Most five-to-fifty person businesses don’t have an IT budget. They have IT expenses — invoices that arrive when something breaks, renewal notices they forgot were coming, a quote for a new server that nobody planned for, an emergency bill from the weekend the email server went down. The owner pays them, files them, and hopes next month is quieter. That’s not a budget. It’s a sequence of surprises with a running total.
The reason this happens isn’t laziness or poor planning. It’s that IT spending is genuinely hard to predict when you’ve never sat down and broken it into categories. The bookkeeping software says “Computer Expenses: $47,000” at year-end, and that number doesn’t tell you whether you spent too much, too little, or roughly the right amount on the wrong things. So next year, you do the same thing and hope the number doesn’t get bigger.
Getting out of that cycle starts with seeing what reactive IT actually costs — not just the invoices, but everything those invoices leave out.
The reactive IT bill is bigger than the invoice
When a small business runs IT reactively — calling someone when things break, paying hourly for emergencies, deferring maintenance until something forces the issue — the visible cost is the service invoice. But the invoice is the small part. The larger costs are absorbed by the business itself, which is exactly why they’re easy to miss.
Start with downtime. IBM’s 2024 Cost of a Data Breach Report puts the global average cost of a data breach at $4.88 million — a number that includes business disruption, lost revenue, and recovery time, not just the technical cleanup. Most small businesses won’t see a breach that severe, but the underlying math scales down. If a six-person accounting firm loses email and file access for half a day during tax season, that’s roughly 24 billable hours unrecoverable, plus the client calls that didn’t get returned, plus the deadline pressure that doesn’t pause because your server did.
Then there’s the productivity drag of small problems that never quite get fixed. A printer that jams twice a day. A laptop that takes eleven minutes to boot. A shared drive that disconnects every time someone opens a large file. Nobody calls the IT provider for these — they’re not emergencies — so they live in the environment for months, quietly costing five or ten minutes per person per day. Across a twenty-person office, that’s two to four hours of payroll per day spent waiting on systems. Over a year, it’s the cost of a junior employee.
Emergency rates are the third hidden cost. Break-fix providers charge premium rates for after-hours and weekend calls — typical onsite emergency rates run $250–$300 per hour with two-hour minimums, and that’s before parts. A weekend server outage that takes six hours to diagnose and resolve isn’t a $300 problem; it’s a $1,800–$2,000 problem, and it shows up on top of whatever else you’ve spent that month.
The fourth cost is the one nobody invoices for: deferred security and maintenance. When IT is reactive, anything that isn’t on fire gets postponed. Patching, backup verification, firewall rule reviews, employee security training, password policy updates, license audits — these get pushed because they’re not urgent. The bill for deferring them arrives later, in the form of a ransomware incident, a failed backup discovered on the day you needed it, or a compliance finding during an audit. The FBI’s 2023 Internet Crime Report documented $12.5 billion in reported losses to internet crime, with business email compromise and ransomware leading the categories that hit small businesses hardest.
If you add the invoice, the downtime, the productivity drag, the emergency premiums, and the eventual cost of deferred work, the reactive IT bill for a typical 20-person office runs well above what the owner thinks they’re spending. The first step in building a real budget is admitting that gap exists.
What actually belongs in an IT budget
A real IT budget has categories. When you can name what you’re spending on, you can plan for it; when it all lives under “Computer Expenses,” you can’t. For a 5–50 person business, six categories cover almost everything.
Hardware lifecycle. Workstations, laptops, servers, network equipment (firewalls, switches, wireless access points), and peripherals all have replacement cycles. Workstations and laptops last 4–5 years before warranty coverage ends and performance degrades; servers run 5–7 years; firewalls and switches 5–8. The budget should treat hardware as an annual line item, not a surprise capital expense. A reasonable planning figure is to set aside one-fifth of your total workstation cost every year — if you have 20 workstations averaging $1,500 each, that’s $6,000 annually toward replacement, even in years you don’t buy anything. The money accumulates and the replacement isn’t a crisis.
Software and licensing. This includes Microsoft 365 or Google Workspace, line-of-business applications (accounting software, practice management, case management, CAD, whatever your business actually runs on), antivirus or endpoint protection, backup software, and any specialty tools. Microsoft 365 Business Standard runs around $20 per user per month at retail; line-of-business software varies wildly by industry. The category is easy to underestimate because licenses renew automatically and the charges blend into credit card statements. Pull a year of charges and total them — most owners are surprised.
