Why One IT Role Isn’t Enough in a Co-Managed MSSP

Tags: managed it services Toronto

Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.

Key Takeaways

  • Co-managed IT pairs an internal IT lead with a managed services provider (MSP) that handles 24/7 monitoring, security, after-hours coverage, and specialist depth the internal lead cannot cover alone.
  • The break-even between fully outsourced and co-managed lands between 50 and 100 users for most Canadian SMBs.
  • Typical Canadian co-managed pricing runs CA$160 to CA$180 per user per month on top of internal IT salary, depending on security stack and compliance scope.
  • Across our 24 Canadian co-managed client engagements through Q1 2026, we measured the median internal IT person reclaiming 12 to 18 hours per week. That time came back once the MSP absorbed help-desk overflow and after-hours response.
  • Co-managed engagements only work when the RACI split is documented in writing before the contract starts.

Book a Co-Managed IT Consultation

What is co-managed IT for a Canadian SMB?

Co-managed IT is a shared-ownership operating model. An internal IT lead keeps primary day-to-day responsibility and an external MSP fills the specialist and capacity gaps. The internal lead handles user-facing work, business context, and project ownership. The MSP handles 24/7 monitoring, security operations, after-hours response, and the specialist engineering one person cannot cover, typically against NIST CSF 2.0.

The model exists because the breadth of modern IT exceeds what one person can credibly own. Help desk, security, cloud architecture, identity, compliance, and after-hours response are six disciplines, and most Canadian SMBs do not need three or four full-time hires to cover them. Co-managed splits the work along skill and time-of-day boundaries. ISED counts 98 percent of Canadian employer businesses as small businesses.

The baseline is published, and it is short. According to the Canadian Centre for Cyber Security, the Baseline Cyber Security Controls run to 13 controls, and control OC.1 scopes them to organizations under 499 employees. Co-managed is the operating choice that puts CISSP-led security leadership and 24/7 monitoring behind those 13 without funding three senior hires.

How does co-managed compare to fully outsourced and in-house IT?

Three models cover the market. According to the Canadian Anti-Fraud Centre (2026), Canadians reported over CA$704 million in fraud losses in 2025, with spear phishing alone at CA$67.9 million. Only 5 to 10 percent of frauds are reported at all, which is why after-hours monitoring beats an annual checklist for a firm in the middle band.

Three operating models cover most Canadian SMBs. Co-managed sits between the other two and wins the middle band, roughly 50 to 200 users. Below 50 users, fully outsourced is usually right because there is not enough work for an internal lead. Above 200, the calculus tips toward a real internal team plus vendor specialists.

Statistics Canada (2024) puts 16 percent of Canadian businesses in the incident column for 2023, with large firms hardest hit at 30 percent. The middle band is where that risk meets the thinnest coverage.

Model Best for Internal IT MSP role Typical cost (50-user firm).
Fully outsourced (managed IT). 10-50 users None Owns everything end-to-end CA$9K-11.5K/month
Co-managed IT 50-200 users 1-3 internal staff Security, after-hours, specialist depth, overflow. CA$160-180/user/month + internal salary.
In-house IT team 200+ users 3+ internal staff Specialist gaps only (24/7 SOC, IR, vCIO). Salary + specialist retainers.
[CONTRARIAN THESIS] The error I see most often in Toronto and Hamilton is hiring one in-house generalist at 50 users and calling that the IT team. I have watched the role work fine at 18 people and break at 50, where breadth and after-hours demand cross what any one person can cover. The person is rarely the problem. The span is.

The 5 triggers that mean a Canadian SMB needs co-managed IT

Five triggers, and one is usually enough. CIS Controls v8.1 gives Canadian SMBs 18 controls and 153 safeguards across 3 implementation groups. A managed provider earns its fee by operating those controls continuously rather than auditing them once a year, and that is the part an internal lead cannot do alone at 2am.

Five triggers move co-managed from optional to required. An internal IT lead who is drowning. A cyber-insurance renewal asking for 24/7 monitoring. A regulatory framework demanding documented controls. A recent security incident. A planned cloud migration or acquisition. Any one of the 5 is usually enough on its own.

