Operating decisions / IT delivery
Compare the service you will actually receive.
An internal salary and a managed-service fee rarely cover identical work. Define the users, systems, hours and decisions involved, then compare internal, managed and hybrid arrangements against that same service. The useful question is who can perform each responsibility, with what evidence and what support when something goes wrong.
Define the comparison
Choose who operates each part of the service.
In-house IT uses your own team to perform and manage agreed IT work. Managed IT assigns specified operating responsibilities to an external provider under an agreement. A hybrid model divides those responsibilities between them. Compare the options on equivalent scope, working hours, expertise, authority, cost and recovery obligations, then check whether the proposed people and processes can support the arrangement.
- Execution and authorization are separate
- An engineer may create an account while a manager decides which access the person needs. State both responsibilities. Delegating technical operation does not supply missing business approval or decide your acceptable risk.
- Response is not resolution
- Define when the clock starts, which hours count, how severity is assigned and what constitutes a response, workaround or resolution. An acknowledgment does not mean that a person can work again.
- Coverage has a boundary
- List users, devices, applications, locations and service hours. Check exclusions, third-party dependencies and project work. A general support label does not establish on-site attendance or out-of-hours help.
Three operating arrangements
Evaluate the conditions behind each option.
A company can use different arrangements for different services. Internal application ownership, external endpoint operation and specialist incident support can coexist, provided the interfaces between them are explicit.
In-house operation
01Operating choice: Build and maintain the capacity to operate the defined service within your organization.
- Worth considering when
- The work needs sustained business context or close coordination and you can support the required capability.
- Needs
- Relevant people, tools, documentation, management time and realistic absence cover.
- Working example
- An internal engineer handles the request, coordinates application owners and records the result.
- Retained authority
- Business owners still decide access, priorities, spending and acceptable disruption.
- Check
- Actual workload, skills coverage, response history and a handover another colleague can use.
- Main uncertainty
- One person becomes the only source of context or cannot cover concurrent incidents and project work.
- Before choosing
- Budget for support, development, leave, escalation and specialist gaps as well as salary.
Managed operation
02Operating choice: Assign a specified service and its operating obligations to a provider.
- Worth considering when
- The required scope can be described and a proposed provider can demonstrate relevant delivery and coverage.
- Needs
- An agreed service description, access boundaries, reporting and client decision contacts.
- Working example
- The provider performs covered tasks and escalates approvals, exclusions or vendor dependencies to named contacts.
- Retained authority
- Your service owner accepts performance and retains business decisions and supplier oversight.
- Check
- Proposed staffing and coverage, meaningful reports, recovery evidence and clearly priced exclusions.
- Main uncertainty
- A contract covers ticket intake while important resolution tasks or systems remain outside scope.
- Before choosing
- Resolve boundaries, incident cooperation, transition and exit responsibilities before access begins.
Hybrid operation
03Operating choice: Allocate distinct tasks across an internal team and a provider with an explicit handoff.
- Worth considering when
- Internal knowledge and external capacity address different parts of the same service.
- Needs
- One service owner, shared request records, agreed escalation rules and compatible working hours.
- Working example
- A provider provisions a device; an internal application owner approves role access; both attach completion evidence.
- Retained authority
- The internal owner resolves gaps between teams and accepts the service as a whole.
- Check
- A request that crosses the boundary without duplicate work, lost context or an unowned exception.
- Main uncertainty
- Both sides assume the other is handling the difficult task or include the same work in their costs.
- Before choosing
- Name the performer, approver, backup and confirmation evidence for every shared step.
Compare like with like
Keep the missing work beside the headline offer.
Use the same service definition for each option. Attach dated evidence and leave unsupported assumptions visible. A difference in coverage may justify a difference in cost; it should not disappear inside a score.
| Criterion | Internal evidence | Provider evidence | Hybrid decision | Unresolved gap |
|---|---|---|---|---|
| Ownership | Named operators and approvers | Service and responsibility schedule | One owner for shared outcomes | No owner for an exception |
| Response | Actual hours and absence cover | Severity, clock and coverage terms | Cross-team escalation window | Acknowledgment sold as recovery |
| Expertise | Skills and available capacity | Assigned capability and escalation | Who handles specialist gaps | Company portfolio only |
| Economics | People, tools and retained effort | Fees, exclusions and changes | Remove overlap, include coordination | Salary compared with partial fee |
| Risk | Access and recovery evidence | Control scope and incident duties | Shared review and containment path | Unreviewed privileged access |
| Transition | Usable records and receiving team | Mobilization and exit obligations | Test the receiving side | Files transferred without usable access |
An illustrative service test
Trace a joiner and a leaver through the proposed arrangement.
