The Hidden Operating Cost of IT Sprawl: When Apps, Devices, and Vendors Multiply Faster Than Headcount
A research report on the operating cost of IT sprawl for companies of 30 to 300 people. It explains why that cost scales with people multiplied by systems rather than with the software invoice, sets out what Zylo's 2026 SaaS Management Index, Productiv's State of SaaS series and Flexera's 2026 State of ITAM report actually measure and where, and gives a practical inventory-and-reduction framework. Observations about Hong Kong and Singapore clients are Brocent's own and are labelled as such.
The short answer: SaaS sprawl cost is mostly not the software bill. When the count of apps, devices and vendors grows faster than headcount, the cost lands in onboarding, offboarding, access reviews, support tickets and accounts nobody owns. Zylo's 2026 index puts unused licences at 36%; the larger, less visible cost is the operating work each extra system adds per person.
Most conversations about IT cost start with the invoice: what a company pays for software, hardware and support each month. This report is about the part of IT cost that never appears on an invoice line. It comes from the number of things a company runs — applications, devices, accounts, vendors — rather than from what each of them costs.
The argument is simple. Every additional system adds a small, recurring amount of operating work: a login to create when someone joins, an account to remove when someone leaves, a permission to review, a renewal to track, a set of tickets to absorb. One extra system is trivial. Dozens of them, multiplied across every joiner and leaver, are not. And because that work is spread across HR, finance, managers and IT, nobody sees it as a single bill.
This report sets out what the published data actually measures, where that data was gathered, where the cost really lands in a 30-300-person company, and what consolidation does and does not fix. It is the mechanism companion to our earlier research on what IT spend does to a growing company's operating margin, which asks the macro question of how much IT spend belongs in a P&L. This piece asks a narrower one: what happens when the count of systems outgrows the count of people.
A disclosure. Brocent is a managed IT provider. One of the remedies discussed below — consolidating onto a managed stack — is something we sell, so we have a commercial interest in how this subject is framed. We have tried to handle that by sourcing every market figure to a named publisher, by labelling our own observations as ours, and by stating plainly where a best-of-breed approach is the better choice.
Key findings
- The named data comes from large organisations. Zylo's 2026 SaaS Management Index, built on more than 40 million licences and US$75 billion in spend under management, reports an average of 305 SaaS applications per company. Zylo's own statistics page puts median annual SaaS spend across organisations at US$20.6 million. That is the profile of a large enterprise, not a 30-300-person firm, and its figures should be read that way.
- Unused licences are a persistent share of the portfolio. Zylo's 2026 press release reports that organisations leave an average of 36% of SaaS licences unused. Productiv's 2023 State of SaaS series reported that only 47% of licences were used over a 90-day period.
- IT no longer controls most of what is bought. Zylo reports that business units now control 81% of SaaS spend, while IT directly manages 15%, and that expense-based SaaS spend rose 267% year over year.
- Visibility is getting worse, not better. Flexera's 2026 State of ITAM report, a survey of 512 technology professionals, found complete IT asset visibility at 36%, with only 31% reporting accurate visibility into AI software. 43% reported increased wasted SaaS spend over the past year.
- Small companies are not exempt — per head, they may pay more. Productiv's 2023 data reported that small businesses paid 49% more per employee for SaaS than large enterprises. We found no comparable current figure.
- The operating cost is mostly unmeasured. No source we could verify publishes a credible per-company figure for the time spent onboarding, offboarding and reviewing access across a sprawling stack. What we say about that cost in Hong Kong and Singapore is Brocent's own qualitative observation, and is labelled as such.
Sprawl is a headcount-ratio problem, not a software-budget problem
The usual framing of SaaS sprawl cost is about waste: licences paid for and not used. That is real, and it is the part the named data measures best. But for a company of 30 to 300 people, it is usually the smaller part of the problem.
The more useful measure is a ratio: how many systems does each person touch, and how fast is that number growing compared with headcount? A company that adds ten employees and two applications in a year is in a different position from one that adds ten employees and fifteen applications, even if both spend the same on software.
The reason is that most IT operating work scales with the product of people and systems, not with either alone.
