Cost is the worst variable to decide this on. The decision is really about coverage hours, escalation depth, institutional knowledge, key-person risk, and who stays accountable to a regulator. Round-the-clock coverage takes four to five people, not one. In-house genuinely wins in three specific situations. For everyone else the honest answer is a hybrid, and federal regulation already describes its shape.

Why does the cost comparison usually mislead?

Because it compares one salary to one invoice, and the two are not the same object.

Start with wage data instead of a vendor's calculator. The Bureau of Labor Statistics publishes national wages by occupation through its Occupational Employment and Wage Statistics program. In the May 2025 national file, the median annual wage for computer user support specialists, the help desk tier, was $61,860 across 717,190 people. Network and computer systems administrators had a median of $99,130 across 314,340 people. Information security analysts came in at $129,180, and computer and information systems managers at $175,140.

Those are medians for one person each, and salary is not the cost of a hire. Payroll taxes, benefits, equipment, tooling, and training sit on top. But the deeper problem is that a help desk salary and a managed contract do not buy the same thing. A salary buys one person, during that person's working hours, at that person's skill ceiling.

There is also a sourcing problem worth naming, because it shapes almost everything published on this question. Nearly every "in-house vs managed IT" cost comparison online is written by a company that sells one of the two options. Search the question and you get page after page of managed providers quoting their own fully loaded cost figures, with no traceable methodology behind any of them. Those numbers are marketing. Government wage data has a published methodology and no stake in the outcome. Prefer it.

What do coverage hours actually cost?

A week has 168 hours. One full-time employee covers 40 of them, which is 24 percent of the week.

If the requirement is genuine round-the-clock coverage, the arithmetic is unforgiving. 168 divided by 40 is 4.2 people, and that is before anyone takes vacation, gets sick, sits in training, or resigns. A real rota needs about five. At the BLS median for a systems administrator, five of them is roughly $495,000 in salary alone, before a single benefit is paid.

Most companies do not need 24/7 and should say so plainly rather than buying it by default. But this is where an honest comparison starts, because the number of hours you actually need covered, and the cost of an uncovered hour, drives everything downstream. A dental practice that closes on Sunday has a different answer than a logistics operation whose warehouse scanners run at 3am.

How deep does escalation need to go?

The second variable is what happens when a problem exceeds the first responder.

An in-house generalist is a single skill ceiling. When a firewall misconfiguration, a compromised mailbox, and a stalled migration all land in the same week, one competent generalist handles some of it and escalates the rest. If there is nobody to escalate to, the escalation is a phone call to a vendor at emergency rates, made by someone with no leverage and no prior relationship.

The BLS medians put a price on depth. Hiring the three tiers outright, help desk at $61,860, systems administrator at $99,130, and security analyst at $129,180, is about $290,000 in salary before benefits, and that still leaves nobody managing them.

A managed provider's actual product is that bench, shared across many clients. That is the thing being bought, which is why comparing it to one salary is a category error rather than a rounding error.

Where in-house genuinely wins

Three situations, and none of them are edge cases.

The first is when IT is not a support function but part of the product. If your systems are how the company makes money, then knowing how they fit together is a competitive asset, and it belongs to people whose incentives are yours.

The second is institutional knowledge that does not transfer cleanly. Every company accumulates undocumented context: which integration breaks at month end, which customer sends a malformed file every quarter, which server nobody is willing to reboot. Someone who has been present for three years carries that in their head. A provider reconstructs it from ticket history, slowly, and loses a portion of it at every staffing change on their side.

The third is scale. Once you are large enough to genuinely staff a rota, the arithmetic inverts. Five administrators is expensive, but at that size you are usually paying a provider a comparable amount and still not employing anyone who understands the business.

Key-person risk moves rather than disappears

The standard argument against in-house is the bus factor. One person holds the environment in their head, and when they leave, the environment leaves with them.

That risk is real. It is also not eliminated by outsourcing, only relocated. Providers have turnover too, and their knowledge of your systems lives in their ticket history and an account manager's memory. The real question is not which model has key-person risk, but whether the knowledge is documented and who is contractually obliged to document it. That is a management decision available in both models, and skipped in both.

Who stays accountable when you outsource?

Here the decision stops being a preference and becomes a legal question, and the rules are unusually direct.

The FTC's Safeguards Rule (16 CFR Part 314) requires covered financial institutions to designate a qualified individual to oversee the information security program. The rule states that this person "may be employed by you, an affiliate, or a service provider." Outsourcing the role is explicitly permitted. But the same section requires that you "retain responsibility for compliance with this part" and "designate a senior member of your personnel responsible for direction and oversight of the Qualified Individual." Section 314.4(f) adds that you must select providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess the provider based on the risk it presents.

That is the entire argument in one rule. You may buy the capability. You may not buy the accountability, and you must keep someone internal senior enough to supervise the vendor.

HIPAA's Security Rule works the same way. 45 CFR 164.308(a)(2) requires a covered entity to "identify the security official who is responsible for the development and implementation of the policies and procedures required by this subpart." Section 164.308(b)(1) permits a business associate to handle protected health information only where the covered entity obtains "satisfactory assurances" through a written contract. The work can leave. The responsibility does not.

The security agencies say it in operational language. In a joint advisory published May 11, 2022 (AA22-131A), CISA, the NSA, the FBI and their counterparts in the UK, Australia, Canada and New Zealand observed that providers "usually require both trusted network connectivity and privileged access to and from customer systems," and put a blunt instruction near the top: "Ensure MSP-customer contracts transparently identify ownership of ICT security roles and responsibilities." That instruction exists because ownership is routinely unclear, and both parties assume the other one has it.

The hybrid is the default, not the compromise

Look again at what the Safeguards Rule describes: a service provider doing the work, and a senior internal person directing and overseeing them. That is a hybrid, written into federal regulation.

For most companies below the size where a five-person rota is defensible, that shape is simply the correct answer. Buy the coverage hours and the escalation bench, because those are genuinely cheaper when shared. Keep one internal person who owns the relationship, holds the context, and is senior enough to tell the provider it is wrong. Write the contract so ownership of each control is named rather than assumed.

The common failure is not picking the wrong model. It is picking either one and refusing to staff the other side of it: an in-house hire with nobody to escalate to, or a managed contract with nobody inside who can evaluate the work.

Commerce Beacon approaches virtual IT management and consulting from that premise. The first question is not which model, but which hours need covering, how deep escalation has to reach, and which control belongs to whom in writing. The same discipline drives GetSmart Cyber Defense, where security maturity is measured against a structured assessment instead of assumed, because assumed ownership is exactly how gaps survive until an audit finds them.

Decide the variables first. The model falls out of them.