Managed IT
We Already Have an IT Person. They Just Cannot Do All of It Alone.
The IT manager at a 46-person industrial distributor in Warren had not taken a full week off in three years. He was good at the job. He knew every server in the building, every quirk of the warehouse scanners, and which sales rep would click on anything. He was also the only person who knew those things, which meant that when he went to his daughter's wedding in June, he answered two calls from the reception and remoted into the file server from a hotel lobby at eleven at night.
The owner did not want to replace him. Nobody in the building wanted that. What the owner wanted was for the company to stop depending on one person's phone being on. That is the exact problem co-managed IT services exist to solve, and it is a different problem from the one most businesses think they are shopping for when they call an IT company.
What are co-managed IT services, in plain English?
Co-managed IT services are an arrangement where you keep your in-house IT person (or small IT team) and add an outside managed IT provider to work alongside them. Your person stays. The outside team takes on the pieces one person cannot realistically carry.
Fully managed IT, which we explain in our guide to managed IT services for small businesses, means the outside company handles everything. Co-managed IT means the work is split on purpose, in writing, between people who know each other's names.
In practice, the outside team usually brings:
- Round-the-clock monitoring. Servers, firewalls, and backups are watched at 2 a.m. and on holiday weekends, when one person is asleep and when attacks tend to land.
- Security tooling and people to read it. Endpoint detection, email filtering, and log review run on platforms priced for organizations much larger than a single company, and someone other than your IT person responds when they alert.
- Patching at scale. Operating system and application updates pushed, verified, and reported across every machine, so patch management stops being a Friday afternoon chore that slips.
- Help desk overflow. Password resets and printer tickets go to a desk that answers, so your IT person gets their day back for the projects only they can do.
- Coverage for time off. Vacations, sick days, weddings, and resignations stop being emergencies.
- A second opinion. Someone to check the firewall change before it goes live, or to say "we saw this same attack at three other businesses this week."
Your in-house person usually keeps what they are best at: knowing the business, the line-of-business software, the people, and the priorities. They become the person who directs the work rather than the person who has to do every piece of it.
How do you know your IT person needs a co-managed partner?
Most owners find out the hard way. A few signs show up well before the crisis, and they are easy to spot once you know to look.
They cannot take real time off. If your IT person checks email on vacation because nothing works without them, the business has a single point of failure with a name and a phone number. Projects keep sliding. The server replacement that was supposed to happen last spring. The Microsoft 365 security settings that are "on the list." When the day fills up with tickets, the strategic work never starts, and the strategic work is usually the part that prevents the next incident. Security has become a side job. Nobody is reading the alerts from the antivirus console. The firewall firmware is two years old. Multi-factor authentication is on for most people but not all. This is not negligence. It is arithmetic. There are not enough hours for one person to do support and security properly. Your insurer or a customer is asking harder questions. Cyber insurance applications now ask about around-the-clock monitoring, tested backups, and incident response. A single IT person cannot honestly check "yes" to 24/7 monitoring, and a wrong answer on that application can become a problem at claim time. They are quietly looking for help. Sometimes the IT person is the one who raises it. If yours asks for "a partner" or "somebody to back me up," take that seriously. It usually means they have been carrying more risk than they wanted to admit.If none of this sounds familiar and your company is closer to 10 employees than 50, you may not have an IT person at all. You may have an employee who became the IT person by accident, which is a different situation that we walk through in the person everybody asks for computer help was hired to do something else. And if your IT person just gave notice, start with what to do in the first 72 hours after your IT guy quits.
How do co-managed IT services divide the work?
This is where co-managed arrangements succeed or fail. The failure mode is simple: two parties each assume the other one has something covered, and the thing nobody owned is the thing that breaks.
The fix is a written responsibility list (some providers call it a responsibility matrix) that names an owner for every recurring task. For the Warren distributor, the split landed roughly like this:
- In-house IT manager owns: the warehouse management system and scanners, the ERP vendor relationship, new-hire and departing-employee setup, on-site hardware, user training, and final say on any change that affects operations.
- Outside team owns: 24/7 monitoring and after-hours response, endpoint detection and response, email security, patching and the monthly patch report, backup monitoring and a quarterly test restore, and help desk overflow during business hours.
- Shared, with a named lead: firewall changes (outside team makes them, IT manager approves them), incident response (outside team leads the technical work, IT manager leads communication inside the company), and the annual technology plan (both at the table with the owner).
Notice that the in-house person did not lose authority. If anything, they gained it. They stopped being the only pair of hands and became the person who decides where the hands go.
