Co-Managed IT vs. Fully Outsourced IT for Architecture Firms
A 25–50 person architecture firm should consider co-managed IT when it already has a capable internal IT employee but needs additional cybersecurity, after-hours coverage, strategic planning, specialized Revit support, or project capacity. A firm should consider fully outsourced managed IT when no internal employee can reliably own support, security, infrastructure, vendor management, and technology planning.
The decision usually depends on five factors:
- Whether the firm has an experienced internal IT professional
- How much support coverage employees require
- How complex the Revit, BIM, cloud, and network environment has become
- Whether cybersecurity responsibilities are clearly assigned
- Whether leadership receives a documented technology roadmap and budget
Neither model is automatically better. The right structure is the one that gives the firm complete coverage without creating duplicated responsibilities, unresolved gaps, or excessive cost.
| IT Support Model | Best Fit | Primary Advantage |
|---|---|---|
| Fully outsourced managed IT | Firms without dedicated internal IT leadership | One provider owns day-to-day support, security, infrastructure, and planning |
| Co-managed IT | Firms with an internal IT employee or small IT team | Internal knowledge is combined with outside tools, specialists, and coverage |
| Internal IT only | Larger firms with enough staff to cover support, security, systems, strategy, and absences | Direct control and deep familiarity with the organization |
| Break-fix support | Very limited situations with low technology dependence | Low recurring cost, but little proactive planning or risk management |
The Six-Part IT Support Model Framework
1. Evaluate the Internal IT Capability
Begin by documenting what the internal IT employee or team can reasonably own. One technically capable employee may still be unable to cover every requirement of a modern architecture firm.
Evaluate experience in:
- Employee support
- Revit and BIM performance
- Microsoft 365 administration
- Autodesk platform administration
- Cybersecurity
- Backup and disaster recovery
- Server and network management
- Cloud services
- Vendor coordination
- Budgeting and strategic planning
- Documentation
- After-hours response
A support specialist may be excellent at resolving employee issues but lack cybersecurity or infrastructure experience. A systems administrator may manage servers and networks well but have limited time for employee support. Co-managed IT can fill these gaps without removing the internal employee's role.
2. Define the Required Coverage
Architecture firms often operate beyond a standard eight-hour workday. Employees may work early, late, remotely, or during weekends to meet project deadlines.
Leadership should define:
- Normal support hours
- Required response times
- After-hours escalation
- Coverage during employee vacations or illness
- Support for remote employees
- Support for consultants and project collaboration
- Emergency response expectations
- Critical-project coverage
A single internal employee cannot provide continuous coverage indefinitely. Even firms that prefer internal IT should establish backup support for absences, major incidents, and simultaneous projects.
3. Separate Operational and Strategic Responsibilities
Daily support can consume the time intended for cybersecurity, documentation, upgrades, and long-term planning. The firm should separate operational work from strategic ownership.
| Operational IT | Strategic IT |
|---|---|
| Password and access support | Three-year technology roadmap |
| Workstation troubleshooting | Hardware lifecycle planning |
| Software deployment | Annual IT budgeting |
| Employee onboarding | Cybersecurity risk prioritization |
| Printer and peripheral support | Cloud and infrastructure strategy |
| Incident triage | Vendor and contract planning |
| Routine account administration | Business continuity planning |
In a co-managed model, the internal employee may retain business-facing and architecture-specific responsibilities while the external provider supplies security tools, monitoring, escalation, strategic guidance, and project resources.
4. Assign Cybersecurity Ownership
Cybersecurity cannot be treated as an informal responsibility shared by everyone. The firm should assign ownership for each required control.
Define who is responsible for:
- Multi-factor authentication
- Endpoint detection and response
- Email security
- Patch management
- Encryption
- Firewall management
- Backup monitoring
- Recovery testing
- Security awareness training
- Administrator access
- Incident response
- Cyber insurance evidence
- Vendor security reviews
A co-managed agreement should identify whether the internal team, external provider, or both are responsible for implementation, monitoring, reporting, and response.
