TL;DR: A 45-person GTA construction firm’s sole IT generalist was spending 70% of his week on reactive support. After moving to co-managed IT, Fusion Computing took over infrastructure, security, patching, backups, and vendor management. The IT lead kept frontline user support and project ownership.
The ticket backlog fell from 47 open items to 12, patch compliance went from 34% to 97%, and a project management platform that had stalled for 18 months went live inside 90 days.
Mike Pearlstein is CEO of Fusion Computing and holds the CISSP, the gold standard in cybersecurity certification. He has led Fusion’s managed IT and cybersecurity practice since 2012, serving Canadian businesses across Toronto, Hamilton, and Metro Vancouver.
Co-managed IT for construction pairs your internal IT lead with an MSP team that carries 24/7 monitoring, overflow tickets, cybersecurity, and planning. Your IT person stays in the role and gets back the hours that reactive work was eating. The MSP supplies the depth and coverage one person cannot provide alone.
KEY TAKEAWAYS
- A 45-person construction firm freed its IT lead from firefighting using co-managed IT.
- The model kept internal ownership while adding 24/7 monitoring, patching, and a help desk.
- A 90-day structured onboarding cleared a backlog of 47 unresolved tickets down to 12.
The challenge: one IT person doing the work of three
According to the engagement record, a 45-person GTA construction firm freed its sole IT generalist from 70% of a reactive week. Fusion Computing took over infrastructure, security, patching, backups, and vendor management, and the in-house generalist kept the projects only an insider can run. Source: Fusion Computing client case study, 2026.

The company had grown to 45 employees across two GTA office locations and several active construction sites. The environment mixed on-premise servers, cloud-hosted project management tools, field devices, and a Microsoft 365 tenant set up years earlier and never properly managed.
Fusion Computing has supported Canadian businesses since 2012, delivering managed IT and cybersecurity services with a 93% first-contact resolution rate. The company’s CISSP-led security leadership and CIS Controls v8.1 alignment serve organizations with 15 to 200+ users across Toronto, Hamilton, and Vancouver.
One IT generalist owned everything: password resets, printer issues, firewall configuration, server patching, software licensing, backup management, and vendor calls. He was good at the job. He knew every employee by name, understood the business applications, and had built most of the infrastructure himself.
But he was drowning.
Patch compliance across endpoints and servers sat at roughly 34%. There was no endpoint detection and response, only Microsoft Defender on default settings. After-hours coverage meant his personal phone rang at 2am when a server alert fired. Vendor coordination consumed 8 or more hours a week. His ticket backlog held 47 open items, many weeks old.
The breaking point came when a phishing email got past basic antivirus and an employee clicked the link. The incident was contained, and it exposed how thin the security layer really was. Meanwhile a project management platform rollout, critical for coordinating jobs across field crews, had been stalled for 18 months because nobody had time for it.
Leadership knew something had to change. They also knew their IT lead was an asset. He did not need replacing. He needed infrastructure taken off his plate.
What is co-managed IT, explained: a short overview
Co-managed IT is a written division of labour between an internal IT person and an outside team. The MSP carries the parts that need scale or 24/7 coverage. The internal lead keeps the parts that need context: the users, the business applications, and the projects. According to the shared responsibility matrix, every task has exactly one owner.
The word that matters in that definition is written. In our experience the co-managed engagements that fail are the ones where the split lived in somebody’s head. When an alert fires at 2am, nobody should be working out who owns it. I keep a copy of the matrix in my own notes for exactly that reason.
The strategy: co-managed, not fully managed
Canadian cyber-insurance underwriters increasingly require 24×7 monitoring, segregated backups, and multi-factor authentication as conditions of coverage rather than as discounts. That reshapes what managed IT has to include, and it is one reason this firm could not stay on a single-generalist model much longer.

This was a textbook co-managed IT services engagement. The IT lead was competent and committed, with institutional knowledge that would take an outside team months to replicate. The goal was to multiply his effectiveness.
After an initial conversation, Fusion Computing and the client agreed a clear division of responsibilities.
Fusion would own the operational layer. That covered 24/7 monitoring, automated patch management, and managed detection and response across every endpoint. It also covered firewall policy management, backup verification, after-hours escalation, and vendor coordination. Documentation was aligned with CIS Controls v8.1, the framework behind Fusion’s cybersecurity services.
