Ordered by how much weight each one carries. Disagree with any of them and the recommendation changes, which is rather the point of showing you the reasoning.
moderateSize and spread
Past the size where one helpful person can absorb it
Somewhere around five or six people, IT stops being occasional and becomes a steady trickle. The trickle lands on whoever is best with computers, and it is rarely their job.
Try this: Ask that person roughly how many hours a month they spend on other people’s computer problems. Multiply it by what an hour of their actual job is worth.
What changes if this is handled: Either fund the role properly or move the work outside. What does not work is leaving it where it is and hoping.
highSize and spread
At this headcount, IT is somebody’s job whether or not it is anyone’s title
Twenty-plus people generate enough accounts, devices, joiners and leavers that the work is now continuous. Businesses this size usually have the volume without the structure, so everything happens reactively.
Try this: Count the IT things that happened last month: new starters, leavers, password resets, anything broken. If nobody can produce that list, the volume is not being tracked, which is itself the finding.
What changes if this is handled: A defined arrangement, whether that is internal, external, or both. The specific shape matters less than somebody owning it.
highSize and spread
Well past what an informal arrangement can carry
At this size the question is not whether IT needs managing but who is doing it and whether they have what they need. Businesses that reach this point without deciding usually have a very overworked internal person and no succession plan for them.
Try this: Ask what happens if the person who knows how everything works is off for two weeks. If the honest answer is "we wait", that is the risk.
What changes if this is handled: A real arrangement with documentation behind it, so the business does not depend on one person’s memory.
moderateSize and spread
More devices than anyone is tracking
Past about ten, the list stops living reliably in someone’s head. Machines then age, fall behind on updates, or sit unused with live accounts on them, and none of it is visible until something goes wrong.
Try this: Try to write down every device the business owns, from memory, in five minutes. Then compare it to what is actually plugged in.
What changes if this is handled: An inventory first. It is dull and it is the thing everything else depends on, including knowing what you are paying for.
highSize and spread
Enough devices that patching and monitoring have to be automatic
At this count, keeping machines updated by walking round is not realistic, so it stops happening. The gap between "we install updates" and "our machines are up to date" gets wide, quietly.
Try this: Ask for a list of your devices with the date each last updated. The time it takes to produce that answer tells you more than the answer does.
What changes if this is handled: Central monitoring and patching. This is the point where a managed arrangement starts saving money rather than costing it.
highSize and spread
No reliable picture of what the business runs
Not being able to answer is the answer. You cannot secure, budget for, or replace things you have not counted, and you are probably paying for some of them twice.
Try this: Compare your software and licence bills against your headcount. Unused licences for people who left are the usual first thing to fall out.
What changes if this is handled: A discovery exercise, then a maintained inventory. It usually pays for itself in cancelled licences before it does anything else.
moderateSize and spread
Support now has to reach people who are not in the building
Walking over to someone’s desk stops being the fix. Home working also puts company data on connections and machines nobody chose, which is a different problem from the one your office setup was built for.
Try this: Ask a home worker what happens when their machine will not start on a Monday morning. Count the hours in the answer.
What changes if this is handled: Remote support and remote management, so where someone sits stops being the deciding factor.
highSize and spread
Multiple sites and, most likely, no one on most of them
Every site has its own network, its own equipment, and its own set of things quietly failing. Whichever site the helpful person is not at gets the worst of it, and its problems get reported latest.
Try this: Ask people at your smallest site what they currently just live with. It is usually a longer list than at head office, and none of it has been reported.
What changes if this is handled: Remote monitoring so every site is visible from one place, rather than support quality depending on geography.
highSize and spread
Too spread out for anyone to hold in their head
At this spread, hands-on support is no longer the model, and anything that depends on someone being physically present will not scale. It also becomes very hard to say what you own and where it is.
Try this: Pick your most remote site or a field worker and time how long a straightforward problem actually takes to resolve, start to finish.