5. Compare Total Cost
Do not compare only an internal salary with a managed service fee. Evaluate the complete cost of delivering the required IT function.
Internal IT costs may include:
- Salary
- Payroll taxes and benefits
- Training and certifications
- Monitoring tools
- Remote support tools
- Endpoint security
- Backup systems
- Documentation platforms
- After-hours coverage
- Recruiting and turnover
- Outside consultants for specialized projects
Managed and co-managed IT fees may include some or all of these services. The firm should request a detailed scope before comparing options.
6. Measure Outcomes
The chosen model should improve measurable business outcomes rather than simply create more activity.
Track:
- Support response time
- Support resolution time
- Recurring incidents
- Employee satisfaction
- Patch compliance
- Endpoint security coverage
- Backup success
- Recovery test results
- Hardware age
- Project completion
- Budget variance
- Cybersecurity findings
Review these metrics quarterly and adjust responsibilities when results are not improving.
What Is Co-Managed IT?
Co-managed IT is a partnership between an organization's internal IT staff and an external managed service provider. Both parties share responsibility according to a documented division of duties.
The internal employee may retain:
- Employee relationships
- Immediate onsite assistance
- Revit application knowledge
- BIM workflow coordination
- Business application administration
- Office-specific technology
- Project-team communication
The external provider may supply:
- Help desk escalation
- After-hours response
- Cybersecurity tools
- Security monitoring
- Patch management
- Microsoft 365 administration
- Server and network support
- Backup management
- Strategic planning
- Project engineering
- Documentation systems
- Coverage during absences
911 IT provides co-managed IT services for organizations that want to retain internal IT while expanding its capabilities, tools, and coverage.
What Is Fully Outsourced Managed IT?
Fully outsourced managed IT places primary responsibility for the firm's technology environment with an external provider. The provider should manage support, monitoring, cybersecurity, infrastructure, vendors, documentation, and strategic planning according to the service agreement.
A complete managed IT model may include:
- Unlimited or bundled help desk support
- Remote and onsite support
- Employee onboarding and offboarding
- Workstation management
- Microsoft 365 administration
- Network and server management
- Cybersecurity controls
- Backup and recovery
- Vendor coordination
- Hardware planning
- Quarterly technology reviews
- Annual budgeting
This model is often appropriate when firm leadership or office management is informally handling IT but does not have the time or technical experience to own it completely.
Learn more about 911 IT's managed IT services for day-to-day support, security, infrastructure, and long-term planning.
When Co-Managed IT Is the Better Choice
The Firm Has a Strong Internal IT Employee
Co-managed IT can help retain a valued employee while giving that person access to specialists, tools, and backup coverage.
The Internal Team Is Overloaded
When support tickets prevent infrastructure, security, and documentation work, the external provider can absorb routine support or specialized projects.
The Firm Needs Better Cybersecurity
An outside provider may supply endpoint security, monitoring, email protection, vulnerability management, and incident-response capabilities that would be expensive to build independently.
There Is No Backup During Absences
Co-managed support reduces the operational risk created when the only internal IT employee takes vacation, becomes ill, or leaves the firm.
The Firm Is Growing
Hiring, acquisitions, office expansion, and remote work may increase workload faster than the internal team can expand.
The Firm Needs Specialized Revit or Cloud Expertise
Internal IT may understand the firm deeply but need assistance with Autodesk performance, Azure Virtual Desktop, network design, Microsoft 365 security, or disaster recovery.
The Firm Wants to Keep Control of Certain Systems
The internal team can retain authority over selected applications, vendors, or workflows while outsourcing the remaining responsibilities.
When Fully Outsourced IT Is the Better Choice
No One Owns IT Completely
If office managers, architects, principals, and outside consultants are all handling parts of IT, a managed provider can establish clear accountability.
The Firm Does Not Need a Full-Time IT Employee
A 25–50 person firm may need broad technical coverage but not enough daily work to justify separate support, security, systems, and strategy employees.
Cybersecurity Responsibilities Are Unclear
A complete managed service can assign responsibility for monitoring, patching, endpoint security, backup, identity, and response.
