All insights

What is co-managed IT, and when does it make sense?

5 min readBy Brendon Whiting, Founder · 8 June 2026

Co-managed IT splits the work between your internal IT capability and a provider: your people keep the day-to-day and the local knowledge, while the provider supplies the heavy machinery, security operations, patching discipline, backup management, escalation depth and after-hours cover. It suits businesses big enough to have IT staff but not big enough to run everything alone.

The model exists because of a gap. Between the business with no IT staff and the business with an IT department sits a long middle, often one IT manager or a small team, holding a job no single human can fully do. Someone has to answer the desk, patch the systems, watch the security alerts, test the backups, run the projects and also sleep, take leave and occasionally resign. The lone IT manager is not failing; the role as commonly designed is impossible, and co-managed IT is the design fix. Most businesses discover the gap through symptoms rather than analysis: projects that never start, patching that happens when there is time, and an IT manager who has not taken a clear fortnight of leave in years.

The split follows a consistent logic: people keep what needs context, providers take what needs scale. Internally that means desk-side help, local knowledge of how the business actually works, internal projects and vendor relationships that are really business relationships. To the provider goes the platform: monitoring, security operations that run all night, patching applied on discipline rather than availability, backup management with tested restores, and depth to escalate into when something exceeds one person's specialities. The single most important artefact in the arrangement is the boundary, written down, owner by owner, because a control both parties assume the other runs is a control nobody runs. A good boundary table is short and dull, a page of functions and owners, and it prevents more incidents than most products.

It is not theoretical. AFM Services, an accounting firm of 47 staff, runs exactly this arrangement with us: the firm's server was decommissioned, its practice moved from MYOB to Xero, security was lifted to Essential Eight Maturity Level 1 with ThreatLocker application control in a Zero Trust posture, and the ongoing model is co-managed, internal capability where context matters, our platform and security operations underneath. Forty-seven accountants during tax season is not an environment that forgives IT gaps, which is rather the point.

When does it make sense? The honest markers: you have at least one genuine internal IT person whose time is consumed by platform grind rather than the projects you hired them for; your security and after-hours coverage depends on one human's stamina; or your business is growing faster than one person can document. When does it not: businesses small enough that fully managed is simpler and cheaper to run, and, at the other end of the scale, organisations truly ready to build a complete internal department, where the provider's role naturally shrinks to specialist services and surge capacity. Growth is the usual trigger: the split that works at twenty staff strains at fifty, which is why the review date matters as much as the table.

The anti-pattern deserves its own paragraph, because it is common: co-managed as a political compromise, adopted to avoid a decision, with no written boundary. That version combines the costs of both models with the accountability of neither, and it is where the arrangement's bad reputation comes from. If a boundary conversation feels too awkward to have at signing, it will be far worse mid-incident.

What belongs in the agreement, minimally: a boundary table naming an owner for every function, patching, backups, security alerts, onboarding, offboarding, escalation paths in both directions, shared access to documentation and tooling so neither side hoards keys, and a review date, because the right split this year is not the right split at twice the headcount. Offboarding deserves particular care, because departures are exactly where co-managed gaps become security holes.

The caveat: co-managed done vaguely is worse than either pure model, so if your business cannot yet say who would own what, start that conversation before any contract. If you want to see how we run the split, including what the first weeks look like, call 1800 456 567.

See how a co-managed start works

Onboarding begins with documenting the environment and writing the boundary down, so your team and ours each know exactly what they own from day one.

Frequently asked questions

Done properly, it changes the job rather than ending it, usually for the better. The internal person sheds the parts one human cannot sustainably carry, nights, leave cover, security operations, patching grind, and keeps the parts where they are irreplaceable: local knowledge, projects and presence. The honest exception is a business that hired for the platform work alone.

Whoever the agreement says, and the agreement must say. Common patterns: staff ring the provider's service desk and the internal person handles walk-ups and hands-on needs, or the internal person is first contact with the provider behind them for depth and after-hours. Either works; staff guessing between two doors is what fails.

Not automatically, because you are paying a salary plus a subset of the managed fee. Its value is capability rather than discount: context and presence from your person, plus platform, security operations and cover from the provider. Businesses choosing co-managed to save money are usually measuring the wrong thing; choose it for the coverage.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.