02 / Knowledge base
An in-house IT hire or an external provider?
9 min read
The decision usually goes like this: somebody puts the cost of an IT salary next to a provider's monthly invoice, sees which number is smaller, and treats the matter as settled. Both figures are easy to obtain, both sit in the same budget line, and both look comparable. They are not. They describe two different things, and neither answers the question that actually matters: what happens on the day the company stops.
Two other quantities are comparable: whose availability stands behind your IT, and how wide the knowledge behind it goes. One person has one head, one holiday calendar and one notice period. A contract with a provider has a defined scope, a defined response time and an obligation that does not disappear when somebody falls ill. Those are the things that can honestly be set side by side.
01
A salary and an invoice are not the same money
The cost of a hire does not end with the number on the employment contract. Add social contributions, equipment, licences for the admin tooling, training, recruitment, and the time of whoever brings the person up to speed — which, for a company's first IT hire, is usually the owner, the most expensive hour the business has. That is still only arithmetic, though, and arithmetic is not what settles this.
The more important difference is in what is being bought. A salary buys presence: a set number of hours a week in which somebody is available. A support contract buys an obligation: a scope of work and a deadline by which somebody will respond — and that obligation binds the firm, not a named person. An employee does not sign for their own availability, and has nothing to sign it against — if they are on holiday, they are on holiday.
It cuts the other way too. A salary buys something a contract does not: undivided attention, and a person who sits in your company rather than in their own office and several other clients'. A company that needs that has a genuine argument for hiring, and it deserves to be taken seriously rather than talked away with a comparison table.
02
One person is one point of failure, and the company finds out last
The typical shape is this: the twentieth of the month, the server running the accounting software will not boot, and the only person who knows that environment is on holiday and reachable in the evenings. Nobody else has the administrator password for that server, because nobody else has ever needed it. The stoppage then lasts not hours, but however long it takes to regain access to your own system.
The scenario is not born of incompetence or bad faith. It is born of the fact that documentation is the first thing to fall off one overloaded person's list: writing down the router configuration helps nobody today, and there are twelve tickets for today. After two years the map of the environment exists in exactly one memory, and nobody in the company is able to check what is missing from it.
The most expensive version is not a holiday, though — it is a resignation. Somebody leaving on less than warm terms takes knowledge that nobody will extract from them in three weeks, because nobody knows what to ask. Recovering administrator accounts after a departure like that can be expensive — and it always happens at the worst possible moment, because somebody else picks the moment.
The test takes a minute. If that one person did not pick up the phone tomorrow, could anybody in the company sign in to the router, to the Microsoft 365 admin console and to the backups? If the answer is “I am not sure”, this is not a question about trusting that person. It is a question about whether the company has documentation.
03
Nobody stays current in all of it at once
Even a twenty-person office now runs an environment made of several independent worlds. Each one moves at its own pace, each has its own traps, and each needs attention that cannot be given in passing.
None of them can be kept current in passing. One person is usually genuinely strong in one or two, competent in the next, and guessing in the rest — and the guessing stays invisible until the first incident, because a badly segmented network looks exactly like a well segmented one. A provider divides these areas between specialisms instead of demanding all of them from a single calendar.
- The network and its edge: router and firewall configuration, segmentation, remote access and a separate guest network — in our case usually MikroTik or UniFi, and each of them rewards a different set of habits.
- Identity and the Microsoft 365 tenant: accounts in Microsoft Entra ID, permissions, MFA, sharing policy and dozens of settings whose defaults are set for convenience rather than for safety.
- Backup and restore: what is copied, where the second copy lives, and whether anyone has ever restored a file from it — a backup nobody has ever restored is a hope, not a backup.
- Workstations: Windows and macOS updates, disk encryption, endpoint protection, and making sure people are not working from an administrator account all day.
- The industry system the business runs on: its database, its updates, the contact with its technical support, and knowing what happens when the vendor ships a release your configuration does not like.
04
When a hire is the better answer
There are companies for which an in-house IT person is simply the right call, and pretending otherwise would be selling rather than advising. Three situations settle it almost on their own.
The first is IT that has grown into the process. In a factory or a warehouse that starts at six in the morning, knowing which handheld scans what and why that particular label will not print is worth more than fluency in Microsoft Entra ID. That knowledge is not bought in a contract; it comes from walking the floor every day and from conversations nobody ever raises as a ticket.
The second is physical presence. If hardware turns over constantly, people work shifts, and every other issue needs somebody to walk to the desk, then somebody has to be there every day. Driving out — ours included, in and around Bydgoszcz — is then a worse answer than a chair in the same building, and there is no point pretending otherwise.
The third is scale and formal obligation. When there is genuinely a full-time job's worth of administration, or a client, an insurer or an auditor requires somebody on your side to watch access, logs and changes to the systems every day and answer for them personally, an external contract priced for that volume stops being cheaper and stops being simpler. That is the moment for an IT department of your own — better recognised than dragged out for another two years.
05
The arrangement that usually settles the choice
Between hiring and outsourcing there is a third option, and it is usually the one worth costing out first: one person inside, close to the staff and the processes, with an external partner behind them for infrastructure, specialist work, and the days that person is away.
The split then makes itself. The internal person knows the users and the industry system, knows whose problem is genuinely urgent, and is there when someone needs to walk to a desk. The partner owns the areas the contract assigns to them — typically the network, identity, backups, security and migrations — the areas one person could not stay current in anyway. Nobody has to be an expert in everything, and nobody is the single point of failure any more.
It is also the only version in which the internal person can grow towards what the company gains most from: automation, order in the data, improvements to the process. Instead of spending Thursday afternoons reading the documentation of a firewall they touch three times a year, they work on the things no external provider will ever know better than they do.
The arrangement has one serious flaw: when the division of responsibility is not written down, each side assumes the other is checking the backups. Draw the line in writing, area by area, before it takes effect.
06
What to check instead of the two numbers
First test: Friday, four in the afternoon, email stops working for everyone. In the hire scenario the answer depends on whether that one person picks up, because nobody has obliged them to be available after hours. In the contract scenario the answer is written down: our standard contract terms are a response within 3 working days for a standard request and within 12 hours for an urgent one, while the IT Business and IT Critical plans get shorter, individually agreed windows written into the SLA. How much work happens outside business hours is a separate clause in that contract rather than an assumption. You can disagree with those windows and negotiate others. What you cannot do is leave them unsaid.
Second test: where the documentation is. Not whether it exists — where. In which file, in whose password vault, last updated by whom, and readable without its author sitting next to you. A company that holds its own hardware inventory, licence list and network diagram can change its IT person or its provider without drama. A company that does not is a hostage, and it makes little difference whether the hostage-taker is an employee or a supplier.
Third test: what the parting looks like — a question worth asking at the very start, in both scenarios. For a hire: what exactly the employee hands over before their last day, and who receives it. For a contract: the notice period, what comes back to you, and in whose name the accounts, domains and licences are registered. “We will sort that out somehow” is also an answer, and worth remembering as one.
07
Who is writing this
Plainly: this was written by one side of the comparison. We are the external option, and we earn when a company chooses a contract over a hire. That is worth holding in mind through every paragraph above — and it is exactly why the part about when a hire wins is written out properly here rather than waved away in a sentence.
We work on a standing agreement with the scope and response times in writing, and with the documentation of the environment built on the client's side and left there — accounts, domains and licences registered to your company from day one, not to us. When a company grows into an IT department of its own, we hand over a tidy environment and say plainly that the moment has come. That is a harder sell than the version where the external provider is always the answer, but it is the only version that survives two years of working together.