BLOG ARTICLE | PERFORMANCE • CONTINUITY • GROWTH

How much does neglected IT infrastructure really cost an SMB?

Manufacturing, wholesale, logistics, professional services, retail and sensitive facilities: the invisible losses of a poorly designed or poorly maintained system.

Business leader and expert analyzing the operational losses linked to an SMB's IT infrastructure.

Everything seems to work. The ERP opens, teams access their files, orders go through, and sites stay connected. Yet every day accumulates slowdowns, re-entries, dropped connections, support calls and postponed decisions. The IT system isn't down; it's holding the business back.

That's precisely what makes the cost hard to see. A clean-cut outage has a start time, a duration and often an invoice. Neglected infrastructure spreads its losses through the business instead: a few minutes per person, an order to redo, an out-of-sync stock level, a delayed delivery round, a deliverable sent later, or a project that stalls for lack of a reliable foundation.

These losses don't always show up on a line called "IT". They appear in overtime, lower productivity, errors, margin, penalties, customer dissatisfaction and investments made under pressure. To understand them, infrastructure must be looked at as a production tool, not merely a collection of hardware.

What it means for the business leader. The right question isn't just "how much does IT cost?" but "how much does it cost us to run IT below the level our business actually needs?"

Neglected infrastructure isn't necessarily old infrastructure

The word "neglected" doesn't necessarily mean every piece of equipment is old. Recent infrastructure can be fragile if it was designed without an overall vision, installed one emergency at a time, poorly documented, badly segmented, or never measured under real usage conditions.

Conversely, some older equipment can still do its job well if it is maintained, supported, monitored and integrated into a well-controlled architecture. The problem starts when the company no longer knows precisely what it owns, what depends on what, which risks it is accepting, and what performance is actually needed.

  • The architecture was built by stacking: every new need added a device, an access, or an exception.
  • Incidents are handled in isolation, without looking for a common root cause or verifying that the fix actually lasts.
  • Configurations, access and dependencies live in the memory of a single person or provider.
  • Investments are triggered by emergencies rather than by a prioritized, budgeted roadmap.
  • Leadership knows the IT budget but has no indicators on avoided losses, availability, or risk.

The ANSSI/DGE guide for small and medium businesses actually opens with a fundamental question: does the company really know its IT estate and business-critical assets? See the guide "Cybersecurity for small businesses in 13 questions" (ANSSI, French cybersecurity agency).

The five kinds of losses to make visible

To avoid reducing the issue to outages alone, it helps to group impacts into five categories. This framing connects technical symptoms to the indicators leadership actually tracks.

Type of lossWhat the business observesWhat to measure
ProductivityWaiting, re-entry, workarounds, hunting for files, restarts and support requests.Time lost, people affected, frequency and fully loaded hourly cost.
SalesDelayed orders, quotes not sent, abandoned sales, incomplete customer information.Missed sales, abandonment rate, margin and complaints.
OperationsSlower production, inconsistent stock, disrupted picking or shipping, lost traceability.Volume not produced, delays, rework, quality and service commitments.
FinancialEmergency call-outs, unplanned purchases, penalties, overtime and duplicate tools.Exceptional spend, cost overruns and budget consumed outside the plan.
StrategicSite opening postponed, difficult migration, blocked automation, unproven client requirements.Delayed projects, lost opportunities, deadlines and critical dependencies.

How to estimate the cost without a perfect measurement system

You don't need to know every loss down to the euro to make a good decision. A cautious estimate, built on a few explicit assumptions, is often enough to compare the cost of inaction with the cost of an improvement.

1 — Quantify recurring friction

Start with the most frequent situations: slow ERP access, Wi-Fi disconnects, sync delays, hunting for a document, redoing an entry, or waiting on support. The simplest formula is as follows:

A deliberately simple example: if 25 people lose an average of 12 minutes a day, over 20 working days, at a fully loaded hourly cost of €35, the estimated loss reaches €3,500 a month. This figure isn't a market average; it illustrates the method and must be recalculated with the company's own data.

Indicative formula. Monthly cost of friction = number of people affected × minutes lost per day × working days × fully loaded hourly cost.

