All articles

What Every Small Business Needs to Know in 2025 | The COVI Way | Episode 17

The Hidden Cost of IT Friction in Small Business

The Hidden Cost of IT Friction in Small Business

The data is clear: the average small business loses three hours of productivity per employee every week due to IT-related friction. For a 30-person company with half the team billing at $150 per hour, that translates to over $300,000 in lost revenue annually. This productivity drain exists alongside an escalating security threat. The malware industry now represents the third-largest economy globally at $10.5 trillion, with 60% of attacks targeting small businesses. When small businesses experience a breach, 60% close within six months. The financial impact averages $220,000 in direct losses before factoring in customer trust erosion, legal fees, and opportunity costs.

COVI addresses these dual challenges through framework-based IT management that balances security with productivity. Rather than reinventing solutions for each client, COVI applies proven NIST and CIS frameworks used by Fortune 500 companies and government agencies to mid-market organizations. This standardization approach protects efficiency in tangible ways. When a laptop fails, standardized equipment means zero friction for end users because drivers and configurations match exactly. The upfront cost difference becomes irrelevant when measured against even 30 minutes of billable time lost to troubleshooting. Recent compliance demands around CMMC, PCI, and FINRA requirements make this systematic approach even more valuable as businesses need repeatable evidence of security controls rather than one-off solutions.

The most cost-effective security upgrade available today is mobile device management. Most professionals spend 60-70% of their work time on mobile devices, yet most organizations cannot remotely wipe company data if a phone is lost or an employee leaves. Modern sandboxing technology solves this problem affordably through per-user licenses that typically cost under $10 monthly. This protection extends to password management platforms that eliminate the security risk of shared credentials while actually saving time through integrated two-factor authentication. The monthly strategic IT meeting makes these proactive decisions possible. Without regular collaboration between IT providers and decision makers, organizations operate reactively, constantly firefighting rather than preventing issues that cost far more than the investment required to stay ahead of them.

https://youtu.be/6-UqSDvYp20

Episode Summary:

Is your IT setup costing you more than you realize? In this episode of The COVI Way, CEO Dave Vint and VP of Sales Cody Lents break down the hidden costs of IT inefficiency and why 2025 demands a different approach to business technology.

Small businesses are losing more than time—they’re losing competitive advantage. Discover why IT productivity matters more than ever and how to protect your team.

Key Topics:

  • Average small businesses lose 3 hours of productivity per employee weekly due to IT friction—that’s over $10,000 per week for a 30-person team

  • 60% of malware attacks now target small businesses, with average losses exceeding $220,000 per incident

  • Mobile device protection through sandboxing technology is one of the most cost-effective security investments available

  • Standardization in IT isn’t bureaucracy—it’s a productivity multiplier that eliminates friction during failures and transitions

  • Strategic monthly IT meetings are essential for staying ahead of compliance requirements and emerging threats

Connect with COVI:

Instagram | Facebook | Website | FREE IT Strategy Analysis

YouTube | Apple Podcasts | Spotify

Episode Transcript

The COVI Way Podcast - Episode with Dave Vint & Cody Lents

David: Welcome to The COVI Way, the podcast where we break down the intersection of people and technology. Because IT shouldn’t just be about solving problems. It should be about enabling people to do their best work. I’m Dave Vint, CEO of COVI. And today I’m sitting down with my co-host, Cody, to review the state of the industry as we’re seeing things today and some common trends that we’re seeing amongst our partners.

All right, Cody. So we’ve been running these podcasts for a little while now as a growing opportunity for both of us as well as for COVI. And I don’t know about you, but I’ve been having a pretty good time so far.

Cody: Yeah, I was very stressed out in quarter one of 2025 about podcasts. But since then, it is definitely a joy. Honestly, it’s been a lot of fun.

David: It is great. We thought we’d take a session this week to dig into state of affairs, state of the industry, and talk a little bit about how the IT environment has changed in 2025 and some things that COVI is looking at for 2026, not only strategically, but also how we’re looking at the needs of some of our customers and what’s on the radar. How’s that sound to you?

Cody: Sounds like a joy.

