Back to Blog
Guides

Co-Managed IT for Plano and Frisco Businesses and Who Acts at 2 AM

Co-managed IT keeps your IT person and adds 24/7 security coverage. It only works if the line between the two teams is written down before an attack.

By Mark Sullivan Sep 21, 2026 1 views
co-managed ITmanaged SOCincident responsePlano Frisco IT
Share:

It is 2:40 on a Saturday morning in Frisco. A security alert fires on the file server of a forty-person distribution company. Somebody on an outside monitoring team sees it within minutes, confirms that it is real, and picks up the phone. They reach the company's IT manager, who is asleep, and who has always assumed that the outside team would simply shut the server down if anything bad happened. The outside team has always assumed that nobody touches a production server without the IT manager's approval. Both are being careful and reasonable. For the next forty minutes, while two sets of competent people figure out who is allowed to do what, the attacker keeps working.

That scenario is the most common way a co-managed IT arrangement fails, and it has nothing to do with skill. Co-managed IT means you keep your own IT person or small IT team for the daily work and bring in an outside partner to cover the parts that team cannot realistically cover, most often security monitoring around the clock. It is a sensible model for a lot of businesses in Plano, Frisco, McKinney and across Collin County. It works well when the line between the two teams is written down. It fails, sometimes expensively, when that line lives only in people's heads.

This post is about that line. If you already have an internal IT person and you are weighing outside help, or you already have an outside partner and you are not sure who is on the hook for what, this is the conversation to have before the alert fires, not during it.

Why Co-Managed Arrangements Usually Fail at the Worst Possible Moment

Most co-managed relationships start well. Monitoring goes in, the weekly reports look fine, and the gap stays invisible because nothing has tested it.

The test arrives on a night or a weekend, because that is when attackers prefer to work. Ransomware crews, the groups that lock up your files and demand payment, time their attacks for Friday evenings and holiday weekends precisely because they know response is slowest then.

In that moment, three questions decide how much damage you take. Who is allowed to disconnect a machine from the network? Who is allowed to disable a user account, including an executive's? Who decides whether the business stops operating for a few hours to contain the problem? If those answers were agreed in writing months earlier, the response takes minutes. If they were not, the response takes as long as it takes to wake up the right person and get a decision out of them.

The business cost of that delay is not abstract. Every extra hour an attacker spends inside your network means more systems to rebuild, more days of downtime, a larger notification obligation if customer data was taken, and a harder conversation with your cyber insurance carrier, who will want to know exactly when you detected the problem and what you did about it. We covered why a single internal IT person cannot close this gap alone in When One IT Person Is Not Enough for a Plano or Frisco Business. This post picks up where that one leaves off, with what the partnership has to look like once you decide to add help.

What Your Internal IT Person Should Keep

A good co-managed arrangement does not shrink your IT person's job. It removes the part of the job that one or two people were never going to be able to do, and leaves them the parts where they are genuinely irreplaceable.

Your internal team should keep user accounts, which means onboarding new hires, offboarding people who leave, and resetting the password someone forgot on Monday morning. They should keep the help desk and the daily support requests, because they know your people and your people trust them. They should keep hardware, business applications and the vendor relationships behind them. They should keep control over changes to your systems, because they are the ones who know that a particular server is configured oddly for a reason nobody wrote down.

That last point matters more than most owners realize. Your IT person carries years of knowledge about how your business actually runs. Replace that person and the knowledge usually leaves with them. The point of co-managed IT is to keep that knowledge in the building. If a provider's pitch starts with replacing your IT team, you are being sold a different product, and it is worth reading Managed IT Provider vs Cybersecurity Specialist and Why Your Business Needs Both to understand the difference before you sign anything.

What the Outside Security Team Should Own

The outside partner should take the work that requires someone to be watching every hour of every day. A week has 168 hours. One IT person works roughly forty of them. Even a team of two leaves most nights and weekends uncovered.