2 — Quantify visible incidents

For each significant incident, add up the time staff were blocked, diagnosis and restoration time, external interventions, overtime, unrealized production or margin, and any penalties. It's important to distinguish the technical duration of an incident from its business duration: a system restored at 3pm can still leave orders to redo until the next day.

3 — Quantify errors and rework

Stock, pricing, shipping, document-version or access-rights errors create a cascading cost. An initial error often mobilizes several people: the one who discovers it, the one who fixes it, the manager who has to arbitrate, and sometimes the salesperson who has to explain the situation to the client.

4 — Quantify delayed projects

Insufficient infrastructure can delay a site opening, a cloud migration, a new application, onboarding a client, or automating a process. The cost is then the expected benefit that gets pushed back, plus the resources tied up for longer and any temporary workarounds put in place.

Principle of caution. Always keep observed data, estimates and assumptions separate. The goal isn't to produce a dramatic number, but to obtain a defensible order of magnitude to prioritize decisions.

The concrete consequences by industry

The same technical weakness doesn't have the same effect in every business. A few minutes of downtime can inconvenience an office, halt order picking, or make a sale impossible. The analysis should therefore start from the business processes most dependent on the network, applications and access.

1 — Manufacturing SMBs: production, traceability and continuity

In manufacturing, business IT, production systems, connected equipment and traceability tools are increasingly interdependent. A poorly controlled architecture can slow a flow without immediately stopping a line entirely, which makes the loss less visible but just as real.

  • work orders transmitted late or production data unavailable;
  • unstable communication between machines, operator stations, servers and applications;
  • lost or inconsistent batch, quality-control or traceability information;
  • production network insufficiently isolated from office use and external access;
  • longer maintenance for lack of mapping, logs or reference configurations.

Dominant impact. Reduced capacity, production rework, a quality risk and missed client deadlines.

What to examine. Dependencies between IT and production, segmentation, interconnections, availability of critical equipment, configuration backups and recovery procedures.

Learn more about securing firewalls, VPNs and remote access →

2 — Wholesale and distribution: stock, orders and margins

For a wholesaler or distributor, infrastructure quality is measured by continuity between the order, the ERP, the warehouse, picking, transport and invoicing. Slow or incomplete synchronization can create discrepancies the team compensates for manually — until volume increases.

  • available stock differs from stock actually picked or shipped;
  • order received but not passed to the right system or site;
  • price, discount, quantity or reference error during a re-entry;
  • picking slowed by unstable terminals, printers or application access;
  • customer delivered late, partially, or without reliable delay information.

Dominant impact. Margin eroded by rework, goodwill gestures, corrective transport and lost sales.

What to examine. Flows between ERP and warehouse, Wi-Fi coverage, link resilience, print queues, multi-site synchronization and monitoring of critical components.

3 — Logistics and transport: delays and lost visibility

In a warehouse or transport operation, value depends on real-time visibility: where goods are, which operation is complete, which route must leave, and what information can be given to the customer. When data arrives late, the team makes decisions with an incomplete picture.

  • WMS or TMS tools go down, making it impossible to confirm an operation;
  • scanners, mobile terminals or label printers unavailable in certain areas;
  • dock, parcel, address or route errors;
  • unstable links between warehouses, branches, carriers and headquarters;
  • customer service unable to give reliable, immediate information.

Dominant impact. Delayed departures, extra mileage or handling, shipping errors and a degraded customer promise.

What to examine. Radio capacity, coverage areas, link continuity, backup paths, quality of service, and the availability of addressing and name-resolution services.

4 — Professional services: billable time disappears

In a firm, a design office, an agency or a consultancy, the main asset is staff time. Infrastructure that slows access to documents, business applications or remote work directly turns billable time into unproductive time.

  • files hard to find, conflicting versions or inconsistent access rights;
  • unstable video calls and disrupted client meetings;
  • slow or unavailable remote access for consultants and field teams;
  • deliverables delayed by poorly managed transfers, syncs or backups;
  • skilled staff time spent working around or explaining the same incidents.

Dominant impact. A lower billable utilization rate, longer turnaround times and a less professional client experience.

What to examine. Cloud access performance, VPN quality, identity and access management, document collaboration, telephony and remote-work continuity.