Support Quality Is Inconsistent
A provider with a staffed help desk can reduce dependency on one individual and create standard response and escalation procedures.
Technology Planning Is Reactive
Fully managed IT should include hardware lifecycle planning, annual budgeting, quarterly reviews, and a documented roadmap.
Leadership Wants One Accountable Provider
A single provider can coordinate internet, cloud services, hardware, licensing, security, and other technology vendors.
When Internal IT Alone May Be Appropriate
Internal IT can be effective when the firm has enough staff, expertise, tools, and management structure to cover the entire environment.
A complete internal team should be able to provide:
- Employee support
- Infrastructure administration
- Cybersecurity engineering
- Security monitoring
- Backup and recovery
- Cloud administration
- Strategic planning
- Documentation
- After-hours escalation
- Coverage during vacations and turnover
For a 25–50 person firm, building all these capabilities internally may cost more than a co-managed or fully outsourced model. The decision should be based on business requirements rather than a preference for internal or external staffing.
Co-Managed IT Responsibility Matrix
A responsibility matrix prevents tasks from being duplicated or ignored.
| IT Function | Internal IT | External Provider | Shared |
|---|---|---|---|
| Employee support | Primary onsite contact | Help desk and escalation | Yes |
| Revit application support | Workflow and user coordination | Workstation, network, and infrastructure troubleshooting | Yes |
| Microsoft 365 | User requests and business decisions | Security, administration, monitoring, and escalation | Yes |
| Endpoint security | Local coordination | Tool management, monitoring, and response | Yes |
| Patch management | Application testing and exceptions | Deployment, monitoring, and reporting | Yes |
| Backup | Business priorities and restore approval | Monitoring, maintenance, and restoration | Yes |
| Network infrastructure | Onsite coordination | Design, monitoring, support, and documentation | Yes |
| Employee onboarding | Business information and equipment coordination | Account, device, security, and application setup | Yes |
| Technology budgeting | Business priorities | Forecasting and recommendations | Yes |
| Incident response | Internal coordination | Technical containment, investigation support, and recovery | Yes |
The exact assignments should be customized and included in the service agreement.
How Much Does Co-Managed IT Cost?
Co-managed IT pricing depends on which responsibilities remain internal, the number of users and devices, required support hours, cybersecurity tools, project complexity, and the provider's role.
| Co-Managed Service Level | Typical Planning Range | Common Scope |
|---|---|---|
| Tooling and escalation | $40–$100 per user per month | Monitoring, patching, security tools, documentation, and advanced escalation |
| Shared help desk and security | $75–$175 per user per month | Help desk, endpoint management, security, Microsoft 365, and project assistance |
| Comprehensive co-managed IT | $125–$225 per user per month | Broad operational support, cybersecurity, infrastructure, strategic planning, and project resources |
These are planning ranges rather than fixed prices. Architecture firms should verify which software, security tools, onsite support, projects, after-hours work, and strategic services are included.
How Much Does Fully Managed IT Cost?
For a 25–50 person architecture firm, comprehensive managed IT may fall within approximately $100–$275 per user per month. Pricing depends on support scope, cybersecurity requirements, infrastructure complexity, cloud services, response expectations, and included projects.
A proposal should state whether pricing includes:
- Remote support
- Onsite support
- After-hours response
- Endpoint protection
- Email security
- Microsoft 365 management
- Server and network administration
- Backup monitoring
- Strategic planning
- Quarterly reviews
- Hardware planning
- Vendor management
- Revit and BIM-related support
The least expensive proposal may exclude important security, strategy, or project services that the firm must purchase separately.
Example Cost Comparison for a 40-Person Architecture Firm
Consider a 40-person firm evaluating three models.
| Model | Illustrative Annual Cost | Coverage Considerations |
|---|---|---|
| One internal IT employee | $95,000–$145,000 including salary, benefits, tools, and outside specialists | May have gaps in after-hours coverage, cybersecurity depth, vacations, and strategic projects |
| Internal IT plus co-managed provider | $145,000–$230,000 combined | Provides internal knowledge plus help desk, tools, security, escalation, and backup coverage |
| Fully outsourced managed IT | $48,000–$132,000 at $100–$275 per user per month | Broad external coverage without an internal salary, depending on included services |
This example is illustrative. Actual internal employment costs and provider pricing vary. The comparison should also account for service quality, response times, turnover, project capacity, security risk, and business continuity.
