Serving regulated mid-market businesses nationwide (888) 901-9686 · [email protected]
← Back to Insights

What 500 Small Firms Spend on IT and Security (and Where the Money Goes)

Small professional services firms follow predictable patterns in how they spend on IT — and where they get it wrong. Here's a plain benchmark to check your own numbers against.

ES
Elevate Solutions
June 26, 2026 · 4 min read

At some point, you will be asked to explain the IT bill. Maybe it is the annual budget review. Maybe a new invoice looks different from last month's. Either way, if you are running the office for a small professional services firm, you want one clear answer: is what we are spending normal?

Here is a plain breakdown of how small firms — ten employees or fewer, running Microsoft 365 Business Premium — typically distribute their IT and security dollars, and where the spending tends to be misaligned.

Small firms under 20 employees typically spread IT and security spending across five areas: productivity licensing, managed IT services, backup and recovery, supplemental security tools, and cyber insurance. Most firms overspend on aging hardware and redundant software while underinvesting in backup, email security, and security awareness training. Microsoft 365 Business Premium, professionally managed, is the most defensible starting point for this firm size.

The five places your IT budget actually goes

Productivity licensing

For most small firms, this means Microsoft 365 Business Premium — email, Teams, Office apps, Intune for device management, and a meaningful set of built-in security tools including Defender for Business and Conditional Access. The security value here is frequently left unconfigured. If you are paying for Business Premium and MFA is not enforced firm-wide or Defender for Business was never set up, you are leaving included protection unused.

Managed IT services

A managed service provider handles patching, monitoring, device management, and helpdesk support for a flat monthly per-user fee. For a firm under 15 people, this is one of the highest-leverage purchases in the budget. The logic that it is cheaper to handle IT in-house rarely holds up once you account for the employee hours spent troubleshooting, delayed fixes, unpatched systems, and the near-certain loss of institutional knowledge if the person managing it leaves.

Backup and recovery

This line item is consistently underweighted. Microsoft 365 includes data retention settings, but retention is not backup. Email, SharePoint files, and OneDrive data each need a separate cloud-to-cloud backup that creates point-in-time snapshots you can actually restore from. If backup does not appear on your current IT invoices, that is the first gap to close — ahead of almost anything else.

Security tools beyond the platform

Business Premium's built-in protections are solid for the price, but there are gaps. Exchange Online Protection handles a significant volume of threats, but not all of them. A dedicated email security layer, DNS filtering, and dark web monitoring for compromised employee credentials each address what the base subscription does not fully cover. None of these are large line items. Most small firms simply have not added them.

Cyber insurance

Premiums for small professional services firms vary by revenue, industry, and the security controls you can document at application time. Firms that can hand an insurer evidence of enforced MFA, active endpoint protection, and a tested backup policy tend to pay less and face fewer disputes at claim time. A qualified MSP should be the one supplying that documentation on your behalf.

Where small firms overspend

  • Aging hardware. Laptops running past their practical useful life cost more in support time and security exposure than they save on the asset side. Once a device stops receiving operating system security updates, it is a liability, not an asset.
  • Redundant software subscriptions. Most small firms carry two or three SaaS tools that duplicate something already included in Microsoft 365. A short audit almost always finds the overlap.
  • Break-fix IT support. Per-incident billing feels controllable. Over 12 months it rarely is — and it produces no ongoing monitoring, no documentation, and no accountability between service calls.

Where small firms underinvest

  • Email security. Business email compromise is the most common and most costly attack vector for firms this size. The filtering layer included in your subscription is not sufficient on its own.
  • Security awareness training. Regular phishing simulations and short training modules reduce the likelihood of a successful attack. Most small firms have nothing of this kind in place.
  • Backup testing. Paying for backup without periodically testing a full restore is common. An untested backup is not one you can rely on when it matters.
  • IT documentation. Who holds admin credentials? Where are the licenses managed? What is the recovery procedure if access is lost? Firms with a managed services agreement rarely face this problem. Firms managing IT themselves almost always do.

How to read your own bill

Pull three months of IT invoices and sort every line item against the five categories above. If backup is absent, that is a gap. If the only IT support you have is a number you call when something breaks, ask a managed services provider to price out an ongoing agreement — the comparison is usually straightforward.

If you already have an MSP, ask them for a one-page summary of what your monthly fee covers and what it does not. A provider that genuinely knows your environment can produce that in a day. If they cannot, that is useful information too.

Elevate Solutions' security and IT advisory team delivers managed cybersecurity (MDR/MXDR), managed IT, and compliance guidance (HIPAA, SOC 2, PCI DSS) for regulated mid-market firms across Los Angeles.

Reviewed by David Faramarzi · Founder, Elevate Solutions
Share:
Next story A Windows patching routine for small firms with no IT department June 26, 2026 · 5 min read