Co-Managed IT
Part of Technology Stabilization & Standardization, alongside Managed IT Services, Cloud IT Services, Backup & Disaster Recovery, and Microsoft 365 Management.
TTS Cyber’s Co-Managed IT is for companies with one IT person or a small IT team of two to five. TTS Cyber gives your team monitoring and management tools. It also handles overflow tickets and covers after hours and vacations. It takes on the security work, runs projects and gives senior help on hard problems.
What does TTS Cyber’s Co-Managed IT include?
TTS Cyber provides monitoring and management tools to your IT team. The service is for companies with one IT person, or a small IT team of two to five people.
TTS Cyber handles overflow tickets. A ticket is one logged request for IT support. TTS Cyber also covers after hours and vacations, and it takes on the security work.
TTS Cyber runs projects such as migrations and upgrades. It gives senior help on hard problems, which is called escalation. That means moving a hard problem to someone more senior. TTS Cyber also helps plan an IT roadmap, which is a plan for which IT work happens and when.
What is co-managed IT, and how is it different from other models?
Vendors and trade sources use the term co-managed IT for an arrangement where an outside managed service provider (MSP) works alongside a company’s own IT staff and provides part of the IT services without taking over completely. One vendor says the customer picks the areas where it wants outside help. No regulator or standards body defines the term.
Sources describe three models. One IT staffing and support vendor frames them by who owns outcomes, who manages the people, and who is accountable when something breaks. Each model is an alternative to the others:
- Full IT outsourcing, or fully managed IT, gives a provider responsibility for IT operations from start to finish.
- Staff augmentation adds individual technical people. You keep full management and operational control.
- Co-managed IT splits responsibilities between your team and a provider, based on a defined division of labor.
One vendor says co-managed IT keeps your team’s knowledge of how the company works and adds capacity and specialization.
When does co-managed IT make sense?
Vendors describe several situations where co-managed IT adds value. These describe fit and are not measured results. Any one of them can be a reason to look at it:
- Your team lacks depth in a specialty. One vendor gives cybersecurity as the example.
- You need coverage to continue, for example after hours.
- You need flexible capacity.
- You have trouble hiring technical talent, or your company is growing fast. A second vendor lists both, along with skill gaps.
What should you agree on in writing with a provider?
Both sides need to know who does what. One IT services vendor suggests a responsibility matrix, which is a written table of who owns each task. It recommends one accountable owner per task where possible. The same vendor lists items such as these:
- Help desk ownership and escalation: how to reach it, its hours, after-hours coverage, how serious problems are ranked, and what response to expect.
- Routine administration kept separate from approval of major changes.
- Security, backup and continuity tasks.
- Named owners for projects.
- Who has decision authority in an emergency.
This is one vendor’s practice suggestion, not a standard.
What do cyber agencies advise about a provider’s admin access?
A joint advisory (CISA AA22-131A) from cyber agencies in the US, UK, Australia, Canada and New Zealand includes advice for MSP customers on the accounts an MSP uses to reach your systems. It was last revised May 11, 2022. It tells customers to:
- Restrict MSP accounts to the systems the MSP manages, and keep them out of your internal administrator groups.
- Grant access on a need-to-know basis, using least privilege (only the access a task requires), and audit that MSP accounts are used for appropriate purposes.
- Disable MSP accounts that no longer manage your infrastructure.
It also says contracts should identify who owns IT security roles and responsibilities. They should require multifactor authentication (MFA, a second sign-in check such as a code) on all MSP accounts used to reach your environment. They should also say the MSP will not reuse administrator logins across customers.
This is guidance, not a law, and it does not say what any provider does. TTS Cyber is not a law firm, and this is general information, not legal advice.
What’s included
- Monitoring and management tools for your IT team
- Overflow ticket handling
- After-hours and vacation coverage
- Security work taken on by TTS Cyber
- Projects such as migrations and upgrades
- Senior help on hard problems (escalation)
- Help planning an IT roadmap
What it’s for
- Your team has outside help with overflow tickets.
- TTS Cyber covers your team’s vacations and after hours.
- Security work and projects have help from outside your own team.
- Hard problems get senior help, and you get help planning an IT roadmap.
Who this is for
- A company with one IT person.
- A company with a small IT team of two to five people.
Frequently Asked Questions
Will an outside provider replace your IT person?
Sources describe co-managed IT as working alongside your staff without taking over completely, as explained above. They describe the model in general and do not say what any one provider does. Ask any provider, including TTS Cyber, how your role and your decisions are handled, and get the answer in writing.
Co-managed, fully managed or staff augmentation: which fits your company?
One vendor says the choice comes down to fit. It describes co-managed IT as a better fit when you already have an internal IT team whose staff know how the company works. It describes a provider that takes over strategy and daily operations as fully managed IT. For a one-time project such as a migration, one co-managed IT vendor says staff augmentation is likely the right option.
Does TTS Cyber cover after hours and vacations?
Yes. This page does not state hours or response times. Ask any provider, including TTS Cyber, what it will put in writing about hours and response before you sign. The list above of what to agree in writing includes hours, after-hours coverage and what response to expect.
Who should own security tasks in a co-managed arrangement?
Decide it in writing before you sign. The responsibility matrix above suggests one accountable owner per task where possible. The advisory above says contracts should identify who owns IT security roles. Ask any provider to show you who owns each security task.
What should you ask about records and access if you end the contract?
One vendor says a well-run provider keeps records, such as configuration changes and incident histories, in systems your team can access. That way the knowledge stays with you. The advisory above says to disable provider accounts that no longer manage your systems. It warns that disabling can be overlooked when a contract ends. Ask any provider how records and access are handed back before you sign.
Related services
Managed IT Services
TTS Cyber runs your everyday IT: monitoring, a helpdesk for your staff, and setting up and shutting off accounts as people join and leave. It is built around how your business works.
IT Strategy & Virtual CIO Services
Senior IT planning help without hiring a full-time executive. You get a written IT roadmap and quarterly planning meetings, with guidance on budget and risk.
Network Operations Center (NOC) Services
TTS Cyber keeps your firewalls, switches, access points and wireless updated and patched. Under a service agreement, they are monitored around the clock and troubleshot when something goes wrong.
Industries