Skip to main content
Dig IT Solutions logo

Managed IT Support

Why business owners shouldn't be managing IT, and the tasks that should never sit with non-IT staff

Why the owner or office manager should not be the IT department: the cost in time and risk, the tasks that need a specialist, and how to delegate safely.

By Dig IT SolutionsUpdated 8 September 20265 min read

Short answer

Business owners should not be managing IT because their time is the most expensive in the company, because small technical problems often signal larger ones that need diagnosis, and because security, backups, access control and patching need to be done consistently by someone whose job it is. Delegating IT keeps decisions with the owner and takes the fixing away.

In most small businesses IT is managed by whoever was least able to avoid it. Often that is the owner, or the office manager, or the one employee who "knows computers". It works, in the sense that things mostly keep running, until the day it does not. This article makes the case for taking IT off the owner's desk, lists the tasks that genuinely need a specialist, and explains how to delegate without losing control.

The owner's hour is the most expensive in the business

A business owner's time is worth what the business earns from it: sales, hiring, customers, planning, the decisions nobody else can make. An hour on a printer driver is an hour of that gone.

The interruptions are the real cost. IT problems do not arrive in a neat block on Friday afternoon. They arrive when a laptop will not connect at 9am, when a customer's email bounces, when a new starter has no account on their first day. Each one breaks whatever the owner was doing, and the hours add up quietly. Ask any owner who has finally handed IT over what changed, and the first answer is usually "I got my mornings back".

Put a number on it. If the owner spends two hours a week on IT at an hourly value of £50, that is £5,200 a year, which is more than a managed contract for a ten-person office on our indicative per-device rates. And the £5,200 understates it, because the interruptions cost more than their duration.

Small problems are usually symptoms

The second reason is diagnostic. A slow computer might just be a slow computer. It might also be a failing disk, a malware infection, a full drive, or a network fault. A dropped Wi-Fi connection might be interference, an overloaded access point, a switch on its way out, or a misconfiguration.

An owner fixing symptoms, by restarting and hoping, is not wrong. They simply cannot tell which of these it is, and the ones that matter get worse while they are being restarted. A provider with monitoring sees the failing disk before it fails and the malware before it spreads. The pattern is described in why unresolved IT issues become expensive.

DIY fixes create the next problem

The third reason is that well-meant fixes have side effects.

  • Security features disabled to "make it work for now" and never re-enabled.
  • Everyone given admin rights because permissions were confusing.
  • A backup job edited and silently broken.
  • A router setting changed that took the phones down the following week.
  • A leaver's account kept "in case", still receiving email a year later.
  • An application update that broke an integration nobody knew existed.

None of these are stupid. They are what happens when someone without the full picture changes one part of an interconnected system. Professional IT works from documentation and process precisely to avoid them.

The tasks that should never sit with non-IT staff

A capable employee can do many IT things once. The tasks below need specialist knowledge and consistent attention, and each has consequences that appear months after the mistake.

TaskWhy it needs a specialistWhat goes wrong when it does not have one
Security strategy and incident responseThreats change constantly, and response under pressure needs a rehearsed planPhishing becomes ransomware, evidence is destroyed, the ICO is not notified in time
User access and permissionsRole-based access, regular reviews, structured joiners and leaversLeavers with live accounts, everyone able to see everything, no audit trail
Backup and recoveryDesign, monitoring, restore testing, recovery proceduresA backup that has never been restored, or that syncs the ransomware
Network configurationSegmentation, firewall rules, Wi-Fi design, firmwareGuest devices on the server network, remote management open to the internet
Cloud tenant configurationMicrosoft 365 identity, sharing, retention, licensingData shared publicly, licences wasted, MFA never enforced
Email securityFiltering, authentication records, monitoringInvoice fraud, impersonation, a compromised mailbox spamming customers
Patch managementScheduling, testing, coverage of every device and applianceKnown vulnerabilities open for months
Compliance controlsEncryption, logging, retention, documentationNothing to show an insurer, a client or the ICO
MonitoringTools, alert triage, trend spottingEvery failure is a surprise

The NCSC's Cyber Essentials controls are a useful check: if nobody in the business can say with confidence that all five are in place on every device, the tasks above are not being done.

