Security

Fragmented IT: When International Growth Creates Security Gaps

avodaq

01. Oct 2026 | 3 min.

image

The Federal Criminal Police Office (BKA) recorded almost 334,000 cybercrime cases in Germany in its Bundeslagebild Cybercrime 2025 (Federal Cybercrime Situation Report). According to the German digital association Bitkom, cited in the report, cyberattacks caused €202.4 billion in damage. Companies whose IT has grown organically over the years and is run on a decentralised basis are particularly at risk. 

Felix Lange, Senior IT Consultant Infrastructure Security and Team Lead at avodaq

Felix Lange is Senior IT Consultant Infrastructure Security and Team Lead at avodaq. Since 2018, he has supported customers from a wide range of industries in modernising and developing their IT infrastructure.

In this interview, he explains why fragmented infrastructure is an underestimated risk and how companies can put their security on a solid footing without rebuilding everything from scratch.

Felix, picture this: six IT staff, sites across Europe, North America and Asia, and every branch running its own infrastructure that has grown over the years. Is that an exaggeration, or do you regularly come across scenarios like this?

There are plenty of companies that manage everything worldwide with one IT team based in Germany. On site, there’s usually just one admin, if that. But the infrastructure keeps evolving regardless. Shadow IT emerges wherever people work with IT and the team responsible for it is based in another country. It’s impossible for a company to keep tabs on all of that remotely. This is a particular issue for hidden champions – highly specialised, often family-owned market leaders – that centralise almost everything at headquarters.

In your view, what are the biggest challenges when a small IT team has to look after sites around the world?

Implementing and maintaining consistent IT standards across individual sites is incredibly difficult. IT often doesn’t know whether the security services are actually being used. Shadow IT includes things like unauthorised internet connections. If the IT department in Germany blocks something, local staff simply set up and use their own DSL lines. We saw exactly that happen with one customer. Their web filter was faulty and went unnoticed for quite some time because internet access wasn’t affected.

Modern technology makes it possible to gain visibility across all sites. However, this requires a cloud instance; otherwise, every system would have to be monitored individually.

Time differences are another challenge. On public holidays, for example, there’s no one from the  IT team on duty here, while business carries on as usual in other countries. One solution would be shift work and on-call duty. On-call duty should be as straightforward as possible: a single access point through which I can manage and control the security services.

What does a decentralised infrastructure like this cost a company, not just financially, but in terms of time and frustration too?

The costs of an organically grown, decentralised infrastructure can’t always be clearly quantified. The real question is: what could my team have been doing to prepare for the future instead of maintaining the existing environment? Admins are constantly working through tickets that take far longer than necessary because the basic information needed for troubleshooting is missing or has to be painstakingly gathered. They should be spending that time on modern technologies, automation, AI and requests from the business. Instead, the team is maintaining a legacy system that should have been retired long ago.

In any case, the costs are very high. But people often prefer not to look too closely.

‘The costs of an organically grown, decentralised infrastructure can’t always be clearly quantified. The real question is: what could my team have been doing to prepare for the future instead of maintaining the existing environment?’

According to the report, around 90% of reported ransomware attacks hit SMEs. How vulnerable are internationally operating companies with fragmented infrastructure?

Extremely vulnerable! Attacks are common in Europe too, but in Asia they’re far more frequent and intense. Attackers assume that security standards at overseas subsidiaries are much lower than at the German headquarters. The sites are interconnected, so the whole network is only as secure as its weakest link.

I wonder how two or three people are supposed to manage around 300 remote sites. Without a central solution, all of this has to be handled on site. It makes far more sense to secure the infrastructure itself, so that malware is never downloaded in the first place. That is exactly what products such as Cisco Meraki and Cisco Secure Access are designed for.

What is the best approach to take? Is there a typical starting point, or does it depend on the individual situation? Does the solution have to be big, expensive and all-encompassing from day one?

I’d take a phased approach. Depending on the maturity of the existing infrastructure, the phases may be longer or shorter. A typical starting point would be to first make site connectivity software-defined and then introduce an SSE (Security Service Edge) solution. These quick wins significantly improve security. Sites are connected intelligently and become more secure at the same time. The company can then govern site-to-site and internet traffic through a single security policy, reducing the effort required at the sites considerably.

How does the IT team’s day-to-day work change once a centralised solution is in place?

Modern platforms come with an API, which opens the door to automation. They include built-in monitoring that automatically tracks access, capacity, device health and more, presenting all this information in a clear dashboard.

Unified security policies also mean every site gets exactly the permissions it needs. Everything can be managed centrally, so there’s no need for highly specialised IT professionals on site; tech-savvy employees are enough.

‘Ideally, the hardware arrives, someone on site plugs it in and the configuration comes entirely from the cloud. No travel, no weeks of lead time.’

What advice would you give to an IT leader whose company is set to expand internationally over the next few years? When should they start factoring this in?

As soon as you notice that setting up a new site is placing a disproportionate burden on the IT team. At that point, every new branch takes up an unreasonable amount of time, but it doesn’t have to be that way. Ideally, the hardware arrives, someone on site plugs it in and the configuration comes entirely from the cloud. No travel, no weeks of lead time. It’s a huge advantage, and one that almost always pays off.

On top of that, a central cloud dashboard gives the IT team control over all sites. Firmware updates, troubleshooting, configuration and monitoring are all in one place. This saves an enormous amount of time and makes IT considerably more resilient.

So what would the ideal next steps look like?

The best thing is to talk first, take a look at the bigger picture and then start with a proof of concept. Our goal is to connect all of a customer’s sites – from the factory floor in Shanghai to the sales office in Munich – on a single secure, simple, future-proof platform.

Thank you very much for the conversation and the fascinating insights, Felix.