The question comes up at predictable moments. You've hit 50 people and the MSP relationship is starting to strain. You're at 150 and wondering whether the person running point on technology should be an employee, not a vendor. Or you're building a budget and need to understand what each model actually costs before the board asks.
Most of the guidance on this decision frames it as a philosophy question. It isn't. It's a math and operations question, and the right answer shifts at different headcount thresholds. Here's the framework.
What in-house IT, MSP, and co-managed actually mean
In-house technology is a model where the organization directly employs the people who manage its technology environment. That can mean a full team with a technology director, helpdesk staff, and specialists, or it can mean a single person who owns the function. What defines in-house is accountability: technology employees are on your payroll, reporting to your leadership, and responsible for the full scope of your environment.
A managed service provider, or MSP, is a contracted firm that manages a defined scope of technology services on your behalf. Most MSP agreements cover reactive support (helpdesk tickets, break-fix), proactive monitoring (patching, alerting, backup verification), and a set of managed tools such as endpoint protection and email security. Per-seat monthly fees are the most common pricing model in the mid-market. The MSP retains responsibility for service delivery within the contract scope; work outside that scope is typically billed separately.
Co-managed technology is an arrangement where an MSP supplements but does not replace an internal function. Your organization employs at least one internal technology resource who handles strategy, vendor management, and escalation ownership. The MSP handles day-to-day helpdesk operations, monitoring, and defined infrastructure management. Responsibilities are divided by a clear contract: each side owns specific obligations, and the internal resource serves as the primary accountability point for the organization.
This is distinct from a fractional CIO or advisory-only engagement, where an external advisor provides strategic input without owning operational delivery. For companies weighing those options alongside managed services, the Seven Roots services page explains how advisory and operational models interact.
The decision by company size
The framework below assumes a typical mid-market company: one that generates between $25 million and $300 million in revenue, operates in a standard office or hybrid environment, and does not produce software as its primary product. Industry-specific factors are covered in the next section.
Under 50 employees, the answer is almost always a managed service provider. At this scale, a full-time internal technology hire requires you to find and retain someone who can cover helpdesk, infrastructure, security, project management, and vendor negotiations. That combination is expensive to hire for and usually underutilized at low headcount. An MSP provides the same breadth at a fraction of the cost, typically $50 to $150 per seat per month for a comprehensive agreement.
Between 50 and 150 employees, the tipping point begins. Tool complexity grows. Projects multiply. Your MSP starts handling things that require context about your business that it doesn't have. This is when a part-time technology director or internal technology lead begins to make economic sense, even if you keep the MSP for day-to-day support. The internal resource owns vendor relationships, project prioritization, and strategic decisions. The MSP remains the operational engine.
Between 150 and 300 employees, co-managed is usually the right answer. The internal technology function should own strategy, policy, security governance, and vendor accountability. The MSP should own the helpdesk, endpoint management, and infrastructure monitoring. Both sides operate under a clear agreement defining who handles what. This model scales better than a pure in-house team at this size, because the MSP handles reactive volume without requiring you to staff for peak demand.
Above 300 employees, most companies move toward a primarily in-house function. The volume of users, the complexity of the environment, and the strategic importance of technology decisions typically justify dedicated internal staff across multiple disciplines. Security operations, project management, architecture, and vendor management often require separate ownership. Specialist MSPs or co-managed security arrangements commonly supplement internal teams in specific areas.
These bands shift based on industry, compliance posture, and M&A activity. The thresholds above are a starting framework, not a fixed rule.
Comparing the three models: what each delivers
The table below compares the three models across the dimensions that matter most to a company in the 100 to 300 employee range evaluating the decision for the first time. Cost estimates are mid-market approximations and vary by region, MSP, and internal compensation levels.
| Dimension | In-house | MSP | Co-managed |
|---|---|---|---|
| Cost structure | Fixed payroll, benefits, recruiting | Predictable monthly fee (per seat or all-in) | Internal salary + reduced MSP monthly fee |
| Breadth of coverage | Limited by headcount and specialization | Broad but defined by contract scope | Broad across operations; strategic depth owned internally |
| Strategic capacity | High, if staffed for it | Low, unless a vCIO service is added | High, owned by internal resource |
| Flexibility | Low (headcount decisions are slow) | Medium (contract scope expands gradually) | High (internal and MSP scope can both adjust) |
| Vendor accountability | Internal (you own the relationship) | MSP-mediated (they manage their stack) | Split: internal resource owns strategy and contracts |
| Typical monthly cost, 200-person company | $25,000–$40,000+ (salary and overhead) | $12,000–$25,000 (per-seat MSP) | $18,000–$32,000 (salary and reduced MSP) |
The dimension worth examining first is strategic capacity. Most organizations that shift from a pure MSP model to co-managed do so because they've hit a ceiling on project throughput and strategic direction. The MSP is competent at what the contract covers. It is not designed to own your technology roadmap, and most contracts don't ask it to.
Industry and complexity factors that shift the framework
Several factors push the threshold for in-house or co-managed coverage earlier than the size-based framework would suggest.
Regulated industries move the threshold. Healthcare-adjacent companies, financial services firms, and manufacturers with operational technology or industrial control systems frequently need in-house ownership of technology governance before headcount would otherwise call for it. Compliance frameworks such as HIPAA, SOC 2, and the NIST Cybersecurity Framework require a named internal owner for security policies and controls. An MSP can support the work, but the organization needs someone internally who owns the accountability relationship with auditors and regulators. An MSP cannot fill that chair.