What changes if this is handled: Remote-first management with on-site work as the exception, and equipment standardised so a replacement is a swap rather than a project.
moderateSupport arrangement
Support is reactive by design
Break/fix is not a bad arrangement, it is a specific one: you pay for repairs and nobody is paid to prevent them. That works while problems are rare. The incentives also point the wrong way, since the provider earns more when things break.
Try this: Add up last year’s IT invoices. Then ask how many of those visits were for something that could have been caught earlier.
What changes if this is handled: Not necessarily a change. If the total is low and the response is good, stay where you are. If it is climbing, a fixed monthly cost is worth pricing against it.
highSupport arrangement
Your IT department is someone who was hired to do something else
This is the most common arrangement I find and the least visible. It costs you their real work, it leaves nothing written down, and it ends the day they leave or finally refuse.
Try this: Ask them, privately, how they feel about it. The answer is usually more strongly worded than anyone expects.
What changes if this is handled: Give the work to someone whose job it is. That can still be part time, and it does not have to mean a full plan.
highSupport arrangement
Nobody owns it, so problems accumulate
When nothing gets reported because reporting achieves nothing, people build workarounds instead. Those workarounds become how the business runs, and they are invisible until someone new arrives and asks why.
Try this: Ask your team what they have stopped bothering to report. Expect a longer list than you were expecting.
What changes if this is handled: One route in, and someone at the other end of it. This is the cheapest change on the list and usually the one people notice most.
moderateSupport arrangement
Steady enough to be a running cost
Monthly is the point where these stop being events and start being a line item, except nobody is adding it up because it never arrives as a bill.
Try this: Use the downtime calculator with your real numbers and a monthly frequency. The annual figure is usually the part that surprises people.
What changes if this is handled: Worth measuring before deciding anything. If the annual figure is small, carry on. If it is not, you now have the number to compare against a quote.
highSupport arrangement
Something is wrong underneath, not just unlucky
Weekly problems are a symptom rather than a run of bad luck. Usually it is ageing hardware, a network that was never designed, or the same fault being re-fixed because nobody recorded it the first three times.
Try this: Ask whether the last five problems were five different things or the same thing five times. If nobody can say, nothing is being recorded.
What changes if this is handled: Find the underlying cause rather than the incidents. That needs a record, which is the thing reactive support never produces.
highSupport arrangement
The business is absorbing the cost of this every week
At this frequency people have stopped noticing, which is worse than complaining. The lost time is now baked into how long everything takes, and it will not show up anywhere you are looking.
Try this: Ask how long a routine task is expected to take, then ask someone who does it daily how long it really takes. The gap is often IT.
What changes if this is handled: This is usually a handful of specific causes rather than everything being bad. Finding them is a short piece of work and the results tend to be immediate.
moderateSupport arrangement
A day or two of someone not working, each time
This is tolerable for a broken printer and expensive for anything a person needs to do their job. The cost lands on you rather than on whoever is slow to arrive.
Try this: Multiply your typical wait by how often problems happen, and by what an hour of that person costs. That is the annual price of the current response time.
What changes if this is handled: An agreed response time, in writing, rather than an informal expectation. It is the difference between a promise and a habit.
highSupport arrangement
No predictable response, so no way to plan around it
Unpredictable is worse than slow. You cannot tell a client when you will be back, you cannot decide whether to send someone home, and you cannot judge whether the arrangement is working.
Try this: Look up when you reported your last three problems and when each was actually resolved. Three very different numbers is the finding.
What changes if this is handled: A written response commitment. Any provider unwilling to put one in writing has told you something useful.
moderateSupport arrangement
Some chasing, which means no system behind it
Chasing is a reliable sign that requests are being held in someone’s head rather than in anything that tracks them. It works until that person is busy, which is exactly when you need them.
Try this: Ask what happens to a request when the person who took it is on holiday. If the answer involves their inbox, there is no system.
