Skip to main content

Why IT Consulting Can Be a Vicious Triangle - and 5 Steps to Escape the Pain

Dennis Drogseth

Enterprise Management Associates (EMA) is looking to extend the reach of its consulting practice, and we'll be soliciting your inputs on your priorities. (The URL for participating in our 5-minute survey is at the end of this blog.) But before you do, I'd like to share some of what we've learned from our work in the past.

Lesson 1: Try to avoid the vicious triangle of IT consulting by learning how to stand in the middle

Just about everyone's heard of the Bermuda Triangle. But the IT Consulting Triangle, though arguably far less elusive, is not nearly as well known. This triangle has three clear corners, each of which can generate its own mini hurricanes.

Let's call the first one process consulting or best practices. This can be very valuable, as it can lead to support from best practices ranging from the IT Infrastructure Library (ITIL) to Six Sigma to the IT Balanced Scorecard to fill in the blank.

The second corner of the triangle, which often comes with a premium price, is organizational consulting. This, too, can be of value, especially as IT often needs to reshape itself in the face of shifting business priorities.

And the third corner is systems integration in all its variations — where actual software and other solutions for managing and optimizing IT are selected, configured and deployed. There's no question that this is often essential.

So what's wrong with this picture?

The problem comes when investments are made across all these areas without a common awareness of interdependencies. Organization, process and technology are indeed not separate discussions in IT, but closely interrelated. This is ever more the case given the dynamic options associated with cloud and the pressures for agile and digital transformation. Investing in advice in each of these areas can be essential. But doing so without common oversight of how they interrelate can lead to a lot of expensive wheel-spinning and sometimes destructive decisions that contradict each other.

Lesson 2: Embrace the need for documenting what's true and what's not

My favorite example here, and one I frequently cite, is a case where EMA required 20 stakeholder interviews in support of a strategic, cross-domain technology initiative. At first the CIO tried to dismiss this. "I've sent out an email," he said. But we insisted and did the interviews. Afterwards that same CIO not only accepted the value of what he'd learned, but wanted us to do 20 more.

The lesson here is that what's really going on within anything more than a mom-pop IT organization in terms of priorities, issues, favored toolsets, and processes (or lack of them) is often full of surprises. And it's rarely consistent across stakeholders and roles. Building a strategy to support all of operations, or all of ITSM, or all of IT (how often do development, security and operations see eye to eye?) requires understanding the human dimensions of what's going on, as well as the technology deficits that are keeping you from going forward.

Lesson 3: Find your true maturity level(s)

I put this in the plural because your IT maturity level can vary across organizations within IT, sometimes in surprising ways. For instance, I once interviewed a development team that pushed a configuration management system with associated automation into development using SCRUM, because development, not operations, was too siloed. Finding out which IT teams relevant to your initiative are ready to fly and which aren't is one of the key ingredients to success. And of course, doing this, depends in large part on honoring Lesson 2.

Lesson 4: Only invest in generic technology winners if your IT organization is also generic

Adopting the right technologies, especially when it comes to managing and optimizing IT business services, is rarely a simple, linear scorecard decision. Generic "winners" are only right for generic IT organizations. But then, happily, I've never encountered a generic IT organization or a generic IT professional for that matter.

Try to find what fits your environment, your skill sets, and your unique needs — which isn't always necessarily what just scored the highest on "Dancing with the Stars."

Lesson 5: Invest in a staged approach to a strategic initiative, both in selecting your technologies, and in integrating them into your environment

EMA, and I'm sure we're not alone, has a ladder with clearly defined steps for going forward with major strategic initiatives — one that can apply to everything from operational and even digital transformation, to analytics, to DevOps, to ITSM-centric initiatives in service modeling and dependency mapping. But whatever staged approach you take, be sure to include dialog, process, technology, communication (a lot of communication!) and listening (a lot of that as well) as you go forward and evolve. Strategic change is not likely to make everyone happy. But needless alienation can not only cause individual pain, it can bring down the effectiveness of the entire organization — leaving digital transformation up to Penn & Teller and not up to you.

I'd like to practice what I just preached and learn from you!

To participate in our 5-minute survey just click here.

Image removed.

Hot Topics

The Latest

Ask most IT leaders about their biggest concern with AI and you'll hear the same answer: hallucinations ... Today, however, the conversation has shifted ... As organizations move beyond chatbots and experiments, they are increasingly deploying AI agents that perform multi-step tasks. These systems retrieve documents, query databases, call APIs, generate reports, write code, and make recommendations. The issue is not whether the model can reason. The issue is whether the organization can see, verify, and govern the decisions being made along the way ...

While organizations want to take control of their telemetry, building telemetry pipelines from scratch can be a very daunting, complicated task, even when leveraging open-source standards like OpenTelemetry. It requires specialized knowledge across distributed systems, data engineering, and security. This fragmented approach across systems causes higher operational costs; it puts a strain on resources and reduces efficiency as teams have to work with different interfaces and processes ...