How Co-Managed IT Supports Revit and BIM
Architecture firms need more than generic desktop support. Revit performance can depend on workstation specifications, model health, storage, network latency, cloud collaboration, add-ins, licensing, and user workflows.
A productive co-managed structure may assign:
- BIM leadership: Model standards, templates, collaboration procedures, and application workflows
- Internal IT: User coordination, application deployment, onsite troubleshooting, and business context
- Managed provider: Workstation performance, networking, security, Microsoft 365, cloud systems, backup, and escalation
This division prevents IT technicians from making BIM workflow decisions and prevents BIM leaders from becoming responsible for endpoint security, firewalls, and backup infrastructure.
911 IT supports technically demanding design environments through its engineering IT support.
How Co-Managed IT Improves Cybersecurity
Internal IT teams may have limited time to monitor alerts, evaluate new threats, manage security tools, and prepare insurance documentation.
A co-managed provider can contribute:
- Endpoint detection and response
- Security monitoring
- Email protection
- Multi-factor authentication projects
- Patch reporting
- Encryption verification
- Firewall management
- Vulnerability remediation
- Security awareness training
- Incident response support
- Cyber insurance readiness
- Quarterly security reporting
The internal employee should still understand the security program, approve changes, coordinate employees, and participate in incident response.
Architecture firms can strengthen identity, endpoints, email, networks, and incident readiness through 911 IT's cybersecurity services.
How Co-Managed IT Reduces Key-Person Risk
Key-person risk occurs when one employee holds critical passwords, system knowledge, vendor relationships, and recovery procedures.
Warning signs include:
- Only one person can administer Microsoft 365
- Only one person understands the firewall
- Backup procedures are undocumented
- Autodesk project administration depends on one employee
- Vendor contacts are stored in one mailbox
- No one can cover vacation or illness
- The firm could not recover quickly after the employee resigns
A co-managed relationship should reduce this risk through shared documentation, delegated administration, standardized tools, and cross-trained support resources.
How to Divide Help Desk Responsibilities
Model 1: Internal First, Provider Escalation
Employees contact internal IT first. Complex issues are escalated to the provider.
This works well when the internal employee is available and has enough capacity. It may create delays when that person becomes overloaded.
Model 2: Provider First, Internal Escalation
Employees contact the external help desk first. Architecture-specific or onsite issues are escalated internally.
This structure protects the internal employee's time for projects, BIM coordination, and strategic work.
Model 3: Split by Issue Type
Employees contact different teams according to the request.
For example:
- Provider: passwords, Microsoft 365, workstation failures, security alerts, and network issues
- Internal IT: application workflows, plotters, conference rooms, and office-specific requests
- BIM team: model standards, templates, families, and Revit workflow questions
This structure requires clear instructions so employees know where to request help.
How to Divide Project Responsibilities
Major technology projects require stronger planning than routine support.
| Project | Internal Role | Provider Role |
|---|---|---|
| Workstation refresh | Identify user roles, project schedules, and application needs | Specify, procure, configure, secure, and deploy systems |
| Office move | Coordinate leadership, employees, furniture, and project requirements | Design internet, network, wireless, phones, security, and migration |
| Microsoft 365 security upgrade | Approve policies and communicate changes | Design, implement, test, and monitor controls |
| Azure Virtual Desktop pilot | Select representative users and evaluate workflow | Design, deploy, secure, monitor, and optimize the environment |
| Disaster recovery project | Define business priorities and recovery targets | Implement backup, recovery, testing, and documentation |
Service-Level Agreements for Architecture Firms
The agreement should define response expectations based on business impact.
| Priority | Example | Illustrative Response Target |
|---|---|---|
| Critical | Firm-wide outage, ransomware, server failure, or loss of active project access | 15–30 minutes |
| High | Several employees affected or a major project deadline at risk | 30–60 minutes |
| Normal | One employee cannot use an application or device | 1–4 business hours |
| Low | Planned change, equipment request, or general question | Same or next business day |
Response time is not the same as resolution time. The agreement should explain how issues are escalated, updated, and handled outside normal hours.
