Control is Not Proximity: Why Your Best Engineer May Be Riskier Than Your Vendor

September 18, 2026 - by Eric Codorniz

Executive Summary

Boards have changed what they expect from CIOs, moving from operational yes-or-no questions to dollar-denominated ones, while the same organizations now need genuine depth across four disciplines they used to cover with one team. I challenge a default assumption here: that an employee offers more control than a vendor does, arguing that control is really about enforceability, since at-will employment carries no continuity obligation while a vendor contract can. I extend this into a practical operating model, a governance approach to third-party risk, and a measurement framework that closes the gap between what a status report says and what the business actually experiences, then close with a concrete 90-day plan and an open invitation to a complimentary Executive Diagnostic. This turns everyday IT operating model decisions into a vendor risk management question long before anyone calls it one.

Something changed in the boardroom over the last few years, and it wasn’t that boards got harder to please. They moved the goalposts, and most IT reporting, including how it accounts for third-party risk never moved with them. Gartner’s 2026 CIO Agenda survey, covering 2,501 CIOs and technology executives, found that only 48% of digital initiatives hit their stated business target flat year over year. That’s not a delivery problem. That’s a translation problem.

The old board questions all had yes-or-no answers: Is it up? Did we ship on time? Did we hold the budget? The new ones all have a number attached, and the number is in dollars: What did that spend earn us? What risk did we retire, in dollars? Where is AI actually paying off, and where isn’t it? Uptime didn’t stop mattering. It became an assumption, and nobody gets credit for an assumption; you only get blamed when it breaks.

None of that is controversial. Every CIO I sit across from can already connect their decisions to revenue growth, operational resilience, workforce productivity, risk reduction, and competitive advantage – the five things a board already owns. The CIOs who consistently make that connection stop being asked to justify spend and start getting invited into the room where strategy gets set. But here’s the trap. Delivering all five now requires genuine depth in four separate disciplines, and most organizations are trying to do it with one team.

Four Disciplines are Now Critical, and None of Them is Anyone Else’s Job

Run, AI, data, and security all became critical at the same moment, and running infrastructure, the thing IT used to get credit for, is now table stakes. Nobody gets a bonus for uptime anymore. ISC2 surveyed more than 16,000 practitioners and found skills gaps jumped from 44% to 59% in a single year, while staffing shortages actually eased over the same period. Sit with those two numbers together: we’re getting better at filling seats and worse at putting in the right expertise in them. That’s not a headcount problem; it’s a depth problem, and the two get solved very differently.

It isn’t only security. The World Economic Forum’s Future of Jobs Report 2025, drawn on more than 1,000 employers representing 14 million workers, found that 39% of workers’ core skills are expected to change by 2030.

What Depth Actually Costs to Own

Run the arithmetic, and it gets concrete fast. Covering a single security seat 24/7/365 takes roughly five people once you account for leave, training, and escalation. At the median analyst wage of $124,910, that’s close to $750,000 a year for one seat in one discipline, and the US Bureau of Labor Statistics projects 29% growth in that role through 2034, so whatever it costs today, it costs more next year. Start multiplying that across every discipline you now need depth in, and the model breaks fast.

Why Do We Believe We Have More Control Over an Employee Than a Vendor?

I’d ask you to actually sit with that question rather than answer it right away. Picture your best engineer – the one who knows why the firewall rules are the way they are resigning on a Friday afternoon. What do you actually have? Two weeks of courtesy, if you’re lucky. No continuity obligation. No named substitute. No compensation for the six months it takes to rebuild what just walked out the door. Now picture a vendor missing that same commitment, and think about what recourse you’d have instead.

I’ll name the conflict of interest here directly: we’re a managed services firm, and we have a clear commercial interest in this argument. That’s exactly why everything behind it comes from peer-reviewed research rather than our own client stories.

The Control We Think We Have

An employee gives you loyalty, context, and institutional memory that no contract creates — I’m not dismissing that. But at-will employment is the legal default in 49 states, which means that relationship contains, by construction, zero continuity obligation. That’s not a criticism of anyone; it’s simply what the arrangement is. Everything on the vendor side of the ledger-defined scope, service levels, continuity and substitution obligations, audit and exit rights, financial consequences for missed commitments – is a term you can negotiate this quarter, not someday.

