← Back to Blog
Small business owner reviewing an IT budget spreadsheet at a desk
IT Budgeting Managed IT
Inter-Quest

How Much Should Your Business Spend on IT?


Most business owners fall into one of two camps on IT spending. Either they treat it as a fixed cost to keep as low as possible, or they have never had a real benchmark to compare against and are simply guessing. Neither approach tells you whether your number is actually right.

There are two straightforward ways to check. Most small businesses should allocate 4% to 7% of annual revenue to their IT budget.[1] As an alternative, the standard per-employee benchmark is $1,000 to $3,500 annually per employee.[2] Neither number is a rule, but both give you something concrete to measure your own spending against instead of a gut feeling.

Getting this number right matters more than it might seem. Spend too little and you are quietly building up risk that eventually surfaces as downtime, a breach, or a scramble to fix something that should have been handled months earlier. Spend too much without a reason and you are tying up cash that could go toward hiring, inventory, or growth. The goal is not to find the lowest possible number. It is to find the number that actually matches what your business needs to run and stay protected.

Two Ways to Benchmark How Much You Should Spend on IT

Revenue-based budgeting is the more common approach. Small businesses with less than $50 million in annual revenue typically average 4% to 6.9% of annual revenue on IT, according to data from Deloitte and Gartner.[1] Organizations with regulatory exposure, rapid growth, or multi-location complexity tend to run higher, typically 8% to 12% of revenue.[1]

The per-employee model works better for businesses where revenue swings a lot year to year, or where headcount is a more stable proxy for how much technology support is actually needed. A meaningful share of that per-employee number, typically 20% to 40% of the total IT budget, goes toward the security tools and monitoring built into day-to-day IT support rather than sitting off to the side as an extra.[2] That is worth keeping in mind, because a bare-bones IT quote that leaves real security coverage out will always look cheaper than one that includes it.

Neither benchmark is meant to be applied blindly. Building a budget from your actual operational needs and compliance requirements tends to work better than applying a flat percentage or per-employee figure on its own.[2] The benchmarks are a sanity check, not a formula.

A useful way to use both numbers together is to run your own math each way and see how far apart the results land. If your revenue-based number and your per-employee number point to roughly the same budget, that is a good sign your spending is proportional to both your size and your income. If they point to very different numbers, that gap is usually worth investigating rather than ignoring. It often means either your headcount has grown faster than your revenue, or your revenue has grown faster than your technology and support needs have kept up.

Either way, the point of running both numbers is to catch a budget that looks fine on paper but is not actually sized to your business. A revenue percentage that looks reasonable can still be too low if you have added staff faster than you have added support. A per-employee number that looks generous can still be too low if it has not kept pace with a growing revenue base and the added complexity that tends to come with it.

What Managed IT Actually Costs Per User

If your business uses or is considering managed IT services, the per-user number is easier to pin down than the revenue percentage. Managed IT services typically range from $100 to $400 per user per month, with $150 to $200 per user per month typical for small businesses.[3] Where you land in that range depends on your environment, risk profile, compliance obligations, and industry, and compliance requirements typically add 20% to 40% above standard rates.[3]

To put that in real terms, a 30-person company at a standard tier lands around $5,250 per month, plus a one-time onboarding fee of one to three times the monthly rate.[3] That is a useful number to hold onto, because it turns an abstract percentage into something you can compare directly against a quote or a current bill.

The onboarding fee catches some owners off guard, but it reflects real work: documenting your environment, migrating accounts and devices, and setting up the monitoring and security tools that make the ongoing monthly rate possible. Treating that as a one-time setup cost rather than folding it into a monthly average gives you a clearer picture of what steady-state IT spending actually looks like once the initial transition is behind you.

That monthly rate is meant to be a complete number, not a base price with security tacked on afterward. When you compare quotes, make sure the per-user figure you are looking at already includes monitoring, patching, and basic security coverage rather than pricing those in later as extras once you are locked in.

This is where a lot of budget comparisons go wrong. Two quotes with similar-looking per-user numbers can cover very different amounts of actual protection, and the cheaper one is not always the better deal once you look at what is and is not included.

The Real Cost of Underspending

The number that changes most owners’ minds is not the recommended budget. It is the cost of getting it wrong. The average small business cyberattack costs $120,000 to $200,000 once you account for downtime, data recovery, lost business, and reputational damage.[4] The average cost of a data breach for a small business reached $164,000 in 2025.[1]

Forty percent of small and medium-sized businesses say an attack costing $100,000 or less could put them out of business.[5] That is the number worth sitting with. It means the gap between a reasonable IT budget and a single bad incident is not close. Prevention costs an estimated 50 to 60 times less than recovery, at $5,000 to $15,000 annually versus $500,000 or more for a single incident.[4] Underspending on IT is rarely a savings. It is closer to a bet, and the math on that bet does not favor the business making it.

This is also where the revenue-percentage and per-employee benchmarks earn their keep. They are not just budgeting tools. They are a way of asking, before anything goes wrong, whether your current spending would actually hold up against the kind of incident that puts smaller businesses out of business entirely. A business spending well below either benchmark, with security treated as an afterthought rather than something built into the plan from the start, is carrying more exposure than the monthly savings are worth.

Building a Budget That Fits Your Business

None of these benchmarks are meant to hand you an exact number. They are meant to tell you whether your current spending is in a reasonable range or badly off in one direction. A business spending well under 4% of revenue or under $1,000 per employee, without real security coverage built into that number, is very likely underspending relative to the risk it is carrying. A business spending well above 12% of revenue with no added complexity to justify it is worth a second look too.

As a business owner myself, I know how frustrating it can feel when you’re not in control of your technology. — Matt Rosenthal, CEO, Mindcore Technologies[6]

That sense of control comes from treating your IT budget as one number you actually understand, not a base rate with security, support, and monitoring bolted on separately later. The fastest way to get past benchmarks and see an actual number for your team is to run it directly. Find out today how much per user it would cost to have your team fully covered using our pricing calculator, built specifically to turn these kinds of ranges into a real figure for your business. If you would rather talk through your specific setup, a conversation about managed IT support can help you see exactly where your current budget stands and where the gaps are before they turn into a bigger cost. Contact us whenever you are ready to talk specifics.