Co-managed IT means your internal person or team keeps doing the work they’re good at, while an outside provider fills the specific gaps, after-hours monitoring, security tooling, overflow tickets, under a written split everyone agrees on ahead of time. It isn’t staff augmentation and it isn’t a takeover. It’s a third option most owners never hear pitched.
A client in Orangetown called us two years ago. Not to switch providers. She wanted to know if a middle option even existed, something between hiring and firing. Their main tech left to work in the private sector, leaving their remaining tech overburdened and under prepared. He needed help, but they didn’t want to put themselves in the position of solely relying on their internal staff, only for this to potentially happen again. “Can we have internal IT and also have an outside team to handle things that internal IT can’t?” Nobody had apparently asked that question out loud before.
It existed. It still does. VJNetworks sells managed IT services, and co-managed arrangements are part of that business. The mechanics underneath don’t change based on who’s explaining them. Ours or anyone else’s.
What Co-Managed IT Actually Means
Three models exist, not two. Fully in-house, where your own people own everything. Fully outsourced, where a provider owns everything and you keep nobody in-house. And co-managed, sitting in the middle, where responsibility for specific functions gets divided in writing between your team and ours. A middle path. Actually workable.
People confuse this with staff augmentation constantly, but the two work differently under the hood. Staff augmentation drops a contractor under your management, doing whatever you assign, billed by the hour. Co-managed IT is different in structure. We own defined outcomes in our lane, not just hours logged. Patching either happens on schedule or it doesn’t. Backups either restore or they don’t. Nobody’s clocking a contractor’s time card to find out.

Who This Actually Fits
Two patterns show up again and again. Mid-size companies with a real internal IT presence, one to three people, who are good at the day-to-day and drowning in everything else. And municipalities, where a small tech staff serves half a dozen departments with completely different needs, from the DPW to the clerk’s office, and specialization was never realistic to begin with.
Neither needs rescuing. Both are stretched thin in a specific, predictable way. Your internal person knows the users, the history, the office politics, and exactly why the third-floor printer hates Tuesdays. None of that transfers to an outside vendor easily. It shouldn’t have to. What doesn’t transfer well the other direction is depth. Security operations, after-hours coverage, specialized tooling. That’s the seam co-managed IT is built to close.
It also matters for hiring math nobody likes to say out loud. One stat says it plainly. CompTIA’s 2024 IT Industry Outlook found that 52% of IT channel firms, the companies whose entire job is supplying tech talent, are themselves struggling to find candidates with the cybersecurity skills they need. If the people who staff IT departments for a living can’t fill those seats fast enough, a 20-person manufacturer competing for the same hire isn’t losing because they did something wrong. They’re losing because the pool is smaller than the demand. Borrowing depth from outside stops being a compromise and starts being the obvious move.
How the Split Actually Works
Every failed co-managed relationship I’ve seen traces back to the same root cause. Nobody wrote down who owns what before starting. Vague splits create dropped tickets, duplicated work, and two teams quietly assuming the other one handled it. A real engagement gets the boundaries in writing first.
| Function | Usually stays with your team | Usually moves to the provider |
|---|---|---|
| End-user support | First-line, in-person, anything needing office context | Overflow tickets, after-hours requests |
| Monitoring | Business-hours awareness, escalation calls | 24/7 network and security monitoring |
| Patching and backups | Approval and scheduling windows | Execution, verification, restore testing |
| Vendor relationships | Owned in-house, full stop | Technical input when asked |
| Security tooling | Policy decisions, incident sign-off | Deployment, tuning, alert triage |
That table is a starting point, not a contract. Every engagement gets negotiated against your actual team’s strengths. A company with a sharp security-minded IT lead keeps more of that column. A company whose one IT person is stretched to breaking on tickets alone hands over more of the first row. The point isn’t the specific split. It’s that a split gets written down before day one, not discovered during an outage.

Where This Actually Breaks
I’ll say the quiet part. The most common failure isn’t technical. It’s fear.
An internal IT person who suspects co-managed is a slow-motion layoff will withhold access, sit on information, and treat every provider recommendation as a turf grab. Nobody hands over the keys cheerfully if they think the next conversation is about their job.
The framing has to be honest, and it has to come from the owner. Not just the provider talking. Co-managed IT extends a team. It doesn’t replace one. If leadership can’t say that plainly and mean it, don’t start the engagement. Your IT person will smell the real intent within a month regardless of what the kickoff meeting slides said.
The second failure mode is quieter. No shared visibility. If your team and ours are looking at two different dashboards, two different ticket queues, two different truths about what’s actually broken, the arrangement degrades into finger-pointing by month three. Shared tooling isn’t a nice-to-have. It’s the thing that keeps both sides honest. No exceptions.
What It Actually Costs
Anyone who gives you a clean number before looking at your environment is guessing. Co-managed pricing swings on scope, headcount, device count, and how much of that responsibility table moves in each direction. Per-seat, per-device, and flat retainer models all exist in the market, and the range across providers is wide enough that a specific figure without context is closer to marketing than information.
Here’s what’s not a guess. VJNetworks’ baseline managed plans start at $995 a month for a company our typical size, and co-managed scopes get custom quotes based on what’s staying in-house and what VJNetworks will handle.
One more data point worth knowing, because it says something about where the industry is actually heading, not just where the marketing points. Kaseya’s 2025 Global MSP Benchmark Report found that 61% of MSP executives reported their co-managed IT revenue grew year over year, and roughly two-thirds now pull up to half their total revenue from co-managed arrangements specifically. This isn’t a niche offering anymore. It’s becoming a normal way mid-size companies structure IT.
Testing the Arrangement Before You Need It
Don’t wait for an outage to find out whether the escalation path actually works. NIST’s federal incident handling guide recommends running tabletop exercises before a real incident forces the test, and that advice applies just as well to a co-managed relationship as it does to a standalone security team. Walk through a fake server failure at 2am. See who gets called, how fast, and whether both sides agree on what happens next. If the answer is fuzzy on a Tuesday afternoon with everyone calm, it will not get clearer during an actual outage.
Municipalities in particular should take this seriously. CISA’s own guidance treats state, local, and tribal government systems as a distinct risk category, not an afterthought bolted onto general small-business advice, because public infrastructure carries consequences a private office doesn’t. A co-managed arrangement that’s never been pressure-tested is a plan on paper. Nothing more. Untested plans fail loudly.
Common Questions on the Way In
Is this just staff augmentation with a different name?
Will this eventually replace our IT person?
We’re a two-person IT shop. Is that too small for this to work?
What if we only want help with one thing, like security monitoring?
What happens if it doesn’t work out?
If any of this sounds like the arrangement your business needs and nobody’s ever offered it, that’s the actual problem this post exists to fix. It’s a real option. VJNetworks runs co-managed engagements today, alongside fully managed IT for companies that want the whole thing handled. If you’re worried specifically about a one-person shop and succession risk rather than augmenting an existing team, we wrote a separate piece on that exact problem.
A free IT assessment maps your current setup against a real responsibility split, no pressure to sign anything. You keep the findings either way.
Over 20 years in the Tri-State area · 97% client retention · a real person responds within 15 minutes
