HD Tech - SecurITy Delivered
Back to Blog
Managed IT

Co-Managed IT Responsibility Map: Who Handles What

By Tom Hermstad · HD Tech

Co-Managed IT Responsibility Map: Who Handles What

What does a co-managed IT responsibility map look like — and exactly who handles what?

The responsibility map is one of the most important documents a business never builds — until something breaks. In a co-managed IT model, HD Tech and your internal IT team split responsibilities across monitoring, patching, ticketing, escalation, onsite response, and compliance reporting — documented upfront, not guessed at.

For Orange County businesses in healthcare, biomedical, accounting, and construction, that clarity isn't just operationally useful. It's legally required. HHS explicitly states that covered entities remain directly liable even when they use outside partners — so "the MSP handles it" is never a complete answer.


By Tom Hermstad, Founder & CEO, HD Tech Published [Date]


Why Orange County businesses are turning to co-managed IT

Here's something I get fired up about every time I see it: a talented internal IT person, doing their best, drowning in a job that's grown three sizes too big.

The responsibility map is one of my favorite things to walk a client through. Once you see it in plain English — who owns what, where the gaps are — everything clicks. A business owner goes from anxious to in control. That's exactly why I love this work.

A manufacturing firm in Anaheim had a solid internal IT coordinator — sharp, trusted, well-liked. He was handling helpdesk, managing the firewall, and trying to keep up with HIPAA documentation at the same time.

Nobody had drawn a responsibility map. Nobody had tested the backups.

When a ransomware event hit on a Friday afternoon, the restore failed. Three days of production, gone. The breach wasn't exotic — it was a gap everyone assumed someone else owned.

A sharp internal coordinator is not the same as a seasoned security team.

That story isn't unique. I've lived it with clients in biomedical, accounting, and construction too. The responsibility map is always missing. The gaps are always identical. And the consequences are always preventable.

Co-managed IT — also called co-managed services — is a model where a business keeps its internal IT staff and brings in an MSP like HD Tech to cover the layers those staff can't handle alone. It's not a replacement. It's a force multiplier.

But it only works when both sides know exactly what they own. Without a written responsibility map, you get duplicated effort in some areas and nobody watching critical ones. That's how breaches happen. That's how compliance audits fail.

If you've been comparing co-managed models and wondering what actually splits where, this is the breakdown HD Tech uses — built around our Lifeguard Loop™ framework and designed for regulated industries where ambiguity is dangerous.


The five layers where co-managed IT responsibility splits

Here's how we map it. Every engagement is customized, but these are the consistent categories where HD Tech and internal IT divide ownership.

1. Monitoring and threat detection

HD Tech owns this.

Around-the-clock network and endpoint monitoring runs through our Relentless Response Engine™ — including AI-assisted threat detection that flags anomalies faster than any human watch rotation can. Your internal IT team shouldn't be watching dashboards in the middle of the night. In most SMBs, they aren't. That gap is exactly when attackers move.

It's not if, it's when. Our team watches for anomalous logins, lateral movement, unauthorized access attempts, and malware execution. When something triggers, we act. Your internal IT is notified when the situation requires their involvement — but the watch never goes dark.

This matters especially for healthcare and biomedical companies. According to HHS Office for Civil Rights data, between 2009 and 2025, 7,418 healthcare data breaches affecting 500 or more individuals were reported to OCR, impacting more than 1 billion individuals in total.

Hacking and IT incidents — a category that includes many ransomware attacks — are the leading cause of large healthcare data breaches. They account for the vast majority of breaches and affected records in recent years. That sustained volume makes continuous monitoring non-negotiable.

2. Patching and vulnerability management

HD Tech leads. Internal IT assists on business-critical systems.

HD Tech schedules, deploys, and verifies patches across endpoints, servers, and network devices. Your internal IT provides context on change windows, production schedules, and systems they manage directly — particularly any line-of-business applications that require coordination before updates.

For construction firms running specialized project management software, or biomedical companies with validated systems, patching without that internal context can break workflows. That's why this is a shared lane — HD Tech drives, internal IT navigates.

3. Helpdesk and ticket management

Internal IT handles Tier 1. HD Tech handles Tier 2 and above.