Use synthetic employee records to discuss this scenario with the proposed operators and your business owners. It tests responsibility boundaries; it does not require changing real accounts or establish full operational readiness.
- 01
Set the same scope
Describe a new starter who needs a device and access to approved applications, plus a departing employee whose access must end at an authorized time. List the systems and working hours included in each delivery option.
- 02
Follow the authorization
Identify who confirms the start or departure, approves the access profile and resolves conflicting dates. Then identify who performs each technical task. Keep the source of authority attached to the request across team boundaries.
- 03
Introduce an unavailable owner
Make the usual approver unavailable and one application dependent on a separate vendor. Ask which work can proceed, who can act as deputy and how the unresolved item is escalated without claiming the whole request is complete.
- 04
Inspect confirmation
Ask what proves the device is ready or access has been removed from each in-scope system. Distinguish a submitted request from a confirmed effect. Record systems or sessions that still require follow-up and the person responsible.
- 05
Compare the effort and conditions
Record operator time, retained approvals, coordination, tools, exceptions and vendor work for each option. Identify what the example did not test. Choose a model, request specific further evidence or revise the service boundary before committing.
Make the arrangement operable
Carry the comparison into everyday management.
These practices apply to internal and external operators. NCSC guidance specifically recommends clear MSP responsibilities, incident cooperation and controlled access; the client must still be able to inspect what is being done.
- Build a complete cost basis
- Compare the same scope over the same period. Include setup and transition, people and cover, tools and licenses, ongoing operation, retained management, specialist work and exit. Keep assumptions about demand, price changes and exclusions explicit. The Sourcing Playbook supports evaluating whole-life costs across internal, market and mixed arrangements.
- Measure service effects
- Agree definitions for response, restoration and resolution, along with recurring problems and overdue actions. Review actual records against the service terms. Include pauses and dependency delays so that a favorable average cannot conceal requests still waiting for an owner.
- Review access and recovery
- Use named, appropriately limited access and review privileged activity. Confirm who maintains backups, tests restoration and cooperates during an incident. For cloud services, distinguish your responsibilities from both the MSP's work and the underlying cloud provider's obligations.
- Prepare for change and exit
- Keep an asset and service inventory, operating records and agreed ownership of accounts. Revisit the arrangement when demand or systems change. Test a handover to a receiving operator and obtain appropriate review of contractual and employment implications before a transition.
Questions before deciding
Avoid a choice based on labels alone.
The answer depends on the work and the proposed arrangement, not the number of employees in the business alone.
- Is managed IT cheaper than an internal team?
- It can only be assessed against equivalent scope and a complete cost basis. A fee may exclude projects, licenses, on-site work or specialist incidents. An internal salary excludes other employment, tooling, cover and management costs. Compare the actual proposals and assumptions rather than claiming a universal saving.
- Does an internal team respond faster?
- Proximity may help with some tasks, but response depends on actual capacity, priorities, hours and dependencies. Compare a defined service target with evidence from the proposed arrangement. Neither an internal desk nor a provider's support portal proves the time needed to restore work.
- Can we outsource all responsibility for IT?
- You can delegate defined operating tasks, but someone in your organization still needs to set priorities, approve business decisions, oversee the provider and accept risk. Write down the retained responsibilities and allocate enough time to perform them.
- When is hybrid IT useful?
- Consider it when internal context and external operating capacity serve different needs. It needs clear boundaries, shared records and an owner for the whole service. Test requests that cross the boundary; otherwise a hybrid model can add coordination work without resolving the original gap.
- Does a certified MSP settle the security question?
- No. Inspect the certification's scope and relevance, then review the specific service, configuration, access and incident arrangements. NCSC guidance notes that even a certified provider's services need appropriate configuration. Certification does not confirm every requirement of your environment.
Source basis
The guidance behind the delivery comparison.
- 01
NCSC
Choosing a managed service providerNovember 2025 SME guidance and checklist reviewed. Informs responsibility, service-level, access and recovery questions. Its example response times are not adopted as universal targets.
- 02
NCSC
Cloud security shared responsibility modelMain guidance reviewed, including the MSP as a third participant and retained customer responsibilities. Reviewed June 2023. Cloud-specific scope does not establish a general outsourcing recommendation.
- 03
GOV.UK
The Sourcing Playbook: delivery model assessmentsSelected delivery-model and whole-life cost sections reviewed. Used for comparison principles, not public procurement or employment-law advice; the page includes older procurement-reform wording.
Start with one real workflow
A Systems Audit is the usual starting point. If the opportunity is already clear, we can move directly into a focused build.
Show Us the WorkflowStart with the free automation readiness checklistOBSERVEQUANTIFYDECIDEBUILD
