Why Fast-Growing Firms Outgrow Their IT Before They Outgrow Their Office
Growth arrives unevenly. A company that doubles headcount in eighteen months will renegotiate its lease, restructure its org chart, hire a finance manager and formalise its HR policies, usually in roughly that order. The technology estate is almost never on the list, because unlike floor space it gives no obvious signal when it runs out. Desks fill up visibly. A network quietly degrades.
By the time the symptoms are unmistakable — the shared drive that takes forty seconds to open, the video calls that drop at 3pm, the new hire waiting three days for a laptop — the business has usually been operating past its technology’s design capacity for a year or more. The cost of that year is paid in productivity nobody logged.
Three thresholds, and what breaks at each
Most growing firms hit the same three inflection points, and each breaks a different assumption the previous setup was built on.
Around fifteen to twenty people
Informal support stops working. Up to this point, technology is handled by whoever is most capable — often a founder or an operations lead who is good with computers. That arrangement is efficient until the person’s actual job starts losing hours to it. The tell is not a technology failure; it is a calendar failure. When a commercially valuable person is spending half a day a week on printer drivers and password resets, the company has already outgrown the model, whether or not anything is visibly broken.
Around forty to fifty people
The estate becomes too complex to hold in one head. Multiple offices or a hybrid workforce, a proper file structure with permissions that matter, an accounting system with audit requirements, customer data that now carries regulatory weight. This is where the absence of documentation starts to cost money: nobody can say with certainty which systems exist, who has access to what, or whether the backups have ever been restored. Companies at this size frequently discover that the “backup” they have paid for annually has never once been tested.
Around eighty to a hundred people
Downtime stops being an inconvenience and becomes a financial event. At this scale, an hour of degraded systems has a measurable revenue cost, clients notice, and the informal tolerance staff extended in the early days is gone. It is also the point at which the company becomes an interesting target: large enough to be worth attacking, rarely mature enough to have hardened.
The three cheap decisions that prevent expensive ones
The good news is that the interventions that matter most at each threshold are neither large nor capital-intensive. They are governance decisions rather than purchases.
Name an owner
Not a department — a person, internal or external, whose defined responsibility is the technology estate and who has protected time for it. Almost every avoidable failure in a growing firm traces back to a task that belonged to nobody in particular. Ownership is free; ambiguity is not.
Write down what you have
A single maintained list of systems, devices, licences, renewal dates and who holds administrative access. This document is unglamorous and takes an afternoon. It is also the first thing an acquirer, an auditor or an insurer will ask for, and the thing that makes a security incident survivable rather than catastrophic. Firms that skip it end up paying a consultant to reconstruct it later, at a much worse hourly rate and under time pressure.
Test the recovery, not the backup
Confirming that a backup job completed is not the same as confirming the data comes back. A restore test once a quarter, of an actual file to an actual machine, is the difference between a bad afternoon and an existential event. Insurers increasingly ask for evidence of this specifically.
Build, buy, or borrow the capability
The structural question every scaling business eventually faces is whether to hire internal IT, contract it out, or run a hybrid. There is no universally right answer, but the trade-offs are well understood.
An internal hire brings presence, institutional knowledge and cultural alignment — and carries the risk of a single point of failure who takes leave, falls ill or resigns. One person also cannot cover the range a modern estate requires: helpdesk, networking, cloud administration and security are genuinely different disciplines, and a generalist will be strong in one or two of them.
An external partner spreads the cost of specialists and 24-hour coverage across many clients, which is why capabilities that would be irrational for a fifty-person firm to own alone — round-the-clock monitoring, tested backup infrastructure, enterprise-grade endpoint security — become affordable. The economics also favour prevention: under a fixed monthly agreement, every incident is a cost to the provider, so the provider profits by making sure incidents do not happen.
The pattern is visible across lean, high-density business economies. In Singapore, where firms typically run deliberately thin administrative headcounts, providers of managed IT services for small business Singapore owners rely on have built around exactly this model — fixed fees, named engineers and prevention-first reporting — precisely because the alternative, an overloaded internal generalist, stops scaling somewhere around the second threshold.
The hybrid arrangement that works best in practice keeps one technically literate person inside the business who owns strategy, vendor selection and data governance, and contracts out the operational layer: helpdesk, monitoring, patching and out-of-hours cover. The internal person’s job is to hold the provider accountable, which requires knowing what good looks like, not doing the work.
The question worth asking this quarter
For a leadership team that suspects it is approaching one of these thresholds, one question surfaces most of the picture: if our main system failed at nine o’clock on our busiest morning, who would we call, how long would they take, and what would the delay cost us before lunch?
Firms that can answer all three parts crisply are appropriately resourced. Firms that hesitate on any of them have already crossed a threshold and have not yet paid for it. The bill arrives eventually — the only variable is whether it comes as a planned investment or as an unplanned outage.




