The 5 Reasons Startups Avoid IT Investment (And Why All of Them Are Wrong)

In hundreds of conversations with founders and ops leaders, I’ve heard the same objections to IT investment over and over. They’re understandable. They’re also, on examination, not correct.

Here are the five most common ones — and why they don’t hold up.

“We’re Too Small for That”

This is the most common objection, and it confuses size with risk.

A 20-person company has real data — customer data, financial data, proprietary information. It has real devices — laptops that get lost, stolen, or compromised. It has real people who join and leave — and whose access needs to be managed.

The risk doesn’t scale with headcount. A breach affecting 20 people’s customer data is the same legal liability as a breach at a 200-person company. A stolen laptop with unencrypted data is the same risk whether the company has 15 employees or 150.

The counter-argument that holds is that the *complexity* of IT scales with size. But the *need* for basic security fundamentals does not.

MDM, MFA, a password manager, and a basic onboarding/offboarding process are relevant at 15 people. They’re essential at 50.

“We’ll Sort It When We’re Bigger”

This is the IT debt argument — the idea that the cost of fixing things later is roughly the same as the cost of building them right now.

It isn’t. IT debt compounds.

A company at 15 people with no MDM and informal onboarding has a manageable problem. That same company at 50 people, having added 35 more people with the same informal process, has a significantly larger problem. They have more unmanaged devices, more inconsistent setups, more access sprawl, more undocumented processes.

The fix at 50 people costs more in time and disruption than the fix at 15. The ongoing risk during the period between “we should fix this” and “we actually fixed this” is real.

The right time to build IT foundations is always as early as possible.

“Our Engineers Handle It”

This one has a particular cost that rarely gets calculated: the opportunity cost of senior technical people doing IT work.

An engineer earning £80,000 per year costs roughly £38 per hour. If that engineer spends 3 hours a week on IT-adjacent tasks — setting up laptops, managing accounts, troubleshooting connectivity issues — that’s £114/week, £5,900/year.

For work that wasn’t what they were hired to do. For work that creates no product value. For work that gets done inconsistently because it’s not their core competency.

Separately: engineers who do IT are not IT managers. They’re usually good at the technical aspects and less experienced with the operational, security, and compliance dimensions. The MDM gets set up but never properly configured. The security policies don’t get written because that’s not interesting work for an engineer.

The “engineers handle it” approach produces technically functional but operationally incomplete IT.

“We Can’t Afford a Full-Time IT Person”

This objection is usually true — and also irrelevant, because a full-time IT person isn’t the only option.

Fractional IT exists precisely for this situation. A fractional IT consultant works with your company for 2-3 days per month, handling the IT programme at a fraction of the cost of a full-time hire.

For a 30-person company, the difference:

– Full-time IT Manager: £55,000-70,000 salary plus employer costs = £65,000-85,000 total

– Fractional IT consultant (2 days/month): £24,000-36,000 per year

The fractional model makes senior IT expertise accessible at a cost point that works for companies at the 20-60 person stage.

“Nothing Bad Has Happened Yet”

This is the most understandable objection. It’s also the most dangerous.

“Nothing bad has happened” is a statement about the past. IT security is a statement about the future. And the future contains threats that the past didn’t prepare you for.

The companies that experience security incidents are not uniquely negligent. They’re companies that assumed they were fine until something proved otherwise.

Ransomware doesn’t target companies by size or funding status. Credential stuffing attacks don’t care whether you’ve been breached before. A lost laptop is a risk regardless of whether you’ve lost one before.

“Nothing bad has happened yet” is not evidence of safety. It’s evidence of luck — luck that has limits.

The companies that build IT foundations before an incident are the ones that avoid the incident. The ones that wait for the incident to motivate them spend months recovering from something that didn’t have to happen.

If any of these objections have been holding your company back, I’d encourage you to start with the free IT risk assessment at itops.zlefterov.com. It takes 15 minutes and gives you a clear, honest picture of where you stand.

Leave a Comment

Your email address will not be published. Required fields are marked *