The Mid-Market Kept Its IT Team. Sell Beside It.
An MSP can grow through two well-known doors. The first is the small company buying IT service for the first time, and the survey data says those deals keep getting smaller. The second is displacement, winning an account away from another provider, which means beating an incumbent who already holds the keys.
There is a third door: the account that employs its own IT people and hires an outside provider anyway, for the pieces its team cannot cover. The industry calls this co-managed IT. Most MSPs treat it as overflow work that shows up on its own. It should be a designed sales motion with its own offers and its own numbers. This is the playbook.
The market permission is already on record
A company with 400 employees has an IT team on payroll, usually a small one. It still buys from MSPs. In Barracuda’s 2025 survey of 2,000 IT decision-makers, reliance on MSPs for security climbs across the entire size range: 61 percent among organizations with 50 to 100 employees, 85 percent at 1,000 to 2,000. Above the smallest band, most of those buyers have IT staff of their own, so most of that reliance is capability added on top of a team the company already pays for.
WatchGuard’s April 2026 survey sampled organizations from 2 to 2,499 employees: 48 percent use an MSP to supplement their internal team, and nearly half describe their provider as a strategic advisor.
The operators who run co-managed practices put the concentration in the middle of the market: companies from roughly a hundred employees up, big enough to employ one to five IT people, too small to staff the entire function. No survey has measured that curve directly, so hold the band as operator consensus. It is also the plain arithmetic of a small team: five people cannot cover the whole stack around the clock.
That is the target profile. The rest of this piece is what to sell them and how to measure it.
Why staffed teams buy
The gaps are stated on the record, and they are specific. 54 percent of organizations say they cannot deliver continuous 24/7 monitoring and response on their own. 67 percent need outside help meeting compliance demands. 75 percent expect their security budgets to grow over the next two years, so the money to close both gaps is already planned.
The labor market keeps the gaps open. ISC2’s 2025 workforce study found 59 percent of organizations citing critical or significant skills needs, up from 44 percent the year before. A three-person IT team loses its night coverage the day one person resigns.
The sales conversation follows from the org chart. A full-outsourcing pitch tells this buyer to disband a team they chose to build, and the person evaluating you is often the person you are proposing to replace. A co-managed pitch makes the IT director the sponsor: you are offering to take the 2 a.m. pages and the audit prep off a team that keeps the work it wants.
Build the entry offer around one gap
The survey data hands you two entry offers. Build both as products, priced and scoped in advance, so a rep can put a number on the table in the first meeting.
The coverage offer sells against the 54 percent. Scope it to what the internal team cannot staff: after-hours monitoring and response, weekend coverage, tier-one triage, and a written escalation line for what wakes their people and what wakes yours. Price it flat per month so the buyer can budget it as one line item. The first proof artifact is a monthly coverage report with response times the IT director can forward to their boss. It makes your sponsor look good, which is the point.
The compliance offer sells against the 67 percent. Scope it to evidence: control mapping against the framework the client actually faces, a standing evidence calendar, audit preparation the team currently does by hand, and a findings list worked between audits. The proof artifact is the audit that goes smoothly.
One gap per entry. Bundling kills the motion, because the value of the first engagement is a fast, visible win that cost the buyer one decision.
Put the division of labor in writing
The core artifact of a co-managed account is a written split of the stack: who owns patching, monitoring, identity, backup and recovery, vendor escalation, audit evidence. Write it during onboarding and revisit it every quarter.
The document does two jobs. First, it protects the sponsorship. What stays in-house is on paper, so the internal team can see the boundary and stops defending against you. Second, it is the expansion instrument. Every quarterly revisit re-sorts the stack: the pieces the team is ready to shed move to your column with a price attached, and the pieces they want to keep stay theirs. Expansion stops being a campaign and becomes a standing agenda item the client expects.
This is also where the account defends itself at renewal. A client holding a documented year of coverage reports, closed audit items, response times, and a division of labor re-signed four times has very little reason to shop.
Stages, and the numbers to run
Define the stages and hold every account to one of them. Supplement: one scope, flat fee. Shared operations: multiple scopes, with the division-of-labor document governing both sides. Primary: your team runs the stack and the internal staff direct it.
Then instrument the motion with four numbers: the share of new logos entering through the co-managed door, second-scope attach by month twelve, stage conversions per year, and revenue per co-managed account tracked beside revenue per full-service account.
No public benchmark exists for any of these, so set internal baselines in the first two quarters and manage against your own trend. The absence works in your favor at diligence: an operator who can produce these four numbers is showing instrumentation the market cannot buy off the shelf.
The revenue justifies the discipline. In Kaseya’s 2025 benchmark, about 61 percent of MSP executives reported co-managed revenue up year over year, and two-thirds said co-managed work produces as much as half of their revenue. A line that size deserves designed offers and a real review cadence.
Qualify for it deliberately
Build the target list on the profile the data supports: mid-market companies with a small internal IT team, a compliance obligation, no overnight coverage, and a security budget already planned to grow. The signals show from outside: job postings for a second or third IT hire, a regulated industry, a tool stack wider than a small team can manage, and an org chart with no overnight shift.
Then fix the sales behavior that kills these deals. A rep who walks into a staffed account with a full-outsourcing pitch turns a warm conversation into a threat, and the deal dies with the IT director as its opponent. Script the co-managed pitch separately, train reps to spot the staffed account before the first meeting, and comp expansion revenue so the account gets worked after the land.
The operating review
If you hold a platform MSP, put four questions in the next operating review. How many of last quarter’s new logos entered beside an internal IT team? What is revenue per co-managed account, and how has it moved over four quarters? Who owns second-scope attach, and what is the number? Which accounts sit one quarterly review away from a stage conversion?
The timing argument is already made: 75 percent of organizations expect security budgets to grow over the next two years, and the staffed mid-market accounts are where those budgets live. If the co-managed column of the closed-won list is empty, the growth plan is leaving its largest deal sizes on the table. Building the motion costs less than buying the equivalent pipeline.
Frequently Asked Questions
What is co-managed IT for an MSP?
Serving accounts that keep an internal IT team by filling named gaps while the team stays. The common entry scopes are the ones buyers state on the record: in WatchGuard's April 2026 survey of 842 IT and security decision-makers, 54% of organizations say they cannot deliver continuous 24/7 monitoring and response themselves, and 67% need outside help meeting compliance demands. The MSP takes defined scopes, the internal team keeps the rest, and a written division of labor governs the split.
What size company buys co-managed IT?
Operators who run co-managed practices put the sweet spot in the mid-market: companies large enough to employ roughly one to five IT staff who cannot cover the entire function. That band is practitioner consensus, because no survey measures co-managed prevalence by company size. The hard data shows MSP reliance rising across the whole range: in Barracuda's 2025 survey of 2,000 IT decision-makers, 61% of organizations with 50 to 100 employees rely on an MSP for security and 85% at 1,000 to 2,000 employees do, and WatchGuard finds 48% of organizations overall using an MSP to supplement their internal team.
How should an MSP measure a co-managed motion?
Track four numbers: the share of new logos entering through the co-managed door, second-scope attach by month twelve, stage conversions per year, and revenue per co-managed account beside revenue per full-service account. No public benchmark exists for any of them, so set internal baselines in the first two quarters and manage against your own trend.