B BROCENT

What IT Spend Actually Does to a Growing Company's Operating Margin

A research report on the relationship between IT spend and operating margin in a growing company: why the macro IT-spending headline describes a market you are not buying in, why the authoritative percentage-of-revenue benchmark is paywalled, where IT cost actually lands in a P&L, what the under-investment and over-investment traps look like in practice, and a stage-by-stage framework for right-sizing IT spend.

A business team reviewing financial charts and growth data together in an office meeting, representing the operating-margin decisions behind a growing company's IT spend
In short: The headline "IT spending is up 14.2%" is not your budget line. Gartner's July 2026 forecast puts worldwide IT spend at $6.37 trillion, but almost all of that growth is AI data-centre capex — IT services grew just 5.3%. For a growing company, operating margin is shaped less by how much you spend on IT than by which failure mode you are in: under-investing, where the cost surfaces everywhere except the IT line, or over-investing, where you pay enterprise rates for a problem you do not have.

Every finance conversation about IT eventually arrives at the same question: what should we be spending? It is asked in good faith, and it is almost always the wrong question. It assumes there is a correct number, that the number is a percentage of something, and that hitting it is what good looks like.

In practice, the companies we work with across Hong Kong, Singapore, and further afield do not get into trouble because they spent 3.1% of revenue on IT instead of 4.6%. They get into trouble because their IT cost is in the wrong shape for their stage — too reactive to prevent the expensive events, or too elaborate to justify against the problems they actually have. Both failure modes damage operating margin. Only one of them is visible on the IT line.

This report looks at what the published data actually supports, what it does not, and how a growing company can reason about IT spend without either benchmarking itself against numbers that were never about it or guessing.

A note on what this article is not. If you are looking for what managed IT support costs as a service — the price list question — that is a different piece: How Much Does IT Support Cost in Singapore in 2026? answers it directly with real local figures. This report is about the downstream question: what that spend, or the absence of it, does to your P&L.

Key Findings

  • The macro IT-spending headline is not the number you are budgeting against. In Gartner's July 2026 forecast, worldwide IT spending grows 14.2% to $6.37 trillion — but data centre systems grow 62.5% and IaaS 29.3%, while IT services grow 5.3% and communications services 4.4%. The growth is concentrated in AI infrastructure capex, which most growing companies do not buy.
  • That forecast moved four times in nine months. Gartner's own successive 2026 releases went from 9.8% growth (October 2025) to 10.8% (February 2026) to 13.5% (April 2026) to 14.2% (July 2026). A benchmark revised upward four times in three quarters is a poor anchor for a fixed annual budget.
  • The authoritative "IT as a percentage of revenue" benchmark is not public. Gartner's IT Key Metrics Data — the dataset most percentage-of-revenue rules of thumb ultimately trace back to — is subscription-gated. What circulates freely is fragments, stripped of the industry, company-size, and year context that made them meaningful.
  • Outage cost is long-tailed, not linear. Uptime Institute's 8th Annual Outage Analysis (May 2026) found 57% of respondents' most recent major outage cost more than $100,000, and one in five cost more than $1 million — the second consecutive year at that level. The useful lesson is the distribution's shape, not a per-minute constant.
  • Over-spending discipline has barely improved in five years. Flexera's 2026 State of the Cloud Report (15th edition, n=753 cloud decision-makers) estimates 29% of IaaS and PaaS spend is wasted — up from 27% and the first increase in five years. In Flexera's 2021 edition the figure was 30%. The waste rate moved by a point in half a decade while the spending base multiplied.
  • The lever is cost structure, not cost level. Predictable per-employee pricing does not make IT cheaper in any given month. It makes IT forecastable, which is what actually lets a growing company plan margin.

Why "How Much Should We Spend on IT" Is the Wrong Question

The headline number is measuring somebody else's spending

On 27 July 2026, Gartner forecast worldwide IT spending would reach $6.37 trillion in 2026, up 14.2% on 2025. That figure gets quoted in board packs and vendor decks as though it describes a general rise in the cost of running IT. Read one level down and it describes something much narrower.

