Outsourced IT vs In-House IT
This decision depends far less on headcount than the usual advice suggests. What actually decides it is whether one person can be unavailable without exposing the business, how many genuinely different disciplines your environment needs, whether anyone has started asking you for evidence of how IT is run — and whether you need someone to decide or someone to do.
A third option is usually missing from the question. Many organisations need an internal owner for decisions and external capacity for the work, and framing this as a binary choice serves them worst of all.
On the numbers you will not find here. Nearly every page on this subject quotes the same per-employee and per-user cost ranges. Those figures trace back to other articles rather than to verifiable sources, so we have not reproduced them — passing on an unsourced number is not the same as informing you. What this page gives instead is the cost structure, which is what actually determines the number in your case.
The Three Models
What each one actually gives you, and where each one breaks
Framed as capability and risk rather than as a cost table. The cost comparison is the part every other page already does, and the part no honest version can put a number on.
One internal IT person
- What it gives you
- Someone who knows your business, is present, and can be pulled onto whatever matters today. Institutional knowledge accumulates in a person who is actually in the room.
- What it costs
- Salary, benefits, employment overhead, tooling and training — and the tooling is frequently forgotten in the comparison. Monitoring, patch management, backup, documentation and security platforms are bought per-organisation, not per-person, so a one-person team pays close to what a ten-person team pays for the same stack.
- Where it breaks
- Coverage and breadth. One person cannot staff a 168-hour week, cannot take leave without the environment going unattended, and cannot hold deep Microsoft 365, network, security and compliance capability simultaneously. That is arithmetic, not a criticism of the person.
An outsourced IT company
- What it gives you
- Breadth across more disciplines than one salary buys, continuity when an individual is away, and a tooling stack already paid for and already operated. Also, usually, documentation — because an external party cannot run on recall.
- What it costs
- A recurring fee, and the real variable is scope rather than headcount. The same label covers wildly different arrangements, which is why comparing two quotes is harder than comparing two salaries.
- Where it breaks
- Context and presence. An external provider will not absorb your business context as quickly as an employee, will not be in the corridor when someone mentions a problem, and — where scope was never properly agreed — will do exactly what was contracted and no more.
Both (co-managed)
- What it gives you
- Your person keeps ownership, context and decision rights; the provider supplies capability and capacity underneath. The internal role shifts from doing everything to directing and holding the relationship.
- What it costs
- Both a salary and a fee, which is why it looks expensive until you compare it against what each alone fails to cover.
- Where it breaks
- Ambiguity. Co-managed arrangements fail on an undefined boundary far more often than on capability. If nobody wrote down who owns what before work began, the boundary gets discovered during an incident, which is the worst moment to find it.
The Decision
Five questions that actually decide it
Answer these honestly and the model usually selects itself. Notice that only one of them is about cost.
Can one person be unavailable without the business being exposed?
The most honest version of the coverage question. If your IT person taking two weeks of leave means nobody can administer the environment, restore a file, or respond to a security alert, you do not have an IT function — you have a dependency. That is true whether the person is internal or a one-person external provider.
How many genuinely different disciplines does your environment need?
A single site running Microsoft 365 and a handful of laptops needs one skill set. Multiple locations, servers, a regulated data type, a line-of-business application and a compliance obligation need four or five. Salaries buy depth in one or two disciplines; they do not buy breadth, and no amount of goodwill makes one generalist expert in all of them.
Is anyone asking you for evidence?
The question most commonly left out of this decision, and the one that most often forces it. A customer security questionnaire, a cyber-insurance renewal, an auditor or an acquirer will ask for access review records, change history, backup and recovery test evidence and a current asset inventory. Informal IT produces none of these as a by-product, and reconstructing them under deadline is where the real cost of the informal model finally appears.
What happens to the knowledge when the person leaves?
Internal IT accumulates knowledge in a person; external IT is forced to write it down, because it cannot operate on recall across a client base. Neither is automatically better — an internal team that documents well beats an external one that does not. But the default behaviour of each model points in opposite directions, and defaults are what you get when nobody is actively managing it.
Do you need someone to decide, or someone to do?
These are different roles and conflating them is the most expensive error in this decision. An organisation that needs technology *decisions* owned internally — priorities, budget, risk appetite, vendor relationships — is not solved by outsourcing, because no provider can hold decision rights for you. An organisation that needs the work *done* reliably does not need those decisions to be made by an employee.
Signals
Six situations and what each one points toward
Including two that point away from hiring anyone.
Nobody can produce a current list of what you have
Toward outsourcing or co-managed
An environment nobody can describe cannot be secured, assessed, insured or handed over. External providers produce an inventory because they have to; informal internal IT frequently never does.
Your IT person is permanently reactive and never gets to projects
Toward co-managed, not replacement
This is a capacity problem wearing a performance problem as a disguise. The usual answer is not to replace the person — it is to take the recurring operational load off them so the role they were hired for becomes possible.
A customer or insurer has started asking for evidence
Toward whichever model will actually produce records
The deciding question stops being cost and becomes whether anyone will generate access reviews, change records and recovery-test evidence as a by-product of operating. Both models can; only one of them does by default.
You are about to replace significant infrastructure
Toward getting outside input before deciding either way
A hardware refresh or a cloud migration is a multi-year commitment made once every several years. It is the single worst decision to make on the basis of whoever happens to be available, and the best time to buy expertise you do not need permanently.
Technology decisions keep stalling internally
Toward neither — fix this first
Where nobody internally owns technology, budget is unavailable, or decisions cannot get made, a new provider arrives into the same conditions and produces the same outcome. The provider was not the bottleneck. This is worth saying plainly even though it argues against hiring anyone.
