Best Co-Managed IT Providers for Canadian SMBs: A Buyer’s Guide
If you already have internal IT staff, you do not need a provider who replaces them. You need one who fills a specific gap. This guide scores co-managed IT providers against the 13 baseline control areas the Canadian Centre for Cyber Security publishes, so you can run the comparison yourself.
Written by Mike Pearlstein, CISSP, MSc Computer Science (AI), CEO of Fusion Computing. Microsoft Solutions Partner. Canadian-owned and operating from Toronto since 2012. Named to Canada’s 50 Best Managed IT Companies in 2024.
What co-managed IT actually means
According to Statistics Canada (2024), the most reported reason Canadian businesses gave for having no dedicated cyber security employees was that they used consultants or contractors to monitor security, at 47 percent. Co-managed IT formalizes that arrangement. Your staff keep daily operations and an outside provider owns one named gap.
The internal team keeps ownership of day-to-day work and institutional knowledge. The provider fills 1 of 4 gaps: security depth, after-hours coverage, project capacity or strategic guidance. Which provider is right depends entirely on which of those 4 you are filling. Our co-managed IT services page carries the full definition, the coverage split and current pricing.
4 factors decide the shortlist: willingness to work alongside internal staff rather than take over, the specific strength added, tooling compatibility and a written division of responsibilities. Ontario firms still choosing between an internal hire and a full contract should read our IT outsourcing vs in-house comparison before shortlisting anyone.
Not sure which of the four gaps you actually have? Ask a CISSP-led team to map it in 30 minutes →
How to compare co-managed providers: criteria you can apply yourself
According to the Canadian Centre for Cyber Security, its baseline controls for organizations under 499 employees cover 13 control areas, from incident response planning through to cloud and outsourced services. Ask every provider on your list to mark which of the 13 they will own and which stay with your team. The areas nobody claims are your real risk.
That single exercise separates a co-managed partner from a vendor. A provider who will put a name against 13 control areas has done the work before. A provider who answers in adjectives has not. Run the same sheet past your own IT lead in Toronto or Hamilton, because the areas your team quietly assumed someone else owned are the ones that surface during a PIPEDA breach assessment.
If the fully managed versus co-managed decision is still open, the same scoring discipline applies one level up. Our guide to how to choose an IT company in Canada runs the 8 criteria, the red flags, and the questions to ask before you sign.
| Scoring question | A strong answer | A weak answer |
|---|---|---|
| Which of the 13 CCCS baseline areas do you own? | A marked-up sheet, named owner per area. | “We cover everything.” |
| Where does a ticket go at 02:00 on a Sunday? | Named escalation path plus a written response target. | “Someone is always on.” |
| Which of our tools do you replace, and which do you join? | Named overlaps and a dated decommission plan. | “Our stack is better.” |
| Who files the PIPEDA breach report? | You do. We assemble evidence and hold the 2-year record. | “We handle compliance.” |
| What happens to our internal IT lead’s role? | A written RACI naming what they keep. | “They can focus on strategy.” |
Best for adding a cybersecurity and compliance layer: Fusion Computing
According to the Canadian Centre for Cyber Security (2025), ransomware is the top cybercrime threat facing Canadian critical infrastructure, and its National Cyber Threat Assessment puts the average Canadian ransom paid in 2023 at $1.13 million CAD, a 150 percent rise across two years. Security is the hardest co-managed gap to staff internally.
When this matters: your internal team handles operations well, you lack dedicated security expertise, and you carry obligations under PHIPA, PIPEDA, FIPPA or CIRO rules.
Fusion Computing runs the security and compliance layer over an internal team: monitoring, governance, incident response and a vCISO function. Fusion Computing is CISSP-led and has operated from Toronto since 2012. The internal team keeps daily IT. Security is the hardest capability for a 50-person Ontario firm to hire for, which is why it is the most common gap we are asked to fill.
Where we are not the answer: if the gap is raw ticket volume rather than security depth, a flat-rate coverage MSP will cost less per seat. If the gap is a single 12-week migration, hire a project bench and stop there. See how the co-managed and fully managed models differ.
“I was worried Fusion would try to take over from our internal IT person. The opposite happened. They documented everything, built the escalation paths around how we actually work, and my IT manager told me it was the first time he felt like he had real backup. The written responsibility matrix was something we should have done years ago.”
Best for after-hours and overflow coverage: a flat-rate co-managed MSP
According to Statistics Canada (2024), total spending on recovery from cyber security incidents roughly doubled to $1.2 billion CAD in 2023, and about $600 million CAD of that was carried by small and medium businesses. After-hours gaps are where a large share of that recovery cost is created, because nobody answers the alert until Monday.
When this matters: your internal team is stretched, and you need help-desk overflow or after-hours coverage so 2 people are not carrying a 24/7 pager between them.
For pure coverage augmentation, a flat-rate provider such as AYCE IT in Toronto publishes an all-you-can-eat flat-fee support model, which suits buyers who want ticket volume to stop driving the invoice. Confirm 2 things in writing before signing: that they will work alongside your IT lead rather than replace them, and exactly where a ticket goes at 02:00 on a Sunday.
Best for project capacity: a larger MSP with a deep bench
According to Statistics Canada (2024), Canadian businesses spent $11.0 billion CAD on preventing and detecting cyber security incidents in 2023, up from $9.7 billion CAD in 2021, and $2.9 billion CAD of that went to software alone. Migrations are where that spending concentrates and where a two-person internal team runs out of hands.
When this matters: your internal team can run operations, and the shortfall is headcount for a defined program such as a Microsoft 365 tenant migration or an office move.
