Blog

2026.08.27

Overseas IT Staff Shortage — 4 Structures for Your Plant

Overseas IT Staff Shortage — 4 Structures for Your Plant

“If one of the expats takes on IT alongside their day job, we can manage for now.” When companies come to us about the information systems at their overseas sites, the conversation almost always opens from that assumption. But over the past few years, two things have shifted at once — the local talent market and the capacity of head office to send people out. Having no dedicated IT person at an overseas site is no longer a temporary vacancy. For a great many Japanese manufacturers, it has become the baseline condition. This article deliberately sets aside the question of what maintenance actually costs and focuses on the one that comes before it: who is actually going to run this.

For what maintenance and operations actually cost and how to structure the contract, see our breakdown of business system maintenance costs. For what to monitor and how to choose the tooling, see our guide to system monitoring in factories. What we cover here is the organisational question — how to design the structure at a subsidiary that has no one to run those mechanisms day to day. We are writing for executives and plant administration teams at Japanese head offices, and for the managers who run administration at sites in Thailand and the wider ASEAN region.

Why “just have one of the expats cover IT” is getting structurally harder

Information systems at overseas sites have long been held together by goodwill and improvisation. Someone who happened to know a bit about IT back in Japan gets posted abroad and ends up handling PC procurement, network questions and the help desk for the production management system. This is not an unusual arrangement at all.

The problem is that the conditions that made it work are eroding. Business Engineering, together with the Deloitte Tohmatsu Institute of Strategy, published the “2026 Survey on IT Adoption at Japanese Companies Operating Overseas” (January 2026, 660 valid responses). The top IT and DX challenge was “a shortage of people,” cited by about 60% of respondents — and it has now ranked first for three years running. Second was “insufficient use of advanced technologies such as AI” at 41.4%. In other words, the talent shortage is not a swing of the business cycle. It has settled in as a structural condition.

The same survey found that 51.2% of companies said IT at their overseas sites needed to be “strengthened significantly” and another 40.7% said “strengthened somewhat” — more than nine in ten acknowledge the need. The list of things that must be done keeps growing while the people to do them keep thinning. That is where most companies stand today.

There is a further shift that tends to go unnoticed: the composition of the expatriate cohort itself has changed. In the same survey, the most common answer for the share of local nationals among managers at department-head level or above was “50 to 99%,” at 38.4%; including companies that are 100% localised, the figure reaches 42.4%. At close to a majority of companies, local nationals already make up more than half of the management layer at these sites. When the pool of Japanese expatriates you can lean on is shrinking, “have one of the expats cover it” starts to fail on simple arithmetic.

Hiring locally does not automatically solve it

The obvious alternative is to hire a dedicated IT specialist locally. That is not simple either. Writing about the reality at Thai subsidiaries, IIJ Global Solutions Thailand notes that people who can handle cloud and infrastructure work are in limited supply and are constantly being fought over in the recruitment market. The result, they observe, is that many companies cannot staff a dedicated IT role at all, and someone in general affairs or accounting picks it up as a side duty.

What exactly is wrong with a side duty? Nothing to do with the person’s ability. Because they have a primary job, their time inevitably tilts toward fixing whatever has stopped working. As the same source points out, preventive operations and monitoring tend to slip down the list. Checking that backups are being taken, applying OS and application updates, reviewing logs, auditing accounts — none of these are urgent, so they get pushed behind month-end close and reporting season.

And head office cannot see any of this. During any period without an incident, the report reads “no particular issues.” Updates may have stalled and the backup restore may not have been tested for years, and the report will look exactly the same. When you assess the IT setup at an overseas site, it is worth remembering that zero incidents is not necessarily a good sign.

The point at which this surfaces most sharply is the handover between expatriates. Postings have fixed terms, so whoever has been covering IT on the side rotates out every few years. What actually gets handed over is usually the PC supplier and a few vendor contacts. How the network is configured, what runs on which server, when the licences expire — that information tends to survive neither in writing nor in conversation. The successor spends their first several months simply working out what exists. The gap repeats with every rotation. Read the other way round, the most natural moment to revisit the whole structure is the day the next rotation is confirmed.