- Onboarding scales with joiners multiplied by the number of systems each joiner needs.
- Offboarding scales with leavers multiplied by the number of systems each leaver had.
- Access reviews scale with people multiplied by systems multiplied by the number of permission levels in each.
- Support scales with the number of distinct systems people can have a problem with, since every additional system brings its own login, its own failure modes and its own vendor to contact.
When headcount grows by 20% and the system count grows by 20%, the product grows by roughly 44%. When system count grows faster than headcount, the operating load can grow much faster than either line on its own. This is why a company can feel that IT is getting harder to run even though its software budget looks reasonable.
Why the invoice hides it
Software invoices measure price multiplied by seats. They do not measure the minutes an office manager spends creating accounts on a new joiner's first morning, the half-day a finance lead spends reconciling which subscriptions are still in use, or the hours an engineer spends tracing which of eight tools a former employee still has access to. Those minutes are paid for, but they are paid for in salaries already on the books, so they rarely appear as an IT cost at all.
What the named data actually measures — and where it was measured
Three publishers produce the most widely cited figures on this subject. Each measures something specific, and each has a sample that matters. Before using any of their numbers, it is worth being clear on both.
The market-scope caveat, stated once and applied throughout: all three datasets are predominantly US or global, drawn from customers or survey respondents of software-management vendors. None is a measurement of Hong Kong or Singapore companies, and none is a measurement of firms with 30 to 300 employees. We use them for direction and mechanism, not as figures that describe a Hong Kong or Singapore business.
Zylo: the 2026 SaaS Management Index
Zylo is a SaaS management platform. Its annual index is built from its own customer data. The 2026 edition was released on 29 January 2026, and Zylo describes it as built on more than 40 million SaaS licences and US$75 billion in spend under management.
What the 2026 edition reports, in Zylo's own published materials:
- An average of 305 SaaS applications per company, per Zylo's SaaS statistics page.
- 36% of SaaS licences unused on average, per the 2026 press release. Zylo's statistics page separately reports licence utilisation improving from 47% in 2024 to 54% in 2025, and other Zylo material cites a higher unused share over a 30-day window. Those are different measures over different periods, which is why we quote the press-release figure and name it as such rather than blending them.
- Licence waste falling from US$20.9 million to US$19.8 million per company, again from the statistics page.
- Business units controlling 81% of SaaS spend, with IT directly managing 15%.
- Expense-based SaaS spend up 267% year over year, with ChatGPT the most expensed application.
- Median SaaS spend per employee of US$9,455.
- AI-native application spend up 108% year over year overall, and 393% in organisations with more than 10,000 employees.
- Large enterprises adding an average of 21 applications per month.
The sample matters more than any single number. Zylo's statistics page puts average annual SaaS spend at US$55.7 million and the median at US$20.6 million, and the customers named in the press release include AbbVie, Adobe, Atlassian, Intuit and Salesforce. A 30-300-person company will not have 305 applications, and it will not waste US$19.8 million a year. What does transfer is the direction: portfolios grow, a large share of licences go unused, and purchasing has moved away from IT.
Productiv: the State of SaaS series
Productiv is also a SaaS management platform, and its reports are likewise built from customer data. Its most recent edition we could find is the 2023 State of SaaS series. As reported by Help Net Security on 4 July 2023, it found:
- Average SaaS spend of US$9.6K per employee in 2023 (projected).
- Small businesses paying 49% more per employee than large enterprises.
- Only 47% of SaaS licences used over a 90-day period on average.
- 51% of SaaS applications still sitting in shadow IT.
Productiv's earlier 2021 State of SaaS Sprawl report is the source of the widely repeated statement that 56% of applications are owned and managed outside IT. CIO Dive's coverage from September 2021 describes that report as based on 30,000 applications used by 190 companies. It is five years old. It is often quoted today without a date, and it should not be presented as a current measurement.
The small-business figure is the most relevant Productiv number for this report's audience, but it is three years old and comes from a vendor's own customer base. We found no current, independent measurement of SaaS spend per employee for small firms, in any market.