For project-shaped gaps, a larger firm such as ProServeIT states publicly that it has managed IT for organizations across North America for over 2 decades and serves companies from 50 employees upward. That is the bench profile a 12-week migration needs. Scope it with a start date and an end date, because an open-ended project retainer quietly becomes an expensive second MSP.
Best for strategic guidance without a full-time hire: a vCIO-led provider
According to the Government of Canada Job Bank (updated November 2025), an information systems manager in the Toronto region earns a median $67.69 CAD per hour, roughly $132,000 CAD a year at 1,950 hours before benefits. Most 40-seat to 150-seat Ontario firms cannot justify that salary for a role they genuinely need 8 days a quarter.
When this matters: you have capable hands-on IT staff in Ontario and nobody at the table for the 4 roadmap, budget and risk decisions a year that actually move the number.
A vCIO engagement fills the strategy gap: technology roadmap, budget planning, vendor management and risk decisions, usually as a fixed quarterly commitment. It pairs well with internal staff who execute but were never hired to set direction. Ask for the last redacted board deck a vCIO produced. A provider who cannot show 1 is selling a job title.
What co-managed IT costs in Canada, and what it requires from you
According to the Government of Canada Job Bank, a computer network technician near Toronto earns a median $35.71 CAD per hour, about $70,000 CAD a year before benefits and recruiting. Fusion Computing publishes co-managed IT at $160+ CAD per user per month, so the comparison a Canadian buyer should run is per-seat cost against a second internal hire.
For an 80-seat Ontario firm, $160 CAD per user per month is roughly $153,600 a year, against about $70,000 CAD for 1 more technician who works 40 hours a week in a single time zone. The honest read is that co-managed costs more than a junior hire and buys 24/7 coverage plus a security stack. Hourly IT work in the GTA runs $150 to $250 CAD per hour, which is why incident-heavy months break that budget.
A co-managed contract also requires 3 things from your side, and buyers routinely forget to budget for them. Name 1 internal owner who signs the responsibility matrix. Send that person to the monthly review. Agree a credential-governance rule before onboarding, because shared admin logins are what turns a PIPEDA incident into an unanswerable question about who did what.
Canadian businesses still spend twice as much on in-house security salary, $3.8 billion CAD, as they do on consultants and contractors at $1.9 billion CAD. Co-managed sits between those 2 columns, which is why the per-seat comparison matters more than the headline rate.
Want the per-seat math run against your own headcount? Get a written co-managed cost comparison →
Where co-managed arrangements go wrong
According to the Office of the Privacy Commissioner of Canada, PIPEDA requires an organization to keep records of every breach of security safeguards for 2 years and to notify affected individuals as soon as feasible. In a split IT model that duty still sits with your business, never with the provider.
[REGULATOR QUOTE] The OPC states plainly that “the law requires you to keep breach records of all breaches of security safeguards for two years”. Four failure modes account for most of the co-managed relationships we are asked to rescue in Toronto and Hamilton.- Ticket limbo. No written handoff rule, so a P2 sits for 36 hours while each side assumes the other picked it up.
- Tool duplication. Two monitoring agents on 1 endpoint, double licensing and conflicting alerts nobody trusts by month 3.
- Compliance drift. Nobody owns the PIPEDA breach log, so the 2-year record does not exist when the OPC asks for it.
- Role erosion. The internal IT lead is slowly reduced to ticket triage, then resigns, and the provider inherits a takeover nobody agreed to buy.
Questions to ask a co-managed IT provider
According to Statistics Canada (2024), only 22 percent of Canadian businesses gave formal cyber security training to non-IT staff in 2023, so ask who owns awareness training in your split. That survey covered 12,462 enterprises at a 71 percent response rate, which makes it the firmest Canadian baseline available.
- Are you comfortable working alongside our internal team, or do you prefer full takeovers? Some MSPs only do replacement. Confirm it up front.
- Which of the 13 CCCS baseline control areas will you own in writing? A marked-up sheet beats any capability slide.
- How do we divide responsibilities so tickets do not fall through the cracks? The handoff model is where co-managed arrangements succeed or fail.
- What specific strength are you adding? Security, coverage, projects or strategy. Vague answers mean unclear value.
- Will your tooling integrate with ours, or duplicate it? Name the 2 or 3 overlaps before onboarding, not after.
- Do you have security leadership credentials such as CISSP? Relevant when security is the gap you are filling.
- Who files the PIPEDA breach report, and who keeps the 2-year record? The answer must be your business, with the provider assembling evidence.
- What is your written priority response target, and what does it exclude? Fusion Computing commits to a 1-hour priority response.
Bringing this list to 3 providers? Ask us the same 8 questions and compare the answers →
FAQ
What is the difference between managed and co-managed IT?
When does co-managed IT make sense?
Will a co-managed provider replace our internal IT person?
How much does co-managed IT cost in Canada?
How do you divide responsibilities between an internal team and a co-managed provider?
How many employees do you need before co-managed IT makes sense?
Does a co-managed provider cover nights and weekends?
Will a co-managed provider work with our existing tools?
Who reports a PIPEDA breach in a co-managed arrangement?
How long does co-managed onboarding take?
Can we start co-managed and move to fully managed later?
Is Fusion Computing the same as Fusion Cyber Group?
Talk to Fusion about co-managed security
If the gap is a security and compliance layer over your own IT staff, talk to a CISSP-led team that has served Canadian SMBs since 2012.
Book a consultation or call (416) 566-2845
Microsoft Solutions Partner. CISSP-led since 2012. Canada’s 50 Best Managed IT, 2024. Related: the co-managed MSSP model, questions to ask before hiring an MSP, top MSPs in Canada 2026, best IT providers for Ontario law firms, top cybersecurity-focused MSPs in the GTA (for firms with no in-house security team).

