Managed IT · Property management

Co-managed IT and network-as-a-service across 120+ property locations

This national property-management company operates more than 120 locations with a capable internal team led by an IT director. The estate had outgrown what any in-house team could reach, and its network and security posture had drifted apart site to site. intSignal works underneath the director as a co-managed extension — adding national reach, 24/7 detection, and specialist depth on demand.

The problem

120+ locations to cover across the country — more estate than any single in-house team is staffed to reach.

What we did

Co-managed IT working under the client's IT director, plus national support.

The outcome

More than $500,000 a year against the cost of building the same capability internally — a reduction of roughly 60–70%.

$500K+
Saved every year against building it internally
60–70%
Below an in-house team
40–50%
Below a comparable managed-service bundle

The challenge

What the business was up against

120+ locations to cover across the country — more estate than any single in-house team is staffed to reach. An IT director who needed reach and specialist depth on demand, not a replacement. Network and security posture that had drifted apart site to site over years of organic growth. No spare capacity for security leadership — strategy, risk, and board reporting.

By the numbers

Indexed to building the same capability in-house = 100. A comparable managed-service bundle quotes support first and adds security and network as separate lines; intSignal delivers the whole scope well below both.

Build in-house100
Comparable MSP bundle61
intSignal34
  • Service desk (2.0)38%
  • Network engineer (1.0)19%
  • Security analyst (1.0)19%
  • Sysadmin / M365 (1.0)19%
  • Fractional CISO (0.25)5%

The thinking

Why we did it this way

A company this size could hire, but not efficiently — you can't hire a quarter of a CISO or a third of a network architect. Co-management under their own IT director let them buy exactly the specialist depth they needed, when they needed it, without carrying five salaries and the turnover that comes with them. We chose to extend the team rather than replace it because the director already owned the estate well; what was missing was reach and depth, and that's precisely what a senior-led partner adds.

The approach

What intSignal did

Co-managed IT working under the client's IT director, plus national support. Network as a Service with SD-WAN and FWaaS across 120+ locations. Cybersecurity and compliance: SIEM, XDR, EDR, password manager, dark-web monitoring. Microsoft 365 and virtual CISO.

Why it works

One vendor, accountable

The bigger lesson underneath the numbers is about accountability. Spread the same scope across a dozen small vendors — one for the firewall, one for email, one for the phones, one for each site — and every incident becomes a conference call where nobody is responsible and everybody points sideways. Consolidating to one provider ends that: a single team owns the outcome, a single number gets called, and the systems are unified rather than bolted together at the seams. It also changes the incentives. A large managed engagement is a serious relationship for the provider — real revenue, real stakes — so the provider has every reason to keep it healthy, where a small vendor with a small contract simply doesn't. You stop being one of a hundred accounts spread thin and become the account that matters.

Built to hold up

Resilience and risk

Round-the-clock coverage is a staffing problem, not a competence one: genuine 24/7 requires four or more analysts on rotation before a single engineer is hired. That arrives with the engagement. A single specialist per domain is a single point of failure — leave, illness and turnover all become outages. A senior-led team brings its own bench and escalation path. Standardized network and security posture across every location, with SIEM, XDR and EDR detection across a distributed footprint. Dark-web monitoring and password management to close credential exposure. Virtual CISO gives the board a defensible risk picture and a plan, at the fraction of the role the business actually needs.

What changed

DimensionBeforeAfter intSignal
Security leadershipNo spare capacityVirtual CISO + board reporting
DetectionInconsistent, site by site24/7 SIEM/XDR/EDR, all sites
Network postureDrifted apart over timeStandardised across 120+ sites
After-hours coverBusiness hours onlyRound-the-clock

Outcome

The result

The engagement standardised network and security across every location, put SIEM, XDR and EDR detection over the whole footprint, and gave the board security leadership through a virtual CISO. Reconstructed from 18 months of production data, the delivered work equates to more than five full-time specialist roles — capability the company holds well below the cost of hiring it, and with round-the-clock coverage an in-house team of that size could not provide.

Roughly 40–50% below a comparable managed-service bundle, where the support line is quoted first and MDR/SOC, virtual CISO and network management arrive as separate items. 5.25 FTE of specialist hiring avoided: service desk across 120+ sites, a network engineer for SD-WAN and NaaS, a security analyst for SIEM/XDR/EDR, a Microsoft 365 and identity administrator, and security leadership. Measured rather than asserted — 18 months of tickets, call logs, dispatch records and SOC/NOC telemetry reconstruct to roughly 150 hours/month of delivered engineering work. Specialist depth is bought in the fraction actually required. A quarter of a CISO and a third of a network architect are not roles anyone can hire, and enterprise licensing for SIEM, EDR, password management and dark-web monitoring lands materially below single-tenant pricing. NaaS removed the purchase, installation and refresh cycle for network equipment at 120+ sites, and SD-WAN replaced premium circuits with resilient commodity broadband.

How these figures were derived

Effort and outcomes are reconstructed from production systems of record — ticket histories, call detail records, dispatch and SOC/NOC telemetry — read end to end rather than sampled. Cost comparisons are indexed to a baseline, never a fee or rate. Where a figure is modelled rather than measured it is labelled as such, and the model is documented and available to defend on request.

Who was this for?

Customer

Shown on request. Some engagements remain confidential by contract.

Facing something similar?

Tell us your environment and priorities — we return scope, ownership, and a plan.