Skip to content
Nearly empty office at night with a single person working at a distant desk
Managed IT Services

How Many IT Staff Does Your Business Actually Need?

The usual benchmark is one IT person per 30 to 100 employees, but that ratio measures ticket capacity, not coverage. A three-person team on business hours covers about 50 of the 168 hours in a week, leaving 118 hours with nobody accountable. Size your IT team by hours covered, not headcount.

Andrei Fomitchev Andrei Fomitchev · · 7 min read

Every IT manager who has ever asked for another headcount has been handed the same question back: what does the benchmark say? Someone pulls up a ratio, usually one IT person per fifty employees, compares it to your org chart, and concludes you are adequately staffed. Then a server dies on the Saturday of a long weekend and the same people who quoted the ratio start asking why nobody picked up.

This post covers where the standard IT staffing ratio comes from, the specific reason it misleads, and a simple piece of arithmetic that tells you more about your real exposure than any headcount benchmark will.

Most organizations run somewhere between one IT staff member per 30 employees and one per 100, depending on how technical the workforce is and how much is outsourced. That range is a reasonable starting point for budgeting ticket capacity, and a poor one for judging whether you are covered. Headcount ratios measure how many requests your team can absorb during business hours. They say nothing about the other 118 hours in the week, which is when the incidents that actually hurt tend to land.

The ratio question and the coverage question are different questions. A three-person IT team can be correctly sized by every benchmark you can find and still leave two thirds of the week with nobody watching. Size for hours covered, not bodies employed.

IT staffing ratio

The IT staffing ratio is the number of internal IT employees a business has relative to its total headcount, usually written as 1:50 or expressed as IT staff per 100 employees. It is a capacity benchmark used in budgeting to estimate how much support demand a team can absorb, and it assumes support demand only arrives during working hours.

What is a good IT-to-employee ratio?

There is no single correct number, and any source that gives you one without qualifying it is selling something. The working range most mid-market organizations land in is one IT person for every 30 to 100 employees. Where you sit inside that range depends on three things: how much of your stack is cloud-hosted rather than self-managed, how technical your users are, and how much of the work has already been handed to an outside provider.

Company profileTypical internal ratioWhat usually drives it
Professional services, mostly cloud, non-technical users1 per 60 to 100Little on-premises infrastructure to maintain
Manufacturing or logistics with plant systems1 per 30 to 50Production equipment, site networks, shift coverage
Regulated (health, finance, public sector)1 per 30 to 50Audit, access reviews, documentation overhead
Software or engineering firms1 per 80 to 150Technical users who self-serve most requests

Use the table to sanity-check a budget conversation. Do not use it to conclude you are safe. Across the GTA mid-market companies we work with, the teams that get into trouble are almost never the understaffed ones by this measure. They are the correctly staffed ones that never mapped their coverage.

How many hours a week does your IT team actually cover?

Do the arithmetic before you do anything else. A week contains 168 hours. A three-person IT team working standard business hours, with overlapping schedules and no formal on-call rotation, covers roughly 50 of them. That leaves about 118 hours a week, roughly 70 percent of the calendar, where your coverage is whoever happens to answer their phone.

118 hours

The weekly gap left by a three-person IT team on standard business hours. 168 hours in a week, roughly 50 covered.

Now subtract further. Vacation, statutory holidays, sick days, and training take another slice. If one of those three people is the only one who understands the firewall or the backup system, your real coverage for that system is one person’s calendar, not three.

This is the number worth taking into a budget meeting. It is concrete, it is impossible to argue with, and it reframes the conversation from “do we need another hire” to “who owns the other 118 hours.” When we run this calculation with a new client’s internal IT lead, the reaction is usually recognition rather than surprise. They already knew. They just had never written it down in a form a CFO could act on.

Why does the IT staffing ratio break down?

The ratio breaks down because it counts tickets and quietly assumes someone is on call for free. It was built to answer a help desk capacity question in an era when the worst thing that happened overnight was a stuck print queue. Three assumptions inside it no longer hold.

  • It assumes incidents arrive during business hours. Attackers deliberately choose evenings, weekends, and holidays because that is when response is slowest.
  • It assumes support work and security work are the same work. They are not. Monitoring alerts and investigating them is a separate discipline with separate tooling, and it does not fit in the gaps between help desk tickets.
  • It assumes people are interchangeable. Three generalists do not equal three of every specialty. Most small teams have exactly one person who genuinely understands each critical system.
Warning:

The single-point-of-failure problem is the one that gets skipped. If the only person who can restore from backup is on a plane, your recovery time objective is not what your documentation says it is. Test that assumption before an incident does it for you.

