The question rarely arrives as a question. It arrives as an invoice for a licence nobody can account for, as half a day of standstill, or as the resignation of the person who «knows the tech stuff». Only then does somebody sit down and do the maths.
This piece does the maths first. It is not about what managed IT covers — that is on the managed IT page. It is about the question that comes before: at what point does keeping IT in-house cost more than handing it over, and how do you spot that point before it finds you.
Three thresholds
There is no headcount at which outsourcing becomes «right». There are three thresholds, and none of them is about size.
First threshold: nobody owns the IT. In many companies someone handles it on the side — whoever knows most. That holds until the person is on holiday, resigns, or lets their actual job slip. If you cannot name who is responsible internally, you do not have an owner. You have a habit.
Second threshold: one day of standstill costs more than a month of support. This one is calculable, and the working is below.
Third threshold: nobody can answer four questions. Which devices are in use. Which licences are running. Who has access to what. When a backup was last restored — not created, restored. If those four questions hang in the air, that is not a knowledge gap. It is the absence of operations.
The calculation that settles it
Most comparisons put a provider's monthly fee against a part-time salary. That is the wrong pairing, because it only shows the planned side of the ledger.
Work with four numbers from your own business instead:
1 · What one day of downtime costs. Take the number of people who cannot work without the central system, times their average daily rate. Add what does not ship or does not get invoiced that day. This is the floor, not the damage — appointments that get pushed do not all come back.
2 · How often it hits you in a year. Not the major incidents: the half-days. A mailbox that stopped syncing. A printer nobody can find any more. Count the last twelve months honestly.
3 · What the in-house arrangement actually consumes. Not the contracted percentage, but the hours that genuinely go into IT — for the person doing it on the side. Those hours are missing from their real job, and there they are usually worth more.
4 · What you need in terms of availability. An internal person takes holidays and gets ill. If your business runs outside 08:00 to 18:00, or a Saturday fault cannot wait until Monday, that is a line of its own — internally payable only through a second person.
Number 1 times number 2, plus number 3, plus number 4. If the result exceeds twelve monthly fees for external support, the question is answered. In the companies we run this with, the point almost always sits earlier than they assumed — not because support is cheap, but because number 2 gets underestimated.
Why recurring faults are the real measure
There is one test that needs no figures at all: if the same fault appears three times in a quarter, what changes?
Under time-and-materials billing, nothing changes. It gets fixed a fourth time, and every fix is a properly delivered service. That is not an accusation against the provider; it is the incentive structure.
Where you pay for a state rather than for hours, the repetition is itself the trigger. It leads to the cause, because a fourth fix would come out of the provider's margin. That is why ticket volume in a working arrangement falls over the months instead of staying flat — and why the ticket curve is the most honest figure you can ask for.
What the first weeks actually look like
Not new software. An inventory: devices, accounts, licences, access, backups, network. Most companies do not have this list, and its absence is why every fault starts expensively — with searching.
Then comes clearing up, before anything is bought. Accounts belonging to people who left. Permissions that grew with a role that no longer exists. Licences for tools nobody opens. In almost every environment we take over, this step pays for part of the support.
If you run Microsoft, a large share of it hangs off a single platform — identity, mailbox, device. What the licence already contains and what lies idle in most companies is broken down in Microsoft 365 for SMEs; setup and hardening sit under Microsoft 365 and Intune.
Where operations end and protection begins
This line gets blurred in both directions. It can be drawn cleanly.
Part of operations are updates, permissions, device management and a backup whose restore has been rehearsed. Those four are not security products, they are hygiene — and they close most of what actually stands open in the environments we take over.
A service in its own right is protection against attacks: network segmentation, endpoint protection, mail security, monitoring for anomalies, incident handling. At ALPENIQ that sits with IT security, not inside the support fee — listed separately so it stays visible what you are buying.
Why the line matters at all: a provider who folds security entirely into the flat fee is either promising more than the fee can carry, or means only the hygiene by it. You want to know which before you sign.
Which gaps most often stand open in smaller environments, and the order in which to close them, is set out in cyber security for SMEs. Backup and restore belong to backup and cloud.
One point that gets overlooked: under Article 24 of the revised Swiss Data Protection Act, a breach of data security must be reported to the Federal Data Protection and Information Commissioner as soon as it creates a high risk for the people affected. You can only report what you know happened, and you only know that if it was logged beforehand. The duty to report is therefore also a requirement on operations, not only on the legal department.
What to ask before you sign
Not the price. The structure of the price — it tells you more than the figure.
What is included, what is billed on top? Incidents outside office hours in particular, and projects such as moves or migrations.
What is the fee based on — people, devices or systems? The three numbers develop differently as you grow. A business with many devices per person pays twice under the wrong basis.
What happens during an outage, concretely? By when does someone respond, by when is someone working on it, and who decides what comes back first. A response time without a prioritisation rule is half a commitment.
Who owns the documentation? Access, passwords, network diagram, licences — all of it must be readable and transferable without the provider. Otherwise you are not buying support, you are buying dependency.
What does leaving look like? Notice period, handover format, data release. A provider who regulates the exit cleanly is counting on you staying because it fits — not because you cannot leave.
An offer that answers these five questions is comparable. One that quotes only a monthly figure is not.
In short
Outsourcing is not a question of company size. It is a question of ownership with a calculation behind it. The point is reached when downtime, internally bound hours and required availability together exceed twelve monthly fees — and it usually sits earlier, because nobody counts the half-days.
The most honest test remains the third threshold. If you cannot answer the four questions, the handover has already begun, just unnoticed.
What that scope looks like in a real operation — firewall, workplaces, identities, backup and support under one responsibility — we have disclosed for an operation we run ourselves. Deliberately not an arm's-length client mandate, and it says so on the page.
What ALPENIQ takes on in IT operations is on ALPENIQ IT. Once you have your four numbers and want to know what they mean, bring them to a free strategy call — thirty minutes, and a straight answer on whether a change pays off for you.
Frequently asked questions
When does IT outsourcing pay off for a small business?
When downtime cost, internally bound hours and required availability together exceed twelve monthly fees for external support. Company size is the wrong yardstick — what decides it is whether the IT has a named owner and whether anyone can say which devices, licences and access rights are in use.
How do I calculate the cost of an IT outage?
People who cannot work without the central system, times their daily rate, plus what does not ship or get invoiced that day. That sum is the floor. Multiplied by the number of incidents in the last twelve months — including the half-days nobody counts in hindsight — it gives you the figure the comparison rests on.
Do I lose control if I hand IT to a provider?
Only if the documentation stays with the provider. Access, network diagram, licences and passwords are yours and must be readable and transferable without them at any time. Put that in the contract and you outsource the work while keeping the decision. Leave it out and you swap a problem for a dependency.
What response time is realistic for an IT fault?
What it covers matters more than the number. Ask for three points in time rather than one: when someone responds, when someone is actually working on it, and who decides which system comes back first. A response time without a prioritisation rule says little — in a real incident, several things are down at once.
What does ALPENIQ take on when we change IT provider?
We inventory the environment, clear up accounts, permissions and licences, and set up monitoring, updates, device management and backup so they run without anyone tending them. After that we keep the operation running, with a named contact and a regular report on what happened and what is coming. Protection against attacks runs alongside as a separate service, so it stays visible what it covers.
