By Jason Small, Partner and Head of Technology, Fantastic IT
If you have capable internal IT staff and want them to continue leading technology operations, we recommend starting with co-managed IT. Keep business priorities, application knowledge, and approval decisions inside your company, and assign a provider the support, maintenance, or specialist work your team needs help delivering. Fully managed IT fits when you want a provider to take primary responsibility for agreed day-to-day services while your employees focus on business applications, projects, or technology leadership.
At Fantastic IT, we approach this decision by looking at the work that needs an owner. Compare what each arrangement covers, what it costs, and what your internal employees will be responsible for afterward.
The short version
Choose co-managed IT if your internal team will continue running IT and needs additional capacity, expertise, or coverage. You might retain employee support and assign monitoring and backups to a provider, or hand over routine support so your staff can focus on business systems.
Choose fully managed IT if you want a provider to lead the agreed support and maintenance functions. You can retain internal IT employees, but their roles should reflect the responsibilities they will keep.
| Decision | Co-managed IT | Fully managed IT |
| Daily operations | Your internal team leads, with defined functions assigned to the provider. | The provider leads operations covered by the agreement. |
| Internal staff’s role | Your staff retain selected support, application, and project responsibilities. | Your staff focus on retained functions, such as application ownership and technology planning. |
| Employee support | Requests follow an agreed division and escalation process. | The provider becomes the main contact for covered requests. |
| Business decisions | Your company approves budgets, priorities, and access. | Your company approves budgets, priorities, and access. |
| Best reason to choose it | You want to strengthen your internal IT operation. | You want to transfer primary responsibility for covered operations. |
This comparison is a planning guide. Your service agreement should define actual responsibilities and coverage.
How should you compare the costs?
Compare the cost of filling the same operational gaps under each option. If you plan to retain your existing IT employee, include that employee’s compensation in both budgets.
The Bureau of Labor Statistics provides a starting point for evaluating additional hiring costs:
| Role | National median annual wage, May 2025 | Estimated annual compensation using the benefits assumption below |
| Computer user support specialist | $61,860 | About $88,400 |
| Computer network support specialist | $76,220 | About $108,900 |
| Network and computer systems administrator | $99,130 | About $141,600 |
The wage figures come from BLS’s support specialist data and systems administrator data. They are national benchmarks, rather than local hiring quotes.
For June 2026, BLS reports that wages represented 70% of private-industry employer compensation costs, with benefits accounting for 30%. The estimates above divide each wage by 0.70. This applies an average across private-industry workers to the IT wage benchmarks, so use it for initial budgeting and replace it with your company’s actual benefits costs. BLS employer compensation costs.
For example, adding a support specialist produces an estimated annual compensation cost of roughly $88,400 under that assumption. Compare an actual provider proposal with that benchmark, then check whether it supplies the support hours, onsite work, maintenance, and specialist services you need.
The services will differ from what a dedicated employee delivers. Ask providers to separate recurring fees, onboarding charges, projects, hardware, and subscriptions, and identify any costs their service would replace.
Hiring may fit better when you need someone physically present throughout the working day or deeply involved in a specialized application. Co-managed IT fits when your gaps span several functions and a provider’s agreed scope covers them.
Which responsibilities should stay inside your company?
Keep decisions that require business authority or detailed knowledge of how your company operates. A provider can advise you and implement approved work, but someone inside the business should own priorities, spending, and acceptable disruption.
We recommend retaining:
- Budgets and priorities. Decide whether an office expansion, application replacement, or security improvement comes first.
- Business application ownership. Keep an internal owner for how accounting, scheduling, production, or other specialized systems should work.
- Access approvals. Have department managers approve employee permissions before IT implements them.
- Recovery priorities. Decide which systems must return first and how much downtime or lost work the business can tolerate.
- Provider oversight. Assign someone to review performance, approve changes, and resolve scope questions.
Consider an illustrative manufacturing company. Internal staff could retain production scheduling requirements and maintenance-window approval, while a provider handles agreed server monitoring and updates.
The written procedure should specify who approves a restart during production and who checks that scheduling software works afterward. That makes the division useful during an actual maintenance task.
Which responsibilities should you give a provider?
Assign work that needs coverage, specialist knowledge, or repeatable execution your team cannot comfortably sustain. Start with tasks that are delayed, depend on one employee, or repeatedly interrupt higher-priority projects.
| Responsibility | Keep internally | Assign to the provider |
| Employee support | Specialized application knowledge and business context. | Agreed routine requests, overflow support, and escalated troubleshooting. |
| Monitoring and maintenance | System priorities and maintenance approvals. | Monitor covered systems, investigate alerts, and perform agreed maintenance. |
| Software updates | Test business applications and approve disruptive changes. | Deploy agreed updates and report failures or exceptions. |
| Backups and recovery | Set restoration priorities and acceptable downtime and data loss. | Monitor backups, investigate failures, and perform documented recovery tests. |
| Security operations | Approve access, business risk decisions, and incident communications. | Operate agreed security tools, investigate alerts, and escalate incidents. |
| Onboarding and departures | HR notifications and manager approval of access. | Create or disable accounts and prepare devices under the agreed process. |
| Projects | Set requirements and accept the finished work. | Perform specialist design or implementation within a defined scope. |
This is a proposed division. Confirm each responsibility in the agreement, including exclusions and separate project charges.
