Managed IT Support
Why business owners shouldn't be managing IT, and the tasks that should never sit with non-IT staff
Why the owner or office manager should not be the IT department: the cost in time and risk, the tasks that need a specialist, and how to delegate safely.
By Dig IT SolutionsUpdated 8 September 20265 min read
Short answer
Business owners should not be managing IT because their time is the most expensive in the company, because small technical problems often signal larger ones that need diagnosis, and because security, backups, access control and patching need to be done consistently by someone whose job it is. Delegating IT keeps decisions with the owner and takes the fixing away.
In most small businesses IT is managed by whoever was least able to avoid it. Often that is the owner, or the office manager, or the one employee who "knows computers". It works, in the sense that things mostly keep running, until the day it does not. This article makes the case for taking IT off the owner's desk, lists the tasks that genuinely need a specialist, and explains how to delegate without losing control.
The owner's hour is the most expensive in the business
A business owner's time is worth what the business earns from it: sales, hiring, customers, planning, the decisions nobody else can make. An hour on a printer driver is an hour of that gone.
The interruptions are the real cost. IT problems do not arrive in a neat block on Friday afternoon. They arrive when a laptop will not connect at 9am, when a customer's email bounces, when a new starter has no account on their first day. Each one breaks whatever the owner was doing, and the hours add up quietly. Ask any owner who has finally handed IT over what changed, and the first answer is usually "I got my mornings back".
Put a number on it. If the owner spends two hours a week on IT at an hourly value of £50, that is £5,200 a year, which is more than a managed contract for a ten-person office on our indicative per-device rates. And the £5,200 understates it, because the interruptions cost more than their duration.
Small problems are usually symptoms
The second reason is diagnostic. A slow computer might just be a slow computer. It might also be a failing disk, a malware infection, a full drive, or a network fault. A dropped Wi-Fi connection might be interference, an overloaded access point, a switch on its way out, or a misconfiguration.
An owner fixing symptoms, by restarting and hoping, is not wrong. They simply cannot tell which of these it is, and the ones that matter get worse while they are being restarted. A provider with monitoring sees the failing disk before it fails and the malware before it spreads. The pattern is described in why unresolved IT issues become expensive.
DIY fixes create the next problem
The third reason is that well-meant fixes have side effects.
- Security features disabled to "make it work for now" and never re-enabled.
- Everyone given admin rights because permissions were confusing.
- A backup job edited and silently broken.
- A router setting changed that took the phones down the following week.
- A leaver's account kept "in case", still receiving email a year later.
- An application update that broke an integration nobody knew existed.
None of these are stupid. They are what happens when someone without the full picture changes one part of an interconnected system. Professional IT works from documentation and process precisely to avoid them.
The tasks that should never sit with non-IT staff
A capable employee can do many IT things once. The tasks below need specialist knowledge and consistent attention, and each has consequences that appear months after the mistake.
| Task | Why it needs a specialist | What goes wrong when it does not have one |
|---|---|---|
| Security strategy and incident response | Threats change constantly, and response under pressure needs a rehearsed plan | Phishing becomes ransomware, evidence is destroyed, the ICO is not notified in time |
| User access and permissions | Role-based access, regular reviews, structured joiners and leavers | Leavers with live accounts, everyone able to see everything, no audit trail |
| Backup and recovery | Design, monitoring, restore testing, recovery procedures | A backup that has never been restored, or that syncs the ransomware |
| Network configuration | Segmentation, firewall rules, Wi-Fi design, firmware | Guest devices on the server network, remote management open to the internet |
| Cloud tenant configuration | Microsoft 365 identity, sharing, retention, licensing | Data shared publicly, licences wasted, MFA never enforced |
| Email security | Filtering, authentication records, monitoring | Invoice fraud, impersonation, a compromised mailbox spamming customers |
| Patch management | Scheduling, testing, coverage of every device and appliance | Known vulnerabilities open for months |
| Compliance controls | Encryption, logging, retention, documentation | Nothing to show an insurer, a client or the ICO |
| Monitoring | Tools, alert triage, trend spotting | Every failure is a surprise |
The NCSC's Cyber Essentials controls are a useful check: if nobody in the business can say with confidence that all five are in place on every device, the tasks above are not being done.
Staff need someone to ask who is not the boss
When the owner is the helpdesk, staff interrupt the owner. Or, more often, they do not, and work around the problem instead: use a personal laptop, email files to themselves, share a password, ignore the update prompt. Workarounds are how security gaps and technical debt accumulate.
A helpdesk staff can contact directly changes the behaviour. Problems get logged and fixed, patterns get noticed, and the owner hears about IT in a quarterly review rather than in the corridor.
What the owner should keep
Delegating IT is not abdicating it. The owner keeps:
- Decisions. What to buy, what to change, what to spend, when.
- Priorities. Which systems matter most, what downtime costs, what risk is acceptable.
- Ownership. Every account, licence, domain and piece of data belongs to the business, and the contract should say so.
- Oversight. Reports on tickets, patching, security and backups, and a periodic review.
What moves to the provider is the doing. Owners with good support generally know more about their IT than they did before, because for the first time someone is reporting on it.
How to hand it over
- Start with security and backup. MFA everywhere, managed endpoint protection, scheduled patching, a monitored and restore-tested backup. These close the gaps that cause the expensive incidents.
- Document what exists. Devices, accounts, credentials in a password manager the business controls, licences, backup locations. If the knowledge is in one head, get it out now.
- Set up the helpdesk. Tell staff who to contact and how, and stop being the first call.
- Agree the reporting. What you will see monthly and quarterly, so oversight replaces involvement.
- Keep the decisions. Insist on being asked before spend or significant change, and on a review a few times a year.
The choice between an in-house hire and a managed contract is worked through in in-house versus outsourced IT support. For most businesses under 100 people the contract wins on cost and coverage, and what it includes is described in managed IT support.
What to do next
If you are the person everyone comes to when the Wi-Fi drops, the IT support cost calculator will show what it costs to make that someone else's job, using our indicative per-device rates. Put the figure next to two hours a week of your own time and the answer is usually clear.