Flexera: the 2026 State of ITAM report
Flexera's annual State of ITAM report is a survey rather than a platform dataset, and it covers the whole IT estate — on-premises software, SaaS, cloud and, now, AI — rather than SaaS alone. The 2026 edition was released on 24 June 2026 and surveyed 512 technology professionals worldwide.
Its findings are about visibility rather than dollars:
- Complete IT asset visibility at 36%, with 62% reporting partial visibility.
- 66% reporting visibility into their SaaS environment, against only 31% reporting accurate visibility into AI software.
- 43% reporting increased wasted SaaS spend over the past year, and 59% reporting increased wasted AI spend.
- 48% audited by a software vendor in the last year, and 44% reporting more than US$1 million spent on software audits over three years.
Flexera does not publish a per-company dollar figure for sprawl, and we do not derive one from it. Its value here is the visibility argument: when roughly two-thirds of organisations in a survey of IT professionals cannot see their whole estate, the operating cost of that estate is necessarily being estimated rather than measured.
What we did not use
The source plan for this report called for Gartner's IT Key Metrics Data as a denominator for IT spend per employee. Those figures sit in Gartner's paid research, and we found no Gartner press release this run that states a per-employee figure we could cite. We have therefore not expressed sprawl cost as a share of total IT spend per head. Zylo's and Productiv's SaaS-per-employee figures, both labelled above, are the only per-head numbers in this report.
Where the cost actually lands
If the invoice is the visible part of sprawl, the operating work is the rest. In our experience it lands in five places. None of them has a reliable public benchmark, so this section describes the mechanism and gives a way to measure it in your own company rather than an industry average.
Onboarding
Every new joiner needs accounts created in each system their role requires: the identity platform and email, the collaboration tools, the file store, the finance or CRM application, the HR system, the password manager, the device management enrolment and often several department-specific tools. In a consolidated environment, most of these are provisioned from one identity source. In a sprawling one, each is a separate step, often owned by a different person.
The cost shows up as delay as much as labour. A joiner who cannot reach a key system on day one, or day three, is being paid to wait. That cost is rarely recorded anywhere.
Offboarding
Offboarding is onboarding in reverse, with a security consequence attached. Every system a leaver had access to needs that access removed, their data transferred or preserved, and any licence reassigned or cancelled. When systems were bought outside IT, the person running the offboarding may not know they exist.
Access reviews
Periodic reviews of who can access what are a normal control for regulated firms and an increasingly common expectation from customers and insurers. Their cost scales with the number of systems and the number of permission levels in each. A review that covers one identity platform is a short exercise. A review that has to reach into a dozen applications, each with its own admin console and its own definition of an administrator, is a project.
Ticket surface area
Every additional system is another thing that can break, another login people forget, another integration that can fail and another vendor whose support process someone has to learn. For a company that outsources its service desk, ticket volume is often the cost driver. More systems usually mean more ticket categories, more escalations to third parties and longer time to resolve, because the engineer handling the ticket has to know or learn each of them.
Licence waste and renewal overhead
This is the part the named data measures best, and it is real. Zylo reports 36% of licences unused on average in its customer base; Productiv's 2023 figure was 47% used over 90 days. Zylo's statistics page also reports the average organisation in its data managing 211 SaaS renewals a year. For a small company the counts are lower, but the overhead per renewal does not shrink with company size: someone still has to notice the renewal date, decide whether the tool is still needed and cancel it if not.
A way to measure it in your own company
Because no credible public benchmark exists for these costs at small-company scale, the most useful number is your own. It can be estimated with four inputs, all of which a company can count:
- Systems per role: how many distinct applications and accounts a typical new joiner needs.
- Joiners and leavers per year: from HR records.
- Minutes per account: how long it takes to create and later remove one account, including the time spent waiting on whoever owns that system.
- Review cycles: how often access is reviewed, and how many systems each review has to reach.
Multiplying systems per role by joiners and leavers, and by minutes per account, gives an hours figure for provisioning alone. Adding review time gives a rough floor for the operating cost of the current stack. This is an estimating method, not an industry figure; the result will be specific to your company and only as good as the counts that go into it.