Give software updates a clear owner
Microsoft publishes its monthly Windows security update on the second Tuesday of each month, typically at 10 a.m. Pacific, and issues out-of-band updates outside that schedule when needed. That creates 12 scheduled releases annually, plus unscheduled work. Microsoft’s Windows update release cycle.
Verizon’s 2026 Data Breach Investigations Report identifies vulnerability exploitation as the most common initial access method, accounting for 31% of breaches in its reporting dataset. It also reports that only 26% of critical vulnerabilities on CISA’s known-exploited list were fully remediated in 2025, with median resolution taking 43 days. Verizon’s 2026 DBIR executive summary.
Our recommendation is to assign update deployment and exception reporting explicitly. Internal staff should approve business application testing and maintenance windows, while the assigned operator tracks failed installations and urgent updates.
Add specialist support where skills are missing
In ISC2’s 2025 survey of 16,029 cybersecurity practitioners and decision-makers, 59% reported critical or significant skills needs, up from 44% in 2024. The study also reports that 33% of organizations lacked the budget to staff their security teams adequately. ISC2’s 2025 Cybersecurity Workforce Study.
These findings support checking which skills you need alongside how much working time you need. If your internal employee handles business systems well but needs help investigating security alerts, evaluate that specific capability in a provider proposal.
What does a documented co-managed arrangement look like?
A provider-published case study describes Cambridge Air Solutions seeking Microsoft 365 expertise and help co-managing its help desk while its limited internal team supported more than 125 users across two locations. Pearl Solutions Group describes shared ticket visibility, defined responsibilities, weekly coordination, a licensing review, and security standardization. Cambridge Air Solutions case study.
The account illustrates a specific division of work and communication, although it is not an independent evaluation. When reviewing proposals, ask how your internal team will see tickets, transfer requests, and review unresolved work with the provider.
How much coverage does your team need?
A 40-hour working week covers about 24% of the 168 hours in a week. That calculation excludes vacation, sick leave, and holidays, and does not mean every business needs round-the-clock support.
List the systems that require attention outside working hours and the response each needs. Overnight production, weekend operations, and employees in different time zones can create different coverage requirements.
Fantastic IT advertises 24/7/365 support, while its Denver page separately lists office hours of 5 a.m. to 5:30 p.m. Pacific, Monday through Friday, and an after-hours contact route. Agree on emergency procedures and response expectations during onboarding. Fantastic IT support hours.
When does fully managed IT make sense with internal staff?
Fully managed IT makes sense when retained employees have a clear role outside the provider’s daily operating responsibilities. An internal specialist might own application integrations, reporting, and workflow improvements while the provider handles covered employee, device, and network support.
Write that future role down before changing service models. If every support request still reaches your internal employee first, that person remains responsible for routing the workload you intended to transfer.
Retain oversight of provider access and security performance, too. Verizon reports third-party involvement in 48% of breaches in its 2026 dataset; that category extends beyond IT providers, but it reinforces the need to assess outside access and responsibilities. Verizon’s 2026 DBIR executive summary.
How do you prevent gaps and duplicate work?
Give each recurring task a named owner, a backup contact, and an escalation path. Record completed work and exceptions somewhere both teams can access.
For an illustrative employee departure, the process might be:
- HR supplies the departure time and required actions.
- The manager approves mailbox or file-access changes.
- The assigned IT team disables access at the agreed time.
- That team records completion and reports exceptions.
- The internal owner confirms that business-specific applications were included.
Test an urgent scenario as well. Ask who responds when your main application fails after hours, who can authorize technical action, and who updates employees.
For backups, ask which system was restored during the latest test, how long restoration took, and whether the application worked. A joint CISA advisory recommends regular backup testing and ensuring contracted backup services meet the customer’s recovery requirements. CISA guidance for providers and customers.
How should you choose?
Start with co-managed IT when your internal team should continue leading operations and you can identify functions a provider should take on. Choose fully managed IT when you want the provider to lead covered operations and have defined a focused role for the employees you retain.
Before requesting proposals, list responsibilities, compensation and vendor costs, coverage gaps, and delayed projects. Compare each proposal against that list, including who performs the work and which charges sit outside the recurring fee.
How Fantastic IT helps
At Fantastic IT, we work alongside existing IT teams and also provide fully managed support. Our managed IT support service describes both approaches, including monitoring, help desk support, backups, and planning assistance. We can help you identify where your team needs support and define responsibilities around those needs.
Related: When should a business consider co-managed IT? · How to manage a mix of IT employees and vendors