The IT lead would own: frontline user support, because he knew the staff and wanted to keep that relationship, business application administration, the project management platform rollout, and the relationship with leadership. He also joined biweekly vCIO review calls to align on priorities and budget.
That split was documented in a shared responsibility matrix during the first two weeks and is revisited quarterly.
What the split needs: the responsibility criteria
A co-managed split needs four things written down before anything is switched over. Who answers first, who escalates, who talks to users during an incident, and who signs off a change. Everything else is detail. When those four are ambiguous, the internal person ends up absorbing whatever falls between the two teams.
- First response. Which queue a ticket lands in, and what happens if it is not acknowledged.
- Escalation. The path from tier one to engineering, with names rather than roles.
- User communication. During an incident, one voice talks to staff. Here that stayed internal.
- Change approval. The internal lead directs, Fusion Computing executes, and both sign the record.
The implementation: 90 days of structured onboarding
According to Statistics Canada, Canadian businesses spent about CA$1.2 billion recovering from cyber security incidents in 2023, double the 2021 figure. A co-managed model layers 24×7 monitoring and CISSP-led security over the in-house lead, so one generalist is no longer the only line of defence.
Fusion Computing followed its standard 90-day onboarding framework, adapted for co-managed work.
Days 1 to 14: discovery and documentation
Fusion ran a 168-point assessment covering endpoints, servers, network topology, firewall configuration, backup status, security posture, user accounts, vendor relationships, and licensing. The IT lead took part throughout, and his knowledge of the environment sped the process up considerably.
Key findings from the assessment:
- 34% patch compliance across endpoints and servers.
- No endpoint detection and response beyond default Windows Defender.
- Backup jobs running but never verified for recoverability.
- Admin credentials shared across systems with no multi-factor authentication.
- No documented incident response plan.
Shared access was established and documentation centralized. No disruptive changes were made in this phase. Only urgent security and backup gaps were closed immediately.
“Within the first week of Fusion’s onboarding, they found unpatched servers, no working backups, and admin credentials that hadn’t been changed since 2019. It was genuinely alarming.”
Derek K., Partner, Law Firm, Toronto. A separate Fusion client, on the same first-fortnight pattern.
That reaction is the normal one. I have run enough of these first fortnights to expect it, and my advice to any owner is to read the assessment findings themselves rather than take a summary. Our engineers found the same three items here that Derek describes: patching behind, backups unproven, admin credentials shared.
Days 15 to 45: parallel operations
Fusion brought monitoring and patching online alongside the existing environment. After-hours coverage went live. A shared escalation matrix defined who handled what and when. Weekly syncs with the IT lead made sure nothing fell through the cracks during the transition.
Vendor handoffs began. Internet support, printer lease management, and software licensing coordination moved to Fusion’s operations team. The IT lead reported that the first thing he noticed was his inbox getting quieter.
Days 46 to 90: security hardening and optimization
Managed detection and response was deployed across all endpoints. Firewall policies were tightened and documented. Multi-factor authentication was enforced on all admin accounts. Backup jobs were reconfigured and verified for recoverability. Security awareness training was rolled out to all 45 employees.
With infrastructure and security off his plate, the IT lead finally had time for the stalled project management platform. He completed the rollout inside the same 90-day window, on a project that had waited 18 months.
The results
According to the engagement record, four numbers moved, and none of them is an estimate. The ticket backlog fell from 47 open items to 12 inside 60 days. Patch compliance rose from 34% to 97%. After-hours incident handling moved entirely to Fusion Computing. The stalled platform went live within the 90-day window.

Ticket backlog.
47 to 12.
60% reduction in 60 days.
Patch compliance.
34% to 97%.
Across all endpoints and servers.
After-hours incidents.
100%.
Handled by Fusion.
Platform rollout.
90 days.
Previously stalled 18 months.
Vendor coordination.
8+ hrs/wk.
Returned to the IT lead.
IT lead retention.
2+ years.
Still in role, focused on growth.
Co-managed vs fully managed: how to choose
According to every co-managed scoping call I have run, the comparison is simpler than providers make it. Fully managed replaces the internal IT role. Co-managed keeps it and removes the work that does not need context. If your IT person is the reason things get fixed quickly, co-managed protects that. If there is no internal person at all, the question does not arise.
