As long as a full-time IT role would not be busy all year, managed IT costs less and covers more: an employee costs roughly 1.44 times gross pay (INSEE, 2022 data) for an average 1,661 working hours a year (INSEE, 2024). Hiring becomes rational once the workload exceeds one full-time post or demands daily on-site presence.
What does an in-house IT technician really cost?
Gross pay is only the starting point. According to INSEE, employer social contributions and other employer costs average 43.7% of gross salary in French companies with 10 or more employees in the non-agricultural market sector (2022 data). A gross figure of 100 therefore becomes an employer cost of around 144.
For the pay level itself, the APEC 2025 barometer — a survey of 26,000 private-sector managerial staff conducted in June 2025 — reports a median gross annual package, fixed plus variable, of €55k for the "IT and information systems" function, and €52k in the Grand Est region. Applying the INSEE rate, an IT manager paid at the regional median represents roughly €75k of annual employer cost.
Those figures cover managerial staff only. For a non-managerial technician we found no reliable public median by occupation, so take away the multiplier mechanism rather than a single number. As a framing benchmark, INSEE reports an average net salary of €2,733 a month in full-time equivalent terms in the French private sector in 2024, against €3,853 in the information and communication sector — IT pays above average, which argues against hiring for a part-time workload.
On top of payroll, several cost lines are routinely left out of comparisons.
- Recruitment itself. INSEE reports that 64% of planned hires for IT technicians and 67% for IT engineers were anticipated as difficult (2023 data), and that 86% of firms struggling to recruit ICT specialists cite a shortage of candidates (2024).
- Tooling: monitoring, remote deployment, ticketing, backup, managed antivirus, patch management. Those licences are bundled into a managed-IT contract; in-house, you buy them separately.
- Ongoing training and certifications, to be renewed in a field whose reference frameworks shift every two or three years.
- Covering absences: holidays, sick leave, training, resignation. A full-time employee covers an average 1,661 hours a year (INSEE, 2024) out of the 8,760 hours in a year.
- Single-person dependency: admin passwords, estate history, carrier contacts. A badly prepared departure costs weeks of reconstruction.
What does a managed IT contract cover, and what does it not?
Managed IT delegates day-to-day operation of the information system to a provider: estate monitoring, updates, backups, user support, incident handling, usually cybersecurity and sometimes hosting. The contract sets the scope, the response times (SLA) and the hours covered.
We publish no generic price, and you should distrust the ones you will come across: cost depends on the number of workstations and servers, the SLA level, the cybersecurity scope and the expected on-site presence. A market average quoted without scope compares contracts that do not cover the same things. Get your actual estate priced.
What a contract does not replace: detailed knowledge of your business processes, budget arbitration, the relationship with your software vendors when it is a daily one, and permanent physical presence if your operations require it. Those four points must be assigned explicitly — to you, to the provider, or to an internal role.
In-house or managed IT: how do they differ, criterion by criterion?
Costs and commitments
- Cost structure — in-house: fixed annual cost, independent of activity volume · managed IT: monthly fee scaled to the number of workstations and servers.
- Entry cost — in-house: recruitment, onboarding, tooling to purchase · managed IT: initial audit and onboarding, tooling included.
- Payroll loading — in-house: about +43.7% in contributions and other employer costs on top of gross pay (INSEE, 2022) · managed IT: not applicable, the fee is the full cost.
- Elasticity — in-house: low, a half-time post is hard to recruit in these roles · managed IT: scope renegotiable at renewal.
- Budget visibility — in-house: payroll known, but projects and specialist expertise subcontracted on top · managed IT: fee known, provided out-of-scope work is bounded in writing.
- Exit — in-house: dismissal procedure and notice period · managed IT: contractual notice, with an obligation to hand back access and documentation.
Skills, coverage and risk
- Hours covered — in-house: an average 1,661 hours a year for a full-time post (INSEE, 2024) · managed IT: contractual window, with optional on-call outside business hours.
- Absences — in-house: covered by a third party, or requests postponed · managed IT: continuity handled by the provider's team.
- Breadth of skills — in-house: one person, so two or three domains genuinely mastered · managed IT: a multi-disciplinary team across network, servers, cybersecurity and telephony.
- Business knowledge — in-house: strong, through daily presence alongside users · managed IT: has to be built, and depends on documentation quality and a stable account contact.