The segment breakdown from that same forecast, as reported in coverage of the release:

  • Data centre systems: $822 billion, growing 62.5%. The single dominant driver.
  • Infrastructure as a service: $287 billion, growing 29.3%.
  • Software: $1,468 billion, growing 15.5%.
  • Devices: $868 billion, growing 9.8%.
  • IT services: $1,570 billion, growing 5.3%.
  • Communications services: $1,354 billion, growing 4.4%.

John-David Lovelock, Distinguished VP Analyst at Gartner, attributed the pattern to accelerating investment in AI infrastructure, cloud platforms, and intelligent applications.

Now map that onto a 40-person professional services firm in Hong Kong or a 120-person manufacturer with offices in Singapore and Shenzhen. Such a company buys IT services, devices, software licences, and connectivity. It does not buy GPU clusters or hyperscale data centre systems. The segments it actually purchases grew between 4.4% and 15.5% — and the two largest of those, services and communications, are at the very bottom of the range.

The 14.2% headline is real. It is simply not a statement about your cost base. Using it to justify — or to resist — a change in your IT budget is a category error.

A forecast that keeps moving is not a benchmark

There is a second problem with anchoring to the macro number, visible only if you look at more than one release. Gartner published four separate 2026 IT-spending forecasts in the space of nine months, and each revised the prior one upward:

  • October 2025: growth of 9.8%, exceeding $6 trillion for the first time.
  • February 2026: growth of 10.8%, totalling $6.15 trillion.
  • April 2026: growth of 13.5%, totalling $6.31 trillion.
  • July 2026: growth of 14.2%, totalling $6.37 trillion.

Nothing about that sequence is a criticism of the forecasting — the AI infrastructure build-out genuinely accelerated within the year, and a forecast that does not update is worse than one that does. But it does tell you something about how the number should be used. A figure that gained 4.4 percentage points in three quarters is a description of a fast-moving market, not a stable yardstick you can set a twelve-month budget against.

The percentage-of-revenue benchmark most people reach for is behind a paywall

Ask a finance lead what a company like theirs should spend on IT and you will usually get a percentage of revenue. Those rules of thumb trace, more often than not, back to Gartner's IT Key Metrics Data — a genuinely rigorous dataset, and a subscription product. It is not publicly available, and we are not going to pretend to figures from it here.

That gating matters more than it sounds. When the authoritative version is locked, what circulates in blog posts and sales decks is second- and third-hand fragments: a percentage detached from the industry it was measured in, the company-size band it applied to, and the year it was collected. Financial services and manufacturing do not have the same IT intensity. A 30-person firm and a 3,000-person firm do not either. Stripped of that context, "spend X% of revenue on IT" is not a benchmark — it is a number with a decimal point in it.

The honest position: if you have access to IT Key Metrics Data through a subscription, use it, with the industry and size cuts intact. If you do not, do not substitute a decontextualised fragment of it. Reason from your own cost structure instead, which is what the rest of this report is about.

Where IT Cost Actually Shows Up in a P&L

The reason percentage-of-revenue benchmarking disappoints is that it only measures one of the two places IT affects your accounts, and it is the smaller one.

Direct IT Spend vs. the Cost of Not Spending — What Each Looks Like in the Accounts

  • Direct IT spend is visible, bounded, and negotiable. Support contracts, licences, hardware, connectivity, cloud consumption. It sits in one or two identifiable lines. Finance can see it, forecast it, and argue about it. This is the part that percentage-of-revenue benchmarks measure.
  • The cost of not spending is invisible, unbounded, and shows up somewhere else entirely. It appears in gross margin when delivery is disrupted, in staff cost when people who were hired to do something else spend their week doing IT, in one-off charges when an incident requires emergency remediation, and in revenue that quietly does not arrive because a proposal went out late or a system was down during a client's business hours.
  • Direct spend is a decision; the cost of not spending is a consequence. You choose the first one annually, in a meeting. The second one is chosen for you, at a time you do not control, and it does not appear in the budget you were benchmarking.
  • Only the first is on the IT line. This is the structural reason IT budgets get cut successfully for years before anything visibly breaks. The savings are booked immediately and precisely; the cost lands later, elsewhere, and is rarely attributed back.
  • They are not symmetric in size. Direct IT spend for a growing company is a predictable monthly figure. The cost of not spending is a distribution with a long right tail — most months it is zero, and occasionally it is very large indeed.

