The Economics of Lean & The Myth of the One-Person IT Department

The Economics of Lean & The Myth of the One-Person IT Department

Last week, I attended the Financial Planning Association of Colorado’s Annual Forum, where Michael Kitces presented research on a question every advisory firm eventually has to confront: what actually makes a financial advisor more productive?

The answer was notable for what was on the list.

It was even more notable for what was not.

Kitces Research identifies four primary drivers of advisor productivity: serving more affluent clients, having the confidence to price services appropriately, maximizing productive face time with clients, and building the right team structure. Technology, despite the amount of attention and capital devoted to it across the wealth management industry, did not make the list.

In fact, when Kitces Research compared annual spending on financial planning technology with revenue per advisor, it found no clear relationship between technology spending and productivity. Firms spending the most on planning technology even showed a slight decline in revenue per advisor in some cases, potentially because additional technology facilitated additional services that clients were not necessarily willing to pay more for.

That conclusion should make every RIA owner think carefully about what they are actually trying to accomplish with technology.

The goal is not more IT.

The goal is a more productive advisory firm.

Technology Is Infrastructure, Not the Product

There is an important distinction here.

Kitces Research is not saying technology has no value. Quite the opposite. The research found that revenue per employee increased from $250,000 to $310,000 between 2022 and 2024 among repeat survey participants, with improved operational efficiency and evolving technology allowing firms to generate more revenue without necessarily adding equivalent back-office headcount.

Technology creates leverage.

But leverage is not the same thing as value.

The client does not hire an RIA because its Microsoft tenant is exceptionally well configured. They do not refer their neighbor because the firm’s endpoint management platform has an elegant dashboard. They do not willingly pay an additional 20 basis points because the firm has six overlapping SaaS applications instead of four.

They hire an advisor for judgment, expertise, communication, and trust.

Technology should make those things easier to deliver.

That distinction matters because the traditional IT model often encourages exactly the opposite behavior: more tools, more complexity, more support capacity, more licenses, more management, and ultimately more overhead.

Given that, the better question is not, “How much technology can we deploy?”

It is, “What is the minimum technology infrastructure required to operate securely, compliantly, and efficiently without distracting the firm from the activities that actually generate value?”

That is a very different economic problem.

The Myth of the One-Person IT Department

One of the strongest findings in the Kitces report concerns team structure.

The most productive configuration in the study was the “1+2” model: one lead advisor supported by two staff members. The model provides enough leverage for the advisor to delegate work that does not require the advisor’s expertise, without introducing the coordination costs and “management tax” that begin to emerge as teams become larger.

There is an important economic principle underneath that finding: the productive advisor does not do every job.

Modern IT increasingly works the same way.

Twenty years ago, a small business might reasonably have hired an “IT person.” Today, even a relatively small RIA operates within a technology environment requiring several distinct areas of expertise. Cybersecurity must be monitored and maintained. Microsoft 365 and cloud infrastructure must be administered. Networks and devices must be managed. Regulatory and compliance requirements must be documented. And, inevitably, someone still needs to troubleshoot Outlook, reset passwords, provision laptops, and figure out why the printer stopped working.

The problem is that these are not interchangeable responsibilities.

A security administrator should not spend the afternoon troubleshooting a printer. A help desk technician should not be responsible for designing the firm’s cybersecurity architecture. And asking one internal employee to maintain deep expertise across security, cloud infrastructure, networking, compliance, and end-user support increasingly means asking one person to do several fundamentally different jobs.

The obvious solution would be to hire specialists.

For most small and midsized RIAs, however, that solution fails a basic economic test.

The firm may need the expertise of a security administrator, cloud administrator, network administrator, and support technician. It is unlikely to need 2,080 hours per year from each of them.

That distinction between access to expertise and ownership of headcount is where the economics change.

The same principle of leverage that Kitces identifies within productive advisory teams can be applied to the technology function supporting them. Instead of requiring the RIA to employ every technical role internally, a shared-services model allows specialized work to reach the appropriate specialist while routine issues remain with the appropriate support resource.

The firm gets the capabilities of a technology team without having to carry the economics of an entire technology department.

This is also where marginal cost matters.

Hiring the first internal IT employee may create substantial value. But as the firm attempts to cover each additional specialty internally, the marginal benefit of another full-time hire can quickly fall below the marginal cost of carrying that employee. The firm is no longer purchasing expertise when it needs it. It is purchasing 12 months of capacity in order to guarantee access to expertise periodically.

In effect, the difference becomes an insurance premium for labor.

ATG’s model approaches the problem differently. Maintain the security and compliance capabilities that must always be present. Maintain access to the specialized expertise the firm cannot afford to be without. Then bring human support capacity to bear when there is actually something requiring human support.

Access the roles. Don’t own the headcount.

Security Is Different

There is one area where “use it only when you need it” is the wrong strategy: cybersecurity.

You cannot install your controls after the breach.

For RIAs, that distinction has become considerably more important under the SEC’s amended Regulation S-P. The amendments require covered institutions, including SEC-registered investment advisers, to maintain written incident-response policies and procedures reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. Those procedures must include assessing the nature and scope of an incident, taking appropriate steps to contain and control it, overseeing service providers, and notifying affected individuals when sensitive customer information has been or is reasonably likely to have been accessed or used without authorization.

