Who owns what in each model
Most of the disagreement about these three options disappears once you write down who is responsible for each piece of work. Below is how the responsibilities usually land.
When an internal hire is the right call
Somewhere past 60 or 70 users, and earlier in a manufacturing or multi-site operation, the volume of hands-on work justifies someone in the building. Physical environments need a person who can walk to the floor. Custom or line-of-business applications need someone who knows them deeply.
The two things that go wrong are predictable. One person cannot cover nights, weekends, and vacations, so the coverage gap is structural rather than a performance problem. And a generalist hired to keep things running is rarely also a security specialist, a network engineer, and a compliance analyst, which is what a cyber-insurance questionnaire now assumes you have.
When co-managed fits
Co-managed works when you already have capable internal staff and the gap is coverage, depth, or tooling. Your person stays the face of IT and keeps context on the business. The outside team brings the monitoring stack, the security operations, the after-hours rotation, and a second opinion on architecture.
The whole model depends on the split being written down. Who closes the ticket, who owns the escalation, who touches the firewall, and who is called at 2 a.m. If those are unclear, both sides assume the other has it. Co-managed IT starts from that written split.
When fully managed is the cheaper answer
Under about 60 users, and especially with a single site and standard applications, an external team covers monitoring, patching, backup, identity, security, and help desk for less than a first hire and across more hours. You also stop being one resignation away from having no IT function at all.
The concern people raise is losing institutional knowledge. That is a real risk, and it is why we put a named owner on the account instead of rotating whoever is free. Documentation of your environment belongs to you either way. Managed IT covers the ongoing side; Fractional CIO/CISO covers the seat at the table when spend and risk need an owner.
A short way to decide
- Count your users and devices. Under 60 users on one site, start with fully managed.
- Ask what happens now at 9 p.m. on a Friday. If the answer is nothing happens, you have a coverage problem rather than a capability problem.
- Look at your last cyber-insurance questionnaire. If nobody can answer it from memory, the gap is security operations and documentation.
- Ask whether your existing IT person is stuck doing password resets instead of the projects you hired them for. That is the clearest signal for co-managed.
- Separate the run from the strategy. Someone keeping systems alive is not the same role as someone deciding what to spend and what to retire.