David: Awesome. So talk to us, share with our listeners, what are some common pain points that have been coming up for customers that you’ve been speaking with over the last couple of quarters?

Cody: Oh, that’s a really good question. The easy answer is growth and expansion. So opening up offices or moving offices is a strategic priority with a lot of especially large organizations. The other is a desire to modernize where in the past we’ve experienced like I don’t want to reinvest in this application or this solution that I’ve already invested in, realizing that that is the bottleneck to their operation and saying, it’s time for us to start figuring out what the appropriate investment is to solve these problems.

And I don’t know in the world or the technology landscape what has changed. If the organizations have just matured, there hasn’t been a cybersecurity event or anything that’s caused that. I think it also might just be that it’s probably four or five years of having that same conversation and it might just be starting to stick and be like, oh yeah, I do see what you’re saying now.

Other strategic priorities from a cybersecurity perspective, we’re seeing a lot of compliance requests come in. If you interface with the DoD supply chain at all, we’re getting a lot of questions about SPARS scores and CMMC. It seems like on a monthly basis, we’re getting questions about PCI compliance from clients who aren’t even retailers. And then anybody who’s interfacing in the finance space, we’re always discussing FINRA and how things are changing in that world and FTC and the way it integrates with IRS requirements for CPA firms.

So the wizards in their towers have been hard at work finding a way to provide an appropriate holistic approach to not just answering their questions, but implementing a program to help provide the visibility to those answers on an ongoing basis and provide evidence for any recommendations that we make in a way that isn’t just the Chip or Cody or Dave or Luke show. It’s a systematized platform and program that we were able to repeat and deliver on a repeated basis.

David: Yeah, absolutely. That’s a big priority to us at COVI that we create IT that is scalable, but not in the way. And the way that we approach that is by not reinventing the wheel, but finding that well established wheel and then finding the best way to apply it to that unique vertical or that unique industry.

As part of our core strategy for 2025 into 2026, we’ve been really focused on NIST frameworks and CIS frameworks. And for our listeners, if you’re not familiar, you can Google those or call us. We’d love to tell you about them. Shameless plug. But there are plenty of IT standards and frameworks out there that are effective. They’re effective in military settings. They’re effective in government settings, they’re effective in Fortune 500 settings. Why wouldn’t we as an IT provider take what already works and not reinvent the wheel, but again, apply it appropriately so that our customers have the best version of security and the best version of productivity, just like any other Fortune 500 company would be after.

And that’s what we’ve seen with Chip founding the company in 2000. One of his core philosophies was always what’s at Enterprise today is going to be at mid market and small business tomorrow.

Cody: That’s right. We have to be out in front of that transition and his prophetic ability or Jack’s technical foresight has always allowed us to be a few years ahead of those types of curves.

David: Yeah, that’s awesome. We talk about it a lot. I think we’ve even talked about it on the podcast, but COVI was one of the first companies to recommend that employers move to the cloud so that their team could be productive and effective anywhere and regardless of what was happening. And this was pre-COVID.

Cody: And this is when it was hard.

David: And this is when it was hard. And not even difficult complex cloud like Microsoft 365 administration was incredibly difficult back then.

Cody: That’s right. Jack coded his own program to simplify it.

David: Yeah. Which is no longer relevant.

Cody: Yeah. He called it no cloud left behind, which I don’t know if there could possibly be a more era appropriate reference.

David: I forgot about that. I always just called it no cloud, but I forgot about that.

Cody: That’s a podcast for another day. I’ve got so much nostalgia right now.

David: I know. Seriously. But it’s something that we’ve always been passionate about. And so as you and I have talked about a lot, as we go into 2026, many of our customers are going to see more of that framework and more of that structure from us as we continue to create that standardization. And as many of you have heard from us many times, standardization is there to create more productivity. It’s there so that we don’t have to reinvent, so that we don’t have to constantly ideate and create needless change. These are frameworks designed to balance security and productivity.

Cody: Can I give an example? Just real low hanging fruit example of that. It’s difficult for a business owner or I don’t know, an HR coordinator who has been purchasing laptops for years or has been Googling online and seeing Dell dot com or chat GPTing if you want to do it that way and finding on Dell dot com that they could get a slightly different model with the same specifications for $100 cheaper.