Which jobs can a small IT team never cover, no matter the headcount?

Three functions do not scale with internal headcount at mid-market size, because each one requires either round-the-clock staffing or a specialization you cannot justify hiring for. Recognizing them is what separates a coverage decision from a hiring decision.

Round-the-clock monitoring

Genuine 24/7 coverage takes somewhere between four and six people doing nothing else. No mid-market business is hiring five analysts to watch dashboards overnight, which is why this function is almost always bought rather than built.

Security detection and response

Investigating an alert is a different skill from resolving a ticket. The Canadian Centre for Cyber Security’s baseline controls expect organizations to have an incident response plan and the means to act on it, which presumes someone is available to notice the incident in the first place.

Vendor and firewall management

Firmware cycles, licence renewals, policy reviews, and end-of-support tracking across a firewall estate are steady background work that gets postponed whenever a user-facing problem appears. It is the most commonly deferred category we see, and deferred firewall maintenance is how a routine exploited vulnerability becomes an outage.

Before you argue for headcount, list every critical system and write one name beside each. Any system with the same name twice, or with a blank, is a coverage gap that hiring one more generalist will not close.

What does the coverage gap actually cost?

It shows up in two places, and the first one arrives long before any incident does. Cyber insurance renewals now ask you to evidence controls rather than describe them, including multi-factor authentication, endpoint detection and response, and monitoring. If you cannot demonstrate that someone is watching outside business hours, that is a premium increase, a coverage exclusion, or a declined application, and it happens on the underwriter’s timeline rather than yours.

The second is incident cost. IBM’s Cost of a Data Breach Report has consistently found that the longer a breach goes undetected and uncontained, the more it costs, and detection time is precisely the variable that overnight coverage changes. A weekend of unnoticed activity is not a scheduling inconvenience. It is the difference between an isolated endpoint and a restore from backup.

Good to know:

A useful test: pull your last cyber insurance application and read the monitoring question. Then check whether the answer you gave is true at 2am on a Sunday. Those two things disagreeing is more common than most leadership teams realize.

How do you size an IT team honestly?

Work in hours, not headcount. The exercise takes about thirty minutes and produces a number you can defend in a budget meeting.

Count your operating hours: Not office hours. The hours your systems need to be up, including any shift, warehouse, or after-hours work. For most businesses this is closer to 168 than to 40.

Count your genuinely covered hours: Scheduled staff only. An informal understanding that someone will probably answer their mobile does not count as coverage, because it cannot be measured or relied on.

Subtract to find the gap: This is your real exposure window, and it is the number that belongs in the budget conversation.

Name an owner for every critical system: One name per system. Duplicates and blanks are your single points of failure, independent of the hour count.

Decide what closes each gap: Some gaps close with a hire. Overnight monitoring and security response usually do not, at mid-market scale, because the headcount required to staff them properly exceeds what the workload justifies.

What comes out of this is rarely “hire two more people.” It is more often a short list where one or two items are genuine hiring needs and the rest are coverage the business should buy, because buying five analysts’ worth of overnight monitoring costs less than employing one.

The ratio was never the question

An IT team is not sized correctly when it matches a benchmark. It is sized correctly when every hour your business operates has someone accountable for it and every critical system has more than one person who understands it. Most mid-market teams fail the second test and never checked the first.

If you run the arithmetic and find a gap you cannot hire your way out of, that is the normal outcome, not a failure of planning. It is the reason co-managed IT exists: your team keeps the work it does well and the institutional knowledge that goes with it, and an outside team covers the hours and specializations that do not fit an internal headcount. We have been doing this for GTA businesses since 1994, and our 24/7 SOC and 15-minute critical response SLA exist specifically to cover the 118 hours most internal teams cannot. If you want a second opinion on where your coverage actually ends, our team will walk through it with you.

Sources

Written by Andrei Fomitchev

Managing Director · MSc.

As Managing Director, Andrei is responsible for the overall strategic and operational leadership of BALANCED+. He works at the intersection of business strategy and technology delivery, ensuring the company consistently meets the evolving needs of its clients while maintaining the highest standards of service. Andrei brings a wealth of experience in managed IT and cybersecurity […]

Frequently Asked Questions

Need IT Expertise?

Our team is ready to help. Book a free consultation and see how we can support your business.