Most comparisons of managed IT and in-house IT assume you are starting from nothing. Plenty of businesses are not. There is already someone doing IT, formally or otherwise, and the real question is not "which model should we adopt" but "what happens to the arrangement we already have".

In short: There are three honest options when internal IT already exists. Replace makes sense when the role is a single point of failure the business can no longer carry, or when the estate has outgrown what the role was designed for. Supplement (co-managed) is the most common outcome and usually the best value: the internal person keeps the business knowledge and user relationships, the provider takes monitoring, patching, out-of-hours cover and specialist depth. Neither is a legitimate answer if the current arrangement is genuinely covering the estate and nothing is being deferred. The deciding factor is rarely cost. It is almost always coverage and breadth.

If you are choosing a support model from scratch rather than deciding what to do with an existing one, the underlying cost and coverage comparison is set out in managed IT vs in-house IT vs break-fix. This guide picks up where that one leaves off.

What an internal IT person actually gives you

It is worth being precise about this, because it is the part that is easiest to undervalue when a provider is quoting and easiest to overvalue when the incumbent is well liked.

An internal person holds context. They know that the finance system has to be up before the month-end run, that the warehouse team cannot be interrupted between certain hours, that a particular integration was built by a supplier who has since gone quiet, and that the reason a server is still running is a licence nobody can replace.

None of that is written down anywhere, and none of it can be acquired by an external provider quickly, or in some cases at all.

They are also present. A person who sits in the building notices that a team has quietly started working around a problem instead of reporting it. That is a genuinely different signal from a ticket queue, and no amount of monitoring replaces it.

What they cannot do is be in two places at once, be current in six specialisms simultaneously, or be available while asleep, ill or on leave. Those are structural limits rather than performance ones, and they do not improve with a better hire.

What a managed provider actually gives you

A provider brings breadth and continuity. The breadth is the part most businesses underestimate: security, identity, cloud infrastructure, networking, backup and compliance each move fast enough that staying current in one is a real commitment. A provider spreads that cost across many clients, so you get access to people who are current in each rather than one person doing their best across all of them.

The continuity is less obvious but often matters more. Monitoring runs whether anyone is in the building or not, patching happens on a schedule rather than when someone gets to it, and cover does not disappear because one person booked a fortnight in Spain. It is the difference between IT being attended to and IT being attended to by someone specific.

What a provider cannot do is know your business the way somebody inside it does, and any provider claiming otherwise in a first meeting is overselling.

"The question worth asking is not whether your internal person is good. It is what happens to the estate during the fortnight they are away, and whether the answer to that is acceptable."

The three options at a glance

  • Replace. The role is a single point of failure the business cannot carry, or was never really an IT role.
  • Supplement (co-managed). The internal person keeps context and relationships; the provider takes monitoring, patching and out-of-hours.
  • Neither. The estate is genuinely covered today and nothing is being deferred.

Option one: replace

Replacing an internal role with a provider is the least common of the three and works in a narrower set of circumstances than providers tend to suggest.

It genuinely fits when the role has become a single point of failure the business cannot carry, and the estate is standard enough that the institutional knowledge is recoverable through documentation rather than irreplaceable. A business running almost entirely in Microsoft 365, with cloud-hosted line-of-business applications and no unusual infrastructure, has less unwritten context to lose than a manufacturer with a production network and twenty years of accumulated decisions.

It also fits when the role was never really an IT role. Plenty of small businesses have an office manager, a finance lead or a technically confident director who absorbed IT because someone had to. That is not a job anyone designed, it is usually costing the business the work that person was actually hired for, and handing it to a provider is straightforwardly better for everyone including them.

The risk to plan for is knowledge transfer. If you are replacing rather than supplementing, the handover period is the whole game, and it needs to be measured in weeks with documentation as a deliverable, not a final-week conversation.

Option two: supplement, or co-managed IT

This is where most businesses with existing internal IT end up, and generally for good reasons.

The division that works is roughly this. The internal person keeps what benefits from presence and context: day-to-day user support, business priorities, vendor and supplier relationships, project ownership, and being the person who decides what matters this quarter. The provider takes what benefits from scale and continuity: 24/7 monitoring, patch management, security tooling and response, backup verification, out-of-hours cover, and the specialist work that comes up a few times a year and has to be right.

Done well, the internal role usually gets better rather than smaller. The week stops being consumed by patching, backup checks and password resets, and starts including the projects that were permanently deferred because there was never a clear fortnight.

The failure mode is specific and worth naming: both sides assuming the other is watching something. It is entirely preventable, and the prevention is a written responsibility matrix agreed at the start covering who owns monitoring, who owns patching, who responds out of hours, who holds the tenant's privileged accounts, and who is accountable when something falls between the two. If a provider will not produce one, that tells you something.

Option three: neither, for now

Not every business with internal IT needs a provider, and it is worth stating plainly because almost nobody selling managed services will.

If your internal arrangement is genuinely covering the estate, if patching is happening on a schedule, backups are being tested rather than assumed, security tooling is in place and current, out-of-hours risk is understood and accepted, and nothing significant is being permanently deferred, then the honest answer is that you do not currently have a problem that a provider solves.

The reason this is worth checking rather than assuming is that most of those things fail quietly. Nobody notices that backups have not been restore-tested until the restore matters.