You have outgrown a one-person arrangement but not reached a team
Toward co-managed
The most common position for an organisation in the roughly 25-to-100-user range, and the one the two-option framing of this question serves worst.
Cost Structure
How to compare the numbers without a benchmark
Six things that determine the figure in your case — and make two quotes comparable, which they are not by default.
Scope, not headcount, is the variable
Two providers quoting the same monthly figure can be selling substantially different things. Before comparing numbers, get both to state what is included AND what is explicitly excluded — the exclusions are where quotes actually differ, and most providers do not publish them.
Per-user and per-device pricing are not interchangeable
An organisation with many shared or frontline devices and few named users prices very differently under the two models. Ask which basis a quote uses and model it against your real counts, not your headcount.
Tooling is an organisation-level cost, not a per-person one
Monitoring, patch management, backup, documentation and security platforms are bought for the environment. This is the item most often missing from the in-house side of a comparison, and it is the reason a one-person internal team is more expensive than a salary suggests.
Ask what is NOT included
Projects, after-hours work, on-site attendance, hardware procurement, third-party licensing, security tooling and monitored detection are each sometimes inside and sometimes outside a managed fee. A quote that will not enumerate its exclusions is not comparable to one that will.
Price the transition, both ways
Security and documentation tooling licensed to a provider rather than to you is often not portable, and backup history frequently does not transfer. That is a real cost of changing arrangements later and is worth establishing before signing, not after.
The cost of informal IT is real but arrives late
It shows up as a failed recovery, a lost contract after a security review, an insurance renewal that cannot be satisfied, or six weeks reconstructing records before an audit. None of it appears in a monthly comparison, which is precisely why the comparison tends to favour doing nothing.
FAQ
Common Questions
Should we outsource IT or hire someone internally?
It depends far less on headcount than the common advice suggests. The deciding questions are whether one person can be unavailable without exposing the business, how many genuinely different disciplines your environment needs, whether anyone is asking you for evidence of how IT is run, and whether you need someone to make decisions or to do the work. Organisations needing decisions owned internally are not solved by outsourcing. Organisations needing breadth, coverage and documented operations usually are. A large number need both, which is the arrangement the two-option framing serves worst.
When should a business hire its first IT person?
The honest answer is that a headcount threshold is the wrong trigger, even though almost every article on this subject offers one. The real trigger is when technology *decisions* need an internal owner — priorities, budget, risk appetite, vendor relationships — because no external provider can hold those for you. Plenty of organisations well past any suggested headcount run successfully with no internal IT and a good provider, and plenty well below it genuinely need someone internal because of the decisions they face.
How much does outsourced IT cost compared to hiring?
We deliberately do not publish benchmark figures here, and it is worth explaining why. Almost every page on this subject repeats the same per-employee and per-user ranges, and those numbers trace back to other blog posts rather than to verifiable sources — so reproducing them would be passing on an unsourced claim. What matters more is the structure: scope rather than headcount drives the number, tooling is an organisation-level cost that the in-house side of a comparison usually omits, and per-user versus per-device pricing can change the answer substantially. Get two or three real quotes, insist each states what is excluded, and compare those.
Is co-managed IT just a more expensive version of both?
On a monthly comparison, yes. Against what each model alone fails to cover, frequently not. Co-managed suits the organisation that has someone internal whose knowledge and decision-making you want to keep, but whose capacity or breadth does not cover the whole environment. It fails on an undefined boundary far more often than on cost — if nobody writes down who owns what before work starts, the boundary gets discovered during an incident.
What does an outsourced IT company actually do day to day?
Typically: monitoring infrastructure and endpoints, patch and maintenance operations, Microsoft 365 and identity administration, backup operations with recovery testing, network and firewall management, vendor coordination, and the documentation and review cadence underneath all of it. The important question is not the list — most providers publish a similar one — but what sits outside it. Scope ambiguity, not capability, is what most commonly goes wrong in these arrangements.
Can we outsource IT and keep our current IT person?
Yes, and it is often the right answer rather than a compromise. The internal person keeps ownership, context and decision rights while the provider supplies capability and capacity underneath. The usual trigger is an internal person who is permanently reactive and never reaches the work they were actually hired for — a capacity problem that replacing them does not solve.
What should we ask an IT company before signing?
What is explicitly excluded from the fee. Who holds the domain registration, Microsoft 365 Global Administrator, licensing relationship, DNS and backup platform — and whether you retain your own access to each. What documentation you receive and whether it remains usable if the engagement ends. Whether a restore has ever been tested, and what the record of that looks like. What the notice period is. These are answerable in a first conversation, and the willingness to answer them tells you as much as the answers.
Does outsourcing IT mean losing control of our systems?
It should not, and if it would, that is a reason to choose differently rather than to avoid outsourcing. Your Microsoft 365 tenant, identities, data and domain belong to your organisation. A competent arrangement leaves you holding your own Global Administrator and break-glass accounts, with the provider’s access additional to yours and revocable by you. Documentation held only inside a provider-owned platform is a dependency rather than a deliverable, and is worth identifying before it becomes one.
Related
If you have decided to bring in a provider, this is the next decision.
If you already have a provider and are weighing a change.
The documentation any arrangement should produce — published so you can ask for it by name.
The ten things auditors, insurers and clients ask for. Informal IT produces none of them by default.
How scope is set, what the first month produces, and the operating cadence.
The published accountability split, including the questions worth settling first.
A read-only review of what you currently have, before deciding anything.
Check whether the records an auditor or insurer asks for actually exist today.
Before You Decide
Start by finding out what you actually have
Whichever model you choose, the first useful step is the same: a documented picture of the current environment — risk, Microsoft 365 posture, backup and recovery, documentation and ownership. You keep the findings whether you hire internally, engage a provider, or do nothing.
We respond within one business day.