How a Toronto Design Studio Scaled from 35 to 205 Users Without IT Becoming the Bottleneck

Tags:

KEY TAKEAWAYS

  • A Toronto design studio went from 35 to 205 users in under 4 years without adding a single internal IT hire.
  • Co-managed, not replaced: the internal lead kept first-line support while Fusion Computing carried monitoring, patching and security operations.
  • Onboarding fell from 4 to 8 hours per hire to 45 minutes, which is the number that unlocked the budget for everything else.

This case study is based on a real Fusion Computing engagement.
Client details have been anonymized, and certain technical details
have been generalized for privacy.

I got the call after the studio’s fourth production-hour outage in
two months. They were a 35-person Toronto design firm. Engagements like this one shape how we structure our wider Fusion Toronto managed IT engagements and our IT support for architecture firms for growth-stage studios and agencies. They had signed
work, a hiring plan that would push them past 60 employees by year-end,
and one capable IT lead who was already the bottleneck.

The CEO said one sentence I still remember: I don’t think
we’re going to make it through this year if I don’t fix IT now.

He was right. What followed became a five-year co-managed engagement
that took the studio from 35 users to 205 users without IT ever becoming
the constraint that paused hiring or delivery.

SNAPSHOT · 35 TO 205 USERS · 2021 TO 2025

Engagement. Co-managed IT, Toronto design studio.
User scale. 35 to 205 users in under 4 years (about 6x).
Infrastructure. Ground-up rebuild: network, servers, MDM, security stack, racks.
Onboarding. 4 to 8 hours per hire dropped to 45 minutes (about 85% reduction).
Help desk FCR. 62% to 91% first-contact resolution.
Security incidents. 2 events in prior 12 months to zero across 3 years post-build.
Cost per user month. Down 24% despite higher security coverage.
Internal IT headcount. 1 internal lead, unchanged (co-managed, not replaced).
Engagement length. Active 5+ years and still running.

Source: Fusion Computing project records, Toronto design studio engagement, 2021 to 2025.

Toronto design studio desk at 35 users with unmanaged laptops stacked for imaging beside handwritten setup notes
Thirty-five users, no MDM baseline, and every setup done by hand. This is what I walked into.

Book a Consultation

What I walked into at 35 users

A Toronto design studio scaled from 35 to 205 users without an internal IT hire by moving to managed IT after repeated production outages. Fusion took over monitoring, help desk, security, and IT strategy, keeping the environment stable as headcount grew nearly sixfold. Source: Fusion Computing client case study, 2026.

According to the National Cyber Threat Assessment 2025-2026 (2024), ransomware is the top cybercrime threat facing Canada’s critical infrastructure, and the Cyber Centre notes ransomware actors are opportunistic rather than industry-specific. A growing studio is squarely inside that opportunistic set.

Across our 30 to 100 user client environments I see roughly the same
four-problem stack about 70% of the time. This studio was textbook, and
in our experience the order in which those four problems get fixed
matters more than the products chosen to fix them.

The four-problem stack I see at this size

The fleet was mixed Windows and Mac with no consistent management.
Some Macs were enrolled in a Mac management tool. Most Windows laptops weren’t enrolled
in anything. There was no MDM baseline, so patching was a guess.

Onboarding took 4 to 8 hours per hire because every setup was
bespoke. Backup was fragmented, with different tools for different
departments, no tested restore, and no offsite copy of the production
NAS. MFA was on Microsoft 365 only. About half the SaaS tools that
actually held client data weren’t covered.

The CEO didn’t need me to find the problems. He needed someone to
tell him whether the architecture had any chance of carrying 70 people,
then 205. The honest answer was no. Not
without a rebuild.

What had to scale first: the criteria I used

I told the CEO 4 things had to change before headcount passed 70,
not after. Large working files moved across the network all day, so the
network design and storage layout were no longer optional. The hardware
profile mattered: designers needed GPU, RAM, and storage performance
that commodity office laptops don’t deliver, so
lifecycle planning
had to reflect that.

Deadlines were fixed, so downtime had real cost. And after-hours
work was real, so a 9-to-5 IT model was already behind the business.