So standardizing or sticking with what is already standardized seems confusing and counterintuitive because we’re losing $100. But the benefit in that scenario of that standardization is we’ve got 50 of these computers deployed. And if we have a problem, we can put this standardized piece or tool in the puzzle. And now there’s no friction for the end user, which protects productivity or you could say it avoids work stoppage. So when they get the new one, all the drivers work and they don’t have to reinstall this different version of this application because of this slight configuration change. It’s standardized so that we can, like you said, protect efficiency.

David: Yeah, that’s huge. And the hundred dollars is a viewpoint at that point because it’s the client I’m particularly thinking of bills over $150 an hour. So that matters. We don’t need much more than a half an hour of friction before we’ve already paid for it.

Another great example of that, I saw an article this week that was analyzing IT and what loss productivity actually represents to a small business. And according to research, I believe the research was 2024, very recently, the average small business loses three hours of productivity to IT related headaches per employee every single week.

Three hours. So if we’re talking about, let’s say $150 an hour, so that’s $450 per, and let’s argue customer facing employee. Think about that for our average customer. Let’s not even say average customer. Let’s say average small business out there. Let’s say you’re 30 seats and half of your team is customer facing. That’s 15 people losing three hours at $150.

Cody: I would say that IT productivity matters a lot per week.

David: Yeah, again, it’s per week.

Cody: Even if you’re lucky enough to be in an industry that can take designated holidays off and everything, you’re still at 48 weeks.

David: That’s right. On average.

Cody: That’s right. Yeah, I would say that’s, yeah, again, maybe even above average. It’s four weeks off a year. We hope that you’re able to take that four weeks. We really do. I think that number, it calculates in paid time off, in vacations and sickness and everything as well. Like the fully loaded time off away from business activity.

David: That makes sense. So yeah, that IT productivity matters. And I think that’s where a lot of our customers, a lot of customers that come to COVI, that’s where they’re currently hung up. They’re losing that much productivity and it’s killing them to the point where their IT decision-making process internally is getting in the way and distracting them from the bigger picture company strategy decisions that need to be made.

And on top of all of that, we still have the security conversation. That metric is just taking into account loss productivity. And we know that a security breach can cost so much more.

Cody: Yeah, it’s over a million average. I think it’s closer to three, if I remember right. But I’m pulling that out of the interwebs in my mind.

David: Yeah, that’s right. Again, we’ve talked about this in the past, but the size of the malware industry now, if it were calculated like a country, US would be number one. China would be number two. And then the malware industry would be number three. That number is projected at the end of 2025 to be 10.5 trillion.

And that’s just malware as a service. That’s not the entire hacking sphere. It’s absolutely crazy. And so if you’re thinking about lost productivity, but then you’re also thinking about the threat of security, the industry is huge. The fact that we wish more small business decision makers knew was that the state of the industry, the malware industry has significantly changed from as recently as two years ago.

It’s growing at an exponential rate and the number one target is small business. 60% of malicious attacks are being leveraged against small business. Why? Because they’re unfortunately the least taken care of from a technical standpoint. They have the most going on as an organization. They’re the busiest and therefore their bank accounts, their literal bank accounts are the most vulnerable.

And so the average amount of money lost to a small business account is over $220,000.

Cody: $220,000. That’s a lot. So that means if they didn’t directly do a wire transfer fraud, this is just the hangover is $220,000.

David: That is correct. It’s immense. And that’s not even the total losses after the event, after loss customer trust, after loss sales, friction with existing customers, not to mention legal fees and other effects depending on the vertical that your business is in. The identity theft protection and notification.

Cody: That’s right. Opportunity cost is huge because the team is now trying to manage the after effect of this attack rather than actually running their business.

David: As a result, a lot of businesses don’t make it. They end up closing within that time period. 60% of small businesses who experience an attack close within six months. It’s in the 60th percentile. It’s that high, which is crazy. And again, it makes sense given our current economic climate, everything that’s going on and the level of resilience that a lot of small businesses already have to function in. When you have this much of a distraction to the business, it can be really bad.

