SeekTech Find a supplier
Buying IT

When Outsourcing IT Stops Making Sense

Headcount, downtime tolerance and compliance load decide whether an SME should hire in-house, outsource, or run both. How to tell which you are.

The Seek Tech editors30 June 2026

The usual framing is outsource versus hire, as though it were one decision made once. In practice most Malaysian SMEs end up with a mix, and the useful question is not which but which parts, and when does that change.

Three things move the answer.

Headcount, but not the way you would guess

The number that matters is not employees. It is endpoints and systems: laptops, phones, servers, sites, and the business applications someone has to administer.

Below roughly twenty endpoints on standard cloud software, a full-time IT hire is usually poor value. The work is real but bursty — most days need an hour, some days need twelve — and one person cannot cover leave, illness or a second site.

Somewhere past fifty endpoints, or the moment you have a second location or a server that must stay up, the arithmetic starts to move. Not because outsourcing has failed, but because the volume of small, context-heavy requests grows faster than a ticket queue handles gracefully.

How long you can be down

This is the sharper test, and it is worth answering in currency.

If your office losing email for a day is annoying but survivable, an external supplier on a next-business-day response is a sound arrangement. If four hours of downtime means missed shipments, idle production or a contractual penalty, then response time is the product you are buying, and it needs to be priced and written accordingly — possibly alongside someone on site.

Work it out concretely: pick your worst realistic outage, put a number on the hours, and compare it against the cost difference between response tiers. The decision usually makes itself, and it is frequently the opposite of what the org chart suggests.

Compliance load

Sector matters. If you handle payment card data, operate in a regulated industry, hold significant volumes of personal data, or answer client security questionnaires as a condition of contract, you have an ongoing obligation rather than an occasional project.

Two ways to meet it. Buy the specialist work — audits, testing, monitoring — from firms that hold the relevant credentials. Or build enough internal capability to own the programme and buy only the specialised parts.

What does not work is assuming your general IT supplier covers it because they are the IT supplier. Managed IT and security assurance are different services with different credentials, and they are usually different companies.

Co-managed is the common landing point

The arrangement most mid-sized businesses converge on is neither: one internal person who knows the business, its systems and its people, plus an external supplier for depth, out-of-hours cover, holiday cover and specialist work.

It works when the boundary is written down and fails when it is not. Put in the contract:

  • Who holds administrator credentials for each system, and who approves changes.
  • Who is first line for a user with a broken laptop, and who is second.
  • Which systems the supplier may change without asking, and which need your sign-off.
  • Who owns the documentation, and where it lives so both parties can read it.
  • How out-of-hours escalation reaches a human, and who pays for it.

Ambiguity here produces the two classic failures: both parties assuming the other applied the patch, and both assuming the other has the backup.

What should never leave the building

Whatever the split, some things stay yours:

  • Ownership of accounts and tenants. Your domain, your cloud tenant, your phone numbers, your management consoles, all registered to your company.
  • A copy of the documentation. Network diagram, asset inventory, licence records, recovery procedure — held by you, not only by them.
  • The vendor relationships that matter. Know who your carrier, landlord and principal contacts are. Relationships mediated entirely through a supplier disappear with that supplier.
  • The decision about what data you hold and where. That obligation is not delegable, whoever operates the systems.

A rough decision, stated plainly

Under twenty endpoints, no server, standard cloud software, a day of downtime survivable: outsource, and spend the effort on the contract instead.

Fifty or more endpoints, or multi-site, or a server that has to stay up, or a compliance obligation: get someone internal who knows the business, and keep a supplier for depth and cover.

In between, which is where most businesses actually are: outsource the work, but hire or appoint an internal owner — even at part of a role. Someone has to hold the supplier to the contract, and that person cannot be the supplier.

Ask for

A written split of responsibilities — what the supplier owns, and what stays yours regardless.

Category-level guidance. It is not a statement about any company listed on this site, and it is not legal advice — confirm current requirements with the issuing body before you rely on them.