Top Heavy at the director level. Multiple promotions of directors to Chief. CTO, CDO, CISO etc. Most of whom don't have practical application or technical expertise for the groups they direct.
This would be fine if there were appropriate controls in place organizationally or appropriate management who could oversee the technical aspects of the departments for them. Sad to say customer service, desktop, access management, infrastructure\server support and computer operations have had no managers for a minimum of 1 year each. Because of this divisions have arisen between those groups, work is not done efficiently, or as a team, and staff get no credit or interim pay for the managerial tasks they have had to pick up.
The lack of technical comprehension from above also leads to staff not being valued or recognized for the technical expertise in their groups and also to the formation of class distinctions – not only from the group aspect but also from a leadership perspective. For one “Chief” there was a clear favoritism among the groups he had no business trying to manage. None the less, he would only listen to the group who he perceived as being more technical. This perception being derived from the fact that one team worked on more critical equipment\projects or perhaps represented themselves better in person. What he did not know is that group was perceived as the weakest group by prior management and directors. This group, which is paid at a premium, gets away with leaving systems down for weeks (cafeteria pos server), deleting active user accounts(multiple times), changing permissions in live environments without testing (causing loss of access to production systems), and corrupting the exchange database(not having email for 20% of our exchange users for over a week). No discipline or consequences for any of these failures.
Hands down the culture of the IT department is one that fosters silos and division. Department heads push the work their teams should be doing off to teams that are already overloaded and have weak managers who don't push back. Clinical applications cutting off the physician help line with no warning and forcing those calls to the helpdesk is a great example. Network team will activate a port but not plug in devices to the network because “this is not their job.” Security team does nothing but write policy, they do not mitigate virus issues even though this is the one application server they own. They didn’t even manage the project tasked to them to update antivirus throughout the enterprise. Better yet, when they were warned of malware that was phishing for user’s bank account information, they turned a blind eye. Nothing was done until accounts were compromised. Project management’s antiquated idea that calling a weekly meeting and asking people if a task is done needed to change 10 years ago. Perhaps some project managers with technical aptitude could be useful in 2016?
Clinical staff run the show and have never heard the word no. No consequences for their lack of planning projects. IT staff is told to jump at last minute moves, installations, projects. Users aren’t required to justify equipment needs hence users will have 3-4 printers in tiny office spaces or have multiple pcs or laptops with no business justification. If policy was enforced around these items - perhaps some decent pay raises or additional staff could be provided.