The other input is coverage. A single generalist cannot provide 24/7 monitoring, and cyber-insurance renewals increasingly expect it. That was the deciding factor here, ahead of any cost comparison. I will say plainly which one I think fits when I have seen the environment, so talk to our team before you commit. If you want the fully outsourced version, Fusion’s managed IT services cover it.
Key takeaways
According to the engagement record, co-managed works when the internal IT person is good but outnumbered. The goal is to multiply their effectiveness. This engagement succeeded because the IT lead kept the relationships, the institutional knowledge, and the strategic ownership that made him valuable in the first place.
After-hours coverage alone justifies the engagement. For any company with a single IT person, no coverage outside business hours is a real risk. One after-hours incident handled by Fusion instead of a 2am phone call changes the quality of the whole working relationship.
The 90-day structured onboarding prevents disruption. The IT lead never lost control of the environment. Fusion integrated alongside him rather than over him, and the weekly syncs during onboarding and biweekly vCIO reviews afterward kept both teams aligned.
Vendor coordination is an underestimated time sink. Internet issues, printer leases, software renewals, and hardware warranties consumed 8 or more hours a week of the IT lead’s time. Handing that over returned an entire workday each week.
Security belongs in the same plan. A 45-person construction firm carries payment-fraud exposure that extra IT hours alone do not close, which our guide to cybersecurity for construction firms in Canada covers control by control.
Construction sits at roughly 7% of Canada’s economy, with construction industry GDP of about CA$170.3 billion against CA$2.36 trillion across all industries in the Statistics Canada May 2026 release. It is also among the slowest sectors to adopt new technology, at 9.2% AI adoption against a 19.2% national average. Thin IT coverage in construction is a sector pattern, not a one-off.
Scope matters when you read the threat reporting. The Cyber Centre’s National Cyber Threat Assessment 2025 to 2026 names ransomware the top cybercrime threat to Canada’s critical infrastructure. Its Baseline Cyber Security Controls v1.2 set the practical floor for firms this size.
Considering co-managed IT for your business? Fusion Computing has run CISSP-led managed and co-managed IT for Canadian businesses since 2012. If your internal IT team is stretched thin, talk to our team about what a co-managed engagement would look like for your environment, or call 416-566-2845.
Frequently asked questions
These 4 come up constantly. I field them from owners of 30 to 100 person firms who have one IT person and a growing list of work that person cannot reach. The answers describe this engagement specifically, so use them to pressure-test whatever proposal you are holding right now.
Would this work for a smaller company?
Yes. Co-managed IT scales down to companies with as few as 20 employees and a single IT person. The scope Fusion owns adjusts with the client’s needs and budget. The core value, which is operational support plus after-hours coverage for your IT person, applies at any size in that 20 to 150 band.
What did it cost?
Fusion managed IT starts at CA$180 per user per month, with cybersecurity priced separately at CA$180 to CA$250+ per user per month. This engagement covered monitoring, patching, managed detection and response, after-hours coverage, vendor coordination, and backup management. Pricing is scoped after assessment rather than applied as a generic per-user number.
What would you do differently?
Start earlier. The client waited until a phishing incident forced the conversation. Had Fusion been engaged 6 months sooner, the gaps of no endpoint detection, no MFA on admin accounts, and unverified backups would have been closed before an incident exposed them. The 90-day onboarding would have run the same. The risk window would have been shorter.
How is co-managed different from fully managed IT?
Fully managed replaces the internal IT role. Co-managed keeps it. Here Fusion took 24/7 monitoring, patching, managed detection and response, firewall management, backup verification, after-hours triage, and vendor coordination. The IT lead kept frontline support, business applications, and the platform rollout, with a shared responsibility matrix and biweekly vCIO calls holding the 2 teams together.
This case study is anonymized to protect client confidentiality. Details have been adjusted for privacy while preserving the accuracy of the engagement’s scope, timeline, and outcomes. If you are a current Fusion client interested in sharing your experience, contact us.
Compare this engagement with a 35 to 205 user IT scale-up, a ransomware recovery, and a GTHA dealership IT overhaul. For background on the model, read the co-managed IT services overview and why one IT role is not enough.

