leaders and technology teams must invest in great architecture review processes and governance. They need to establish shared visibility across the enterprise with IT teams into which problems are needing to be solved, not the solutions different organizational silos think are needed. IT teams must also have the time and resources to map the channels, watch the weather, establish shipping rules, figure out clearances, escorts, traffic rules, capacity and to set standards enabling safe and efficient passage.
Back to the Strait analogy a ship of certain tonnage can safely go through this part of the strait at this time under these conditions, but if the conditions change maybe we need more ships that are lighter, or a different route around the strait altogether. Architecture governance does not decide which cargo matters; that belongs to business and portfolio leadership. Its job is to determine how—and occasionally whether—that cargo can move safely through shared channels without blocking everything behind it. Great architecture review and governance is a partnership that exists for enablement of business strategy.
The fourth level of maturity is called anticipatory. At this level information is shared in a timely and relevant fashion. Resources are not so constrained that all anyone can do is react. Systems of record are up-to-date and well-maintained, data is clean and very ready for AI and automation, processes are well-defined and efficient. At this level IT is not just making sure capital investments can pass through the straits: it’s actively planning routes, identifying threats, finding new channels, updating architectural standards to continually increase the speed of business. At this level what was once a recurring chokepoint is now a value pipeline moving capital investments in technology, data, and intellectual property straight to customers and allowing profit to flow.
Make no mistake: chokepoints are costly, not just at the gas pump, but as everyday risks in business. The 2024 CrowdStrike outage offered a public reminder of how shared technical dependencies create correlated risk: CISA cited Microsoft’s estimate that the faulty update affected 8.5 million Windows devices worldwide. The issue was not simply that a change failed. It was that a widely deployed component sat in front of critical operations across countless organizations with limited visibility and no value mapping back to the customer side.
🗺️ Clear the Channel Before Buying the Ship
So how does an organization move from Chaos to Anticipatory? It starts with communication and commitment. Bring IT to the table before a solution is selected. Engage with security, data, architecture, and IT subject matter experts while the business need is being defined, not after a go-live date or a vendor has been selected. Second, defining the outcome should always precede defining a tool - there will always be someone to sell a solution, don’t buy it until you have fully defined the problem to solve. State what must change, who benefits, what data is involved, success measures, and the consequences of failure all before looking at any solutions. Define explicitly any exception. Nonstandard routes are always possible but make them the exception not the rule and explicitly acknowledge and accept the risk from these exceptions. Finally treat enterprise visibility as a leadership problem. IT can only manage the traffic it can see. A current service map, clear ownership, portfolio transparency, and early communication are not nice-to-haves - they are essential to eliminating chokepoints.
A quick summary:
Bring IT into the conversation before selecting a solution.
Define the outcome before defining the tool.
Make nonstandard routes and accepted risks explicit.
Treat enterprise visibility as a leadership responsibility.
Every department has ships to move: a new customer experience, a regulatory obligation, a workforce initiative, a financial process, a product launch, an AI use case, or a market commitment. IT’s role is not to prevent those ships from sailing. Its role is to help the enterprise understand and safely navigate the straits they all share.
The organization moves faster when leaders engage IT before committing to the vessel, the route, and the arrival date. That gives the enterprise time to assess capacity, reuse what already exists, protect critical data, sequence competing work, and make risk decisions deliberately. A mature architecture function does not slow strategy down. It helps strategy arrive safely.
Before your next major initiative is announced, ask: Have we defined the need—or have we already purchased a ship and asked IT to clear the channel?
What’s next? In the next articles, I will explore why so many IT organizations remain trapped in reactive mode, how a modern Architecture Review Board can improve flow rather than create bureaucracy, and why CMDB/CSDM work is not documentation for its own sake—it is the map required to see and manage the enterprise system