The useful exercise is not a sales conversation but an audit. When was the last successful test restore? What is the current patch compliance figure across devices? What happens at 2am? And what has been on the "when we get time" list for more than six months? If those answers are comfortable, wait.

The full comparison

ReplaceSupplement (co-managed)Neither
Institutional knowledgeAt risk, needs formal transferRetained internallyRetained internally
Coverage outside working hoursProvider's defined hoursProvider's defined hoursUnmanaged gap
Specialist breadthProvider's benchProvider's benchLimited to the individual
Single point of failureRemovedRemovedPresent
Cost shapeContract replaces salarySalary plus contractSalary only
Best suited toStandard estates, or where the role was never really an IT roleMost businesses with existing internal ITEstates genuinely well covered today
Main riskLosing context that was never written downUnclear split of responsibilityQuiet failures nobody is watching for

How to work out which one you are

Four questions, answered honestly, usually settle it.

What happens during a fortnight's leave? If the answer is "things wait", you have a coverage problem, and it is the most common reason businesses move. If the answer is "nothing, it is covered", ask who is doing the covering and whether they agreed to it.

How much is being deferred? Every internal IT function has a list of things that would be good to do. If that list has not moved in a year, capacity is the constraint, and supplementing addresses it directly.

How many specialisms does the estate actually demand? Count them honestly: identity, endpoint security, network, backup, cloud infrastructure, compliance, and the line-of-business applications. If the number is above three or four and one person is covering all of them, breadth is the constraint.

What is written down? If the answer is very little, that is an argument for supplementing before replacing, because the handover risk in a replacement is proportional to how much only lives in one person's head.

Where Systech fits

We work in all three of these arrangements and are straightforward about which one we think fits. Co-managed is the most common shape of our work with businesses that already have internal IT, and it is usually what we recommend, because it keeps the thing that is genuinely hard to buy, the knowledge of your business, in your business.

We are also clear about our own limits. If what you actually want is somebody physically present most days handling desk-side requests as they arise, an internal hire will serve you better than we will. Where we are a strong fit is Microsoft cloud, identity, security and well-run managed support behind whoever holds the relationship internally.

Our published starting price and what sits inside it are on the pricing page, and the underlying support models are compared in full in managed IT vs in-house IT vs break-fix. If you are still working out what kind of provider you are shopping for, MSP vs CSP vs MSSP is the shorter read.

Frequently asked

Does using an MSP mean making our IT person redundant?

It shouldn't, and in most arrangements it doesn't. The co-managed model exists precisely because the two roles are complementary rather than competing: an internal person holds the institutional knowledge a provider cannot hold from outside, the priorities, the vendor relationships, the reasons things are set up the way they are, while the provider carries the 24/7 monitoring, patching, out-of-hours cover and specialist depth that no single hire sustains across security, cloud, networking and compliance at once. Where roles do change, it is usually the shape of the job rather than its existence: the person stops spending their week on password resets and patching and starts owning projects, vendors and internal priorities. If a provider's first proposal is to replace your internal person entirely, ask them specifically what happens to the knowledge that person holds, and how they plan to acquire it.

At what point does one internal IT person stop being enough?

Usually not at a headcount, but at a breadth threshold. A capable generalist covers a surprising amount until the estate starts demanding genuine specialism in several directions at once. Security, cloud infrastructure, networking, identity, compliance and day-to-day service desk volume are each deep enough to be a career on their own, and the point where one person can no longer be current in all of them arrives well before the point where the business could justify hiring a second, third and fourth specialist. The other common trigger is coverage rather than skill: the moment the business genuinely cannot tolerate IT being unavailable during annual leave, illness or outside working hours, one person has become a single point of failure regardless of how good they are.

What is co-managed IT?

An arrangement where an internal IT person or small team and an external provider divide responsibility for one estate deliberately, rather than one covering for the other's absence. In practice the internal side usually keeps user-facing support, business priorities, vendor relationships and project ownership, while the provider takes monitoring, patching, security tooling, out-of-hours cover and the specialist work that comes up occasionally but has to be right when it does. The important part is that the split is written down. Co-managed arrangements fail when both sides assume the other is watching something, and that failure mode is entirely preventable by agreeing a responsibility matrix at the start rather than after the first incident.

Is a managed provider cheaper than hiring someone internally?

It depends on what you need covered, and comparing a salary against a monthly contract is the wrong comparison. A salary buys one person's working hours, one person's skill set, and nothing during their annual leave, illness or notice period. It also carries costs that sit outside the base figure: recruitment, training, tooling, and the coverage gap while the role is vacant. A managed contract buys defined coverage hours and access to a wider bench, spread across many clients. The honest question is not which is cheaper but what each leaves uncovered for a similar spend, and for many businesses the answer that actually fits is neither alone but a smaller internal role alongside a provider.

We have an IT person who is very good. Why would we bring in a provider at all?

Often for the things that are structurally impossible for one person rather than anything to do with their ability. One person cannot be awake at 3am, on holiday and in a meeting simultaneously. One person cannot be current across security, cloud, identity, networking and compliance as all five move. And one person is a single point of failure for institutional knowledge, which becomes acute the moment they hand in notice. A provider alongside them removes those structural limits without removing the thing that makes them valuable. If none of those limits is currently causing you a problem, that is a legitimate reason to wait.