Most articles about IT support present two doors: hire your own IT staff, or outsource everything to a managed service provider. Co-managed IT is the third door, and for companies between roughly 50 and 250 employees it is often the best one. Your internal IT people and an outside provider share the work, each doing what they are structurally better at. Here is how the model works, what it costs, where it shines, and where it goes wrong.
The plain definition
Co-managed IT (sometimes written co-MITs or called hybrid IT) is an arrangement where a company keeps internal IT staff and also contracts with a managed service provider, with responsibilities explicitly divided between them. It is not a consultant on retainer, and it is not an MSP with your IT manager awkwardly in the loop. Done properly, it is a written split of duties: the contract says who owns the helpdesk, who owns the servers, who watches security alerts at 3 a.m., and who decides what gets bought.
If you are still weighing whether to have internal staff at all, start with MSP vs in-house IT; if MSPs are new territory entirely, What is a managed service provider? covers the fundamentals.
How the split usually works
There is no single standard division, but most co-managed arrangements land in one of three patterns:
Internal strategy, outsourced operations
Your IT manager or director sets direction, owns vendor relationships and the budget, and handles executive-facing work. The MSP runs the helpdesk, the monitoring, the patching, and after-hours coverage. This is the most common pattern and fits companies whose IT leader is drowning in tickets that a helpdesk should be absorbing.
Internal helpdesk, outsourced depth
Your internal tech handles day-to-day user support (they know the people, the printers, and the quirks), while the MSP provides the heavy expertise: network architecture, cloud infrastructure, and above all security operations. Common in companies whose internal staff are capable generalists but cannot cover specialized domains.
Everything shared, tooling provided
The MSP supplies its enterprise tooling (monitoring platform, ticketing, security stack, documentation system) and acts as overflow and escalation, while internal staff work inside those tools. Internal IT gets tooling priced for thousand-seat fleets that it could never license alone; the MSP provides surge capacity and vacation coverage.
Which pattern fits depends on what your internal people are best at and what your risks are. Getting that division right is a design problem, and it is exactly what our composition strategy service works through with clients.
What co-managed IT costs
Because the MSP is covering part of the workload rather than all of it, per-user pricing runs below full management: typically $50 to $125 per user per month depending on the split, versus $100 to $250 for fully managed coverage (full ranges in our pricing guide). A 100-person company pairing one internal IT manager (roughly $120,000 to $160,000 all-in in the Bethesda labor market) with a co-managed agreement at $75 per user (around $90,000 per year) spends about $220,000 to $250,000 annually, which is usually less than a three-person internal team and buys broader coverage than either model alone.
Watch the same fine print as any managed agreement: what counts as "in scope" for the MSP, after-hours rates, project pricing, and who pays for security incident remediation.
Why companies choose it
- It ends the single point of failure. When your IT manager is on a plane, the monitoring, the helpdesk, and the security operations center keep running.
- Your best people stop doing password resets. The most common complaint of internal IT leads is that ticket volume eats the strategic work they were hired for. Offloading tier-1 support is often the single highest-value part of the arrangement.
- Enterprise security becomes affordable. Around-the-clock security monitoring and response is staffed for dozens of clients at once; no 100-person company can build that internally at a defensible cost.
- Coverage scales with growth. Doubling headcount changes a line item, not your org chart.
- Institutional knowledge survives. The MSP's documentation platform means your environment no longer lives in one person's head, which also makes an eventual internal hire or transition far less painful.
Where it goes wrong
Co-managed IT fails in predictable ways, all avoidable:
- Fuzzy boundaries. If the contract does not say who owns a category of work, each side will assume the other has it, and you find out during an outage. The responsibility split must be written, specific, and revisited yearly.
- Threatened staff. If your IT people hear "we hired an MSP" as "you are being replaced," they will quietly sabotage the relationship. Position it honestly, and mean it: the MSP takes the work they resent, not the work they value. Involve them in selecting the provider.
- The wrong MSP. Some providers only really know how to fully manage clients and treat internal IT as an obstacle. Ask any candidate how many co-managed clients they support today, and have your IT lead interview them; the ones built for it will talk about shared tooling and escalation paths, not takeover. The rest of the vetting checklist is in 12 questions that matter.
- Tool sprawl. Two ticketing systems and two monitoring platforms is worse than one of either. Agree up front on one stack, usually the MSP's, with your team given real access.
The Bethesda fit
Co-managed IT suits Bethesda's business mix unusually well. The area is dense with organizations that are too sophisticated for a two-person MSP relationship but too specialized to outsource blindly: biotech and life-science companies along the 270 corridor with lab systems and intellectual property an outside helpdesk cannot be trusted to improvise around; law firms whose document management and client-confidentiality requirements need someone in the building; medical practices and research organizations near NIH and Walter Reed carrying HIPAA and federal data obligations; and government contractors serving agencies across the D.C. line, where CMMC requirements demand documented security operations beyond what one internal admin can run alone. In each case the winning combination is the same: internal staff who hold the institutional and regulatory context, plus a provider supplying depth, coverage, and compliance-grade security operations.
The labor market pushes the same direction. IT salaries in Montgomery County are among the highest in the country, and a 100-person company that would need three internal hires elsewhere can often run leaner here by pairing one strong IT leader with the right provider.
Is it right for you? A quick test
- You have at least one internal IT employee you want to keep, and they are stretched past capacity.
- You are between roughly 50 and 250 employees, or growing toward that range.
- You have security or compliance obligations that exceed what your internal team can cover around the clock.
- Your IT person spends most of their week on tickets rather than the projects you actually hired them for.
- You worry about what happens if your IT person resigns tomorrow.
Three or more of those, and co-managed IT belongs on your shortlist of models. From there the work is choosing the split and choosing the partner: define the division of responsibilities first, then evaluate providers against it (a structured RFP works as well for co-managed arrangements as for full outsourcing, and forces candidates to commit to the split in writing). For one-off initiatives that outgrow the arrangement, like a migration or an office buildout, dedicated IT project management can bolt on without disturbing the day-to-day relationship.
Find a provider built for sharing
Our free brokering service knows which Maryland MSPs genuinely run co-managed relationships and which just say they do, and matches you accordingly.
Start Your Free Match