The internal IT lead was capable. The job, at 35 users heading toward
100, was already too big for one person. That’s the gap a co-managed
model is built for, and it’s the call we made together: co-managed IT services
rather than full outsourcing.

What is co-managed IT, explained through what I built here

Co-managed IT splits one job across two teams. According to the Canadian Centre for Cyber Security, its Baseline Cyber Security Controls (2022) set out 13 control areas for organizations under 500 staff, on an explicit 80/20 premise. The split below assigned every one of those areas to the in-house lead or to Fusion Computing.

I told the CEO upfront that Fusion Computing was not going to
replace his IT lead. He
was the one piece of this that already worked: he knew the team, he
knew the workflows, and he was the face of IT inside the business.

Replacing that proximity with a purely external model would’ve
created a different kind of gap. So Fusion Computing built a
co-managed structure with a clean division of responsibilities, and the
internal lead stayed exactly where the business needed him.

The responsibility split, line by line

The split looked like this:

Internal IT lead owned Fusion Computing owned
L1 support, frontline troubleshooting, workstation readiness, hands-on local issues, the day-to-day relationship with users. Monitoring, patching, security operations, escalation, vendor coordination, backup oversight, infrastructure lifecycle, strategic guidance.

That split did two important things. First, it removed
single-person dependency on critical systems. Second, it made the
internal lead more effective. Instead of drowning in routine
operational drag, he could focus on the business-facing work that
benefits from being in-house, which at 35 users was already most of
the job.

Fusion Computing also trained him to our operational standards:
how to document, how to handle tickets with consistency, how to follow
patching schedules, and how to escalate the right issues at the right
time.

Whiteboard architecture sketch for a Toronto design studio rebuild showing identity, device and network layers
The whole rebuild started as one whiteboard drawing of three layers.

Five years in, the model still works. That’s the point. Plenty of
IT setups look good in the first 90 days. Very few survive growth,
hardware refresh cycles, vendor changes and shifting business demands.
This one did.

Talk to Fusion

The three-layer stack we landed on

Three layers, chosen to scale. According to Statistics Canada (2024), 16% of Canadian businesses were impacted by a cyber security incident in 2023, and large firms were the most exposed at 30%. A studio carries the same exposure with far fewer people, which is the argument for building the security layer under CISSP-led leadership before headcount forces it.

Why three layers and not one platform

Once the operating model was clear, the technology choices fell out
of it. We build to three layers rather than one vendor stack, because
each layer has to survive being replaced without disturbing the other
two. Every choice below had to scale to 200 users without
re-architecture.

Layer What we deployed
Identity and device Microsoft Entra ID for SSO, with Conditional Access as the policy engine. Microsoft Intune for Windows MDM, plus a dedicated Mac management platform. Device compliance enforced before any SaaS access.
Security stack EDR on every endpoint. Microsoft Defender for Office 365 email security. MDR monitoring against the CIS Controls v8.1 baseline. MFA on every account that touched client data.
Network and platform A next-generation firewall, structured cabling sized for the studio’s production workload, hybrid Azure plus on-prem servers. Performance-sensitive workloads stayed local. Backup, disaster recovery, and selected services moved to Azure.

Fusion Computing runs that stack as one service rather than three
products, and we monitor all of it from the same console. Project records
for this engagement show zero unplanned downtime across the 4-month
phased deployment. MFA covered every account that touched client work,
which is also what the
Office of the Privacy Commissioner (2018)
expects of a business holding client records under PIPEDA.

Three years and four numbers later

The build phase was the easy part to plan. The proof is what happened
over the three years that followed. According to Fusion Computing project
records for this engagement, covering 2021 to 2025, six operating numbers
moved. Two of them, onboarding time and first-contact resolution, are the
ones I would check first in any studio of this size.