What “no IT owner” actually looks like when it surfaces

Discussions about structure drift toward the abstract, so it is worth laying out how the problem actually shows up. This is also territory where alarmism is easy, so we will keep facts and interpretation separate.

As a matter of fact, the “2026 Survey on Corporate IT Utilisation” conducted in January 2026 by the Japan Institute for Promotion of Digital Economy and Community (JIPDEC) with the cooperation of ITR found that 45.8% of organisations overall had been hit by ransomware — roughly one company in two. By sector, manufacturing was the highest at 57.1%, well above the overall average.

How to read that figure calls for care. There is no single reason manufacturing stands out. More environments now connect production equipment to the information network; a lot of equipment cannot be stopped, which makes update windows hard to find; and there are intrusion routes that run through supply chain partners. Several factors are likely overlapping. What every one of them has in common, though, is that the outcome turns on whether someone is tending the systems day to day. Applying updates, spotting suspicious traffic, reviewing access rights — none of it happens unless somebody looks regularly.

There is a second issue, less dramatic but a heavy load on the site: the hours during which anyone is available to respond. IIJ Global Solutions Thailand also raises the risk of operational stoppages caused by Thai public holidays and substitute holidays announced at short notice. The Thai government sometimes designates a substitute holiday at the last minute, and the calendar drifts out of alignment with head office in Japan. Japan working while the Thai side is out — or the reverse — happens many times over a year. In a one-person setup, capacity drops to zero the moment that person is away.

The same article quotes the concern that comes up again and again — “we have no IT person on site, so we worry about what happens if something goes wrong.” That worry exists even with no incident on the books. And as a motivation for redesigning the structure, that “if something goes wrong” scenario is in fact the most important one.

How it surfacesWhen it tends to happenWhat a side-duty setup produces
Delayed security updatesNo window to update terminals and servers tied to production equipmentUpdates stall for years and vulnerabilities stay open
Backups in name onlyBackups run, but a restore has never been attemptedYou discover the restore fails only during the incident
Key-person dependencyConfiguration details and vendor contacts live in one person’s headThe information is lost when they repatriate or resign
Gaps at night and on holidaysThai public and substitute holidays do not match the head-office calendarResponse stops entirely once that one person is away
Deferred decisionsNobody in-house to consult during normal operationsUpdate and replacement decisions slip by years

To avoid a misreading, these risks do not carry equal weight everywhere. A site with a few dozen employees whose core systems sit at head office and a site of several hundred people running its own production management system and equipment network have completely different priorities. Decide where to start based on how many sites you have and how much of the system estate is actually held locally. Trying to fix everything at once usually means nothing moves.

Four structural patterns for overseas IT

In practice, IT structures at overseas sites fall into roughly four patterns. None of them is the correct answer; what fits depends on the size of the site and the capacity of head office.

Overseas IT Staff Shortage — 4 Structures for Your Plant - figure 1

The expat dual-role model. Someone posted from Japan in administration or production takes on IT alongside their main job. At sites in the start-up phase, or where the system estate is narrow, this genuinely works. The advantages are fast communication with head office and almost no additional cost. The weaknesses are that the knowledge leaves when they repatriate, and that the quality of the whole structure depends entirely on that individual’s expertise.

The head-office remote model. The information systems department in Japan manages the overseas sites as well. For governance, nothing else comes close — licence management and standardisation are easier to drive, and security policy is straightforward to unify. But it stops dead the instant physical work is required on site. Plugging and unplugging cables, swapping hardware, standing alongside the equipment team. None of that has a remote equivalent. Time zones and language are real constraints too; expecting a head-office engineer to also handle shop-floor conversations in Thai is not realistic.

The local dedicated hire model. You recruit an IT specialist locally and station them at the site. For response speed and understanding of the shop floor, this is the strongest option. But as noted, people who can handle cloud and infrastructure are being fought over in the market, so the hiring itself is not easy. And if you hire one person, you are left with the question of what happens if that one person resigns. Unless you design for retention and succession as well, you can be back at square one within a few years.

The outsourced model. You contract part or all of operations and maintenance to a local or regional provider. This structurally addresses both key-person dependency and the holiday gap, and it takes you out of the recruitment race. The weakness is that if you scope the engagement badly, you end up handing everything outside without understanding any of it. We come back to that point in a later section.

