Skip to main content

Operating decisions / IT delivery

Compare the service you will actually receive.

An internal salary and a managed-service fee rarely cover identical work. Define the users, systems, hours and decisions involved, then compare internal, managed and hybrid arrangements against that same service. The useful question is who can perform each responsibility, with what evidence and what support when something goes wrong.

Define the comparison

Choose who operates each part of the service.

In-house IT uses your own team to perform and manage agreed IT work. Managed IT assigns specified operating responsibilities to an external provider under an agreement. A hybrid model divides those responsibilities between them. Compare the options on equivalent scope, working hours, expertise, authority, cost and recovery obligations, then check whether the proposed people and processes can support the arrangement.

Execution and authorization are separate
An engineer may create an account while a manager decides which access the person needs. State both responsibilities. Delegating technical operation does not supply missing business approval or decide your acceptable risk.
Response is not resolution
Define when the clock starts, which hours count, how severity is assigned and what constitutes a response, workaround or resolution. An acknowledgment does not mean that a person can work again.
Coverage has a boundary
List users, devices, applications, locations and service hours. Check exclusions, third-party dependencies and project work. A general support label does not establish on-site attendance or out-of-hours help.

Three operating arrangements

Evaluate the conditions behind each option.

A company can use different arrangements for different services. Internal application ownership, external endpoint operation and specialist incident support can coexist, provided the interfaces between them are explicit.

In-house operation

01

Operating choice: Build and maintain the capacity to operate the defined service within your organization.

Worth considering when
The work needs sustained business context or close coordination and you can support the required capability.
Needs
Relevant people, tools, documentation, management time and realistic absence cover.
Working example
An internal engineer handles the request, coordinates application owners and records the result.
Retained authority
Business owners still decide access, priorities, spending and acceptable disruption.
Check
Actual workload, skills coverage, response history and a handover another colleague can use.
Main uncertainty
One person becomes the only source of context or cannot cover concurrent incidents and project work.
Before choosing
Budget for support, development, leave, escalation and specialist gaps as well as salary.

Managed operation

02

Operating choice: Assign a specified service and its operating obligations to a provider.

Worth considering when
The required scope can be described and a proposed provider can demonstrate relevant delivery and coverage.
Needs
An agreed service description, access boundaries, reporting and client decision contacts.
Working example
The provider performs covered tasks and escalates approvals, exclusions or vendor dependencies to named contacts.
Retained authority
Your service owner accepts performance and retains business decisions and supplier oversight.
Check
Proposed staffing and coverage, meaningful reports, recovery evidence and clearly priced exclusions.
Main uncertainty
A contract covers ticket intake while important resolution tasks or systems remain outside scope.
Before choosing
Resolve boundaries, incident cooperation, transition and exit responsibilities before access begins.

Hybrid operation

03

Operating choice: Allocate distinct tasks across an internal team and a provider with an explicit handoff.

Worth considering when
Internal knowledge and external capacity address different parts of the same service.
Needs
One service owner, shared request records, agreed escalation rules and compatible working hours.
Working example
A provider provisions a device; an internal application owner approves role access; both attach completion evidence.
Retained authority
The internal owner resolves gaps between teams and accepts the service as a whole.
Check
A request that crosses the boundary without duplicate work, lost context or an unowned exception.
Main uncertainty
Both sides assume the other is handling the difficult task or include the same work in their costs.
Before choosing
Name the performer, approver, backup and confirmation evidence for every shared step.

Compare like with like

Keep the missing work beside the headline offer.

Use the same service definition for each option. Attach dated evidence and leave unsupported assumptions visible. A difference in coverage may justify a difference in cost; it should not disappear inside a score.

CriterionInternal evidenceProvider evidenceHybrid decisionUnresolved gap
OwnershipNamed operators and approversService and responsibility scheduleOne owner for shared outcomesNo owner for an exception
ResponseActual hours and absence coverSeverity, clock and coverage termsCross-team escalation windowAcknowledgment sold as recovery
ExpertiseSkills and available capacityAssigned capability and escalationWho handles specialist gapsCompany portfolio only
EconomicsPeople, tools and retained effortFees, exclusions and changesRemove overlap, include coordinationSalary compared with partial fee
RiskAccess and recovery evidenceControl scope and incident dutiesShared review and containment pathUnreviewed privileged access
TransitionUsable records and receiving teamMobilization and exit obligationsTest the receiving sideFiles transferred without usable access

An illustrative service test

Trace a joiner and a leaver through the proposed arrangement.

Use synthetic employee records to discuss this scenario with the proposed operators and your business owners. It tests responsibility boundaries; it does not require changing real accounts or establish full operational readiness.