That is what a security operations center is for. A security operations center, usually shortened to SOC, is a team of analysts whose entire job is to watch your systems for signs of an intruder and respond when they find one. In a co-managed arrangement, the SOC owns round-the-clock monitoring, sorting real threats from false alarms so your IT person only hears about confirmed problems, and taking containment action when something is actually happening.

Beyond monitoring, the outside team is usually the right owner for a handful of jobs that tend to fall off an overloaded IT person's list. Vulnerability scanning, which is an automated check of your systems for known weaknesses an attacker could use, belongs here along with deciding which patches matter most this week. So does dark web monitoring, which watches criminal marketplaces for stolen company passwords before someone uses them to log in as one of your employees. So does the evidence your cyber insurance carrier and your larger clients keep asking for on their security questionnaires.

The important word in all of this is "own." It is not enough for the outside team to watch these things. For each one, the contract should say that the outside team is responsible for it, what they do when something is found, and who they tell. On our co-managed IT and security engagements, that split is written down and signed by both teams before a single tool is installed, because the split is the product.

The Decisions Only You Can Make

There is a third category that neither your IT person nor the outside team should own, and it is the one most arrangements forget entirely. Some decisions during an incident are business decisions, and they belong to the owner, the operations lead or the controller.

Whether your order system can go offline for four hours on the last business day of the month is a business decision. Whether to notify customers, and when, is a business decision with legal consequences, since most states set deadlines for telling people their personal information was exposed. Whether to call your insurance carrier before you call anyone else is a business decision, and it is often the right one, because many cyber insurance policies require you to use approved response firms and to notify the carrier quickly or risk the claim.

None of these should be made for the first time at 3 a.m. by a technician who does not know your contracts, your cash position or your customers. The strongest arrangements settle them ahead of time as standing instructions. For example, you might decide in advance that the outside team may isolate any single laptop or server immediately without asking anyone, but that shutting down the whole network requires a call to one of two named people. Those are small decisions on a Tuesday afternoon and enormous ones half awake on a Saturday.

Write down who those named people are, give the outside team a way to reach them that is not the same email system an attacker might be sitting inside, and review the list whenever someone leaves the company. That one page does more for your response time than any tool you will buy.

What a Response Time Promise Has to Say in Writing

Every provider will tell you they respond quickly. The question worth asking is what, exactly, the clock measures. We went through this in detail in What an IT Response Time Guarantee Actually Covers in Frisco and Plano, and it matters even more in a co-managed setup, because a fast response from the outside team is worthless if the next step waits on your IT person waking up.

A response time can mean several very different things. It can mean the time until an automated system acknowledges an alert. It can mean the time until a human being looks at it. It can mean the time until someone calls you with a confirmed problem and a plan. Or it can mean the time until a compromised machine is actually cut off from the rest of your network. A contract that only says "fast response" does not tell you which one you bought.

Our commitments on co-managed engagements are specific. Within 15 minutes, the SOC triages the alert and calls with confirmed details and the containment steps being taken, rather than forwarding a raw alert to someone's inbox. On a confirmed active incident, containment action happens within 30 to 60 minutes at any hour, including weekends and holidays. Clients on an incident response retainer get a guaranteed response within two hours with a named engineer on the call. Whatever provider you choose, ask them to tell you in writing what their number measures and what happens in the first hour after it. If the answer is an acknowledgement and a ticket, your IT person is still the one doing the work at 3 a.m.

What This Looks Like for a Plano or Frisco Business

Go back to the distribution company in Frisco from the opening. Here is the same night with the boundary written down.

The alert fires at 2:40. The SOC confirms within minutes that a user account is behaving the way attackers behave, logging in from an unfamiliar location and touching files it never touches. Because the standing instructions say the outside team may isolate a single server without asking, they cut the file server off from the network immediately and disable the account. Then they call the IT manager, who wakes up to a phone call that says what happened, what has already been done, and what they need from the IT manager in the morning. The IT manager does not have to decide anything in the dark. The owner gets a call at 7 a.m., not at 3, because nothing that required an owner's judgment came up overnight.

