How Many Employees Before You Need Dedicated IT?
"We're probably too small to need real IT support, right?" Owners ask us this at 8 employees, at 15, and sometimes — after a bad week — at 40. The honest answer isn't a single number, but there are clear thresholds where the risk math flips, and most businesses cross them earlier than they think.
The short version: by 10 employees almost every business needs professional IT support in some form; by 20 the DIY approach is actively costing money; the first internal IT hire rarely makes sense before 50–100 employees, and usually alongside an MSP rather than instead of one. Regulated data — patient records, financial information, defense work — moves every threshold toward zero.
What Do the Thresholds Look Like?
Support needs scale with people, but risk scales with consequences. Here's the pattern across hundreds of small businesses, stage by stage:
| Headcount | What typically works | What typically breaks |
|---|---|---|
| 1–5 | Cloud apps, MFA, a password manager, an IT firm on call | Nothing — until a compromised email or dead laptop with no backup |
| 5–10 | Same, plus business-grade email security and backup | The founder is still the helpdesk; hours vanish |
| 10–20 | Managed IT (market rate ~$100–$250/user/mo) | The "accidental techie" model; unmonitored everything |
| 20–50 | Fully managed IT with security stack and QBRs | Break-fix hourly; unbudgeted IT spend; compliance gaps |
| 50–100 | First internal hire + co-managed MSP | A lone internal person with no backup or after-hours coverage |
| 100+ | Internal team + specialized MSP/MSSP services | Anything without formal structure |
Why Is 10 Employees the First Real Line?
Because around 10 people, three things happen at once: the technology surface (accounts, devices, apps) exceeds what anyone manages part-time, the cost of downtime crosses four figures per day, and you become a statistically normal target for phishing and credential attacks. Attackers don't check your headcount — automated campaigns hit 10-person companies with the same tooling used on enterprises, and industry breach reports consistently show small organizations over-represented in ransomware incidents precisely because defenses are thinnest there.
This is also where the "office manager does IT" model quietly fails. It's not about skill — it's that nobody is monitoring systems, nothing is documented, MFA is inconsistent, and backups are unverified. Those gaps are invisible until the day they're the whole story. If several of these feel familiar, our article on the signs you've outgrown your IT support goes deeper.
When Does an Internal IT Hire Beat Outsourcing?
Almost never before 50 employees, on pure math. A fully loaded IT generalist in the Sacramento market costs $85,000–$120,000 per year for one person's business hours — no nights, no vacations covered, one set of skills. Managed IT for a 25-person company at market rates runs roughly $30,000–$75,000 per year with a team, 24/7 monitoring, and enterprise security tooling behind it. We walk through the full comparison in In-House vs. Outsourced IT.
Past 50–100 employees, the equation legitimately shifts: there's real daily on-site work, business-specific systems worth dedicated attention, and enough volume to fill a role. Even then, the winning pattern is usually co-managed IT — your hire handles hands-on and institutional-knowledge work while an MSP provides the monitoring, security stack, after-hours coverage, and escalation bench no single human can.
How Does Industry Change the Answer?
Regulated data overrides headcount entirely. The thresholds above assume ordinary business data; these situations need professional IT at any size:
- Medical and dental practices — HIPAA applies to a two-provider office exactly as it does to a hospital system
- CPA and financial firms — the FTC Safeguards Rule requires a written security program, MFA, and monitoring regardless of size
- Defense subcontractors — CMMC requirements flow down the supply chain to the smallest shop
- Anyone with cyber insurance — carriers now require MFA, EDR, and tested backups as underwriting conditions
If you're in any of these categories, the question isn't whether you need professional IT — it's whether your current setup would survive an audit or a claim. Our IT compliance services page maps what each framework demands.
Not sure which side of the line you're on? Get a free IT assessment — we'll inventory your environment, benchmark it against businesses your size, and tell you honestly if you're too small to need us yet.
The Practical Playbook by Stage
- Under 10: Nail the free-and-cheap basics — enforced MFA, password manager, auto-updates, tested backup, business email security — and have an IT firm you can call.
- 10–20: Move to managed IT. This is the stage where prevention starts out-earning reaction, and where managed IT services cost less than the problems they eliminate.
- 20–50: Full stack — monitored EDR, tested backup and recovery, quarterly reviews, an IT budget. Compliance and insurance requirements usually arrive in this band; get ahead of them.
- 50+: Consider your first internal hire, structured co-managed from day one.
We support businesses at every one of these stages across the Sacramento region, from Sacramento to Elk Grove. The most expensive pattern we see isn't companies buying IT support too early — it's companies discovering, one incident too late, that they'd needed it for years.