What the outage data does and does not tell you

That last point is the one worth grounding in real numbers, because it is where the worst statistics in this field live.

Uptime Institute's Annual Outage Analysis 2026 — the eighth edition, published 13 May 2026 — reports that 57% of respondents said their most recent major outage cost more than $100,000, and that one in five reported costs exceeding $1 million, the second consecutive year at that level. Roughly 10% said their last outage had serious or severe impacts. The report also found per-site outage rates declining for a fifth consecutive year, though the pace of improvement has slowed. Power remains the leading cause of impactful outages — UPS systems, transfer switches, generators — with human error, in the form of procedure failures and inconsistent processes, the top underlying driver. Andy Lawrence, Founding Member and Executive Director of Uptime Intelligence, has characterised digital infrastructure overall as remarkably resilient even as costs edge upward.

Read that carefully, because it is easy to misuse. Uptime's respondents are data centre and digital infrastructure operators. They are not 60-person companies in Kowloon or Tanjong Pagar. You cannot take "57% cost more than $100,000" and apply it to your own outage risk — the population is wrong, and the scale of the systems being measured is wrong.

What transfers is the shape. Outage cost is not linear in duration. It is long-tailed: most incidents are cheap, a minority are severe, and the severe ones are severe enough to dominate the average. That is why the right question is not "what does an hour of downtime cost us" but "what is our exposure to the bad tail, and what reduces it."

One figure you should refuse to accept, from anyone. The claim that downtime costs "$5,600 per minute," almost always attributed to Gartner, is a stale mid-2010s citation that has been re-quoted for a decade without provenance and without regard to company size or industry. It is not a defensible number for a growing company in 2026, and any analysis built on it is built on sand. If a vendor puts it in front of you, that tells you something useful about the vendor. Use a distribution, from a named and dated source, or use nothing.

The Under-Investment Trap — What It Looks Like in Practice

The following observations are Brocent's own, from operating managed IT services since 2007 — first from Beijing, then from Hong Kong since 2016 and Singapore, where the group has been headquartered since 2021. They are qualitative on purpose. We are not going to attach invented percentages to them, and you should be sceptical of anyone who does.

Under-investment rarely looks like a company with no IT. It looks like a company whose IT is entirely reactive, and it degrades margin through three consistent mechanisms.

Reactive-only support makes outages longer, not just more frequent

A break-fix arrangement — a number you call when something stops working — has a structural property that is easy to miss: nothing in it is trying to prevent the call. Patching drifts. Backups are configured once and never verified. Monitoring either does not exist or nobody is watching it, which is the same thing.

The consequence is not primarily more incidents. It is longer ones. When the first person to notice a failure is a user rather than a monitor, and the first responder arrives without a documented environment, diagnosis starts from zero. The difference between an issue caught at 02:00 by a monitoring alert and the same issue discovered at 09:15 by thirty employees who cannot log in is not a technical difference. It is a P&L difference, and it lands in the operating lines, not in IT.

Preventable security incidents cost a multiple of the prevention

The pattern we see most often is not an exotic attack. It is a known vulnerability that was not patched, a credential without multi-factor authentication, or a backup that had been failing silently for weeks and was discovered at the moment it was needed.

The economics are uncomfortable in a specific way: the remediation is almost always more expensive than the control that would have prevented it — not marginally, but by a wide margin — and it arrives as an unbudgeted charge, usually alongside a period of degraded operations and, increasingly, a disclosure obligation. This is the clearest case of an IT-line saving that reappears, larger, in a line that has nothing to do with IT.

The generalist doing IT badly is the most expensive arrangement of all

Almost every growing company has one: the operations manager, the finance analyst, the technically-inclined founder who ends up owning IT because someone had to. They are usually competent, usually willing, and it is usually a bad trade.