Trigger What it sounds like. Why co-managed fits
Internal IT overload “Our IT person works weekends just to keep up”. MSP absorbs overflow, internal lead reclaims strategic time.
Cyber-insurance renewal “Carrier is asking for documented EDR and 24/7 SOC”. MSP provides documented monitored response.
Compliance pressure “We need PIPEDA / PHIPA / OSFI E-21 evidence”. MSP runs the audit-ready security stack.
Recent incident “We had a phishing breach and never want that to happen again”. MSP brings post-incident programme rebuild.
Cloud or M&A transition. “We are migrating to Azure / acquiring a 30-person company”. MSP brings architecture depth internal lead does not have.

What does the MSP cover, and what does the internal IT lead keep?

The single most important artefact in a co-managed engagement is the written RACI matrix. It records who is Responsible, Accountable, Consulted, and Informed for every category of work. Every failed co-managed engagement I have been called into failed on this line, with both parties assuming the other was handling something neither was.

Function Internal IT lead MSP
User-facing help desk (business hours). Owns Overflow + specialist escalation.
After-hours and weekend coverage. Out of scope Owns
Endpoint protection, EDR, MDR. Day-to-day administration Owns 24/7 SOC, threat hunting, response.
Patching and vulnerability management. Owns business-app patching Owns OS, infra, security tooling patching.
Backup and disaster recovery. Defines RPO/RTO with leadership. Operates backup, runs quarterly restore tests.
Compliance evidence and audit prep. Internal liaison with legal/board. Generates evidence packs from controls.
Strategic technology roadmap Owns business context vCIO advisory, quarterly review.
Vendor and procurement management. Owns relationships Specs and security review.

Get a custom co-managed RACI matrix scoped to your environment.

[FIELD NOTE] FROM MIKE

“The pattern in failed co-managed engagements is always the same. Nobody wrote down the split. Six months in, the internal lead thinks I own patching, I think the internal lead owns it, and a Windows Server box hits end-of-support with nobody watching. The RACI is not bureaucracy. It is the one page that protects both parties from quiet drift.”

Mike Pearlstein, CISSP, CEO, Fusion Computing. I have signed 24 of these and read the failed ones.

How much does co-managed IT cost in Canada?

Canadian co-managed pricing runs CA$160 to CA$180 per user per month on top of the internal IT salary. The band moves with the security stack tier and the compliance scope. For a 75-user firm that is roughly CA$9,750 to CA$13,500 per month for the MSP layer. Our managed IT services cost Canada guide breaks the fully managed comparison down further.

Seat band. MSP layer monthly Plus internal IT salary. Total annual (typical).
50 users CA$6,500-9,000 1 generalist (CA$85K-110K) CA$163K-218K.
100 users CA$13,000-18,000 1-2 staff (CA$120K-170K) CA$276K-386K.
200 users CA$26,000-36,000 2-3 staff (CA$220K-310K) CA$532K-742K.

The band moves most with the security stack tier (basic EDR against full MDR plus SIEM) and the compliance overlay (PIPEDA only against PHIPA, OSFI E-21, and SOC 2). Per-incident fees are a red flag and are not part of standard co-managed pricing in Canada. Send us your seat count and we will price the layer against your actual compliance scope.

How do you onboard a co-managed engagement?

Standard co-managed onboarding for a 50 to 100 user Canadian SMB runs six to eight weeks from signed contract to steady state. The first two weeks are discovery and asset inventory. Weeks three to five build the security and monitoring stack against NIST CSF 2.0. Weeks six to eight transfer help-desk overflow and run the documented handoff.

I keep the internal lead operationally responsible throughout the transition, because a handover with no owner is how drift starts. The federal Get Cyber Safe programme publishes the same baseline controls a co-managed provider should be operating from day one.

[ORIGINAL DATA] Across our 24 Canadian co-managed client engagements through Q1 2026, we measured the median internal IT person reclaiming 12 to 18 hours per week. In our practice that time lands in three places: project work, vendor management, and finally taking vacation without the company going dark.

How to evaluate a co-managed IT provider: the 6 criteria

Six criteria separate a credible co-managed partner from a vendor selling the label, and I would verify each one before signing. The Canadian Centre for Cyber Security publishes 10 due-diligence areas for buyers of managed services in ITSM.50.030, which is the questionnaire I hand clients. To score named providers side by side, use our buyer’s guide to the best co-managed IT providers for Canadian SMBs.