What changes if this is handled: Anything that tracks requests and reports back without being asked. The tracking matters more than the tool.
highSupport arrangement
You are the tracking system
If nothing progresses unless you push it, then managing your IT provider has become part of your job. That is time you are already paying for, on top of the invoice.
Try this: Count the follow-up emails and calls you sent about IT last month. That is the unbilled hours you are contributing.
What changes if this is handled: A provider that reports without being asked, or an internal system that does. Either way you should not be the one holding the list.
moderatePlanning
A change coming, and reactive support does not do projects
Break/fix answers the phone. It does not plan a move, size a network for twice the headcount, or work out what a new system needs before you have signed for it. Those get handled at the last minute, which is where the cost is.
Try this: Ask who is going to work out the IT side of it, and when. If the answer is "we will sort it nearer the time", the budget for it does not exist yet.
What changes if this is handled: Get the IT requirements scoped before the commitment rather than after. That is advisory work and it is usually the cheapest part of the project.
highPlanning
More change than a reactive arrangement can absorb
Individually these are manageable. Together they interact: new people need devices and accounts, a new site needs a network, new software needs both. Handled separately and late, they collide.
Try this: Put the changes on one calendar with dates. Overlaps you had not noticed are usually visible within a minute.
What changes if this is handled: One plan covering all of it, sequenced. This is the clearest case on the list for having someone whose job includes looking ahead.
moderateObligations
You are signing for controls somebody needs to be maintaining
The application asks whether multi-factor sign-in is enforced and whether backups are tested. You sign to say yes. If an answer is wrong at claim time, the insurer can decline. Somebody has to keep those answers true all year, not just on the day you signed.
Try this: Read last year’s application again and pick the answer you are least sure of today. That is the one to check.
What changes if this is handled: Make each answer somebody’s responsibility with a date attached. The paid Network Security Assessment exists specifically to produce that document.
highObligations
Contractual obligations with nobody assigned to them
A security clause in a contract is a commitment you can be held to commercially. Reactive support does not evidence anything, so when a client asks for proof there is nothing to send, and that conversation tends to happen during a renewal.
Try this: Find the security clause in your largest contract and read it. Then ask who would answer it if the client asked tomorrow.
What changes if this is handled: Someone owning the requirements and keeping evidence as they go. Assembling it retrospectively costs several times more.
highObligations
Regulated obligations on an unmanaged setup
The obligation does not adjust for how your IT happens to be arranged. It stays yours regardless of who is or is not looking after it, and "nobody was managing it" has never been a defence.
Try this: Ask who would produce the evidence if it were requested this week, and how long it would take them.
What changes if this is handled: A defined arrangement with documentation. What that has to cover depends on your regulator, and it is worth reading their requirements rather than anyone’s summary of them, mine included.
moderatePlanning
Replacement happens at the worst possible moment
Buying under pressure means paying whatever the day costs, taking whatever is in stock, and losing a person for however long setup takes. The same machine bought in a planned month costs less and interrupts nothing.
Try this: Work out what the last emergency replacement cost you all in: the machine, the lost day, and the setup time. Compare it to replacing two a year on a schedule.
What changes if this is handled: A simple refresh schedule spread over a few years. It turns a series of bad surprises into a budget line.
highPlanning
No replacement plan, so the estate is ageing invisibly
Without a plan, machines are replaced only after failing, so the average age of everything creeps up together. That means the failures arrive in a cluster rather than spread out.
Try this: Find the age of your five oldest machines. If they are all similar, they were bought together and they will fail together.
What changes if this is handled: Age the estate on paper, then spread the replacements. The first pass takes an afternoon and settles the budget conversation for years.
highPlanning
Nobody can say how old the equipment is
This usually means no inventory, which means no plan is possible yet. It also means hardware is probably still in service past the point of getting security updates, which quietly turns a budgeting question into a security one.
Try this: Check what version of Windows the oldest machines run and look up its support end date. That date is a deadline and it will not move.
What changes if this is handled: An inventory with ages and warranty dates. It is the smallest useful first step and everything else depends on it.