5 — Retail and points of sale: every minute can become a lost sale

In a store or retail network, the customer is present at the moment of the incident. A slow till, an unavailable payment terminal or an out-of-sync stock level isn't just a technical task: it lengthens the queue, erodes trust and can lead to an abandoned purchase.

  • checkout slowed or impossible on one or more registers;
  • prices, promotions or stock not updated in time;
  • unstable connection between store, headquarters, sales platform and logistics;
  • unable to check availability or arrange a click-and-collect pickup;
  • manual reconciliation of operations after service is restored.

Dominant impact. An immediate loss of revenue, abandoned sales, till discrepancies and more time spent on corrections.

What to examine. Access redundancy, flow separation, failover of critical services, store monitoring, standard configurations and the ability to run temporarily in degraded mode.

6 — Healthcare and sensitive facilities: availability, access and confidentiality

In a medical practice, a lab or a care facility, downtime doesn't only affect productivity. It can delay access to needed information, disrupt a care pathway, prevent the use of an application, or increase the risk of inappropriate access to sensitive data.

  • delayed access to records, results, schedules or applications;
  • shared accounts or overly broad rights used to compensate for difficult access management;
  • unstable connections between devices, workstations, sites and providers;
  • insufficient logging to understand a malfunction or an access event;
  • continuity or restoration procedures that are incomplete and rarely tested.

Dominant impact. Disruption to care and operations, combined with heightened confidentiality, integrity and availability stakes.

What to examine. Access-rights management, segmentation, traceability, protection of remote access, backup, restoration and continuity measures suited to actual usage.

7 — Construction and multi-site companies: coordination fragments

Construction companies and organizations spread across headquarters, branches, depots and job sites depend on reliable remote access. When plans, files, management tools and field information don't circulate properly, teams create local copies and parallel channels that make control even harder.

  • plans or documents unavailable at the moment of an intervention;
  • different versions used by headquarters, the design office and the field;
  • remote access that is too slow, too broad, or hard to administer;
  • poor data synchronization and a multiplication of manual exchanges;
  • opening a new site delayed by links, cabling, Wi-Fi or security.

Dominant impact. Teams waiting, traveling unnecessarily, redoing work, or making decisions from incomplete information.

What to examine. Multi-site architecture, VPNs, access rights, link availability, the mobile experience, centralized management, and the process for opening or closing a site.

Discover our site interconnection offer →

Why the cost keeps rising even though "everything still works"

Fragile infrastructure has a cumulative effect. The more a company grows, the more users, applications, sites, connected devices and providers it adds. A weakness that seemed tolerable at 20 people can become critical at 60 — not because it's new, but because more processes now depend on it.

  • Workarounds become habits. Employees learn to restart, wait, resend or re-enter instead of reporting the problem.
  • Technical debt reduces freedom of choice. Every new project has to work around exceptions, unsupported equipment or missing documentation.
  • Urgency costs more. A short deadline reduces competition, limits testing, and pushes teams to buy what's available rather than what's suitable.
  • Dependency on one person grows. The more that person alone fixes incidents, the more knowledge stays concentrated and the less transferable the environment becomes.
  • Trust erodes gradually. Teams end up working around official tools, and clients notice the delays even without knowing their cause.

Seven signals it's time to regain control

1 — The same complaints keep coming back with no reliable indicator

Users report slowdowns or outages, but no one can link them to a specific time period, site, link, application or device.

2 — A simple change becomes risky

Adding a workstation, a VLAN, an access point, a partner access or a firewall rule requires disproportionate research because the dependencies are poorly understood.

3 — The documentation no longer reflects reality

Available diagrams, inventories, addresses, access and configurations are incomplete, contradictory, or known only to one person.

4 — Critical equipment is no longer supported

It still works, but the patches, parts, licenses or skills needed to keep it running are becoming hard to obtain.

5 — Growth reveals the limits

Wi-Fi, links, remote access, addressing or interconnections suited the company's former size but no longer keep up with current usage.

6 — Business projects are waiting on infrastructure

A migration, a new site, an automation project or a client connection is delayed because the technical foundation isn't sufficiently understood or prepared.

7 — Decisions are made with no order of priority

The list of needs exists, but the company can't distinguish what threatens the business, what reduces performance, what prepares for growth, and what can reasonably wait.

To dig deeper into the technical symptoms, also read the ARCrezo article on the 10 signs an SMB should launch a network audit before a failure.