The security half of the bill — orphaned accounts and unowned tools
The cost of sprawl is not only time. The same mechanism that makes offboarding slow makes it incomplete, and an incomplete offboarding is a security exposure.
What follows is Brocent's own operational observation, drawn from onboarding and offboarding work and from access reviews across our client base in Hong Kong, Singapore and other markets we serve. It is qualitative. We do not publish averages or percentages about client behaviour, because our client base is not a representative sample and we have not measured it in a way that would support one.
What shows up in onboarding tickets
The number of distinct systems a new joiner needs provisioned is consistently higher than the client expected when we first ask. The gap is usually department-level tools — a design application, a project tracker, a survey tool, a specialist finance add-on — bought by a team lead on a card and never registered with whoever runs IT. They surface when a new hire in that team asks for access and nobody in IT knows who the administrator is.
What shows up in access reviews after departures
When we run an access review for a new client, or after a run of departures, the finding we see most often is the orphaned account: an account belonging to someone who has left, still active in an application outside the main identity platform. The common causes are predictable:
- the application was never connected to single sign-on, so disabling the main account did not disable it;
- the person who bought the tool was also its only administrator, and they are the one who left;
- the account was a shared or generic login whose password was never rotated.
We are not claiming these accounts are routinely exploited. We are saying they are routinely present, and that each one is a credential outside the company's control.
Why this matters more as AI tools arrive
Flexera's 2026 survey found only 31% of respondents with accurate visibility into AI software, and Zylo reports ChatGPT as the most expensed application in its 2026 data. AI tools are being adopted the way earlier SaaS was: by individuals, on cards, often with company data pasted into them. The same mechanism applies, and it applies with a data-handling question attached that earlier productivity tools did not raise as sharply.
This report stays with a narrow point: sprawl creates unowned access, and unowned access is a cost even when nothing goes wrong, because someone eventually has to find it.
Why sprawl accelerates exactly when a company is growing fastest
Sprawl is not evenly distributed over a company's life. In our experience it concentrates in growth phases, and the reasons are structural rather than a failure of discipline.
- Teams form faster than processes. When a company adds a new function — a sales team, a marketing team, an office in a new market — that team arrives with tools it already knows. Asking it to wait for an IT review would slow the very growth the company is pursuing.
- Buying is easy and decentralised. Zylo's 2026 data shows business units controlling 81% of SaaS spend and expense-based purchasing up 267% in a year. Flexera describes applications entering the environment through expense reports, credit cards and browser logins. The barrier to adding a tool has fallen close to zero.
- Nobody owns the inventory. In a 30-300-person company, IT is often a part-time responsibility or an outsourced function engaged per ticket. Neither model naturally includes the job of knowing every system in use.
- Acquisitions and new offices import whole stacks. A company that buys another business or opens in a second market tends to inherit a second set of tools. Running two identity platforms, two file stores or two collaboration suites side by side is common for months and sometimes years.
- Removal is nobody's project. Adding a tool solves an immediate problem for someone. Removing one creates a migration task with no visible benefit to the person asked to do it. So tools accumulate.
This is why a growing company can find, a year or two into rapid hiring, that its IT environment feels more fragile than it did at half the size, even though nothing obvious has gone wrong.
Consolidated stack vs. best-of-breed vs. unmanaged sprawl
There are three broad ways a company ends up running its IT. Only one of them is a failure state, and it is not the one usually criticised.
The three models compared
- Consolidated stack: most needs are met by one productivity and identity platform plus a small, deliberately chosen set of additional tools, operated by one provider or team. Strengths: fewer accounts per person, provisioning from one identity source, one support path and a short access review. Weaknesses: some individual tools are less capable than a specialist alternative, and the company depends more heavily on one platform and, if outsourced, one provider.
- Best-of-breed: the company deliberately chooses the strongest specialist tool for each function and invests in integrating and governing them, usually through single sign-on, automated provisioning and a maintained inventory. Strengths: each team gets the best tool for its job, which can matter a great deal for engineering, design or analytics-heavy firms. Weaknesses: integration and governance work is real and ongoing, and it needs someone who owns it. This is a legitimate choice, not a failure — it fails only when the governance is left out.