The cost is not their time at their salary rate, though that alone is often larger than a support contract once you count it honestly. It is the opportunity cost of what they were actually hired to do, plus a coverage gap that no single person can close — they take leave, they get sick, they eventually resign, and when they do, an undocumented environment leaves with them. It also caps the ceiling: a capable generalist can keep things running, but they cannot provide the security depth or architectural direction that a growing company begins to need somewhere between thirty and a hundred staff. For that shape of problem, a virtual CIO engagement exists precisely because the need is real long before a full-time CIO is affordable.

The Over-Investment Trap — Paying Enterprise Rates for a Growing Company's Problem

The opposite failure is less discussed and more common than it should be, largely because it is comfortable. Nobody gets criticised for buying too much resilience. It still costs margin.

Waste is not a discipline problem — the five-year data says so

Flexera's 2026 State of the Cloud Report, the fifteenth annual edition, surveyed 753 cloud decision-makers and estimates that 29% of IaaS and PaaS spend is wasted. That is up from 27% the prior year — the first increase in five years — which Flexera attributes to added cost complexity from AI workloads and new PaaS and SaaS offerings.

The number that should stop you is not 29%. It is 29% compared to five years earlier. Flexera's 2021 edition put estimated waste at 30%. Half a decade of FinOps tooling, cost dashboards, and cloud-cost discipline moved the waste rate by roughly one percentage point.

Meanwhile the base it applies to grew enormously. In Flexera's 2021 data, 36% of large enterprises spent more than $1 million a month on cloud; in the 2026 edition, 76% spend more than $5 million a month. The rate held roughly flat while the absolute waste multiplied.

Two conclusions follow, and they are more useful than the headline percentage:

  • Waste is structural, not behavioural. If it were a discipline problem, five years of concerted industry attention would have moved it more than a point. It persists because complexity generates it faster than governance removes it.
  • Because the rate is stubborn, the controllable variable is scope. The most reliable way to spend less on something is not to manage it more tightly — it is to have less of it in the first place. Every additional platform, tier, and tool arrives with its own permanent share of that 29%.

Flexera's respondents also named their top cloud challenges as understanding application dependencies (54%), assessing technical feasibility (44%), and comparing on-premises with cloud costs (43%) — all three are complexity problems, not price problems. And on scale: 69% of SMBs in the survey spend under $50,000 a month on public cloud, which is a useful reminder that the enterprise cost patterns dominating industry commentary are drawn from a very different population.

What over-investment looks like in a growing company

  • Enterprise tooling bought for enterprise failure modes. Platforms designed for organisations with a dedicated security operations team, deployed at a company with no one to run them. The licence is the small part of that cost; the unrealised capability is the large part.
  • Resilience engineering the business case does not carry. Multi-region redundancy protecting a workload whose actual recovery-time requirement is measured in hours. The right answer here is not less resilience in general — it is resilience matched to a stated recovery objective, which most companies have never actually written down.
  • Tool sprawl accumulated one reasonable decision at a time. No individual purchase was wrong. Each solved a real problem on the day. Nobody ever removed the previous one, and the integration and administration burden compounds quietly.
  • Consultancy in place of operations. Recurring advisory spend that produces recommendations nobody has capacity to implement. Advice is only worth its cost when there is an operating capability behind it.

None of these is stupidity. Each is a locally sensible decision that was never revisited when the company's stage changed.

A Framework for Right-Sizing IT Spend to Company Stage

Rather than a percentage, reason from what actually changes as a company grows. The transitions below are where IT cost structure should change — and where, in our experience, it usually changes too late.