And we believe that most IT companies have been downright irresponsible in not staying in front of this when they’ve accepted liability for these environments. And to be transparent, on a much smaller scale than what I usually see, we’re one of those companies as well. There are certain clients that won’t listen or don’t show up that I failed to force them in a kind, nurturing way to be like, look, it is my responsibility for you to know that this server is gonna blow up if we don’t make some strategic decisions about it right now, and that includes finances or in the next year, it’s probably a more realistic example.

And recently I was consulting for someone who wasn’t a COVI client and their IT partner had told them about a server that was failing for four years straight and it still failed because they didn’t make any decisions or actions around it. And they lost seven years of financial data. And then when I came in to consult, they were in the middle of an email incident where there was a cybersecurity situation with their email.

Cody: You are always really good at being very intentional and articulating this point. I don’t hear this in our industry hardly ever, and I’m still struggling to absorb it fully into my DNA that in sales, we say it’s your job to be annoying if that’s part of the process to get there. It’s your job to make sure that the follow-up’s met, it’s made sure to do all of it. And in revenue generation, everybody gets it. Sometimes we hate it, but we understand why it’s there.

In IT, it is our job to be annoying with air quotes, to get in there and make sure that the decision makers have the appropriate information to make the appropriate decisions. We as an industry at large really suck at it, which is one of the greatest sources of joy that I get from you joining our team, coming with a whole different layer of experience and making that a reality here very quickly.

I think we kind of lucked into that just being a part of our culture and DNA over the years and having really good clients that partnered with us. So it didn’t really cause any major problems. I’m sure it cost some. But then you took it to where it’s a very intentional part of almost every process we have, if not every process we have. So thanks.

David: Well, you know, Cody, there’s a big part of who I am that comes from radical candor from the book Radical Candor. And again, we talk about it all the time.

Cody: Yeah.

David: But it’s this concept of ruinous empathy, which says I can be nice to you, Cody, and not tell you what I probably need to tell you because I’m concerned about your current state of affairs in the short term. So out of genuine concern or genuine empathy, I’m not going to tell you something that you need to hear. But what happens is six months down the road, six years down the road, 60 years down the road, you come to an impasse because that information that you needed to take care of your future self, I didn’t give to you because I was looking at the short term instead of the long term. And therefore I hurt Cody a lot more than if I had just hurt him a little bit in the beginning. Because sometimes that full candor, that radical candor can be really painful, really uncomfortable, but my God, the pain after.

The example in the book is an individual, if I’m remembering this correctly, who struggled with presenting and presentations and slides and went a really long time with the team just saying, ah, you did fine, it’s okay. The individual needed to be removed from the team later because they simply needed someone in that seat. And this individual asks, why are you letting me go? Well, you just can’t do this. And he says, why didn’t you tell me this years ago? All you had to do was say something. I would have fixed it.

So if we take that through the lens of IT and relationships, we know a couple of things. Let’s just be plain and candid right here. One, we know that IT by our own industry’s fault has become a pain in the butt that wants to get into the weeds on a lot of nerdy things, not always presented in a way that is relevant to the task or business at hand and not always relevant to a company’s strategic vision. That’s an issue. Why? Because over time, if everything is loud, nothing is. And so over time, anyone who’s not an IT, they slowly turn that volume level down. That master level just keeps coming down. And so when an IT company wants to come to the table and say, hey, this might be a risk. Yeah, but so was everything else. It hasn’t been calibrated over time.

At COVI, we’re really passionate about developing that radical candor with our customers so that we’re coming to the table and bringing areas of concern. We have that place where a customer can say, hey, you’re giving me a lot of priorities. This seems like a lot. I need some help with understanding order. And on the other side of the equation, we can come to the table and say, hey, I know that based off of your IT experience, these IT meetings haven’t been of strategic relevance to you and therefore not a great use of your time.