Security. Endpoint detection and response (EDR), security operations center (SOC) monitoring, email filtering, security awareness training for employees, multi-factor authentication tooling, and vulnerability management. In a reactive model, most of this either doesn’t exist or exists in name only — Windows Defender on workstations, a basic spam filter, nobody watching. In a managed model, security is bundled in. Either way, it belongs as a line item in your budget so you can see what you’re spending and what you’re not.
Support labor. This is what you pay someone — internal staff, a break-fix shop, or a managed provider — to actually do the work. In the reactive model, this is the hourly invoices. In the managed model, it’s the monthly fee. The honest comparison is total annual labor spend, not hourly rate, because the rate alone hides volume.
Backup and recovery. Local backup, offsite or cloud backup, and the ongoing monitoring that verifies the backups actually work. A backup nobody tests is a hope, not a backup. Cloud backup storage is typically priced by data volume; for a 20-person business with a single file server, this is usually a few hundred dollars a month.
Compliance, where applicable. If you’re a CPA firm, you have IRS Publication 4557 obligations and a written information security plan requirement under the FTC Safeguards Rule. If you’re a dental or medical practice, HIPAA applies. If you’re a law firm, ABA Model Rule 1.6 imposes a duty to protect client information using reasonable safeguards. Compliance work — risk assessments, policy documentation, training, audit support — has real costs that show up nowhere else if you don’t budget for them.
Run those six categories against a year of actual spending and you’ll usually find one of two patterns. Either the total is much higher than expected (because the invoices added up faster than memory tracked them), or several categories are at zero (because nobody was budgeting for them, which means nobody was doing them).
What the numbers actually look like
For a 5–50 person business, total IT spending typically falls in the range of 3–6% of revenue, with higher percentages for businesses in regulated industries or those heavily dependent on technology (a CPA firm, a clinic, a software-using design shop) and lower for businesses where computers are incidental to the work.
A cleaner way to plan, especially for service businesses, is per-user. For a managed IT services model that covers monitoring, maintenance, security, SOC coverage, backup, and support, expect roughly $100–$200 per user per month, depending on coverage level and complexity. Hardware and software licensing are separate from that figure. For a 20-person office, that’s $24,000–$48,000 per year in support and security, plus hardware lifecycle (around $6,000–$8,000), plus licensing ($10,000–$20,000 depending on what you run), plus backup and any compliance work.
Add those up and a realistic total annual IT budget for a typical 20-person professional services office lands somewhere between $50,000 and $90,000. Owners who’ve been running reactively often discover, when they add up the year’s invoices honestly, that they’re already spending in that range — just unpredictably, and with most of the categories above coming in at zero on the security and compliance side.
The managed-versus-break-fix math
The natural objection at this point: “Managed IT looks expensive when you write it as a monthly figure. Break-fix is cheaper because I only pay when I need it.”
That’s true on paper if the only thing you count is the support invoice. Once you account for what break-fix doesn’t include, the math reverses.
Break-fix labor is billed hourly, typically $150–$200 per hour during business hours and $250–$300 for emergencies. Monitoring, patching, security tooling, SOC coverage, backup verification, and strategic planning are not included — those are separate purchases, or they don’t happen. In a managed model, those services are bundled into the monthly fee. A managed plan at $150 per user per month for a 20-person office is $36,000 a year. Hitting that same total on break-fix would require about 240 hours of billable work — which sounds like a lot until you realize that’s twenty hours a month, and that figure doesn’t include the security tools, SOC, or strategic guidance that managed clients get on top of the labor.
The bigger shift, though, is what managed IT prevents. Continuous monitoring catches drive failures, certificate expirations, and backup errors before they become outages. Patching closes vulnerabilities before they’re exploited. SOC analysts watch for unusual login activity around the clock. None of that prevention shows up as a line item, which is why it’s easy to undervalue. It shows up as the year nothing went catastrophically wrong — which, if you’ve had a year where something did, you understand the value of immediately.
The right comparison isn’t “what does managed cost versus break-fix?” It’s “what does my total IT cost — invoice, downtime, productivity drag, emergencies, deferred risk — actually total under each model?” For most businesses in the 5–50 range, managed wins that comparison, often by a wider margin than expected.
How size and complexity change the budget
A 5-person law office with two laptops, a cloud-based case management system, and no on-premises server has a fundamentally different IT budget than a 45-person manufacturing company with a domain controller, a line-of-business ERP system, shop-floor workstations, and a remote sales team. Both are “small businesses.” Their budgets shouldn’t look alike.