  • Under roughly 10 people — optimise for not thinking about it. The genuine risk at this stage is distraction, not downtime. Managed devices, managed identity, verified backup, and a support number that answers. Anything more elaborate is a tax on attention you cannot afford to pay. What you should refuse: multi-year commitments, and any architecture that assumes you will still be this size in two years.
  • Roughly 10 to 50 people — the transition that gets missed. This is where informal IT stops working and almost nobody notices in time. Onboarding and offboarding become real processes with real security consequences; the generalist who has been handling IT becomes a single point of failure; the first compliance or client security questionnaire arrives. The correct move is to formalise support and access control before an incident forces it, and it is the single highest-return transition on this list.
  • Roughly 50 to 200 people — buy predictability, then buy direction. Ad-hoc costs become material and lumpy at this size, which is precisely when a variable IT cost starts distorting monthly margin. Predictable per-seat support handles the first half. The second half is strategic: someone needs to own a roadmap, a risk register, and a vendor consolidation plan, which is the virtual CIO function whether or not you call it that.
  • Above roughly 200 people, or in a regulated sector at any size — the regulator sets the floor, not the benchmark. Financial services in Hong Kong under HKMA expectations, or any business with meaningful cross-border data obligations, has requirements that no percentage-of-revenue rule will produce. Cost here is a compliance output. Right-sizing means meeting the obligation efficiently, not deciding whether to meet it.
  • At every stage — separate run cost from change cost. The most common budgeting error we see is a single "IT budget" mixing the two. Run cost should be predictable and, per employee, roughly flat or gently declining as you grow. Change cost — a migration, an office build-out, a security uplift — is project-shaped and should be justified individually. Blending them makes both invisible: run cost looks uncontrolled, and change never gets properly evaluated.

Three questions that beat any benchmark

  • "What would this cost us if it failed on our worst day?" Not an average day. Uptime's distribution exists because the tail is where the money is.
  • "Who does this if the person who normally does it is unavailable for two weeks?" If the honest answer is "nobody," you have found a real risk that no spending percentage would have surfaced.
  • "What are we paying for that solved a problem we no longer have?" Asked annually, this reliably finds more savings than any benchmarking exercise — and unlike a budget cut, it removes cost without removing capability.

What Predictable, Per-Employee Pricing Changes About This Decision

There is a structural argument for per-seat managed IT pricing that is separate from, and more durable than, the question of whether it is cheaper in a given month.

Brocent publishes real per-user monthly list prices rather than quoting on request. As of this writing, our managed IT support tiers are:

  • Startup (1–5 employees): HK$855.14 / S$126.36 / US$89.10 per user, per month.
  • Established (5–300 employees): HK$1,247.40 / S$185.08 / US$130.50 per user, per month.
  • Growth (10–500 employees): HK$1,561.21 / S$227.20 / US$160.20 per user, per month.
  • Enterprise (25+ employees): custom-quoted, because at that point the scope genuinely varies.

A disclosure about the US figures. These are Brocent's own published US list prices, set internally as a fixed derivation from our Singapore pricing. They are not derived from US market research and should not be read as a benchmark of US market rates. The Hong Kong and Singapore figures are our real local list prices for those markets. Full current details, including add-ons, are on our pricing page.

We publish these for the same reason this report argues against percentage benchmarks: a real, verifiable number that you can check against your own headcount is worth more than a decontextualised industry average, even when the real number is higher than you hoped.

What changes when the cost becomes a per-head line

  • It converts a variable cost into a modellable one. A company adding twenty people over a year can state its support cost for that year to within a small margin. The same company on time-and-materials cannot, because its cost is a function of how many things break — a variable it does not control and cannot forecast.
  • It removes the incentive problem in break-fix. Under hourly billing, the provider's revenue rises when your environment is unstable. Under a fixed per-seat fee, stability is the provider's margin. That alignment is worth more than most of the feature comparisons in a typical proposal.
  • It makes the run/change separation enforceable. When run cost is a per-seat number, anything outside it is visibly a project, with its own justification. The blended budget problem described above largely dissolves.
  • It prices the coverage a headcount cannot buy. One employee cannot provide out-of-hours cover, security specialisation, and continuity through leave and resignation simultaneously. A managed services arrangement is not primarily buying labour hours; it is buying a coverage shape that a single hire structurally cannot produce, regardless of budget.

What it does not do: make IT cheap. In some months, a per-seat contract costs more than a good month of break-fix. That is the point — you are buying the elimination of the bad months, which is where the margin damage was concentrated to begin with.

Frequently Asked Questions

What percentage of revenue should we spend on IT?

There is no defensible general answer, and the datasets that could give an industry- and size-specific one — principally Gartner's IT Key Metrics Data — are subscription products. Percentages circulating freely have usually been stripped of the industry, company size, and year that made them meaningful. Reason from your cost structure and stage instead: what your run cost per employee is, what your exposure is on a bad day, and what you are paying for that no longer solves a current problem.