  1. Written RACI matrix in the contract. Not a placeholder. Names every category of work and who owns it.
  2. CISSP-led security practice. The 24/7 SOC and security strategy are the hardest parts to staff in-house. The MSP must bring genuine security depth.
  3. Documented SLA with response-time bands by severity. P1 / P2 / P3 / P4 with credit clauses for missed bands.
  4. Quarterly business review (vCIO) cadence. Built into the contract, not surfaced as an upcharge.
  5. Defined escalation path with the internal lead. Named contacts on both sides; clear authority for what the MSP can do without internal-lead approval.
  6. Exit and portability terms. Ask for a 12-month renewable term with a documented off-ramp and a data-portability clause. A 36-month term with no exit clause is worth negotiating before signature.

Frequently Asked Questions

What is the difference between co-managed IT and fully managed IT?

Fully managed IT means the MSP owns everything end-to-end; the client has no internal IT staff. Co-managed IT means the client retains an internal IT lead who handles user-facing day-to-day work, while the MSP handles security, after-hours coverage, and specialist depth. Co-managed wins when the client has 1 to 3 internal IT staff and wants to keep them strategic rather than swamped, which in Canada is most firms between 50 and 200 users.

When does co-managed IT make sense for a Canadian SMB?

Co-managed IT typically wins for Canadian SMBs in the 50 to 200 user band that already employ an internal IT lead. Below 50 users, fully outsourced is usually right because there is not enough work for an internal hire. Above 200, the calculus tips toward a real internal team plus vendor specialists.

How much does co-managed IT cost in Canada?

Canadian co-managed pricing runs CA$160 to CA$180 per user per month on top of internal IT salary, depending on security stack tier and compliance scope. For a 75-user firm, the MSP layer lands at roughly CA$9,750 to CA$13,500 per month, with internal IT salary continuing separately. Fully managed IT with no internal lead starts at CA$180 per user per month.

What does the MSP do in a co-managed engagement?

The MSP typically covers 24/7 monitoring and SOC, after-hours and weekend response, security stack operation (EDR, MDR, SIEM, identity), backup and disaster recovery operations, compliance evidence packs, and quarterly vCIO advisory. The exact split is documented in the RACI matrix at the start of the engagement.

What is the most common reason co-managed engagements fail?

Undocumented RACI splits. When neither party has a written matrix of who owns what, both sides assume the other is handling something. Six months in, a Windows Server box hits end-of-support, a backup fails to restore, or a Microsoft Defender alert sits unread because both teams assumed the other was watching. The RACI matrix is the single artefact that protects both parties from quiet drift.

Can co-managed IT satisfy Canadian cyber insurance requirements?

Yes, when the MSP layer covers documented EDR or MDR, 24/7 SOC monitoring, immutable backup with tested restores, and incident response. Most Canadian carriers as of 2026 require these as renewal conditions. Documented co-managed coverage with a CISSP-led MSP satisfies the carrier control attestation in nearly every renewal we have observed.

Does the internal IT lead become redundant in a co-managed model?

No. The internal lead becomes more strategic, not less needed. The MSP absorbs the parts of the role that scale poorly with one person (24/7 coverage, security operations, specialist depth). The internal lead handles business context, project ownership, and the internal liaison role with leadership. Both seats exist for a reason.

How is co-managed different from staff augmentation?

Staff augmentation places an external technician inside the client team under client management. Co-managed is a partnership between the internal team and an MSP that operates its own security stack, SOC, and tooling. Co-managed brings depth and tooling that staff augmentation does not, including the 24/7 SOC and the CIS Controls v8.1 evidence trail. Staff augmentation brings hands. Co-managed brings hands plus stack.

Get a Custom Co-Managed Scope

Fusion Computing operates co-managed IT engagements with Canadian SMBs from Toronto, Hamilton, and Metro Vancouver, under a CISSP-led security practice. Tell us where your internal lead is drowning and we will scope the split.

Fusion Computing has provided managed IT, cybersecurity, and AI consulting to Canadian businesses since 2012. Fusion’s CISSP-led team supports organizations with 15 to 200+ users across Toronto, Hamilton, and Metro Vancouver.

93% of issues resolved on the first call. Named one of Canada’s 50 Best Managed IT Companies two years running.

100 King Street West, Suite 5700
Toronto, ON M5X 1C7
(416) 566-2845
1 888 541 1611