M&A-active companies need in-house strategic ownership earlier for the same reason. Technology due diligence, integration planning, and post-close systems work require a person inside your organization who can move quickly and who has full context about the deal. An MSP relationship doesn't provide that, and a co-managed model only functions well if the internal resource was in place before the deal closed.
Private equity-backed portfolio companies often operate co-managed by design. PE sponsors require standardized technology management across portfolio companies, with documented visibility into costs and risks. Co-managed arrangements, with a technology director who can interface directly with the sponsor's operating team, typically satisfy that requirement better than either a pure in-house team or a pure MSP model at portfolio scale.
Security-sensitive environments push toward co-managed specifically to avoid giving the MSP administrative control over the full environment. When one vendor holds all keys, your security posture depends entirely on theirs.
The hybrid and remote-first questions
When people ask whether they can do a hybrid model, the answer is that co-managed is the hybrid model. The question usually comes from organizations that want the cost structure of an MSP but are starting to recognize the strategic gaps it creates. Co-managed is the structured version of that instinct: the MSP handles the volume, and an internal resource owns the direction.
Remote-first companies sometimes assume that in-house technology is harder to justify because many of the traditional on-site advantages disappear. That's partly right. Physical security management and on-site desktop support no longer favor an in-house model when your workforce is distributed. But the strategic leadership argument still holds: someone inside the organization needs to own vendor relationships, make technology decisions, and maintain the security posture. Remote-first companies often find that MSP and co-managed arrangements work well for their environment, since those models already deliver services remotely and don't depend on geographic proximity.
The one area where geography still matters is compliance. If your industry requires on-site security controls, audit access, or documented physical safeguards, you may need an internal resource regardless of where the rest of your team works.
Signals the current model no longer fits
Knowing when to shift models is harder than choosing the right model to start with. These are the concrete signals that your current arrangement has reached its limit.
Reactive volume is exceeding the contract. When your MSP is consistently billing for out-of-scope work, or ticket volume is growing faster than the agreement can absorb, the model has outgrown the contract. The fix is not always a larger contract: sometimes it is an internal resource who reduces ticket volume through better systems and user training.
The MSP has become the de facto technology decision-maker. This is a governance problem. When purchasing decisions, vendor negotiations, and architecture choices are effectively being made by the MSP without internal review, the organization has outsourced accountability along with operations. That exposure tends to surface during audits, security incidents, or acquisitions.
The internal team is underwater and cannot get ahead of the backlog. When your technology staff spend every day in reactive mode with no capacity for projects or strategy, the model is wrong-sized for the organization.
Leadership is asking for strategic technology input the current arrangement cannot deliver. When the board or CEO wants a technology roadmap, a budget defense, or an AI strategy and neither the MSP nor the internal team can provide it, the gap is at the leadership level.
If any of these describe where you are, that's the right moment for an honest outside read. Heartwood is an advisory panel for exactly that kind of decision.
Common questions about in-house IT vs MSP vs co-managed
At what headcount does in-house IT start paying off?
The math typically shifts somewhere between 50 and 100 employees for a part-time internal resource, and between 100 and 150 for a full-time technology hire. Below 50, an MSP almost always costs less and covers more ground. The exact threshold depends on your industry, the complexity of your environment, and what you need the internal person to own. At 80 employees in a regulated industry, an internal hire may already be warranted. At 120 employees in a simple environment, an MSP may still be the right answer.
What does a good co-managed arrangement look like?
A good co-managed arrangement has a clear division of responsibilities in writing. The internal resource owns strategy, vendor accountability, security governance, and escalation decisions. The MSP owns helpdesk operations, endpoint management, backup verification, and defined infrastructure tasks. Both sides review the division at least annually. The internal resource attends MSP service reviews and can pull performance data directly. The arrangement is not co-managed if one side is waiting for the other to define the scope.
Can we do a hybrid model?
Co-managed is the hybrid model. If you're running an MSP relationship and feel like you need more internal ownership without going fully in-house, that is exactly what co-managed is designed to solve. Start by identifying which responsibilities the MSP currently fills that would be better owned internally, then build the internal role around those gaps. Most transitions from a pure MSP to co-managed happen gradually, as an organization adds internal capacity alongside the existing MSP agreement.
How does this change for remote-first companies?
Remote-first companies often find that MSP and co-managed models fit their environment well, since those models already deliver services remotely. The main in-house advantage that disappears with a distributed workforce is on-site support and physical security management. The strategic leadership argument doesn't change: someone inside the organization still needs to own vendor decisions, security policy, and technology direction. For most remote-first companies at mid-market scale, co-managed with a strong internal technology director is the right answer.
What's the total cost of in-house IT vs MSP for a 200-person company?
A comprehensive MSP agreement for a 200-person company typically runs between $15,000 and $25,000 per month depending on scope and tooling. A fully in-house technology team at the same scale typically runs $300,000 to $500,000 per year in total compensation when you include a technology director, helpdesk staff, and benefits. Co-managed, with one internal technology director and a reduced MSP scope, typically runs $200,000 to $350,000 per year all-in. These figures vary significantly by market and MSP.
One technology decision a month, taken apart.
The decision brief: one technology decision a month, taken apart. No spam, unsubscribe anytime.
Have a decision in front of you? Let's talk it through.
A 20-minute diagnostic call, then a written read-back of what we heard. No pitch, no pressure, just a straight read on whether we can help.
Start a diagnostic conversationNot sure what you need yet? Ask the panel.
Heartwood is an AI advisory panel for mid-market executives who need on-demand technology strategy guidance. Start with your toughest question.
Try Heartwood free