Your internal IT staff is best positioned to handle password resets, printer issues, and "my computer is slow" calls. They know your people and your office.

HD Tech handles escalations: complex infrastructure issues, security incidents, server failures, and anything requiring deeper expertise. Our Plain-English Promise™ means your team gets clear communication at every handoff — no jargon, no finger-pointing.

Chris Whitehead, IT Liaison at Buntich in Upland, described exactly this kind of operational clarity: "I now have a simple icon on my desk reviewing all outstanding issues and can see my past resolved issues. I now don't need to hunt my emails for open and closed tickets. HD Tech made my job easier and our experience better."

That's what a clean ticket workflow looks like in practice.

4. Onsite response

Shared — based on issue type and urgency.

For routine hardware swaps and office walk-throughs, your internal IT handles onsite visits. For security incidents, infrastructure failures, or anything that requires incident documentation (especially under HIPAA), HD Tech responds onsite or remotely with documented procedures.

Under HIPAA's Security Rule — the specific set of HIPAA standards governing how organizations protect electronic health data — incident response must be formalized, not improvised. That means written policies, documented actions, and timelines.

Your internal IT may be the first on the scene. HD Tech provides the framework and the paper trail.

5. Compliance documentation and reporting

HD Tech leads. Internal IT owns day-to-day policy execution.

This is the layer most co-managed models leave undefined — and it's the most dangerous one to leave to chance.

HD Tech builds and maintains the compliance documentation: risk analysis, audit logs, security evaluations, vendor management records, and BAAs (Business Associate Agreements — the legal contracts that define each party's responsibilities for protecting your data).

Your internal IT executes the day-to-day policies — workforce training acknowledgments, access provisioning and deprovisioning, and physical security procedures.

HHS makes clear that HIPAA requires ongoing administrative, physical, and technical safeguards — not a one-time setup. The mistake most small teams make is treating compliance as a project rather than an ongoing operational function.

Healthcare data breaches carry costs that dwarf whatever a firm might save by leaving compliance documentation to chance.


Trust, yet verify: The plain-English RACI

A RACI is a responsibility chart. R means you do the work. A means you're accountable if it fails. C means you're consulted. I means you're kept in the loop. Here's what that looks like for a co-managed IT engagement.

Function HD Tech Internal IT
Continuous network & endpoint monitoring R, A I
Threat detection & alerting R, A I
Patch management (endpoints, servers) R, A C
Patch management (line-of-business apps) C R, A
Tier 1 helpdesk I R, A
Tier 2+ escalation & resolution R, A C
Security incident response R, A C
Onsite response — routine C R, A
Onsite response — security/infrastructure R, A C
HIPAA risk analysis & documentation R, A C
Audit logging & access control review R, A C
Workforce security training C R, A
Vendor/BAA management R, A C
Backup verification & recovery testing R, A C
Strategic IT planning R, A C

Scan that table and look at the rows where HD Tech carries the R and A. Those are the functions that typically fall through the cracks without a co-managed partner.

What it means for your day: your internal IT person stops being the person responsible for everything and starts being the person who knows your business — while we handle the rest.

This isn't theoretical. Every HD Tech co-managed engagement starts with the Listen & Learn phase of our Lifeguard Loop™ — a discovery process where we map your current team's capabilities, document your compliance obligations, and define these ownership lines in writing before we start.


How a clear responsibility map becomes your competitive edge

Here's something most business owners don't think about until it's too late: the responsibility map isn't just about avoiding downtime. It's about winning.

When your RACI is documented and current, you walk into a compliance audit with confidence — not a folder full of guesses. When a healthcare client or government contractor asks about your data security posture, you have a real answer. When a competitor without this structure scrambles through an incident, you keep operating.

That's the competitive edge hidden inside a well-built co-managed IT model.

Your internal team knows the business. HD Tech knows the threat landscape and the compliance framework. Together, you project the kind of stability and preparedness that builds customer trust and closes contracts.

Companies that can demonstrate documented security practices and clean audit records are winning business that less-prepared competitors simply can't touch. That's what our Outcome Obsession Framework™ is built around — not just keeping the lights on, but turning your IT posture into something that actively supports growth.


What happens when roles aren't defined

Two things happen when co-managed IT runs without a responsibility map.