StructureWhere it fitsMain weakness
Expat dual-roleStart-up phase, narrow system scope, a single siteKnowledge leaves on repatriation, preventive work slips
Head-office remoteHQ has an IT department and wants to drive standardisationNo physical or shop-floor response, time zone and language limits
Local dedicated hireLarge site with a lot of locally owned systemsHard to recruit, resignation risk in a one-person setup
OutsourcedCannot staff a dedicated role, multiple sites, want night and holiday coverPoor scoping leaves no knowledge inside the company

In reality, most companies combine them. Standardisation and licence management at head office, day-to-day monitoring and first response outsourced, and an expatriate acting as the bridge with the local site — that three-layer structure is a sensible shape for a company with several sites. What matters is writing down who owns which task. Run it without writing it down and you will create tasks that nobody owns.

A scoring model — where should your company start?

Here is a way to organise the decision around four variables. Score each one from 0 to 2.

Variable0 points1 point2 points
Number of sites in Thailand and ASEANOne site onlyTwo or three sitesFour or more sites
Scope of systems held locallyCore systems at HQ, locally just terminals and networkSome systems such as production management held locallyProduction management, equipment network and servers all local
Current IT ownershipA dedicated person is in placeOne person covers it as a side dutyEffectively nobody owns it
Hours where downtime is unacceptableRecovery within weekday business hours is fineSome operation at night or on weekendsRound-the-clock operation, or equipment runs through long holidays
Overseas IT Staff Shortage — 4 Structures for Your Plant - figure 2

Rough scoring is fine. On the third variable, though, we would suggest not relying on the site’s own assessment — compare it against how head office sees it. It is not unusual for the site to answer “we have someone” while head office believes “that person surely has another job to do.”

Total scoreA realistic way forward
0 to 2 pointsThe current structure will hold for now. The priority is reducing key-person dependency — document configuration details and the list of vendor contacts
3 to 5 pointsConsider outsourcing selected tasks. Start with the ones easiest to standardise, such as monitoring, backup verification and update application
6 to 8 pointsMove to designing integrated operations across multiple sites. Using a different vendor per site drives up the cost of consolidating later

Even at a low score, there is work worth doing now that pays off later — the documentation named in the 0-to-2 row. A network diagram, an inventory of servers and licences, the vendors under contract with their account contacts, and how passwords are managed. Simply having these in one place transforms how quickly a new owner gets up to speed. Conversely, if you start exploring outsourcing without them, the discovery work alone can take months.

We have deliberately left cost out of this scoring model. Budget matters as an input, but if you set the budget envelope first, the discussion about what structure you actually need quietly turns into a discussion about how much you can afford. Deciding the shape first and adjusting scope afterwards makes internal agreement easier to reach. On the fourth variable, think about “hours where downtime is unacceptable” as covering not only equipment run time but also month-end close and shipping peaks. Plenty of factories have just a handful of days a year that absolutely cannot be interrupted.

The reason we recommend integrated operations from six points upward has more to do with design consistency than with cost. Contract a different company at each site and the security baselines and backup methods will not match, and head office loses any view of how well each site is actually protected. The more sites you have, the more that inconsistency costs you.

Key questions when using outsourcing or managed operations

If hiring is hard, going outside is a rational call — and there is data behind it.

A survey run by JETRO jointly with the East Asia Business Council (EABC) from 16 June to 10 July 2025, covering 536 companies across ASEAN+3, found that 83.6% of Japanese companies in ASEAN cited “a talent shortage and a widening skills gap” as an obstacle to digitalisation. The most cited underlying factors were “insufficient education and training opportunities” at 44.8%, “differences in work permit and visa systems between countries” at 32.8%, and “talent outflow” at 31.9% (multiple responses).

That breakdown explains why the self-contained answer of hire-and-train is so difficult. A lack of training opportunities is the flip side of having nobody in-house qualified to teach. Differences in work permit and visa regimes show that filling the gap by moving people from Japan runs into regulatory limits. Talent outflow is the problem of people leaving after you have trained them. None of the three can be changed quickly by one company acting alone. Using an external operations structure is a realistic way around them.

The premise, however, is that you do not simply hand the whole thing over. Decide at the outset which work can go outside and which must stay in.

