Every small company has a version of this story. A 40-person marketing agency has one IT administrator. He's good at his job, and he goes home at six. At 11:04 PM a disk on the file server crosses 95%. The monitoring tool sends an email — to an inbox nobody will open for nine hours. By 6:30 AM the disk is full, the nightly backup has failed silently, and the first designer to arrive can't open the project drive. The IT admin spends his morning firefighting instead of working, and the agency loses most of a billable day.
Nothing in that story is exotic. No ransomware, no catastrophe — just a full disk and an empty chair. That's what makes it expensive: it's the kind of failure that happens not once but quietly, repeatedly, every year, and almost never gets counted.
The arithmetic of dark hours
Start with the coverage gap itself. A standard in-house IT function covers roughly 9 AM to 6 PM, five days a week — about 45 of the week's 168 hours. Everything else, including every weekend, is dark. That's 73% of the calendar in which an alert lands on nobody's desk.
One unwatched incident — illustrative arithmetic
Those numbers are deliberately conservative — they assume nothing is customer-facing. If the thing that fails at 11 PM is your e-commerce checkout, your client portal, or the API your customers integrate with, the meter runs much faster, and some of what you lose (a churned client, a missed SLA) never shows up on any invoice.
Why the obvious fix — a second hire — usually fails
The instinctive answer is to hire a second IT person for evenings. The arithmetic kills it almost immediately. A competent systems administrator costs $60,000+ a year in most Western markets before benefits. For that money you get coverage of maybe 40 more hours a week — still not 24/7, still no weekends, and the person you've hired does perhaps two hours of real work a night. The rest is paid waiting.
Worse, night-shift roles are miserable to staff. Turnover is high, the talent pool is thin, and a single person is a single point of failure — the night your one night-shift admin is sick is statistically the night the switch dies. Serious coverage needs a rota of at least three people, and now you're not buying a hire, you're building a department.
The timezone answer
There is a structural way out, and it isn't a gimmick: somewhere in the world, your night is someone else's working day. When it's 11 PM in New York or London, it's morning in India. An engineer there isn't bleary-eyed on a graveyard shift — they're an hour into a normal workday, caffeinated and alert, precisely when your infrastructure is most alone.
This is the model that large enterprises have quietly used for decades through global ITES providers. What's changed is that the tooling — remote monitoring, ticketing integrations, documented runbooks — has become cheap and standard enough that the same coverage now makes sense for a 40-person company, sold as a monthly retainer rather than an outsourcing megadeal. (It's the entire premise of how we run our own operations center.)
The practical difference shows up in the first response number. An unwatched alert waits for sunrise; a watched one gets a human response in minutes. Across a year, that gap — minutes versus hours, every incident, every night — is most of the money.
The compliance catch nobody budgets for
If your company is in the UK or EU, there's a second dimension to getting after-hours help: whoever watches your systems at night is, legally, a data processor. That means signed processing agreements under UK GDPR and EU GDPR, lawful transfer mechanisms (the ICO's IDTA for the UK, Standard Contractual Clauses for the EU) if the provider sits outside your jurisdiction, and — for a growing number of mid-size firms — supply-chain obligations under NIS2 or, in financial services, DORA's rules on ICT third parties.
None of this is a reason to avoid overnight coverage. It is a reason to treat "we're compliant" claims with precision: ask which frameworks, ask what's certified versus aligned, and get it in writing before signature. A provider who volunteers that distinction unprompted is telling you something useful about how they'll handle your 3 AM incident, too. We keep a full map of the frameworks that matter — including the obscure ones like PECR and the UK's new Data (Use and Access) Act — on our compliance page.
What to actually look for in overnight coverage
If you take one checklist away from this article, make it this one. A real overnight operation has staffed shifts, not one heroic founder — ask how many people are awake at 3 AM your time and what happens when one of them is ill. It has documented escalation — who wakes your senior engineer, and at what severity. It plugs into your existing stack rather than forcing a new one. It sends you a morning report every single day, incident or not, because silence should be evidence of watching, not of absence. And it puts its first-response SLA in the contract, in minutes, with numbers you can audit.
Price matters less than most buyers expect. The spread between a cheap and a good retainer is usually a few hundred dollars a month — less than the cost of a single unwatched incident. What you're really buying isn't a helpdesk. It's the ability to stop doing arithmetic about the dark hours at all.
Cost figures in this article are illustrative estimates for a typical 40-person professional-services firm and will vary with salaries, industry and infrastructure. NoctaDesk Technologies operates a 24/7 helpdesk and NOC from India for clients in the US, UK, EU, Australia and the Middle East. Nothing here is legal advice — for GDPR, NIS2 or DORA questions specific to your business, talk to your counsel.
Stop doing 3 A.M. arithmetic.
Tell us about your environment and we'll come back within one business day with a scoped proposal — and an honest answer if we're not the right fit.
Get 24/7 Coverage →