- Unmanaged sprawl: tools are added as needed by whoever needs them, with no central inventory, inconsistent single sign-on and no owner for removal. Strengths: speed in the moment. Weaknesses: every cost described in this report, plus the security exposure of orphaned accounts.
The real comparison is not consolidated against best-of-breed. Both are managed. The comparison that matters is managed against unmanaged, and most companies that think they are running best-of-breed are, on inspection, running unmanaged sprawl with some good tools in it.
Where consolidation fits Brocent's own offer
Brocent's published Managed IT Support pricing shows plan tiers with per-user monthly prices in four markets, and lists the same set of services included in every plan — among them 24/7 NOC monitoring, help desk, managed firewall, patch management, base antivirus and EDR, backup and disaster recovery, password and credential management, DMARC monitoring, web content filtering, and customer-owned documentation and credentials. Several of those are things a small company would otherwise buy as separate subscriptions from separate vendors. Some further security services appear on the page as add-ons, and some of those add-on prices are marked as indicative pending market confirmation; we do not quote them here.
The checkable point is narrow: a bundled managed plan replaces several separately procured tools and their separate renewals with one contract and one support path. Whether that is cheaper than a company's current stack depends on what the company currently runs, and the honest way to answer it is to count. Our pricing overview sets out the options in one place.
A practical inventory-and-reduction framework
The following framework is the sequence we use in assessments. It does not require new software, and the first two steps are worth doing whether or not anything is changed afterwards.
Step 1: Build the inventory from money, not from memory
Asking managers which tools they use produces an incomplete list. Searching card statements, expense claims and accounts-payable records for recurring software charges produces a much more complete one, because Zylo's and Flexera's data both point to purchases entering through expenses and cards. Add the applications connected to your identity platform and the tools your IT provider manages.
Step 2: Give every system an owner
For each item, record a named business owner, a named administrator, the renewal date, the number of paid seats and whether it is connected to single sign-on. A system without a named owner is the first candidate for review; a system whose only administrator has left is an immediate access risk.
Step 3: Map systems to roles
For each role, list the systems a new joiner actually needs. This becomes the onboarding checklist and, reversed, the offboarding checklist. It also shows where several teams are paying for overlapping tools.
Step 4: Decide keep, consolidate or retire
Sort every system into one of three groups:
- Keep: genuinely specialised, actively used and owned.
- Consolidate: duplicates a capability already present in the core platform or another kept tool.
- Retire: unused, unowned or replaced.
Step 5: Connect what remains to identity
Every kept tool that supports single sign-on should use it, so that disabling one account removes access everywhere. Tools that cannot should be listed explicitly on the offboarding checklist.
Step 6: Make the inventory a standing process
The inventory decays from the day it is built. A quarterly check of new recurring charges, combined with an access review on the same cycle, keeps it current. This is the step most companies skip, and the reason the first inventory often has to be rebuilt from scratch.
If you would rather have the first pass done independently, a structured IT assessment and audit covers identity, endpoints, backup and the application inventory in one exercise.
What consolidation does and does not fix
Consolidation is the natural response to sprawl, and it is what we sell, so it is worth being precise about its limits.
What it fixes
- Fewer accounts per person, so onboarding and offboarding take fewer steps.
- One identity source for most access, so disabling one account removes most access at once.
- Fewer renewals and fewer vendors to track, negotiate with and pay.
- A shorter, more reliable access review.
- One support path, so tickets do not bounce between vendors.
What it does not fix
- Ownership. A consolidated stack still needs someone to decide what is added to it. Without that, sprawl returns within a year or two, inside the new platform or around it.
- Shadow purchasing. As long as anyone can buy a tool on a card, some will. Consolidation reduces the need; it does not remove the ability.
- Genuine specialist needs. Some teams need specialist tools. Forcing them onto a general-purpose platform can cost more in lost productivity than the sprawl it removes.
- Migration cost. Moving data and habits from several tools to one is real work, and the benefit arrives after the cost.