Staff need someone to ask who is not the boss

When the owner is the helpdesk, staff interrupt the owner. Or, more often, they do not, and work around the problem instead: use a personal laptop, email files to themselves, share a password, ignore the update prompt. Workarounds are how security gaps and technical debt accumulate.

A helpdesk staff can contact directly changes the behaviour. Problems get logged and fixed, patterns get noticed, and the owner hears about IT in a quarterly review rather than in the corridor.

What the owner should keep

Delegating IT is not abdicating it. The owner keeps:

  • Decisions. What to buy, what to change, what to spend, when.
  • Priorities. Which systems matter most, what downtime costs, what risk is acceptable.
  • Ownership. Every account, licence, domain and piece of data belongs to the business, and the contract should say so.
  • Oversight. Reports on tickets, patching, security and backups, and a periodic review.

What moves to the provider is the doing. Owners with good support generally know more about their IT than they did before, because for the first time someone is reporting on it.

How to hand it over

  1. Start with security and backup. MFA everywhere, managed endpoint protection, scheduled patching, a monitored and restore-tested backup. These close the gaps that cause the expensive incidents.
  2. Document what exists. Devices, accounts, credentials in a password manager the business controls, licences, backup locations. If the knowledge is in one head, get it out now.
  3. Set up the helpdesk. Tell staff who to contact and how, and stop being the first call.
  4. Agree the reporting. What you will see monthly and quarterly, so oversight replaces involvement.
  5. Keep the decisions. Insist on being asked before spend or significant change, and on a review a few times a year.

The choice between an in-house hire and a managed contract is worked through in in-house versus outsourced IT support. For most businesses under 100 people the contract wins on cost and coverage, and what it includes is described in managed IT support.

What to do next

If you are the person everyone comes to when the Wi-Fi drops, the IT support cost calculator will show what it costs to make that someone else's job, using our indicative per-device rates. Put the figure next to two hours a week of your own time and the answer is usually clear.

Frequently asked questions

Can a business owner handle basic IT tasks themselves?
Yes. Restarting a router, helping a colleague reconnect to Wi-Fi, or resetting a password in Microsoft 365 are fine. The problem is not the tasks, it is the drift: the owner becomes the default helpdesk, spends hours a week on it, and the tasks that need a specialist, such as patching, backup testing and access reviews, never get done because nobody owns them.
What IT tasks should never be left to non-IT staff?
Security strategy and incident response, user access and permissions, backup and recovery design and testing, network configuration, cloud tenant configuration, email security, patch management, compliance controls and system monitoring. Each needs specialist knowledge and consistent attention, and mistakes in each have consequences that appear months later. A capable employee can do some of them once. Nobody can do all of them properly alongside another job.
What are the biggest risks of DIY IT management?
Data loss from mishandled backups or deletions, security settings disabled to make something work and never re-enabled, leavers with live accounts, unpatched systems, and undocumented configurations that only one person understands. Individually these look minor. Together they are the environment in which a phishing email becomes a ransomware event and a failed disk becomes permanent loss.
How much time do owners spend on IT?
In businesses without support it is commonly hours a week, mostly in interruptions: a laptop that will not connect, a printer, a password, a suspicious email. At an owner's hourly value, that is usually more than the cost of a managed contract for the whole business. The larger cost is what did not get done in those hours: sales, hiring, customers, planning.
Does delegating IT mean losing control of it?
No. You keep every decision: what to buy, what to change, what to spend, what the priorities are. What moves to the provider is the doing: monitoring, patching, security, backups, joiners and leavers, and the helpdesk. You own every account, licence and piece of data, and the contract should say so. Owners with good support know more about their IT than they did before, because someone reports on it.
What should be the first IT task a growing business hands over?
Security and backup, together. Enforce MFA, put managed endpoint protection on every device, get patching on a schedule, and set up a backup that is monitored and restore-tested. Those four close the gaps that cause the expensive incidents. Access control, documentation and the helpdesk follow. It is also the order a new provider works in during the first month.

Next step

Talk to an engineer, not a sales script

Tell us what is not working, or what you are planning, and we will give you a straight view on what it would take to fix.

WhatsApp us