Co-managed IT keeps an internal technology team in place while a provider owns agreed operational or specialist work. It succeeds when responsibilities are explicit. It fails when both sides assume the other owns monitoring, patching, backup, identity, vendors, incident response, or after-hours escalation.
Current as of 2026-08-15
CISA’s joint MSP advisory recommends that providers and customers define security controls and responsibilities in contractual arrangements. Co-managed IT does not transfer executive accountability for business risk.
Decision summary
- Start with a responsibility matrix, not a list of tools.
- Separate service ownership, approval authority, and evidence ownership.
- Use named identities, least privilege, MFA, logging, and periodic access review.
- Test escalation and exit before an incident or provider change.
Choose which gaps the provider will own
- Overflow or after-hours service desk.
- Endpoint, server, network, cloud, and backup operations.
- Security monitoring and incident response.
- Projects, architecture, compliance support, or vendor coordination.
- Strategic planning, budgeting, lifecycle, and executive reporting.
Write a responsibility matrix
For every service, name the party that performs the work, approves consequential changes, receives alerts, communicates with users, retains evidence, and owns exceptions. Include subcontractors and platform vendors. “Shared” is not a sufficient owner. Reconcile the matrix during service reviews and after personnel, platform, or scope changes. Record each exception, decision, accountable owner, due date, and acceptance evidence.
Protect privileged access
CISA recommends MFA, logging, monitoring, and controls on MSP access. Use provider-specific named accounts, least privilege, time limits where practical, and fast revocation. Review access and log retention on a fixed cadence.
Measure the operating model
- Time to acknowledge and restore by priority.
- Backlog age, recurrence, and root-cause closure.
- Patch, backup, identity, and asset coverage.
- Escalation quality and change failure rate.
- User experience and progress against business risks.
Next step
Draft a responsibility matrix for ten critical services and resolve every row that has two owners or no owner. For an environment-specific baseline, request an ITECS technology and security assessment.
Primary Sources
- CISA — Joint advisory for MSPs and customers
- CISA — SMB vendor and MSP assessment guidance
- NIST — CSF 2.0 resources for small business
Review trigger: Review after staff, provider scope, coverage hours, privileged access, platforms, compliance duties, or escalation contacts change.
continue reading
More ITECS blog articles
About ITECS Team
The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.
View full profile and articles