COVI is going to approach IT decision making very differently. We’re very careful, for example, about change management and rolling out security platform initiatives to keep customers or keep your customers and your employees safe. But we have to have that decision ahead of time so that it can be done without disruption. We need to be able to come to the table with our customers and say, hey, this isn’t the way it’s worked before, but this conversation is important. Here’s exactly why it’s important, and here’s what we need to maintain the maturity and relationship. Here’s what we’re gonna discuss, and no more. We’re going to respect your time, but we’re letting you know how important this is.

And if you wanna schedule a lunch so we can talk about volleyball and kids’ sports, which we all do, we’ll schedule a lunch to talk about volleyball and sports when we have when we both have capacity instead of trying to force it into a really full meeting of really important topics.

Cody: That’s right. And we admit we own this proudly. We have a lot of eyes. If you’re in the disc world here at COVI, extroverts, extroverts, that’s right. For example, I’m a D.I. in the disc world. I believe you to be an I.C.

David: I am. Yes.

Cody: That’s weird. If you know, you’re just going to be like, what is across the plane?

David: Yeah, we all know I’m weird. If you know me, you know, I’m a weirdo. So point being, we love to talk. Cody loves to talk in great detail and I love to talk passionately.

Cody: It’s trouble. I love to talk passionately in great detail.

David: Great detail. Exactly. And I’m driving for it. And so we admit we’re guilty about this at times. But again, it comes back to for IT to function appropriately, which means we’ve protected productivity. We’ve saved that two to three hours a week per employee 95% of the time. And we’ve protected you from security risks, which are worth a lot more than two to three hours. In order for us to do those two things, it all comes back to the monthly meeting. Without that monthly meeting, we have one arm tied behind our back. And our decision makers have one arm tied behind theirs.

Cody: It’s core to COVI’s approach and it’s core to COVI’s strategy because within 30 days a lot can happen, which is, it’s not that new, but somewhat new and definitely not commonly known. I mean, what we have, two standardization projects this year that we didn’t get on the roadmap last year that we normally would have because things change so fast and priorities were reconfigured to require some small investments in really important things like password management and protecting against personal devices.

David: Yeah, that’s right. Things that, you know, I get really passionate about the mobile device piece and device compliance because we don’t think about how much we use this computer over our desktop computers. We probably live 60, 70% of our productive lives on this device. And once we go home, we keep working from it.

Cody: 90% of our unproductive lives.

David: Yeah. And exactly. Is this protected? Is this safe? And for company decision makers out there, when you send your employees home with your data on this device, is it safe? Can you pull it back if the phone is lost? I’m not talking about if your employee can do it for you. Can you as an organization protect your company information, your company financials, your customer information? Can you do it? And a lot of organizations out there, most organizations out there, the answer is no, because they don’t have any kind of mobile protocols in place.

So an IT provider has to do more than just protect your computers, and it has to do more than protect your network. It has to protect your information where it lives, and that means mobile devices. The good news is that technology has come such a long way, especially in the Apple ecosystem. And we love Apple here at COVI, not just because I have past affiliation, but also because they take an approach called sandboxing where the company data lives in its own sandbox. And if that employee leaves the company, when configured appropriately, that sandbox within an hour in most cases can be deleted and gone. We’re not messing with your employees or ex-employees personal information. We’re not messing with anything else. The information is gone.

And that, by the way, is the case, whether it’s a personal device or a corporately owned device, it is possible to create and place those protections. And if you’re an organization that can’t do that today, you are operating with huge exposure to risk. And probably in breach of some type of regulatory compliance because—

Cody: No doubt. They’re growing and growing so often, depending on your industry, and in most industries.

David: Yeah, that’s right. The risk is huge. And so for our customers at COVI, that’s one of our larger initiatives to say, hey, if you’re an organization that hasn’t made this move because this is still an opt-in, this is still something that we allow our customers to say yes or no to, we want that ownership and agency for them. This is something that we’re really encouraging you to do. And what we love at COVI is the cost to implement this is often just a handful of licenses. It’s usually very small for one of the biggest changes we can make.

Cody: And to be clear, those licenses are like Microsoft user licenses.

David: Yeah. I mean, in password management, it’s like, what, seven, eight dollars a user?