For decades, enterprise networks were designed around a simple assumption: work happened inside the office. Applications lived in centralized data centers, employees connected through internal infrastructure, and security focused on protecting the perimeter that surrounded everything ... But the way organizations operate today bears little resemblance to that environment. Cloud platforms host critical applications, employees connect from homes and airports as often as they do from offices, and partners collaborate through shared systems that exist far beyond corporate walls. In short, the corporate network no longer resembles the environment it was designed to protect ...

As an analyst who researches how IT organizations design, build, and operate their networks, I find that network data is a constant source of pain. Network teams struggle with data quality, fragmentation, authority, access, and trust. And these issues undermine everything they try to do. Here are the numbers: Only 45% of network teams are completely confident in the accuracy of their network source of truth, which documents the intent of their network ...

The 2026 Global Data Center Survey from Uptime Institute reveals an industry navigating workforce constraints, escalating outage expenses, even as rising costs remain the top concern for management teams ...

The next observability gap may not be in the code. It may be under the rack. That sounds strange until you think about how AI incidents actually feel in the middle of an investigation ... The application dashboard may be accurate. It may also be stopping at the wrong boundary. AI systems depend on software, but they also depend on a dense physical stack: racks, power paths, thermal margin, maintenance activity and, in many environments, liquid cooling. Those physical dependencies can change slowly before they look like a software incident ...

Certificate expiration is the rare outage you can see coming. Every TLS certificate carries the date it stops working, so the moment it will begin breaking connections is knowable in advance. That's what makes an expired certificate such a frustrating way to lose a service. What's changing now is how often that date comes around ...

Enterprises operate different combinations of workloads across cloud, hybrid and multicloud environments. For business-critical workloads, teams need to consider monitoring and observability early so they can detect health issues, investigate failures, and understand operational impact. Organizations place workloads on cloud platforms based on a combination of technical requirements, economics, existing dependencies, organizational standards, and business priorities. Their monitoring priorities therefore depend on what they operate and where those systems run. Those priorities will not look the same for every organization ...

Top-performing businesses prioritize data-driven decision making, enabling leaders to move from intuition and gut feel towards evidence-based judgment. But that judgment is only sound when the data underpinning decisions is accurate. With incident management, data accuracy is particularly important. Long-term revenue, customer trust, and operational stability depend on high-quality data that enables teams to quickly identify and address the root cause of major incidents. Against this backdrop, governance becomes a critical endeavor to ensure the right data drives the right action ...

In MEAN TIME TO INSIGHT Episode 26, Shamus McGillicuddy, VP of Research, Network Infrastructure and Operations, at EMA discusses network compliance ... 

Why IT Consulting Can Be a Vicious Triangle - and 5 Steps to Escape the Pain

Dennis Drogseth

Enterprise Management Associates (EMA) is looking to extend the reach of its consulting practice, and we'll be soliciting your inputs on your priorities. (The URL for participating in our 5-minute survey is at the end of this blog.) But before you do, I'd like to share some of what we've learned from our work in the past.

Lesson 1: Try to avoid the vicious triangle of IT consulting by learning how to stand in the middle

Just about everyone's heard of the Bermuda Triangle. But the IT Consulting Triangle, though arguably far less elusive, is not nearly as well known. This triangle has three clear corners, each of which can generate its own mini hurricanes.

Let's call the first one process consulting or best practices. This can be very valuable, as it can lead to support from best practices ranging from the IT Infrastructure Library (ITIL) to Six Sigma to the IT Balanced Scorecard to fill in the blank.

The second corner of the triangle, which often comes with a premium price, is organizational consulting. This, too, can be of value, especially as IT often needs to reshape itself in the face of shifting business priorities.

And the third corner is systems integration in all its variations — where actual software and other solutions for managing and optimizing IT are selected, configured and deployed. There's no question that this is often essential.

So what's wrong with this picture?

The problem comes when investments are made across all these areas without a common awareness of interdependencies. Organization, process and technology are indeed not separate discussions in IT, but closely interrelated. This is ever more the case given the dynamic options associated with cloud and the pressures for agile and digital transformation. Investing in advice in each of these areas can be essential. But doing so without common oversight of how they interrelate can lead to a lot of expensive wheel-spinning and sometimes destructive decisions that contradict each other.

Lesson 2: Embrace the need for documenting what's true and what's not

My favorite example here, and one I frequently cite, is a case where EMA required 20 stakeholder interviews in support of a strategic, cross-domain technology initiative. At first the CIO tried to dismiss this. "I've sent out an email," he said. But we insisted and did the interviews. Afterwards that same CIO not only accepted the value of what he'd learned, but wanted us to do 20 more.

The lesson here is that what's really going on within anything more than a mom-pop IT organization in terms of priorities, issues, favored toolsets, and processes (or lack of them) is often full of surprises. And it's rarely consistent across stakeholders and roles. Building a strategy to support all of operations, or all of ITSM, or all of IT (how often do development, security and operations see eye to eye?) requires understanding the human dimensions of what's going on, as well as the technology deficits that are keeping you from going forward.