Here’s the part that should bother all of us. World Commerce and Contracting surveyed 937 organizations and found service levels rank fourth most important contract term, yet don’t appear anywhere in the top ten most negotiated. We know they matter. We spend our negotiating energy on liability caps instead. If you’re worried a heavier contract poisons a relationship, the research says the opposite: a meta-analysis spanning 149 studies and more than 33,051 interorganizational relationships found contractual governance positively correlated with trust. Writing it down is what lets the relationship work, not what threatens it.

I think of a mid-sized company whose entire integration layer between its ERP system and everything else lived in one engineer’s head; a very good engineer, nothing written down. He left for a better offer, which was entirely reasonable. It took the company the better part of three months to get back to where it had been on the Friday he resigned: no notice obligation beyond courtesy, no named backup, no enforced documentation requirement, and no financial consequence. Compare that to a similar scope of work contracted out with substitution and continuity terms actually written into the agreement – a named lead, a named backup, a documentation obligation, and a service credit if coverage lapsed. About two years in, that partner’s lead engineer left too. The company never found out until it came up as a routine personnel note in a quarterly review. The vendor didn’t have better people or lower turnover. What they had was a contract that made turnover their problem instead of the client’s.

One limit on this argument: it’s about enforceability, not about people. Your good employees are not the problem. The absence of a contract with them is.

Leaders Inside, Doers Outside

This is fundamentally an IT operating model decision. The model isn’t “outsource everything.” It’s a relatively small internal team with real technical depth whose job is to lead and govern, plus specialists who execute. Keep architecture and technology strategy, vendor and service integration governance, security risk ownership (not the SOC itself), data governance and AI policy, business relationship shaping, and commercial and contract ownership inside. Contract out service desk and end-user support, server, network, and cloud operations, security monitoring and response, data engineering and analytics build, AI development and agentic workflow build, and application maintenance.

This isn’t a new idea invented to sell services. MIT Sloan published the nine core capabilities of an IT function back in 1998, drawn from interviews across 61 organizations, and four of those nine are supplier governance. That’s been the academic consensus for more than 25 years. One guardrail: research spanning 328 outsourced and in-house processes found the single factor separating outsourcing that works from outsourcing that disappoints is retained technical expertise. The inside column has to be real engineers with real opinions; staff it with contract administrators instead, and the model fails.

Third-party Risk is Now the Cyber Conversation

One trend line matters here more than any other. Verizon’s DBIR shows third-party involvement in breaches climbing from 15% to 30% to 48% across 2024, 2025, and 2026 – same publisher, same methodology. Your security posture is now mostly a statement about other companies’ security posture. You can run an excellent internal program and still get hit through somebody you contracted with. Your board already knows this: in April 2026, the National Association of Corporate Directors handed every director this question: who are our riskiest vendors, and how is our organization managing that risk?

The Measurement Problem Hiding Underneath All of This

Even a well-governed vendor estate can look perfect on paper while the business quietly suffers. A report can say 99.95% availability, 94% of tickets closed within SLA, and zero severity-one incidents, while a new hire waits six days for system access and sales needs three systems to produce one quote. Nobody logs a ticket for a workaround – they just route around the pain, which means the worse an experience gets, the quieter your reporting looks. That’s why boards quietly discount IT reporting: every one of them has met someone living through the workaround while reading a report that says everything is green.

The fix is holding every vendor to one experience standard instead of eight separate green dashboards. Take one measure and baseline it properly: time from quote requested to quote delivered. Pull 30 recent quotes and time them; that’s an afternoon of work, sales already tracks it, and your board already cares about it. Anybody can name an experience metric. Almost nobody can tell you how they’d establish the before, and without a before, you don’t have a measurement; you have an assertion. I’ll be honest about the limits of this argument too: there’s no neutral, disinterested statistic on experience-level-agreement adoption; every source, including ours, is selling something. What I can point to is SIM’s 2025 study of more than 700 IT executives, which found customer satisfaction is now the number one criterion for judging a CIO, while cost control fell to 22nd.