The variables that move the budget most are: number of users, number of physical locations, whether you have on-premises servers, the sensitivity of your data (regulated industries cost more to protect properly), how much of your stack is cloud versus on-prem, and whether you have remote or hybrid workers (which adds VPN, conditional access, and endpoint management complexity).
For the smaller end of the range — 5 to 15 people, cloud-first, no server, low regulatory burden — IT budgets often run $15,000–$35,000 annually, all-in. For the larger end — 30 to 50 people, on-premises infrastructure, regulated data, hybrid workforce — $80,000–$150,000 is more typical. The shape of the spending shifts too: smaller cloud-first businesses spend proportionally more on software licensing and less on hardware; larger businesses with servers spend more on infrastructure and security.
When to handle it yourself and when to bring in help
Some businesses can run IT internally for a while. If you have under ten people, your stack is entirely cloud-based, nobody on your team handles regulated data, and you have someone technically competent who’s willing to spend a few hours a week on patching, account management, and the occasional issue — you can defer a managed relationship. The risk is that “someone technically competent” usually turns out to be the owner or an office manager who’s already doing two other jobs, and the IT work gets done when it gets done.
The honest signals that DIY has run its course: you’ve had a security incident or near-miss; you’ve missed a backup verification and discovered it during a recovery attempt; you’ve put off a software upgrade for more than a year because nobody knows how to do it; you can’t answer basic questions about who has access to what; an audit, insurance application, or client questionnaire has asked you for documentation you don’t have. Any one of these is a reasonable trigger to bring in a managed provider. Multiple at once means you’re already past the point where DIY was working.
What’s actually in your environment right now
Building a budget without knowing what you have is guessing. Before you can decide what to spend, you need a clear picture of the current state: what hardware you own and how old it is, what software you’re licensed for and what you’re actually using, what security tools are in place and what they’re actually catching, whether your backups work, who has access to what, and where the obvious gaps are.
Most owners can’t produce that picture from memory, and the inventory lives in a dozen places — the bookkeeper’s records, the IT person’s head, an old spreadsheet, the renewal emails. A few honest questions you can ask before any provider walks in:
- How old are the workstations and laptops? When was the last one replaced, and what’s the plan for the next replacement cycle?
- What’s running on your server, if you have one? When was the operating system last updated, and when is support for it scheduled to end?
- What endpoint protection is installed, and is anyone monitoring its alerts?
- When was the last time someone restored a file from backup to verify the backup actually works?
- Who has administrative access to your Microsoft 365 or Google Workspace tenant, and is multi-factor authentication required on those accounts?
- If your office lost power or internet for a full day, what would your business actually do? Who would you call, and how long would it take to get back to work?
If any of those questions are uncomfortable to answer, the budget conversation can’t start until they’re answered. A budget built on guesses about the current state will be wrong by enough to matter.
The next step is an assessment, not a quote
When a business owner asks an IT provider for a quote without first letting them look at the environment, they’re asking the provider to guess too. The number that comes back is either padded (to cover unknowns) or low (to win the work, with change orders later). Neither is a budget you can plan against.
ForeverOn‘s free IT assessment exists for exactly this reason. The process is two visits. The first visit gathers data on the actual state of your environment — hardware, software, security posture, backup status, network configuration, the things you can’t see from a sales conversation. The second visit walks you through the findings in plain English, with color-coded charts showing where the urgent gaps are and what’s in reasonable shape. The output isn’t a sales pitch. It’s a picture of where you actually stand, which is what you need to build a budget you can defend.
From that assessment, the conversation about a managed IT plan becomes specific instead of abstract. ForeverOn’s managed plans — Essential Care, Preferred Care, and Total Care — start around $100 per user per month and scale based on coverage level, response time SLAs, and what’s included. All three include the same 24/7 security operations center, ransomware response, and endpoint protection; the differences come in onsite support inclusion, response time guarantees, and which services move from “billed separately” to “fully included.” For a 20-person office with one server and one backup, plans range from about $1,935 a month at the Essential tier to $3,585 at Total Care. The right fit depends on what the assessment finds, not what someone guesses on a phone call.
If you’re in Washington County, Frederick County, or the surrounding Maryland area and you’re tired of IT spending that arrives as a series of surprises, the assessment is the first concrete step. Call ForeverOn at (301) 739-7311 — a real person answers, no phone tree — or book a discovery meeting through the consultation page. The assessment is free. The budget conversation it makes possible is the one most business owners have been trying to have for years without the information to have it well.