What is co-managed IT and when does it make sense?

Short answer

Co-managed IT is an arrangement where a managed IT provider works alongside your internal IT person or team instead of replacing them. Your staff usually keep business applications and user relationships, while the provider adds monitoring, security tooling, patching, after-hours coverage and project capacity. It makes sense when you value your internal staff but lack depth or coverage, and only works with a written split of responsibilities.

How the work is usually split

There is no standard split. CISA advises that the balance of responsibilities between a customer and a provider be jointly agreed after weighing the risks, and recorded as the provider's duties, your duties and shared duties. A common pattern looks like this:

  • Your internal team: business applications such as ERP, user relationships and on-site support, onboarding and offboarding decisions, and knowledge of how your company actually works
  • The provider: monitoring and alerting, endpoint protection and other security tooling, patching, backup operations, and help-desk overflow or after-hours coverage
  • Either side, agreed in advance: projects and migrations, Microsoft 365 administration, compliance documentation and evidence for frameworks such as CMMC
  • Your leadership, always: risk decisions, budget, and approval of who holds administrator access

When co-managed fits better than fully outsourced

Co-managed IT fits when you already have capable IT staff who know your systems and people, but they are stretched: one person cannot watch alerts at night, run security tools, keep up with patching and still deliver projects. It also fits when you need compliance depth your team does not have, or want to avoid losing institutional knowledge.

Fully outsourced IT usually fits better when you have no IT staff, your needs are fairly standard, or you would rather hold one provider accountable for the whole function. Neither model removes your own responsibility: CISA states that outsourcing to an MSP does not absolve an organization of its risk management responsibilities.

How to define the split

Write it down before work starts, and review it whenever staff or scope changes. NIST CSF 2.0 frames this as governance: roles, responsibilities and authorities for cybersecurity risk should be established, communicated, understood and enforced, including for suppliers.

  • A RACI matrix for each service area: who is responsible, who is accountable, who is consulted, who is informed
  • Shared tooling: one ticketing system, one monitoring platform and one documentation store both teams can see
  • Escalation paths: what the provider fixes on its own, what it hands to your team, and who decides during an incident
  • Access rules: named, individual provider accounts with multi-factor authentication and least privilege, with logs you can review
  • Reporting: regular reports on tickets, patch status, backups and security alerts, reviewed by someone with authority

Risks to manage

The biggest risk in co-managed IT is blurred ownership. If both teams assume the other is patching a server or reviewing an alert, nobody is. Duplicate tools are a close second: two remote-management agents, two antivirus products or two backup systems add cost, conflict and attack surface.

Security accountability needs the most care. The joint CISA, NSA, FBI and international advisory on MSP threats recommends contracts that transparently identify ownership of security roles and responsibilities, multi-factor authentication on provider accounts that access your environment, and internal incident response plans that are regularly exercised. CISA also recommends keeping your own logs of provider activity and backups of critical data separate from the provider's storage.

Common follow-up questions

Will co-managed IT replace my internal IT staff?

It should not. The model is built around your internal person or team staying in place and owning the work that depends on knowing your business. The provider adds coverage, tooling and depth. If replacement is the goal, that is a fully outsourced engagement and should be planned openly.

Who is accountable when a security incident happens?

Your company remains accountable for the risk. The contract and RACI should name who detects, who responds, who leads communication and who makes decisions, so that during an incident nobody has to work out whether the internal team or the provider owns the next step.

Can we move from co-managed to fully outsourced later?

Yes. Shared tooling and documentation make the transition easier because the provider already knows your environment. Make sure your company, not either party, owns administrator credentials, licenses, domains and documentation, so you keep options open in either direction.

Need help with this?

LAN Service Group provides co-managed IT alongside in-house IT teams as well as fully outsourced IT for small and mid-size businesses.

Talk to LAN Service Group (888) 281-7243

Sources