Warning Signs of a Poor Co-Managed Relationship
Responsibilities Are Not Written Down
When both teams assume the other party is handling backups, patching, or security alerts, important work may be missed.
The Provider Treats Internal IT as Competition
A co-managed provider should strengthen the internal team, share knowledge, and respect established responsibilities.
The Internal Team Withholds Documentation
Critical system information should be available to authorized backup support. Documentation should not depend on personal memory.
Employees Bypass the Support Process
Requests sent through informal messages, hallway conversations, and personal email make performance difficult to measure and can delay support.
No One Owns Strategic Planning
Co-managed support should not become two teams focused only on tickets. Assign responsibility for budgeting, roadmaps, security, and lifecycle planning.
Tools Are Duplicated
Two endpoint tools, two remote-access platforms, or overlapping backup systems may increase cost and create conflicts. Agree on the standard platform for each function.
There Is No Escalation Process
Employees and technicians should know when an issue moves from internal IT to the provider and who remains responsible for communication.
Questions to Ask a Co-Managed IT Provider
- How will you work with our internal IT employee?
- Which responsibilities can remain internal?
- Will you provide a written responsibility matrix?
- Can our internal employee access your documentation and tools?
- How are support requests escalated?
- Who communicates with the employee during escalation?
- What happens when our internal IT employee is unavailable?
- Do you provide after-hours response?
- Which cybersecurity tools are included?
- Who monitors security alerts?
- Who is responsible for patching?
- How are backup failures and recovery tests handled?
- Can you support Revit and BIM environments?
- Do you provide Microsoft 365 and Azure expertise?
- How are major projects scoped and priced?
- Do you provide vCIO services?
- How often will leadership receive reports?
- How will you reduce key-person risk?
- Who owns the documentation?
- How can responsibilities change as our firm grows?
Questions to Ask a Fully Managed IT Provider
- Which services are included in the monthly fee?
- Are remote and onsite support included?
- What are your response-time commitments?
- How do you support Revit and Autodesk applications?
- How do you evaluate workstation performance?
- Which cybersecurity controls are standard?
- Do you provide after-hours monitoring and response?
- How are Microsoft 365 and Autodesk accounts secured?
- How are backups monitored and tested?
- What strategic planning is included?
- Will we receive a hardware lifecycle plan?
- Will you prepare an annual IT budget?
- How do you support remote employees?
- How do you handle vendor coordination?
- Which projects cost extra?
- How is documentation maintained?
- What happens if our primary technician is unavailable?
- Can we review references from similar firms?
- How is offboarding handled if we change providers?
- Who owns our accounts, licenses, and data?
Example: Co-Managed IT for a 45-Person Architecture Firm
Consider a 45-person architecture firm with one internal IT manager. The manager understands the firm's employees, Revit environment, plotters, conference rooms, and project workflows but is overwhelmed by support, security, and infrastructure projects.
A practical co-managed structure could assign:
| Internal IT Manager | Co-Managed Provider |
|---|---|
| Onsite employee coordination | Primary help desk coverage |
| Revit application deployment | Workstation, network, and performance escalation |
| BIM team coordination | Microsoft 365 administration and security |
| Plotters and office technology | Endpoint detection and response |
| Business application ownership | Patch management and reporting |
| Leadership communication | Backup monitoring and recovery testing |
| Project scheduling | Server, firewall, and cloud engineering |
| Approval of technology changes | vCIO roadmap, budgeting, and security planning |
The expected results may include:
- Reduced ticket workload for the internal manager
- Coverage during vacations and illness
- Faster escalation of complex problems
- Consistent cybersecurity monitoring
- Completed infrastructure projects
- Better documentation
- A three-year technology roadmap
A 30-Day IT Support Model Assessment
Week 1: Inventory Responsibilities
- List every support, security, infrastructure, cloud, and planning responsibility.