- On-site responsiveness — in-house: immediate · managed IT: a function of SLA and distance; check the provider has technicians near your sites.
- Cybersecurity — in-house: depends on one person's level · managed IT: externally verifiable through a label, for example ExpertCyber, awarded by Cybermalveillance.gouv.fr after a documentary and technical audit by AFNOR Certification.
- GDPR and NIS2 compliance — in-house: you carry and document it yourself · managed IT: the provider documents the technical measures, but legal accountability stays with the company's director.
- Discontinuity risk — in-house: dependency on a person · managed IT: dependency on a contract, mitigated by a written reversibility clause.
When should you hire an IT technician?
There are situations where in-house is objectively the right answer, and saying so is part of the advice.
- The workload fills a full-time post. If day-to-day operations, projects and support already saturate one role, hiring is economically coherent, and managed IT alone would cost more for the same scope.
- Your business applications are bespoke or heavily customised: an in-house ERP, production software, a PLC chain. No outsider will learn that faster than a dedicated employee.
- Permanent physical presence is required: a workshop where an hour of downtime is expensive, a site running three shifts, a public-facing building with self-service terminals.
- You run several sites with a constant flow of user movements — arrivals, departures, role changes.
- Your sector or a major client requires a named IT contact reachable inside the company.
When is outsourcing the better choice?
- The real workload stays below one full-time post. This is the most common case in organisations of a few dozen workstations: paying for a full-time post to cover a partial workload is a bad trade.
- You need several scarce skills at once: cybersecurity, network, virtualisation, IP telephony. One employee will not cover all of them well.
- You want coverage beyond office hours without organising an internal on-call rota.
- You cannot recruit. In IT occupations, hiring difficulties are documented and structural (INSEE), not cyclical.
- Security is your priority and you want capability that an outsider can verify: a third-party-audited label beats a claim on a brochure.
- You would rather turn a fixed cost into an adjustable fee, during growth, restructuring or a change of ownership.
Does the hybrid model actually work?
Yes, and beyond a certain size it is often the target setup. But only if the split is written down. The hybrid model fails when it stays implicit: each side assumes the other is watching the backups, and nobody is. The split that holds over time puts in-house on the users and the business, and the provider on infrastructure and security.
- Local support and business applications — in-house: first line, user training, vendor relationship · managed IT: second and third line escalation.
- Infrastructure and security — in-house: oversight and priority setting · managed IT: monitoring, patching, backups, incident response.
- Projects — in-house: requirements and acceptance testing · managed IT: design, implementation, documentation.
- On-call and holidays — in-house: business hours · managed IT: continuity and cover.
Two conditions make it work: a named responsibility matrix reviewed at least once a year, and shared access to the same monitoring and ticketing tools. Without those, the hybrid model stacks up the costs without stacking up the benefits — and that is the scenario we most often see fail.
How do you decide in practice, within a week?
- Measure the real workload over three months: number of support requests, time spent, projects on hold. Compare it with the volume of a full-time post, around 1,661 hours a year (INSEE, 2024).
- Cost the full employer burden of the hire you are considering: target gross pay multiplied by about 1.44 (INSEE, 2022), plus tooling, training and recruitment cost.
- Ask two providers to price managed IT against a strictly identical written scope, including SLA, hours covered, on-site visits and a list of out-of-scope services.
- List what must stay in-house whatever happens: business applications, physical presence, sensitive access. If that list fills a post, hire. If it fills a third of one, outsource the rest and keep a part-time internal contact.
Why does cybersecurity move the threshold?
Because it shifts the tipping point. The 2025 activity report from Cybermalveillance.gouv.fr, published in March 2026, records more than 500,000 assistance requests, up 20% year on year, with a 107% rise in requests linked to data breaches; account takeover ranks first among threats affecting professional users, up 45%.
One internal person, however capable, cannot alone sustain threat monitoring, configuration hardening, detection and incident response. This is where team effect and external verifiability weigh most. The ExpertCyber label is awarded by Cybermalveillance.gouv.fr following a documentary and technical audit by AFNOR Certification, covering securing, maintenance and assistance activities. BISPRO holds it.
To give a sense of what a pooled workload looks like: BISPRO, founded in 2012 in Saint-Avold, Moselle, maintains 5,000 devices for 215 business clients and carries out around 5,000 interventions a year. That volume is what keeps network, server, cybersecurity, IP telephony and video surveillance skills permanently available — something a single post structurally cannot offer.

