Most small businesses don’t need an IT department. If you have 10, 20, or 30 employees, hiring a full-time IT person probably doesn’t make financial sense, much less building an entire department with people responsible for support, cybersecurity, cloud services, networking, backups, and everything else that has become part of business technology.
Where small businesses sometimes get into trouble is making the leap from “we don’t need an IT department” to “we just need somebody to call when something breaks.”
Those aren’t the same thing.
There’s a big difference between having someone who can fix your computers and having someone responsible for managing your technology. Twenty or thirty years ago, the first option might have been enough for a lot of small businesses. Today, it usually isn’t.
The IT Guy Isn’t an IT Strategy
For decades, small-business IT was pretty straightforward. You bought some computers, found somebody who knew more about them than you did, and kept their phone number handy. If a computer broke, the printer stopped working, or you couldn’t get your email, you called the IT guy.
There’s nothing inherently wrong with that arrangement. Having someone capable of fixing a problem when it happens is useful. The problem is that modern business technology has become much bigger than fixing computers.
Even a fairly small company may now depend on Microsoft 365 or Google Workspace, cloud applications, laptops, mobile devices, networks, backups, security systems, multifactor authentication, software subscriptions, and a growing collection of online accounts. Employees come and go, computers get older, software reaches end of support, and new security threats appear constantly. Most of this needs attention long before somebody calls to say something isn’t working.
That’s the fundamental difference between break/fix IT and managed IT. The person you call when the computer breaks has an incentive to fix the computer. The person responsible for managing your IT has an incentive to keep it from breaking in the first place.
Sometimes Everything Looks Fine Until It Isn’t
We worked with a nonprofit that initially used us for its networking infrastructure and occasional support, while an in-house “IT guy” handled its computers. That arrangement seemed to be working, and from the organization’s perspective there wasn’t much reason to change it.
Then one of their primary operations employees was hit with ransomware.
This wasn’t a spare computer sitting in the corner. It was a system being used every day by someone important to the organization’s operations, and there was no backup or recovery plan for it. Suddenly the problem wasn’t simply removing malware and getting a computer running again. The organization had to worry about the data on that computer and whether it could be recovered.
After the ransomware incident, they asked us to take over management of their computers as well.
As part of onboarding, we inventoried and evaluated their systems. What we found was almost as concerning as the ransomware incident itself: roughly 30% of their computers were running operating systems that were so old they were no longer supported.
The computers weren’t necessarily broken. They turned on every morning and people were using them to work, which is why the problem had been easy to overlook. But an unsupported operating system isn’t receiving the security updates and support that a business should be relying on.
Nothing had failed yet. That didn’t mean everything was fine.
“It Still Works” Isn’t a Lifecycle Management Plan
Small businesses are remarkably good at keeping computers alive. I understand the thinking. If a computer turns on every morning and the employee sitting in front of it can still do their job, replacing it can feel like spending money to solve a problem you don’t have.
Unfortunately, computers have a lifecycle whether you plan for it or not. Hardware warranties expire, operating systems eventually stop receiving security updates, applications stop supporting older versions, and aging computers become slower and less reliable. Eventually, something that could have been replaced on your schedule becomes an emergency because it finally dies on a Tuesday morning when someone has a deadline.
When we discovered how many outdated systems the nonprofit had, telling them to immediately replace 30% of their computers wouldn’t have been particularly useful. They had a budget to work within, as every nonprofit and small business does.
Instead, we developed a three-year replacement plan. We identified the systems presenting the greatest risk, prioritized what needed to be addressed first, and spread the remaining replacements across future budgets. They went from waiting for computers to fail randomly to knowing what needed to be replaced and when.
That’s lifecycle management. Someone should know what technology your business has, how old it is, whether it’s still supported, when warranties expire, and what needs to be replaced next. You shouldn’t have to wait for smoke to come out of something to discover that it’s old.
Cybersecurity Has Changed What Small Businesses Need
Cybersecurity is probably where the old “call the IT guy when something breaks” model has become most outdated.
There was a time when small-business cybersecurity mostly consisted of antivirus software, a firewall, and repeatedly telling employees not to click on things they shouldn’t. We still tell employees not to click on things they shouldn’t, with varying degrees of success, but everything else has changed considerably.