- Assign the current owner.
- Identify responsibilities with no owner.
- Document tasks that depend on one person.
Week 2: Measure Workload and Gaps
- Review support ticket volume.
- Identify recurring problems.
- Review cybersecurity coverage.
- Document delayed projects.
- Evaluate vacation and after-hours coverage.
Week 3: Compare Support Models
- Estimate the complete cost of internal IT.
- Obtain co-managed and fully managed proposals.
- Compare tools, service levels, projects, and security.
- Review architecture and Revit experience.
Week 4: Design the Operating Model
- Select the preferred model.
- Create a responsibility matrix.
- Define escalation and communication.
- Set performance metrics.
- Approve a 90-day transition plan.
IT Support Model Scorecard
| Category | Evaluation Question |
|---|---|
| Support coverage | Can employees receive timely support during all required hours? |
| Architecture knowledge | Does the support team understand Revit, BIM, rendering, and project workflows? |
| Cybersecurity | Is each security control assigned to a qualified owner? |
| Infrastructure | Can the team manage servers, networks, cloud platforms, and remote access? |
| Continuity | Can support continue during vacation, illness, turnover, and major incidents? |
| Documentation | Are systems, vendors, passwords, procedures, and configurations documented securely? |
| Strategy | Does leadership receive a roadmap, budget, and lifecycle plan? |
| Projects | Can the team complete office moves, cloud projects, and security improvements without delaying support? |
| Cost | Does the firm understand the complete cost of tools, staffing, services, and projects? |
| Accountability | Is every important IT responsibility assigned and measured? |
Frequently Asked Questions
What is the difference between co-managed and managed IT?
Co-managed IT shares responsibility between internal IT and an external provider. Fully managed IT places primary responsibility with the external provider.
Does co-managed IT replace the internal IT employee?
No. A well-designed co-managed relationship supports and extends the internal employee. It can reduce workload, provide specialist expertise, and improve coverage.
How many employees should a firm have before hiring internal IT?
There is no universal threshold. The decision depends on support volume, technology complexity, security requirements, office locations, and whether the firm still needs outside specialists and tools.
Can a co-managed provider handle only cybersecurity?
Yes. Some firms retain internal support and infrastructure management while using a provider for endpoint security, monitoring, email protection, training, incident response, and insurance readiness.
Who should own Microsoft 365 in a co-managed model?
Ownership can be shared. Internal IT may manage employee requests and business decisions while the provider manages security, configuration, monitoring, and advanced administration.
Can co-managed IT provide after-hours support?
Yes, when it is included in the agreement. Confirm the support hours, response targets, escalation process, and additional fees.
Is fully outsourced IT less expensive than internal IT?
It can be, especially when the comparison includes salary, benefits, tools, training, security, backup coverage, and specialist services. Cost should be evaluated alongside quality and risk.
Should the managed provider support Revit directly?
The provider should understand Revit workstations, networking, storage, cloud collaboration, licensing, and performance. BIM workflow and model-management questions may remain with the firm's BIM team.
Who owns the technology documentation?
The architecture firm should retain access to documentation about its systems, accounts, configurations, vendors, and procedures, regardless of the support model.
Can a firm switch from fully managed to co-managed IT later?
Yes. As the firm grows or hires internal IT, responsibilities can be reassigned. The service agreement and documentation should support a controlled transition.
Choose an IT Model That Eliminates Gaps
The best IT support model is not defined by whether employees are internal or external. It is defined by complete coverage, clear accountability, architecture-specific expertise, measurable service, and a practical technology roadmap.
911 IT supports architecture and engineering firms with co-managed IT services, fully managed IT services, cybersecurity services, and specialized engineering IT support.
Schedule a discovery call to compare co-managed and fully outsourced IT for your architecture firm and build a responsibility model that fits your team.