Before and after, six numbers

Metric. Before. After.
User count. 35. 205 (about 6x).
Onboarding time per hire. 4 to 8 hours. 45 minutes (about 85% reduction).
Security incidents. 2 in prior 12 months. 0 across 3 years post-build.
Help desk FCR. 62%. 91%.
Cost per user month. Baseline. Down 24% despite higher security coverage.
Internal IT headcount. 1 lead. 1 lead, unchanged.
Four Numbers, 2021 to 2025. User count went from 35 to 205, about six times. Onboarding time per hire went from 4 to 8 hours down to 45 minutes, about an 85 percent reduction. Help desk first-contact resolution went from 62 percent to 91 percent. Security incidents went from 2 in the 12 months before the engagement to zero across 3 years after the build. Source: Fusion Computing project records for this engagement. Four Numbers, 2021 to 2025. One Toronto design studio. Same internal IT headcount. User count. 35 to 205 About six times, no IT hire. Onboarding per hire. 45 min Down from 4 to 8 hours. Help desk resolution. 62% to 91% First contact, no escalation. Security incidents. 2 to 0 Prior year, then 3 years clean.
Source: Fusion Computing project records, Toronto design studio engagement, 2021 to 2025.

What the table doesn’t capture is the operational story behind it.
Fusion Computing’s monitoring caught the kind of pattern an internal IT
lead never has time to root-cause alone. Fusion Computing handled the
office relocation as a controlled IT project, not a cutover gamble.
The infrastructure was rebuilt before hiring velocity forced emergency
decisions, which meant the business never had to pause to re-architect
under pressure.

They didn’t replace my IT guy, they made
him better. Three years in, we’re six times bigger and IT isn’t even
on my list of risks anymore.

CEO, Toronto design studio (anonymized)

The Canadian Centre for Cyber Security scopes its headline ransomware
judgement to Canada’s critical infrastructure, and it also notes that
ransomware actors are opportunistic rather than industry-specific. That
second half is the part a growing studio should read twice: fast growth is
exactly when controls lag headcount. Three years without an incident
through a sixfold scale is the number I value most about this engagement.

“It is refreshing to work with a technology vendor that is reactive in an expedient manner to our needs as a business. Fusion takes the time to learn what your current and future goals are, and offers options to help you achieve them.”

Naomi Clarke, Idea Factor, a different Fusion Computing client in the creative sector. Testimonial published on the Fusion Computing design industries page.
Printed before-and-after scaling comparison for a Toronto design studio showing onboarding and resolution figures
The before-and-after sheet the CEO still keeps in his top drawer.

Co-managed vs fully managed IT: how much it costs and how to choose

Two models, one decision. Fully managed suits a business with no internal IT team. Co-managed IT services suit a business that already has a capable lead and needs deeper coverage around them. In our experience at Fusion Computing the deciding question is simple: is the in-house role worth protecting? If it is, replacing it is the expensive answer.

Question. Co-managed. Fully managed.
You already employ IT. Yes, one lead or a small team. No, or the role is being retired.
Who owns L1 support. The internal lead, on site. The provider, remotely.
Best fit by size. Roughly 30 to 150 users. Under 30, or a single site.
Main failure mode. An unwritten responsibility split. Nobody in the building at 8am.

Pricing sits in the same band either way. Fusion Computing prices managed IT from CA$180 per user per month, with a CA$160 floor on lighter scopes and roughly CA$230 where after-hours coverage and heavier compliance work are bundled. Managed cybersecurity is priced separately at CA$180 to CA$250+ per user per month. Co-managed usually lands lower per user, because the internal lead keeps L1. Want that mapped to your own numbers? Ask a CISSP-led team.

Free download

The MSP RFP Kit

The written responsibility split in the table above is what kept this studio stable from 35 to 205 users. The kit turns that table into an RFP you can send: who owns monitoring, patching, escalation, and backup oversight, plus a scoring sheet and the after-hours questions most providers answer vaguely.



No sales call required. Want the split mapped to your own environment? Book a consultation.

What I’d tell another scaling-stage CEO

Build ahead of growth. Having internal IT is not the same as being covered, and a co-managed split only works when it is explicit and written down. Creative production environments need a different IT standard than low-complexity offices. The right outcome is never dependence on the provider: a good arrangement makes the internal IT person more valuable, not less. My CISSP-led team is measured on exactly that.