On Monday, the company is back to normal work with one server being restored from backup. That restore works because someone tested it last quarter, which is its own discipline and is covered on our data backup and recovery page. The insurance carrier gets a clear timeline.

None of it required a larger IT staff. It required a signed page that said who owns what. Businesses we work with across Plano and Frisco are usually in the same position: one or two capable IT people, growing client demands for security answers, and an insurance renewal asking questions they cannot say yes to. Co-managed IT fits that shape well because it adds coverage without disrupting what already works. If you are a managed service provider rather than a business owner, and you want to add security for your own clients, the arrangement is different and is described on our MSP and partner integration page.

You should also know what it costs before you get on a call. Our per-user plans are published on our pricing page rather than held behind a sales conversation, and most co-managed engagements fall into one of two tiers depending on how much monitoring coverage you need. Your IT person can see exactly what our analysts see through shared dashboards in the CyberOne platform, so nobody is waiting on a monthly report to find out what happened.

How to Get the Boundary Written Before You Need It

You can start this conversation this week, with or without us. Sit down with your IT person and ask three questions. What happens if something goes wrong at 2 a.m. on a Saturday? Who is allowed to disconnect a machine or disable an account without waking anyone up? Which decisions require the owner, and how does the person on duty reach that owner if email is down? If the answers are vague, you have found your gap, and it is far cheaper to find it now than during an incident.

If you would like help, our team in McKinney will review what you have today, what is actually being watched, and where the handoffs break down. You get the findings whether or not you hire us. Book a free assessment, reach us through our contact page, or call 512-518-4408 to talk it through with someone who has sat on both sides of that 2 a.m. phone call.

Frequently Asked Questions

What is co-managed IT and how is it different from a managed service provider?

Co-managed IT means your internal IT person or team keeps the daily work, such as user support, hardware and business applications, while an outside partner covers specific responsibilities like round-the-clock security monitoring. A traditional managed service provider replaces your IT function entirely. Co-managed keeps the institutional knowledge of your existing staff and avoids the disruption of migrating everything to a new provider.

Will co-managed IT replace my internal IT person?

It should not, and an arrangement that ends with your IT person leaving has usually gone wrong. The outside team takes the work one or two people cannot cover, mainly nights, weekends and incident response, and leaves your IT person the work where they are irreplaceable. Most internal IT staff are relieved to hand off the overnight alerts.

Who is responsible when there is a cyber attack in a co-managed arrangement?

That depends entirely on what is written in your agreement, which is why it must be written before an incident. In a well-run arrangement, the security partner is accountable for detection, confirming the threat and containing it, while your business owns decisions like taking systems offline, notifying customers and contacting your insurer. If nobody has written this down, assume the answer is unclear and fix it now.

How much does co-managed IT cost for a small business in North Texas?

Most providers price co-managed security per user per month, and the total depends on how many users you have, which services are in scope and the contract term. We publish our per-user plans openly on our pricing page so you can estimate the cost before any sales call. The more useful comparison is against the cost of hiring enough staff to cover all 168 hours in a week, which is far higher for most small businesses.

What should a co-managed IT agreement include?

At minimum it should list which responsibilities belong to your internal team, which belong to the outside partner, and which decisions require a named person at your business. It should state what the response time actually measures and what the outside team is allowed to do without asking first, such as isolating a single machine. It should also include how the outside team reaches your decision makers if your email system is compromised.

Need Help With This?

Innovation Network Design helps businesses across McKinney, Dallas, and nationwide with expert cybersecurity services.

M

Mark Sullivan

Innovation Network Design

With nearly a decade in cybersecurity and IT infrastructure, our team delivers expert insights to help businesses in McKinney, Dallas, and across DFW make informed security decisions. Have a question? Get in touch.

Ready to Secure Your Business?

Get a free security assessment and find out where your organization stands.