Work that travels well to a providerWork that must stay in-house
Availability monitoring and first response for servers and networkDeciding which systems get updated or replaced, and when
Verifying backups and running restore testsDeciding where your data is stored and how it may be handled
Applying OS and software updatesApproving who is granted which access rights
Triage during incidents and liaison with vendorsManaging vendor contract terms and spend
Routine account creation and deletionDefining business requirements tied to production and quality

What the right-hand column has in common is that every item carries judgement and accountability. A provider can carry out the work; it cannot make your business decisions for you. The left-hand column, by contrast, is work where a defined procedure produces the same result regardless of who performs it. Outsource with that line left vague and you will lose time on “who decides this?” every time an incident occurs.

A few things are worth checking when selecting a provider. First, whether they have engineers in-country — swapping hardware and checking cabling cannot be completed remotely. Second, the languages they work in. You need reporting to head office in Japanese and day-to-day exchanges with local staff in Thai or English — two language tracks running at once. Third, the coverage hours. Thai and Japanese public holidays do not coincide, so confirm before signing which calendar the service runs on. Fourth, the reporting format. Whether you end up with a monthly record of what happened and what was done has a direct bearing on whether the arrangement holds up over time.

A word on how to transition. Trying to switch from your current setup to an external provider in one move usually stalls, because the information gathering for handover never finishes. The realistic path is to pass work across in order of how routine it is. Monitoring and backup verification first, then OS and software updates, then first-line help desk. Because each step produces its own written procedure, you also accumulate documentation inside the company as a by-product. It is not unusual for the first step alone to take several months, so work backwards from the next expatriate rotation when you set your start date.

On the cost side and how to think about contract structures, our breakdown of business system maintenance costs takes the cost structure apart in detail — worth reading alongside this when you reach the budgeting stage.

What is specific to Thailand and ASEAN

Everything above applies to overseas sites generally. A few circumstances are particular to Thailand and the region.

For background, the squeeze on talent is not confined to IT roles. JETRO’s FY2023 Survey of Japanese-Affiliated Companies Overseas (Asia and Oceania edition) found that 40.4% of Japanese companies in Thailand cited a talent shortage as a challenge. In a market where skilled professionals across the board are being competed over, assuming you can conveniently recruit an IT specialist is not realistic.

Overseas IT Staff Shortage — 4 Structures for Your Plant - figure 3

The second factor is geographic dispersion. Among Japanese manufacturers it is common to run separate plants near Bangkok and in the eastern industrial estates, plus further sites in Vietnam or Indonesia. If your mental model is one IT person per site, headcount scales with the number of sites. Yet the workload at any individual site is often less than a full-time role. That mismatch is the practical reason overseas IT structures are so awkward to get right.

The workable answer here is not a person at each site but a single operations desk that looks after all of them. Consolidate monitoring and the help desk, and send people to site only when physical work is needed. Under that split, headcount does not scale with the number of sites. It also means head office can see every site against the same yardstick and compare which one is still running outdated configurations.

Language design is unavoidable in ASEAN as well. Reporting to head office in Japanese, working with site administration in English, and speaking with operators on the floor in Thai or Vietnamese — three language layers run simultaneously. Unless you decide in advance which language carries the first notification during an incident, you will lose time waiting for translation at exactly the wrong moment. In practice we find first-line intake in the local language, reporting to head office in Japanese, and records kept in English to be a workable combination. That said, the right shape varies by organisation, so set it against your own reality.

One regulatory point to close. When you select a provider, confirm where your data will be stored. Thailand’s Personal Data Protection Act (PDPA) is in force, and handling employee and business partner information requires internal rules to be in place. Where cloud data resides and how far the provider’s access extends are matters to confirm in writing at contract stage.

Frequently asked questions

How can we secure IT staff for an overseas site?

There are broadly three routes — post an expatriate from Japan, hire a dedicated specialist locally, or outsource operations. Which one fits depends on how many sites you have and how much of the system estate is held locally. With a single site and core systems at head office, an expat covering IT alongside head-office remote support will hold for the time being. With several sites and a production management system and equipment network on the ground, one hire will not constitute a structure. Score the four variables in this article’s model, and if the total is three or more, start considering outsourcing selected tasks.