Get in Touch

Frequently asked questions

Is co-managed IT only for larger businesses?

No. Co-managed IT usually starts to make sense when a business
has one internal IT person or a small team that’s stretched too thin.
It fits best when a company has enough support volume to justify
internal presence but not enough for deep in-house specialization.
Fusion Computing sees the strongest fit in the 30 to 150 user range,
where the internal lead is the relationship anchor and the MSP carries
the operational depth.

Would fully managed IT have made more sense for this studio?

No. The studio already had internal IT value worth preserving, and
the better answer was to support that role rather than remove it. A
fully managed model makes sense when there is no internal IT team, or
when leadership wants to outsource ownership entirely. At 35 users that
distinction was already worth money. It is the most common reason a
co-managed engagement either succeeds or fails.

How long does a buildout like this usually take?

It depends on procurement, site readiness, and how much
standardization is required. Fusion Computing typically scopes an
initial design and implementation phase of 3 to 6 months for a
30 to 100 user environment. A stabilization period follows, where
documentation, patching baselines, escalation paths and support
rhythms get cleaned up and formalized. The studio engagement ran
4 months for the build and roughly 6 more for full stabilization.

What should a business expect from a co-managed provider?

Clarity. The provider should explain exactly who owns what, how
escalations work, what happens after hours, and how monitoring,
patching, security, and backup oversight are handled. If those
answers are vague, the engagement will get messy fast. Ask Fusion
Computing, or any provider, to put all 8 responsibility lines on
paper before signing. A real co-managed
agreement looks like the table earlier in this case study, not a
generic SLA.

How did Fusion Computing handle cybersecurity while the user base grew six times?

Security was built into the operating model from day one rather
than treated as a future phase. EDR ran on every endpoint, Microsoft
Defender for Office 365 covered email, MDR monitoring ran against a
CIS Controls v8.1 baseline, and MFA was enforced on every account
that touched client data. Fusion Computing’s project records show
zero material security incidents at the studio across 3 years post-build,
against 2 in the 12 months before engagement.

What lessons from this engagement apply to a 30 to 100 user SMB planning similar growth?

Three lessons travel well. First, identity and device baseline
(SSO, MDM, conditional access) is the foundation everything else sits
on. Skip it and every later layer leaks. Second, templated onboarding
pays back the day a hiring plan accelerates: the studio’s 85%
reduction in setup time was the difference between IT being a hiring
constraint and IT being invisible. Third, the co-managed split has
to be written down. Verbal agreements drift into chaos.

How much does co-managed IT cost per user in Canada?

Fusion Computing prices managed IT from CA$180 per user per month,
with a CA$160 floor on lighter scopes and roughly CA$230 where
after-hours coverage and heavier compliance work are bundled. Managed
cybersecurity is priced separately at CA$180 to CA$250+ per user per
month. Co-managed usually lands toward the lower end, because the
internal lead keeps first-line support.

What should be in the written co-managed responsibility split?

A named owner beside each of these 8 lines, with the response
commitment written next to it. Fusion Computing supports critical
issues with a 1-hour priority response.

  • First-line support.
  • Monitoring and alerting.
  • Patching.
  • Endpoint security.
  • Identity and access changes.
  • Backup oversight and restore testing.
  • Vendor coordination.
  • After-hours escalation.

Fusion Computing helps growing businesses scale infrastructure
without IT becoming the bottleneck across the GTA,
Hamilton and
Metro Vancouver. If your
business has one internal IT person carrying too much, a co-managed
structure adds depth and after-hours coverage without
replacing what already works.

See the sibling case studies for an internal lead supported by co-managed IT
and a multi-site cannabis retailer,
or book a consultation with Mike Pearlstein.

Fusion Computing has provided managed IT, cybersecurity, and AI consulting to Canadian businesses since 2012. Fusion’s CISSP-led team supports organizations with 10 to 150 employees across Toronto, Hamilton, and Metro Vancouver.

93% of issues resolved on the first call. Named one of Canada’s 50 Best Managed IT Companies two years running.

100 King Street West, Suite 5700
Toronto, ON M5X 1C7
(416) 566-2845
1 888 541 1611