The One Page You Lead With

Everything downstream of a funding or measurement conversation comes down to a single artifact: one page with five elements. The claim, in one sentence; something like, “we moved $4 million of run spend into change spend and cut quote turnaround from nine days to four.” The evidence: two measures, with a baseline, a current value, and the dates both were taken. The risk retired, priced in dollars, insurance terms, or regulatory exposure, never in severity levels. One specific decision, with a date attached. And what you’ll report again next quarter, using the same two measures.

Two of those five elements do most of the work. The decision matters because most of what gets sent to a board is an update, and updates don’t need a board – boards are constituted to decide, not to be briefed. And the repeat measure matters because reporting the same two numbers three quarters running is what stops a board from quietly discounting your reporting.

I’ve watched pricing go wrong the same way with a cloud migration priced as a straight cost reduction. The business case promised 30% out of the infrastructure line, and the board approved it on that basis. Eighteen months later, the infrastructure line was flat, or slightly up, because two estates were running in parallel and new specialists had been hired. The project got called a failure. But the migration had actually worked; release cycles got shorter, and month-end closed faster. None of that had been in the business case, so none of it counted. It wasn’t a bad decision. It was priced against the wrong thing.

What to do Before Your Next Board Meeting

None of the first thirty days requires budget, a platform, or a vendor. Days 1 to 30: build one inventory – every application, its owner, its cost, the revenue it touches, and every vendor with access to your data. Days 31 to 60: sort today’s work into what your team must own and what a specialist does better, and name one owner for one outcome. Days 61 to 90: at your next renewal, add experience levels, AI use disclosure, audit trail, and exit rights, then write the one page. Renewal is the only moment you get to add terms without reopening the entire agreement, and most organizations let it pass every year without touching it.

If you take one thing from all of this, take the question I opened with: why do you believe you have more control over an employee than a vendor? If you can answer that with a contract instead of an opinion, the exercise has already paid for itself.

To know more, watch the On-Demand Webinar – How CIOs Turn Tech Investments into Board-Level Wins.


About the Author

eric codorniz

Eric Codorniz

Co-Founder of Synoptek

Eric Codorniz is the Co-Founder of Synoptek. He drives PE-led value creation conversation across diligence, integration, and portfolio transformation. As an entrepreneur and leader with over 25 years of Business Technology & Consulting experience, Codorniz has launched multiple businesses and, most recently, had a successful exit from a Global IT Management & Consulting firm headquartered in Southern California.

Frequently Asked Questions

Because control feels like proximity, someone sitting down the hall seems easier to manage than someone under contract. But proximity isn't enforceability. At-will employment carries no continuity obligation by default, while a vendor contract can carry service levels, substitution rights, audit rights, and financial consequences for missed commitments. The vendor relationship is often more governable precisely because it's written down.

No. The model is a small, high-depth internal team that leads and governs, plus specialists who execute the work. Keep architecture, security risk ownership, vendor governance, and data and AI policy inside; contract out day-to-day operations, monitoring, and build work. Research is clear that this only works if the internal team retains real technical expertise, not just contract administration.

Usually one of three things: the page asks the board to be updated instead of to decide; the number is still "IT's number," with no other executive in the room owning it; or the board hears it for the first time in the meeting instead of in the one-on-ones that should have happened beforehand.

Start with something the business already feels and already tracks somewhere; quote turnaround is a good first choice. Pull 30 recent examples and time them; that's an afternoon of work. Without a "before," you don't have a measurement; you have an assertion, and a board can tell the difference.

Five things, and nothing more: the claim in one sentence, two measures with baseline, current value, and dates, the risk retired in dollars or regulatory terms, one specific decision with a date, and the same two measures you'll report again next quarter.

Spend the first 30 days building one inventory of every application, its owner, its cost, and every vendor with data access - no budget required. In days 31 to 60, sort your team's work into what only they should own versus what a specialist does better, and prove the model on one business outcome. In days 61 to 90, use your next contract renewal to add the terms this piece describes, since renewal is the only point you can add them without reopening the whole agreement.