  1. 01

    Set the same scope

    Describe a new starter who needs a device and access to approved applications, plus a departing employee whose access must end at an authorized time. List the systems and working hours included in each delivery option.

  2. 02

    Follow the authorization

    Identify who confirms the start or departure, approves the access profile and resolves conflicting dates. Then identify who performs each technical task. Keep the source of authority attached to the request across team boundaries.

  3. 03

    Introduce an unavailable owner

    Make the usual approver unavailable and one application dependent on a separate vendor. Ask which work can proceed, who can act as deputy and how the unresolved item is escalated without claiming the whole request is complete.

  4. 04

    Inspect confirmation

    Ask what proves the device is ready or access has been removed from each in-scope system. Distinguish a submitted request from a confirmed effect. Record systems or sessions that still require follow-up and the person responsible.

  5. 05

    Compare the effort and conditions

    Record operator time, retained approvals, coordination, tools, exceptions and vendor work for each option. Identify what the example did not test. Choose a model, request specific further evidence or revise the service boundary before committing.

Make the arrangement operable

Carry the comparison into everyday management.

These practices apply to internal and external operators. NCSC guidance specifically recommends clear MSP responsibilities, incident cooperation and controlled access; the client must still be able to inspect what is being done.

Build a complete cost basis
Compare the same scope over the same period. Include setup and transition, people and cover, tools and licenses, ongoing operation, retained management, specialist work and exit. Keep assumptions about demand, price changes and exclusions explicit. The Sourcing Playbook supports evaluating whole-life costs across internal, market and mixed arrangements.
Measure service effects
Agree definitions for response, restoration and resolution, along with recurring problems and overdue actions. Review actual records against the service terms. Include pauses and dependency delays so that a favorable average cannot conceal requests still waiting for an owner.
Review access and recovery
Use named, appropriately limited access and review privileged activity. Confirm who maintains backups, tests restoration and cooperates during an incident. For cloud services, distinguish your responsibilities from both the MSP's work and the underlying cloud provider's obligations.
Prepare for change and exit
Keep an asset and service inventory, operating records and agreed ownership of accounts. Revisit the arrangement when demand or systems change. Test a handover to a receiving operator and obtain appropriate review of contractual and employment implications before a transition.

Questions before deciding

Avoid a choice based on labels alone.

The answer depends on the work and the proposed arrangement, not the number of employees in the business alone.

Is managed IT cheaper than an internal team?
It can only be assessed against equivalent scope and a complete cost basis. A fee may exclude projects, licenses, on-site work or specialist incidents. An internal salary excludes other employment, tooling, cover and management costs. Compare the actual proposals and assumptions rather than claiming a universal saving.
Does an internal team respond faster?
Proximity may help with some tasks, but response depends on actual capacity, priorities, hours and dependencies. Compare a defined service target with evidence from the proposed arrangement. Neither an internal desk nor a provider's support portal proves the time needed to restore work.
Can we outsource all responsibility for IT?
You can delegate defined operating tasks, but someone in your organization still needs to set priorities, approve business decisions, oversee the provider and accept risk. Write down the retained responsibilities and allocate enough time to perform them.
When is hybrid IT useful?
Consider it when internal context and external operating capacity serve different needs. It needs clear boundaries, shared records and an owner for the whole service. Test requests that cross the boundary; otherwise a hybrid model can add coordination work without resolving the original gap.
Does a certified MSP settle the security question?
No. Inspect the certification's scope and relevance, then review the specific service, configuration, access and incident arrangements. NCSC guidance notes that even a certified provider's services need appropriate configuration. Certification does not confirm every requirement of your environment.

Source basis

The guidance behind the delivery comparison.

  • 01

    NCSC

    Choosing a managed service provider

    November 2025 SME guidance and checklist reviewed. Informs responsibility, service-level, access and recovery questions. Its example response times are not adopted as universal targets.

  • 02

    NCSC

    Cloud security shared responsibility model

    Main guidance reviewed, including the MSP as a third participant and retained customer responsibilities. Reviewed June 2023. Cloud-specific scope does not establish a general outsourcing recommendation.

  • 03

    GOV.UK

    The Sourcing Playbook: delivery model assessments

    Selected delivery-model and whole-life cost sections reviewed. Used for comparison principles, not public procurement or employment-law advice; the page includes older procurement-reform wording.

[ WORKFLOW / SYSTEMS AUDIT ]
THE FIRST ENGAGEMENT

Start with one real workflow

A Systems Audit is the usual starting point. If the opportunity is already clear, we can move directly into a focused build.

Show Us the WorkflowStart with the free automation readiness checklist

OBSERVEQUANTIFYDECIDEBUILD