- Provider dependence. Consolidating onto one outsourced provider concentrates risk in that provider. That is a reason to check the provider's documentation, credential-ownership and exit terms before signing, not a reason to avoid consolidation.
For a worked example of one company going through this, see Five Vendors, One Bill, the story of a Hong Kong professional services firm that collapsed five IT suppliers into one contract. And for how a managed model compares with building the same capability in-house, our managed services overview sets out what is included.
Frequently asked questions
What is SaaS sprawl cost?
SaaS sprawl cost is the total cost of running more software applications than a company can effectively manage. It includes licence waste, but the larger part for most small and mid-sized companies is operating work: provisioning and removing accounts, reviewing access, handling support tickets and tracking renewals across many separate systems.
How many SaaS apps does a company use?
Zylo's 2026 SaaS Management Index reports an average of 305 applications per company in its customer base, which skews towards large enterprises with median annual SaaS spend of US$20.6 million. A company of 30 to 300 people will typically run far fewer. We are not aware of a credible current public figure for that size band, so the useful number is your own inventory.
What is shadow IT, and what does it cost?
Shadow IT is software bought and run outside the IT function's knowledge or control. Productiv's 2023 data put 51% of applications in shadow IT; its widely quoted 56% figure dates from 2021. The cost is less the subscription itself than the access it creates outside central control and the time spent finding it later.
How much unused software licence waste is typical?
Zylo's 2026 index reports 36% of licences unused on average, and Productiv's 2023 series reported 47% of licences used over a 90-day period. Both come from vendor customer bases skewed towards larger organisations. They indicate direction, not a benchmark for a specific company.
How long should onboarding and offboarding IT take?
There is no credible public benchmark for small companies. The time depends mostly on how many systems each role needs and whether they are provisioned from one identity source. Counting systems per role and timing one complete joiner and one complete leaver gives a more reliable figure than any industry average.
Is best-of-breed software a mistake?
No. A deliberate best-of-breed approach, with single sign-on, automated provisioning and a maintained inventory, is a legitimate choice, particularly for engineering, design or analytics-led companies. The problem is unmanaged sprawl, where tools accumulate without owners or governance.
Does consolidating onto a managed IT provider save money?
It can reduce the number of subscriptions, vendors and renewals, and the operating work of provisioning and access reviews. Whether it costs less overall depends on what a company currently runs. The reliable way to decide is to build the inventory first and compare like for like.
Sources
- Zylo, 2026 SaaS Management Index — press release, 29 January 2026; Zylo SaaS statistics page, updated 8 February 2026.
- Productiv, 2023 State of SaaS series — as reported by Help Net Security, 4 July 2023.
- Productiv, 2021 State of SaaS Sprawl — as reported by CIO Dive, 20 September 2021.
- Flexera, 2026 State of ITAM Report — press release and Flexera blog, 24 June 2026.
- Brocent, published Managed IT Support pricing page — plan tiers and services included in every plan.
- Brocent operational observation — qualitative, from onboarding, offboarding and access-review work across our client base; labelled in the text.
Brocent has provided managed IT services since 2007, with headquarters in Singapore since 2021 and an office in Hong Kong since 2016.
Share:
Ready to take action?
Turn these insights into a roadmap for your business.
Book a 15-minute no-obligation consultation with our APAC IT experts. We'll review your current setup and provide a tailored IT roadmap within 24 hours.
Explore all servicesFree Checklist
10 Critical Checks Before Expanding IT to Greater China
PIPL compliance, network segmentation, bilingual helpdesk setup, and more — everything your IT team needs before Day 1 in China.
Request the checklist →📬 Monthly Asia IT Insights
China compliance updates, cybersecurity alerts, and IT tips for APAC teams — once a month.
No spam. Unsubscribe anytime.
Related Articles
Sep 09, 2026
What IT Spend Actually Does to a Growing Company's Operating Margin
Sep 23, 2026
The True Cost of an IT Hire: Wage, Statutory On-Costs, and Coverage Economics in Hong Kong, Singapore, and the United States
Aug 28, 2026
Five Vendors, One Bill: A Hong Kong Firm's IT Consolidation Story