Is IT spending really rising 14% a year?

Not for the things a growing company buys. Gartner's July 2026 forecast of 14.2% growth to $6.37 trillion is driven overwhelmingly by data centre systems (62.5% growth) and IaaS (29.3%) — AI infrastructure. In the same forecast, IT services grew 5.3% and communications services 4.4%. If your spend is services, devices, software, and connectivity, the headline number is describing a market you are not buying in.

How much does downtime cost per minute?

Treat any per-minute constant as a red flag, particularly the widely-quoted "$5,600 per minute" figure attributed to Gartner — it is a stale mid-2010s citation repeated without provenance. The better-founded view comes from Uptime Institute's 2026 Annual Outage Analysis: 57% of respondents' most recent major outage cost over $100,000 and one in five cost over $1 million. Those respondents are data centre operators, not SMEs, so the figures do not transfer directly — but the shape does. Outage cost is a long-tailed distribution, and your planning should target the tail.

We have never had a serious IT incident. Doesn't that mean we are spending enough?

It may. It may also mean you are early in a distribution whose costs are concentrated in rare events. The distinguishing test is not incident history but coverage: is anything actively preventing the expensive failure modes — verified backups, current patching, enforced multi-factor authentication, monitored alerting — or has nothing simply gone wrong yet? The first is a control. The second is a run of luck, and it is not a budget position.

Can we just hire someone instead?

That is a different question from this one, and it turns on coverage economics rather than headline cost: a single hire cannot simultaneously provide out-of-hours cover, security specialisation, and continuity through leave and attrition. Many growing companies end up with both — an internal owner for context and priorities, and a provider for depth and coverage. This report deliberately does not render a verdict on the model choice; it is about what either choice does to margin.

Is cloud spending where our IT budget is leaking?

Possibly, and the data suggests it is structural rather than a failure of attention. Flexera's 2026 State of the Cloud Report estimates 29% of IaaS and PaaS spend is wasted, up from 27% and the first rise in five years. Its 2021 edition estimated 30% — five years of industry-wide cost-management effort moved the rate roughly a point. Because the rate is so stubborn, reducing scope reliably beats managing scope more tightly.

What is the single highest-return change for a company of 30 to 60 people?

Formalising the things that are currently informal, before an incident forces it: documented onboarding and offboarding, verified backups rather than configured ones, enforced multi-factor authentication, and a support arrangement that does not depend on one person's availability. It is unglamorous, it is inexpensive relative to what it prevents, and it is the transition companies most reliably make about a year later than they should.

The Conclusion Worth Keeping

The question "how much should we spend on IT" invites benchmarking, and benchmarking against a paywalled dataset's fragments, or against a macro forecast that describes somebody else's AI capex, produces confident answers that are not about you.

The better frame is structural. IT damages operating margin in two directions. Under-investment hides its cost outside the IT line, in longer outages, in preventable incidents, and in capable people doing work they were not hired for. Over-investment shows its cost plainly but attaches it to failure modes you do not have — and the five-year waste data suggests that once complexity is in place, discipline does not remove much of it.

Between those, the objective is not a number. It is a cost structure that matches your stage, that is predictable enough to plan against, and that is reviewed when the company changes rather than when the budget cycle happens to come round.

If you want to work through what that looks like for your own headcount and markets, talk to us — or start with the published per-seat pricing and check it against your own numbers first.

Share:

Ready to take action?

Turn these insights into a roadmap for your business.

Book a 15-minute no-obligation consultation with our APAC IT experts. We'll review your current setup and provide a tailored IT roadmap within 24 hours.

📋

Free Checklist

10 Critical Checks Before Expanding IT to Greater China

PIPL compliance, network segmentation, bilingual helpdesk setup, and more — everything your IT team needs before Day 1 in China.

Request the checklist →

📬 Monthly Asia IT Insights

China compliance updates, cybersecurity alerts, and IT tips for APAC teams — once a month.

No spam. Unsubscribe anytime.