First, things fall through the cracks. Nobody patches a specific server because each side assumes the other is doing it. Audit logs go unreviewed for months. Backup restores never get tested.

Second, compliance fails. HHS OCR enforcement data shows that enforcement actions are frequently tied to missing risk analysis and inadequate incident response — not exotic exploits. OCR enforcement actions consistently cite missing or insufficient risk analysis and inadequate incident response planning, rather than novel technical exploits.

The breach doesn't have to be dramatic. A missing document or an untested restore can be just as costly.

For accounting firms, construction companies, and healthcare practices in Orange County, the stakes are identical: a gap in responsibility becomes a gap in protection. If you want to understand how hiring internal IT staff compares to partnering with a managed services provider, the calculus usually comes down to coverage depth — not headcount.


How HD Tech structures the co-managed engagement

We start with the Lifeguard Loop™ — Listen & Learn, Implement & Integrate, Fortify & Future-Proof, Educate & Empower. The responsibility map is built during Listen & Learn and updated as your business changes.

Kathleen Urquidez, President of Urquidez & Associates CPAs in Long Beach, described the outcome directly: "Data security is always a large concern, but with HD Tech on our side, we know we are doing everything we can to avoid a data breach and we rest easier."

That's the after-state. No fire drills. No guessing who owns what. Just confidence that the coverage map is complete and someone's always watching.

If you're comparing co-managed IT services options and want to see exactly how this model would work for your team, start with the responsibility map. If your current provider can't show you one in plain English — that's your answer.


Frequently Asked Questions

Here's what I tell every client who asks this: co-managed IT keeps your internal IT staff in place and adds HD Tech to cover the gaps — continuous monitoring, deeper cybersecurity, compliance documentation, and Tier 2+ escalation. Fully managed IT replaces internal staff entirely. Co-managed fits when you have capable people who need more depth than they can provide alone. Think of it as a force multiplier, not a replacement. Your people stay. The coverage gets stronger.

I get excited about this question because the answer protects you. Yes — in most cases. When HD Tech accesses or maintains systems that store ePHI (electronic protected health information — any patient or health data stored in digital form), we formalize that relationship in a Business Associate Agreement. Trust, yet verify: that agreement and the responsibility map make your obligations and ours explicit, so nothing gets assumed away. No surprises. No gaps.

Here's what I tell every client on day one: HD Tech leads it — building the documentation, identifying vulnerabilities, and maintaining the record HHS requires. Your internal IT contributes context and executes day-to-day policies. The covered entity always retains ultimate accountability, which is exactly why the responsibility split has to be written down, not guessed at. We show our work. Every time. That's the Plain-English Promise™ in action.

No ego here — and I mean that with everything I've got. Co-managed IT isn't a takeover. Your internal staff keeps what they already handle well: Tier 1 helpdesk, routine onsite support, day-to-day policy execution. HD Tech fills the gaps they can't cover alone. In my years of doing this, I've watched internal IT teams go from skeptical to relieved inside the first 90 days. The pressure goes down. The coverage goes up. Keep paddling — together.

Absolutely — and here's why I get fired up about this one. Both industries face compliance and uptime pressures that one generalist IT person can't stay current on alone. That's not a criticism; it's the reality of how complex these environments have become. Your internal person knows the business. HD Tech knows the threat landscape and the compliance framework. Together, you cover the full picture. Don't be a casualty because a responsibility gap went unaddressed.


Failing to plan is planning to fail — and if any row in that responsibility map is blank or guessed at, that's exactly where your next breach or compliance failure will come from. It's not if, it's when. The Cyber Preparation Assessment exists to fix that before the when arrives. We'll map your current team's responsibilities against the RACI you just read, identify the gaps, and show you precisely how the co-managed split would work for your business.

Book your free Cyber Preparation Assessment and let's make sure you're ready.

co-managed IT
Tom Hermstad, President of HD Tech

Tom Hermstad

President & CMO, HD Tech

Tom Hermstad has led HD Tech since 1995, building one of Southern California's most trusted managed IT and cybersecurity firms. He specializes in helping Orange County businesses eliminate IT headaches and stay ahead of evolving cyber threats — in plain English.

Need Help With Your IT?

Get a free, no-pressure IT health check. We'll show you exactly where you're exposed — in plain English.