Two practical details make the split work day to day. First, both teams use one ticketing system, so a ticket opened by a warehouse lead at 6 a.m. is visible to everyone and nobody works the same problem twice. Second, the documentation lives in one place that both sides can edit (network diagrams, passwords in a shared vault, vendor contacts), so the company's knowledge is no longer stored in one person's head.
Is co-managed IT the same as replacing your IT person?
No, and it is worth saying that out loud to your IT person before you start looking, because the fear is real.
A good co-managed provider is not angling to take the job. The in-house person's knowledge of your business is exactly what makes the arrangement work, and it is the part an outside team cannot buy or replicate quickly. The outside team is there to take the 2 a.m. calls, the security grind, and the overflow, not the relationships and the judgment.
Handled well, co-managed IT tends to make an in-house IT job better. The person gets real vacations, gets to work on projects instead of password resets, and gets peers to learn from. For a small company, that is also a retention strategy. The IT person who has backup and room to grow is less likely to leave for a larger employer in Pittsburgh or Cleveland, and if they do leave someday, the company is not starting from zero.
When you talk with providers, listen for how they describe your IT person. If the pitch sounds like "we will eventually handle all of this for you," that is a fully managed sales conversation wearing a co-managed name tag. Our guide on how to choose an IT company for a small business covers the questions that separate the two.
How do co-managed IT services help with compliance?
For regulated businesses, the case for co-managed IT gets stronger, because the rules usually assume more than one person is doing the work and checking it.
Take a 22-person accounting and tax practice in Erie. Tax preparers are covered by the FTC Safeguards Rule, which requires a written information security program and a designated "Qualified Individual" who oversees it. The rule allows that Qualified Individual to be employed by a service provider, as long as the firm keeps responsibility, designates a senior person on its own staff to oversee the provider, and requires the provider to maintain appropriate safeguards. The rule also calls for regular reporting to the firm's leadership, ongoing monitoring or periodic testing, and multi-factor authentication for anyone accessing customer information.
A firm with one IT generalist can struggle to show all of that. In a co-managed setup, the in-house person handles the day-to-day, the outside team supplies the monitoring, testing, and documentation, and a partner at the firm oversees both. That structure maps directly onto what the rule asks for. The IRS pushes tax professionals in the same direction with its written security plan guidance, and busy season in February and March is the worst possible time to discover a gap.
Medical and dental offices face a parallel structure under HIPAA. The Security Rule requires a designated security official and a documented risk analysis, and any outside IT provider that can access patient information needs a signed business associate agreement. A practice in Meadville or Kittanning with one IT person can use a co-managed partner to carry the risk analysis, the monitoring, and the audit logs, while the in-house person keeps the electronic health record running for the front desk.
These are general descriptions, not legal advice. Ask your attorney or compliance advisor how the specific requirements apply to your business.
What should a co-managed IT agreement spell out?
Before you sign, make sure the agreement answers these in writing:
1. The responsibility list. Every recurring task with a named owner, including the shared ones. If a task is not on the list, assume nobody owns it.
2. Access and permissions. What administrative access the outside team gets, how it is logged, and how it is removed if the relationship ends.
3. After-hours escalation. Who gets called for what, in what order, and when the outside team is allowed to act without reaching your IT person (for example, isolating a computer that is actively being encrypted).
4. Tools and ownership. Which monitoring and security platforms the provider brings, who owns the data in them, and what you keep if you leave.
5. Reporting. A monthly or quarterly report both your IT person and the owner can read, covering patch status, alerts handled, backup tests, and open risks.
6. Documentation. Where it lives, who maintains it, and a clause that it belongs to you.
7. Exit terms. How either side ends the arrangement without leaving your systems half-handed-off.
Pricing for co-managed IT varies with how much of the work the outside team carries, so a provider should scope it after looking at your environment, not quote it on the first call. Our post on managed IT services pricing explains how per-user and per-device models work and what drives the number up or down.
How did it work out in Warren?
The distributor signed a co-managed agreement in July. The outside team took over monitoring, security, patching, and help desk overflow. The IT manager kept the warehouse systems, the ERP, and the final say on changes. The first monthly report showed eleven machines that had been missing security updates for more than ninety days and a backup job that had been failing quietly since spring. Both were fixed in the first two weeks.
In September, the IT manager took five days off. His phone rang once, from the owner, asking how the fishing was.
MCR Business Tech Solutions works alongside in-house IT staff at businesses across Mercer, Lawrence, Butler, Crawford, Erie, Armstrong, and Allegheny counties in Western Pennsylvania, and across Trumbull and Mahoning counties in eastern Ohio. Whether you need full managed IT support or a partner for the IT person you already trust, call 833-859-9021 or Request an IT assessment through our contact page. We will start by learning what your IT person already handles well, and build around that.