What are the risks of having an expatriate cover IT as a side duty?

Three. First, preventive work slips. Because they have a primary job, low-urgency tasks such as applying updates and verifying backups reliably fall to the back of the queue. Second, knowledge leaves on repatriation. If the configuration details and vendor contacts exist only in that person’s head when the rotation happens, their successor starts the investigation from scratch. Third, the night and holiday gap. Thai substitute holidays are sometimes set at short notice and drift from the head-office calendar, and in a one-person setup response capacity on that day is zero. The practical counter is to combine documentation with outsourcing the routine work.

What does outsourcing IT operations typically cost?

Cost is determined almost entirely by three things — the scope of work, the number of devices covered, and the coverage hours. Contracting monitoring and first response during weekday business hours sits at a very different level from round-the-clock cover that includes recovery work. Contract structures vary too, from a fixed monthly maintenance fee to usage-based charging for work performed, or a combination. Our breakdown of business system maintenance costs sets out the cost components in detail. Before you build a budget, we would suggest first drawing up the list of tasks you want to hand over — you cannot compare quotes until the scope is settled.

Can we leave this to local staff?

Yes, but it needs to be designed. The common failure when relying on local staff is to assign only day-to-day operational support while tacitly leaving decisions on security configuration and backup methods to them as well. Keep head office or an external specialist involved in anything that carries judgement. Concentrating everything on one person also magnifies the risk when they resign. Document the procedures and hand routine work such as monitoring and backup verification to an external provider, and operations continue even when the person changes.

How does IT structure relate to security?

Closely. Where the owner is absent or covering IT as a side duty, updates do not get applied, access rights do not get reviewed, and traffic does not get monitored. The finding that manufacturing has the highest ransomware infection rate by sector at 57.1% is very likely connected to the growing number of environments where equipment and information systems are linked. For how to think about protection that extends to the production network itself, see our guide to OT security in factories.

Will monitoring tools solve the absence of an IT owner?

Monitoring tools take you as far as detecting an anomaly and sending an alert. Receiving that alert, making a judgement and carrying out the recovery is human work. Deploying a tool is therefore not a solution to having no owner — it is a precondition for running with fewer people. For what to monitor and how to choose the tooling, see our guide to system monitoring in factories. When you evaluate a deployment, decide first who receives the alert and who responds. Skip that routing design and all you are left with is an alert that keeps ringing.

Summary

The absence of an IT owner at overseas sites should be understood as a structural condition rather than a failure of effort at any individual company. In a survey of Japanese companies operating overseas, the top IT and DX challenge for the third consecutive year was “a shortage of people,” cited by about 60% of respondents. At the same time, more than nine in ten said IT at their overseas sites needed strengthening, and localisation of the management layer continues to advance. More to do, and a thinner pool of Japanese expatriates to lean on. It is reasonable to assume both will persist.

What surfaces as a result is rarely a dramatic outage. It is the quiet risk — stalled updates, backups that exist in name only. The fact that manufacturing’s ransomware infection rate of 57.1% sits above the overall average shows that outcomes turn on whether someone is tending the systems day to day. That said, the weight of each risk varies with the size of the site and the scope of its systems, so set priorities before you start.

The structural options are four — expat dual-role, head-office remote, local dedicated hire, and outsourced. Score the four variables of site count, locally held system scope, current IT ownership, and hours where downtime is unacceptable. At three points or more, consider outsourcing the routine work; at six or more, look at integrated operations designed across multiple sites. Given that 83.6% of Japanese companies in ASEAN cite a talent shortage and skills gap as an obstacle, looking to in-house recruitment and training alone for the answer is not realistic.

And whichever structure you choose, keep decision-making and data handling inside your own organisation. Work can be delegated; judgement cannot. Even at a low score, the effort of documenting a network diagram and a list of vendor contacts will pay you back later.

Having spent years inside the operations of Japanese manufacturers in Thailand, we can start simply by taking stock of your current structure with you and sorting out which work can go outside and which should stay in. You do not need to have decided to change anything first. Whether you are gathering material for an internal discussion or checking the scope of a handover ahead of an expatriate rotation, feel free to reach us through our contact page.

Reference material