Your IT director should not also be your SOC.
A single internal generalist at a growing group is usually competent, overloaded, and structurally unable to cover 24/7 detection, a compliance program, and a help desk queue at the same time. Co-managed engagements split the work along the line where that stops being reasonable. We are explicit about who owns what, in writing, before we start.
Included in: Available on any tier. Scoped per engagement.
Six things, described plainly.
No capability matrix and no maturity model. This is what we do, why it matters in a clinical environment, and where the number comes from.
A written responsibility matrix
Every function assigned to your team or ours, with escalation paths. Ambiguity in a co-managed relationship shows up during an incident, which is the worst possible time to discover it.
We take the coverage your person cannot provide
24/7 detection and response, after-hours escalation, and the compliance program. Nobody should be the sole on-call for a clinical environment.
Your person keeps the relationships
Internal IT usually knows the physicians, the workflows, and which vendor actually answers. That knowledge is worth more than any tool, and we do not try to replace it.
Shared tooling and shared documentation
Your team gets access to the RMM, the documentation platform, and the ticket queue. A co-managed engagement where the partner hoards the tooling is a hostage situation with a nicer name.
Coverage when your person is out
Vacation, illness, and departure stop being crises. This is the most common reason a group calls us: the one IT person quit.
The security baseline is not negotiable
Co-managed does not mean we skip MFA enforcement or EDR on servers. If we are named anywhere in the response plan, the baseline applies.
Which tier includes this.
Our rates are published. If a service you need is only in a higher tier, this page says so rather than making you find out in a proposal.
The rest of what we run.
Managed IT and help desk
The day-to-day. Tickets answered by a named pod, not a rotating queue.
Cybersecurity and 24/7 detection and response
24/7 monitored detection with contractual authority to contain, not just to alert.
HIPAA compliance program
The risk analysis, the risk management plan, and the evidence file. The flagship.