Lesson 3: Find your true maturity level(s)

I put this in the plural because your IT maturity level can vary across organizations within IT, sometimes in surprising ways. For instance, I once interviewed a development team that pushed a configuration management system with associated automation into development using SCRUM, because development, not operations, was too siloed. Finding out which IT teams relevant to your initiative are ready to fly and which aren't is one of the key ingredients to success. And of course, doing this, depends in large part on honoring Lesson 2.

Lesson 4: Only invest in generic technology winners if your IT organization is also generic

Adopting the right technologies, especially when it comes to managing and optimizing IT business services, is rarely a simple, linear scorecard decision. Generic "winners" are only right for generic IT organizations. But then, happily, I've never encountered a generic IT organization or a generic IT professional for that matter.

Try to find what fits your environment, your skill sets, and your unique needs — which isn't always necessarily what just scored the highest on "Dancing with the Stars."

Lesson 5: Invest in a staged approach to a strategic initiative, both in selecting your technologies, and in integrating them into your environment

EMA, and I'm sure we're not alone, has a ladder with clearly defined steps for going forward with major strategic initiatives — one that can apply to everything from operational and even digital transformation, to analytics, to DevOps, to ITSM-centric initiatives in service modeling and dependency mapping. But whatever staged approach you take, be sure to include dialog, process, technology, communication (a lot of communication!) and listening (a lot of that as well) as you go forward and evolve. Strategic change is not likely to make everyone happy. But needless alienation can not only cause individual pain, it can bring down the effectiveness of the entire organization — leaving digital transformation up to Penn & Teller and not up to you.

I'd like to practice what I just preached and learn from you!

To participate in our 5-minute survey just click here.

Image removed.

Hot Topics

The Latest

Ask most IT leaders about their biggest concern with AI and you'll hear the same answer: hallucinations ... Today, however, the conversation has shifted ... As organizations move beyond chatbots and experiments, they are increasingly deploying AI agents that perform multi-step tasks. These systems retrieve documents, query databases, call APIs, generate reports, write code, and make recommendations. The issue is not whether the model can reason. The issue is whether the organization can see, verify, and govern the decisions being made along the way ...

While organizations want to take control of their telemetry, building telemetry pipelines from scratch can be a very daunting, complicated task, even when leveraging open-source standards like OpenTelemetry. It requires specialized knowledge across distributed systems, data engineering, and security. This fragmented approach across systems causes higher operational costs; it puts a strain on resources and reduces efficiency as teams have to work with different interfaces and processes ...

For decades, enterprise networks were designed around a simple assumption: work happened inside the office. Applications lived in centralized data centers, employees connected through internal infrastructure, and security focused on protecting the perimeter that surrounded everything ... But the way organizations operate today bears little resemblance to that environment. Cloud platforms host critical applications, employees connect from homes and airports as often as they do from offices, and partners collaborate through shared systems that exist far beyond corporate walls. In short, the corporate network no longer resembles the environment it was designed to protect ...

As an analyst who researches how IT organizations design, build, and operate their networks, I find that network data is a constant source of pain. Network teams struggle with data quality, fragmentation, authority, access, and trust. And these issues undermine everything they try to do. Here are the numbers: Only 45% of network teams are completely confident in the accuracy of their network source of truth, which documents the intent of their network ...

The 2026 Global Data Center Survey from Uptime Institute reveals an industry navigating workforce constraints, escalating outage expenses, even as rising costs remain the top concern for management teams ...

The next observability gap may not be in the code. It may be under the rack. That sounds strange until you think about how AI incidents actually feel in the middle of an investigation ... The application dashboard may be accurate. It may also be stopping at the wrong boundary. AI systems depend on software, but they also depend on a dense physical stack: racks, power paths, thermal margin, maintenance activity and, in many environments, liquid cooling. Those physical dependencies can change slowly before they look like a software incident ...

Certificate expiration is the rare outage you can see coming. Every TLS certificate carries the date it stops working, so the moment it will begin breaking connections is knowable in advance. That's what makes an expired certificate such a frustrating way to lose a service. What's changing now is how often that date comes around ...

Enterprises operate different combinations of workloads across cloud, hybrid and multicloud environments. For business-critical workloads, teams need to consider monitoring and observability early so they can detect health issues, investigate failures, and understand operational impact. Organizations place workloads on cloud platforms based on a combination of technical requirements, economics, existing dependencies, organizational standards, and business priorities. Their monitoring priorities therefore depend on what they operate and where those systems run. Those priorities will not look the same for every organization ...

Top-performing businesses prioritize data-driven decision making, enabling leaders to move from intuition and gut feel towards evidence-based judgment. But that judgment is only sound when the data underpinning decisions is accurate. With incident management, data accuracy is particularly important. Long-term revenue, customer trust, and operational stability depend on high-quality data that enables teams to quickly identify and address the root cause of major incidents. Against this backdrop, governance becomes a critical endeavor to ensure the right data drives the right action ...

In MEAN TIME TO INSIGHT Episode 26, Shamus McGillicuddy, VP of Research, Network Infrastructure and Operations, at EMA discusses network compliance ...