How to reduce losses without launching an oversized project

Regaining control doesn't mean immediately replacing the entire infrastructure. A useful approach starts by making what exists understandable, measuring the impacts, and building a roadmap suited to the SMB's constraints.

1 — Identify critical processes

List the activities that can't wait: production, orders, checkout, picking, shipping, access to files, telephony, remote work and site interconnection. For each one, specify the applications, equipment, links and people it depends on.

2 — Map technical dependencies

Reconstruct the main flows, critical crossing points, equipment, external access and fallback solutions. The map needs to be precise enough to diagnose and decide, without chasing a completeness that would delay action indefinitely.

3 — Measure what actually affects the business

Availability alone, latency, loss, errors, saturation, radio quality, application response time and incident frequency don't tell the same story. Select the indicators that link a user-visible symptom to technical evidence and a business impact.

4 — Prioritize by impact, urgency and effort

Rank each topic by the criticality of the affected process, the likelihood of an incident, the scope of users involved, the difficulty of recovery, and the effort to fix it. This grid separates real emergencies from irritants and stops the most recently reported incident from automatically becoming the top priority.

5 — Separate quick wins from structural fixes

An update, a rule, a Wi-Fi channel change, a configuration backup or an alert can quickly reduce a risk. But these actions shouldn't mask the underlying needs: segmentation, redundancy, planned renewal, multi-site architecture or an addressing overhaul.

6 — Document, test and monitor

Every improvement should leave a usable trace: a diagram, an inventory, a reference configuration, clear responsibilities, a change procedure, a restore test and alert thresholds. Documentation turns a one-off project into a lasting capability and reduces dependency on individuals.

Decision expected. At the end of the diagnostic, leadership should be able to clearly distinguish: what needs to be secured now, what should be planned, what can be optimized, and what can be knowingly accepted.

The right investment isn't the most expensive one — it's the most justified one

An SMB doesn't need an oversized architecture or a catalog of technologies. It needs a foundation suited to its usage, its risks, its pace of growth and its ability to operate it. The decision may be to reconfigure, document, monitor, segment, build targeted redundancy, or gradually replace certain elements.

The point is to compare three amounts: the current cost of losses, the risk of a larger incident, and the cost of an improvement roadmap. This comparison makes the budget discussion more objective. It avoids presenting infrastructure as an abstract expense and puts it back in its real role: protecting continuity, productivity, margin and the ability to grow.

Frequently asked questions

Can infrastructure that works still cost a lot?

Yes. It can stay available while generating slowdowns, errors, rework and risk. Binary availability doesn't measure quality of service, time lost, or the ability to absorb growth or recover quickly after an incident.

Do all old devices need to be replaced?

No. The decision should factor in vendor support, available patches, capacity, criticality, redundancy, maintainability and the cost of a failure. A useful audit distinguishes what can stay, what must be fixed, and what must be replaced according to a justified priority.

How do you calculate a cost if the company has no history to go on?

Start with a sample: a few recent incidents, two or three critical processes and a short observation period. Document the number of people affected, the duration, the rework and the impacts. A cautious, traceable estimate is more useful than a precise figure that can't be defended.

Does the cloud eliminate infrastructure problems?

No. It shifts some of the dependencies. Cloud applications require reliable links, suitable Wi-Fi, available DNS services, properly protected access and sometimes backup paths. Poor connectivity can make a high-performing cloud service just as unusable as a local server.

Could a diagnostic disrupt operations?

Most inventory, configuration, documentation and observation checks can be performed read-only. Any test that could alter traffic or configuration must be identified, authorized, scheduled and paired with a rollback plan.

What budget should be planned to modernize infrastructure?

There's no relevant figure without a defined scope. Budget depends on the number of sites, criticality, equipment, usage, required availability levels and existing gaps. A priority-based roadmap allows for progressive investment and avoids an unjustified blanket renewal.

Reference sources

Make the losses visible before they become an emergency

ARCrezo helps SMBs understand, strengthen, secure and evolve their network infrastructure. The approach starts from business usage and risk, measures points of weakness, and turns findings into clear, independent, documented and financially controlled decisions.

Does your infrastructure genuinely support your business, or is it generating invisible losses?
Assess my IT infrastructure