Most business owners who hire their first IT person feel like they’ve solved something.
Then the second year hits.

There’s a certification renewal, an emergency weekend call, a recruiting cycle because the IT person left for a 20% raise somewhere else, and a three-week gap where nobody’s quite sure who owns the firewall. That feeling of “solved” turns out to have been expensive optimism.
Running IT in-house at under 100 employees is rarely the budget-friendly move it looks like on paper. The salary line is just the beginning. What sits underneath it, the turnover costs, the skills gaps, the uncovered hours, and the reactive emergency spend, tends to run significantly higher than what most owners budget when they make the original hire. This breakdown examines what in-house IT actually costs at smaller company sizes, where the numbers get ugly, and what the comparison to managed services actually looks like when you count everything.
The Salary Line Is the Smallest Part
Here’s the number most owners start with: the salary. It feels concrete. You post a job, you see market rates, you make an offer. But salary is only about 70% of what an employee costs you.
According to the U.S. Bureau of Labor Statistics, the median annual wage for network and computer systems administrators was $96,800 in May 2024. Add the standard employer burden of roughly 30% for benefits, payroll taxes, and health insurance, and that one person costs you closer to $126,000 before you buy a single piece of software or pay for a single training course.
Then come the line items owners rarely budget in year one:
- Certifications and ongoing training: $3,000 to $10,000 per year
- Security and monitoring tooling: $20,000 to $50,000 annually for a proper stack
- Recruiting and onboarding when they leave: easily $15,000 to $25,000 per cycle
For a company with 40 employees, you’re looking at a fully loaded annual IT cost well north of $150,000, and you still have one person, working roughly 40 hours a week, with zero coverage on nights and weekends.
The Single-Point-of-Failure Cost Ladder
One person cannot do everything IT requires simultaneously. The problem isn’t competence, it’s physics. And this is where smaller companies run into what I’d call the Single-Point-of-Failure Cost Ladder: a sequence of compounding exposure that kicks in every time your sole IT person is unavailable.
Step 1: Planned absence. Your IT person takes a week of PTO. No monitoring, no patch deployments, no help desk. Non-critical issues queue up; some become critical by the time anyone notices.
Step 2: Unplanned absence. They get sick on the same day your email server throws an error. You’re calling in a contractor at emergency rates, paying $150 to $250 per hour, with no guarantee they know your environment.
Step 3: Turnover. They resign. The technology sector runs an annual turnover rate around 13%, and the institutional knowledge they carry out the door, your VPN configs, your backup schedules, your vendor relationships, leaves with them. You spend three to six months recruiting before someone new reaches full productivity.
Step 4: Skills ceiling. Your business grows into compliance requirements, cloud migrations, or cybersecurity needs that exceed a generalist’s skill set. You either hire a second specialist or you go without. Most companies under 100 employees quietly go without.
Each step on that ladder costs money. Most of it never shows up in the IT budget column.
What Downtime Actually Does to a Sub-100-Employee Company
The financial case for in-house IT usually assumes the system works. When it doesn’t, the math changes fast.
Consider a concrete scenario: a 40-person professional services firm. Average employee total compensation runs roughly $75,000 a year, or about $36 per hour. A four-hour outage, maybe a failed server update or a ransomware event that locks file access, idles all 40 people. That’s $5,760 in pure labor burn before you count missed billable hours, delayed client deliverables, or the emergency vendor call to remediate.
“Downtime costs extend beyond a single invoice: revenue loss, idle staff, delayed deliverables, and reputation damage.” This framing from corporate IT analysts captures why SMBs consistently underestimate their exposure, because they tally the fix cost instead of the full operational impact.
The painful irony is that reactive IT is more expensive than proactive IT. Emergency remediation bills at a premium. Contractor availability during an outage is not guaranteed. And the root cause, an unpatched system or an unmonitored network anomaly, is often something a proactive maintenance program would have flagged weeks earlier.
Why SMBs Are Shifting Toward Managed Services
The business case for outsourcing IT isn’t new, but the adoption numbers show it’s clearly gaining ground. A Techaisle survey of over 5,100 SMBs and midmarket firms found that managed services are a priority for 79% of SMBs, driven by the need to improve security, reduce risk, and contain unpredictable IT costs. That’s not a fringe trend. It reflects what a lot of owners have figured out through trial and expensive error.
The managed services pricing model addresses most of what makes in-house IT financially awkward. Instead of a loaded salary plus variable emergency spend, you get a fixed monthly fee per user that covers help desk support, 24/7 monitoring, patch management, backup, and a baseline security stack. For a 40-person company, that predictable monthly cost is almost always lower than the fully loaded equivalent headcount cost, and it comes with a full team instead of one generalist.
For companies with compliance obligations, the depth advantage becomes even clearer. A single hire who handles network administration probably does not also hold a security operations background and a compliance framework specialization. An established provider, like those offering expert IT management for small and mid-sized businesses, staffs multiple disciplines under one contract, which means your security, your helpdesk, and your strategic IT planning aren’t competing for the same person’s attention on the same Tuesday afternoon.
The Honest Comparison: A Side-by-Side Look
| Cost Category | In-House IT (40 Employees) | Managed IT Services (40 Employees)
|
|---|---|---|
| Base salary + benefits burden | ~$126,000/year | Included in monthly fee |
| Tools and licensing | $20,000–$50,000/year | Typically bundled |
| Training and certifications | $3,000–$10,000/year | Provider’s responsibility |
| Recruiting/turnover (amortized) | $5,000–$8,000/year | None |
| After-hours/weekend coverage | Not covered or overtime cost | Included in 24/7 plans |
| Estimated annual total | $154,000–$194,000+ | $48,000–$96,000 (per-user model) |
The table above uses conservative figures. Real costs at the high end of the in-house column push significantly higher once you add emergency remediation events and compliance gaps.
How to Decide: Three Questions Worth Answering First
Not every company should outsource IT. There are real scenarios where in-house makes sense, usually when you’re above 100 employees with specialized, proprietary infrastructure that demands dedicated internal ownership. But below that threshold, the math rarely works in favor of building internally. Before you make the call either way, answer these three questions honestly:
- What does one hour of downtime cost your business, fully loaded? If you can’t answer this, you don’t have enough information to evaluate either model fairly.
- Does your IT workload require more than one skill set? Network administration, security monitoring, cloud infrastructure, and compliance readiness are four separate disciplines. One generalist covers maybe two of them adequately.
- Can your current coverage model handle 2 a.m. on a Sunday? If your answer is “we’d figure it out,” you’re describing reactive IT, which costs more per incident than preventive IT costs per year.
What makes most owners resistant to outsourcing isn’t the cost. It’s the loss of visible control, having a person in the office who feels like your IT is handled. That feeling of control is worth examining carefully. A person in the office who is also your only line of defense, your only coverage, and your only institutional memory is a concentrated single point of failure. A managed services team is still your IT. It just isn’t fragile in the same way.
What’s the IT model your company would choose if you built it from scratch today, knowing everything you now know about what in-house really costs?