Modern cybersecurity relies on multiple layers. There may be protection on the computer itself, email security, identity and account monitoring, multifactor authentication, backup, security awareness training, vulnerability management, and systems watching for suspicious behavior. If one layer misses something, another layer should have an opportunity to catch it.
Some of the security technologies available through managed IT providers are the same kinds of tools and services used by much larger organizations. Others are specifically designed to be delivered through IT and security providers and may not even be practical for a small business to purchase and operate independently.
Access to the tools is only part of the advantage. Someone still needs to configure them, maintain them, monitor the alerts they generate, investigate suspicious activity, and know what to do when something actually happens. Buying cybersecurity software is relatively easy. Building the people, processes, and expertise around it is the expensive part.
That’s one of the reasons managed IT makes sense for a smaller organization. You’re effectively sharing access to technology and expertise that would be difficult to justify building internally for a company with 15 employees.
Security Problems Don’t Wait Until Monday Morning
Cybersecurity also creates a staffing problem that most small businesses can’t reasonably solve themselves.
Attackers don’t particularly care what your office hours are. If something suspicious happens at 2:00 Sunday morning, waiting for somebody to notice it when they get to work Monday isn’t a great response plan.
A properly equipped managed IT provider can have security systems monitored around the clock, with security professionals available to investigate and respond when those systems detect a threat. That’s very different from expecting a small business owner, office manager, or lone IT employee to keep an eye on security alerts all weekend.
That doesn’t mean someone needs to be standing by at 2:00 AM because Bob can’t print.
There’s a difference between providing 24/7 help desk support and providing 24/7 security monitoring. Most small businesses probably don’t need the first. Increasingly, they do need the second.
Somebody Needs to Be Responsible for the Whole Picture
Ultimately, that’s what I think businesses should expect from managed IT. It’s not simply an arrangement where you pay a monthly fee instead of receiving an invoice every time somebody fixes a computer.
Someone needs to be responsible for looking at the entire technology environment.
That means keeping computers patched and supported, monitoring backups, managing employee access, keeping an eye on security, maintaining the network, tracking warranties and equipment age, managing Microsoft 365 or Google Workspace, and planning for what needs to be replaced or changed in the future. It also means understanding how those pieces affect each other instead of treating every problem as an isolated support ticket.
In a large company, an IT department handles those responsibilities. There might be separate people responsible for security, networking, cloud services, support, and planning. A small business obviously isn’t going to hire five different technology specialists.
The responsibilities don’t disappear just because you only have 15 employees.
That’s really the problem managed IT is supposed to solve. It gives a smaller business access to many of the capabilities of an internal IT department without having to build one.
Managed IT Should Be About More Than Support
When businesses compare IT providers, it’s easy to focus on support because that’s the part employees see. When something isn’t working, they want somebody to fix it, and preferably before they’ve rebooted the computer four times and started threatening it.
Support absolutely matters. Downtime costs money and frustrates everyone involved.
But I don’t think the number of support tickets an IT company closes is the best measure of whether your technology is being managed well. Over time, good IT management should make your technology more predictable. Aging equipment should be identified before it fails. Security risks should be addressed before they become incidents. New employees should get the access they need, departing employees should lose access promptly, and backups should exist before ransomware makes everyone suddenly interested in whether there is a backup.
There will always be unexpected problems. Technology has been keeping me employed for more than four decades largely because it continues finding creative new ways to misbehave.
The goal isn’t to eliminate every problem. It’s to eliminate as many preventable ones as possible and have a plan for dealing with the rest.
So What Should You Expect?
You don’t need to become an IT expert to figure out whether your technology is actually being managed. You just need to ask a few questions.
Ask whoever handles your IT how they know when your computers need to be replaced. Ask what happens if a security threat is detected after hours. Ask whether your backups are monitored and what the recovery plan is if something happens. Ask who is responsible for making sure your computers and software remain current and supported.
Most importantly, ask what they’re doing when you’re not calling them with a problem.
That’s where the difference between IT support and IT management becomes pretty obvious.
A small business doesn’t need to recreate the IT department of a 500-person company. It would be expensive, unnecessary, and probably involve far more meetings than any reasonable person should have to endure.
But a small business still needs support, planning, cybersecurity, monitoring, lifecycle management, backup, and someone taking responsibility for how all of those pieces work together.
Your business may be too small to have an IT department.
It isn’t too small to have its technology properly managed.