The practical implication goes beyond having an Incident Response Plan sitting on a shelf. An RIA should be able to demonstrate how the firm will continue operating and restore critical technology when an incident actually occurs. That means understanding which systems are mission-critical, where recoverable copies of customer information exist, who has authority to isolate compromised identities or devices, how communications continue if Microsoft 365 or another core platform is unavailable, how systems and data are restored, and how the firm validates that restored environments are safe before returning them to production.

This is where incident response begins to overlap with business continuity and disaster recovery. The IRP answers, “What do we do when an incident occurs?” A mature BCDR program answers the next questions: “What must remain operational? What can be unavailable, and for how long? Where does our data come back from? Who restores it? In what order? And have we actually tested that recovery process?”

Reg S-P also pushes that responsibility beyond the RIA’s own network. Covered institutions must maintain written policies and procedures for due diligence and monitoring of service providers, and the SEC has emphasized that firms may outsource functions but cannot outsource their ultimate compliance responsibility. A vendor saying that it “has backups” is therefore not the same thing as the RIA knowing the vendor’s recovery capabilities, escalation process, access to customer information, and role in a reportable incident.

Finally, firms must maintain written records documenting compliance with the amended Safeguards and Disposal Rules. That shifts cybersecurity from a collection of technical controls toward something much more defensible: controls, documented procedures, evidence, testing, and recoverability.The SEC gave larger entities until December 3, 2025 and smaller entities until June 3, 2026 to comply. In other words, for RIAs today, this is no longer an approaching regulatory requirement. It is the operating environment.

This changes the economics of IT.

Security, compliance, identity management, device management, monitoring, and incident preparedness are not discretionary support tickets. They are infrastructure.

They need to exist whether an employee calls the help desk that month or not.

Everything layered above that should face a much harder question:

Are we paying for an outcome, or are we paying simply to have somebody available?

Keep the Controls. Lose the Management Tax.

There was another Kitces finding that resonated.

The typical lead advisor spends only about 16% of their time in client meetings, or roughly seven hours per week. Productivity increases as client-facing time approaches 30% to 35%, or approximately 13 to 14 hours per week, before eventually plateauing.

The constraint, therefore, is not simply how many hours an advisor works. It is what those hours are being used for.

Every hour spent troubleshooting access to SharePoint, coordinating a laptop replacement, reviewing security alerts, chasing a vendor, figuring out why an employee cannot authenticate, documenting a control for an examiner, or determining whether an unusual login constitutes an incident is an hour that has been moved away from the highest-value activities of the firm.

This is where outsourced IT should function much like the external support described in the Kitces productivity model.

Kitces Research found that highly leveraged teams can benefit from centralized or outsourced resources for important needs that arise periodically but do not justify building permanent internal capacity.

That is remarkably close to how we think about IT at Adams Technology Group.

Maintain the infrastructure that must always be there.

Maintain the security controls that cannot wait.

Maintain the compliance evidence that regulators expect.

Then bring human support capacity to bear when there is actually something requiring human support.

The alternative is effectively paying an insurance premium for labor: maintaining excess capacity every month because someday the firm might need it.

More Technology Is Not the Objective

This also explains why technology spending by itself is such a poor predictor of advisory-firm productivity.

According to Kitces Research, the typical service team spends approximately $3,500 per advisor each year on financial planning software. Yet across spending levels, the study found no clear relationship between how much firms spent and how much revenue they generated per advisor.

More software does not automatically create more leverage.

More vendors do not automatically create better processes.

More IT staff do not automatically create better IT.

In some circumstances, they simply create additional fixed costs and additional things to manage.

The better technology strategy is often surprisingly boring.

Standardize the environment.

Secure identity.

Secure devices.

Protect data.

Monitor the controls.

Document them.

Test incident response.

Remove unnecessary applications and complexity.

And make sure somebody competent answers when something actually breaks.

ATG’s approach is built around precisely that foundation. Our Microsoft 365-native Zero Trust architecture focuses on Identity, Data, and Device, reinforced by controls such as identity threat detection, endpoint detection and response, security monitoring, and tested incident-response procedures. ATG has also obtained SOC 2 Type I attestation for the Security trust services criterion.

The point is not to make IT more visible inside an advisory firm.

It is to make the risk visible while making the technology itself increasingly invisible.

The Fifth Driver

Kitces’ four productivity drivers ultimately describe where an advisory firm’s scarce resources should go.

Work with clients who value the firm’s expertise.

Charge appropriately for that expertise.

Give advisors enough support to spend meaningful time with those clients.

Keep the organization lean enough that the support structure does not become its own source of inefficiency.

Technology should reinforce all four.

It should never become a fifth competing priority.

For an RIA, the ideal IT environment is therefore not necessarily the biggest technology budget, the largest internal team, or the longest list of applications.

It is the environment that is secure enough to protect the firm, disciplined enough to satisfy its regulatory obligations, simple enough not to create unnecessary overhead, and responsive enough to be there when something actually happens.

That is lean IT.

Not less protection.

Less waste.