Every business of a certain size has one. The IT person — maybe the whole department is one person — who's been there for two decades, built half the network with their own hands, and can tell you which switch port feeds the warehouse scanner just from memory. Nobody wrote it down because nobody had to. He knows.
He's also somewhere in his sixties now. And one of these years, he's going to retire.
When he does, he doesn't just take a desk plant and a going-away cake with him. He takes the only working map of your network, the reason your fire panel still passes inspection, the login to a vendor account nobody else has touched since 2019, and the institutional memory of "why we built it that way" for a dozen decisions nobody else was in the room for. What's left behind is a business that finds out, usually during an outage, that "one of my guys handles that" was never actually a plan.
This Warning Is Almost 20 Years Old
It's tempting to treat this as a fresh problem. It isn't. In September 2007, the National Association of State Chief Information Officers (NASCIO) published a survey called, fittingly, State IT Workforce: Here Today, Gone Tomorrow? Forty-six states responded. The findings should sound familiar to any CEO today.
Census data at the time showed that 60.6 percent of the state government workforce was age 40 or over, compared to 47.4 percent in the private sector — a workforce visibly older than the businesses around it, concentrated in the baby boomer generation. When NASCIO asked state CIOs what share of their IT staff would become eligible to retire within five years, the average answer was 27 percent. Eighty percent of states said they were already struggling to recruit new IT employees. Nearly 61 percent said they were not confident they could promote existing staff to fill the shoes of the people retiring. And when asked if they had an actual contingency plan for it, 65 percent said no.
Some states told NASCIO they were already re-hiring their own retired employees back as contractors to keep aging systems running — people the report described as having "unique knowledge of systems and applications that is not widely available in today's marketplace." NASCIO's own conclusion was blunter: future outsourcing to fill these gaps "may mean business outsourcing to the private sector, use of supplemental staffing services, or re-hiring retired employees on a contractual basis who may be the only people with intimate knowledge of these systems." That was the fallback plan in 2007. For a lot of businesses, it still is.
That report is now old enough to have a driver's license. The retirement wave it warned states about has largely already happened in the public sector — and the same demographic math applies to every private business that built its IT function the same way: hire one capable generalist, let them grow into "the guy who knows everything," and never get around to writing any of it down. The wave didn't skip small and mid-sized businesses. It just hasn't made the news, because nobody surveys them the way NASCIO surveyed the states.
The Replacement Market Got Harder, Not Easier
Here's what makes 2026 a worse time for this problem than 2007: even if you go looking for a replacement, you're hunting in a market that doesn't have one to spare — for a job that's gotten dramatically more complicated in the meantime.
Cybersecurity Ventures puts the number of unfilled cybersecurity jobs globally at 3.5 million as of 2025, with more than 750,000 of those openings in the United States alone. That's up from roughly one million openings in 2013 — 350 percent growth in a little over a decade — and the figure has held steady rather than closing. Experienced cybersecurity professionals are, in the research firm's words, operating in a "near-zero unemployment marketplace," even as broader tech hiring has cooled.
Layer cloud on top of that and the picture gets tighter. ISC2's 2025 Cybersecurity Workforce Study found that cloud computing security is now the second most commonly cited skills need among security teams worldwide — 36 percent of organizations flagged it, up 6 points from the year before, trailing only AI. And it's not just a hiring problem; it's a knowledge problem inside the workforce that already exists. Just 34 percent of cybersecurity professionals told ISC2 they have significant knowledge of cloud security. Fifty-three percent said they have some. Thirteen percent said they have none at all. Meanwhile Gartner projects that 90 percent of organizations will be running a hybrid cloud strategy by 2027 — meaning nearly every business is about to depend more on cloud infrastructure at the exact moment the people qualified to secure it are the scarcest resource in the industry.
CompTIA's own research tells a matching story from the hiring side: the imbalance between the skills companies need and the skills available has kept cybersecurity at the top of the list of hardest gaps to close, year over year. Facing that reality, more organizations are choosing to train the people they already have rather than compete for people who don't exist in the numbers needed — a rational response, but one that does nothing to solve the underlying shortage.
Why "One of My Guys Handles That" Doesn't Work Anymore
In 2007, or even 2015, it was plausible for one sharp, dedicated IT generalist to genuinely cover a small or mid-sized business: keep the servers up, manage the network, handle the help desk, and glance at antivirus alerts often enough to catch something obvious. That world is gone.
Today the same business is running workloads across multiple cloud platforms, fielding phishing attempts built with AI, meeting compliance obligations that didn't exist a few years ago, and getting probed by automated attack tools around the clock — not just during business hours. No single person, no matter how good, reasonably covers network engineering, systems administration, help desk, cloud architecture, identity management, and active security monitoring at the depth each one now demands. Something always gets the leftover attention. Historically, in businesses this size, that something is security — because it's the one job that only shows its cost when it's already too late.
"One of my guys handles that" was never really a security program. It was one person, splitting attention across five jobs, hoping nothing serious happens on the days they're focused elsewhere. That was a manageable risk when the job was simpler and the person doing it wasn't approaching retirement. It's a much bigger bet today.