Cody: Yeah. And so it’s, I mean, if you have 50 to 100 users, that sounds like a lot of money, but we need to make sure that you understand the risks so you can understand if that’s a lot of money or not, because we don’t know what that answer is. It’s our job to make sure you have the information so you can know what the answer is.

David: That’s right. Man, password management. That one’s come a long way, hasn’t it?

Cody: Yeah, I mean, there’s been a lot of things for like, I don’t know, it feels like a decade now in that space.

David: Yeah, that’s huge. Our platform that we use internally that we recommend to our customers we’ve been loving. One, because it allows us to have shared password banks, which I know sounds crazy for an IT company to say what? And yet it’s implemented that well that we can for whatever platforms those happen to be appropriate use cases or requirements because they don’t have an option to do it differently.

Cody: Exactly. Like a platform limitation.

David: Yeah, like a bank portal. You’re not going to be able to have a user specific log into that. It’s going to be the company one. So what this tool does is it allows you to have these shared banks organized as small as department level, if you like, and then have individual banks where passwords can be saved and again, ultimately controlled by the company. And so what it does is it gets you away from using a platform specific password managers that you can’t control or make decisions around.

Cody: And you’re meaning like a Google Chrome.

David: Like a Google Chrome. Exactly. And it gets you to something that’s standardized that can even do two factor. So you know the Microsoft Authenticator app and the equivalent of that. These password managers in a safe, secure way that COVI trusts can save that two factor information. So it’s entering your password and the two factor code. Which means not only are you preventing risk and you are stopping the sharing of written down passwords or text passwords. But you’re actually saving time again with two factor codes. So I love it when something gets to be more secure and saves time.

Cody: Yeah, I mean, there was not that long ago a CEO who had taken over from their predecessor for five years and still didn’t have access to certain web applications or there were portals. And so they were literally getting text messages of two factor authentication tokens from the CEO who had been gone for five years.

And there are limitations to certain solutions like those types of portals that may or may not be able to integrate into these types of platforms. If you can integrate them to Google Authenticator or Microsoft Authenticator, it can go on the platform. But if it requires an email, we have a very standard and secure process for that. If it requires a text message or an SMS message, we have a clunkier version that’s also standardized and secure that we hope that you don’t have to use. But if you have a solution that requires it because it’s not modern enough is basically what it comes down to. And you see that a lot with industry specific solutions where their industry hasn’t had to modernize for a bunch of reasons that other industries have. So there’s these little features that aren’t there.

Our team, the wizards in their towers have documented down to like, hey, here’s the three options. And if these options don’t exist, then you are just exposed. There’s been a lot of change. There’s been a lot of movement. There are a lot of new platforms out there.

David: As an IT provider, as we’re looking at state of affairs this year and the next year, small businesses are busier than ever. Our big encouragement to these company decision makers is to evaluate the time you’re spending with IT and make sure you’re getting the time out of it, the objectives out of it that you need.

As we wrap today’s COVI podcast, we have a couple of call outs that we want to make. One, we encourage everyone to evaluate the time that they’re currently spending with their IT management company. Are you getting out of that conversation what you need to get out of it? And honestly, that includes our existing COVI customers as well. Our goal is to create that space where we can make decisions together. And we know that’s not what you’re probably used to based off of the history of IT management from other companies. But at COVI, we’re passionate about being an extension of your own leadership team in a very time efficient way. And by us investing that time, it means you can get in front of a lot more.

We talked about the three hours lost a week per employee due to bad IT decision making. And we talked about the increasing and growing risk of malware as a service. These are things that COVI is very passionate about staying in front of. It’s that monthly time that we spend with you that makes that forward looking strategy possible. And we believe that the time investment has an ROI of tenfold. And we’re really excited to continue those conversations.

The last tech takeaway, mobile protection is probably the most cost-effective thing COVI has ever rolled out. And that’s true for most IT companies, not just us. We strongly recommend that you look at your mobile protection strategy. What are you doing to protect the device that you spend 60% of your productive hours on. It matters. And at COVI, we’re passionate about protecting that too.

And that’s a wrap for today’s session of the COVI podcast. We will see you next time.

Covi — Business + IT

Let’s grow together.

Start a conversation