The Hybrid Answer: Keep the Relationship, Outsource the Depth
None of this means the fix is firing your longtime IT person and buying an enterprise security stack you don't have the staff to run. For most businesses, the more realistic — and more affordable — fix is a hybrid model: keep the local relationship and institutional knowledge for the things that genuinely benefit from a person who knows your business, and hand the specialized, always-on disciplines to outside teams built to do nothing else.
This is the same shift Gartner is describing when it says hybrid cloud will cover 90 percent of organizations by 2027 — businesses aren't choosing all-in-house or all-outsourced, they're deliberately splitting the workload to wherever it's actually handled best. Applied to staffing rather than infrastructure, the same logic holds: your internal person (or small team) stays the relationship owner and the first call for day-to-day support, while the deep, specialized, never-sleeps functions move to a partner who does that one thing at scale.
Managed Detection and Response Is the Clearest Example
Nowhere is the gap between "someone glances at it" and "someone is actually watching" clearer than cybersecurity monitoring. Managed Detection and Response (MDR) is exactly what it sounds like: a dedicated security operations team, watching your environment continuously, whose entire job — not a fifth of their job — is noticing something wrong and acting on it immediately. Not logging a ticket. Not flagging it for Monday. Isolating the affected device, killing the malicious process, and calling you, often within minutes of an alert firing.
Compare that to the realistic alternative in a business without it: alerts accumulate in an inbox or a dashboard nobody has time to check between everything else on their plate, until either nothing bad happens and it feels like money saved, or something does happen and it's discovered days later. Given that 3.5 million cybersecurity jobs sit unfilled globally and most existing security professionals rate their own cloud security knowledge as partial at best, building that always-on capability internally isn't a realistic option for the vast majority of businesses — the people to do it well simply aren't available to hire at any reasonable price. Renting that capability from an organization built around it is, for most companies, the only version of "real" security monitoring that actually exists.
"The upcoming exodus of state IT employees appears to be certain and imminent... tough questions still remain: Who will replace the IT management and technical expertise? How will the existing IT workforce be transformed to meet the demands?" — NASCIO, 2007
Almost two decades later, those are no longer future questions. They're the ones every CEO should be asking about their own organization this quarter.
Questions Worth Asking Before It's Someone Else's Emergency
You don't need a NASCIO-scale survey to find out where you stand. A short, honest conversation with whoever runs your technology will tell you most of it:
- If our IT lead left tomorrow, what would we lose — and how would we even find out? If the honest answer involves the word "eventually," that's your answer.
- Who is actually watching for threats after 5 p.m. and on weekends? And is "watching" a person accountable for taking action, or a dashboard nobody's assigned to check?
- What percentage of how our systems actually work exists only in one person's head? Passwords, vendor relationships, "why we set it up that way" — none of it should live in exactly one place.
- Do we have a current, written inventory of our environment that a stranger could pick up on day one? Most businesses that answer honestly say no.
- When did we last test our incident response plan with someone other than that one person in the room?
None of these questions require replacing anyone or spending a fortune. They require an honest inventory of where the risk actually sits — which is exactly the kind of assessment a vendor-neutral outside advisor is built to provide, because we have no stake in whether the answer points toward keeping something in-house or moving it out.
Where Carrier Hub Fits
This is the same bridge-building role Carrier Hub plays between IT teams and the C-Suite more broadly (a dynamic we've written about before) — except here the translation isn't about a single vendor decision, it's about the shape of your entire technology and staffing strategy. We're not an MSP and we don't run a security operations center ourselves. What we do is sit down with your business, map out where the real key-person risk lives, and use our vendor-neutral position — backed by tools like AVANT's Pathfinder analysis platform and relationships with more than 250 vendor partners — to identify which functions genuinely benefit from staying in-house and which ones belong with a specialized MDR, cloud, or managed services partner who does that one job better than any generalist could.
Because our advisory work is funded by vendor commissions rather than client fees, there's no cost to finding out where you stand before you have to find out the hard way.
The Bottom Line
The IT retirement wave isn't a future risk. It's a documented, nearly 20-year-old prediction that has already worked its way through public-sector IT departments and is now working its way through every business that built its technology function around one irreplaceable person. What's changed since 2007 isn't whether this happens — it's how much harder the job has gotten to backfill, and how much more expensive the mistake of not planning for it has become.
You don't have to solve all of it this quarter. You do have to know where you stand. If you're not sure, a free technology analysis is a good place to start — no commitment, no sales pitch, just a clear picture of what would happen the day your most important technology relationship walks out the door.
Carrier Hub is an independent, vendor-neutral technology advisor serving SMBs and enterprises across connectivity, communications, and operations. Our advisory services are free to clients. Sources: NASCIO, State IT Workforce: Here Today, Gone Tomorrow? A National Survey of the States (September 2007); ISC2, 2025 Cybersecurity Workforce Study; Cybersecurity Ventures, 2025 cybersecurity jobs data; CompTIA, IT Industry Outlook 2025; Gartner hybrid cloud adoption forecast as cited by ISC2.