Fully Managed or DIY? Stop and Consider the Third Way
- Tim Sullivan
Why the outsourcing pendulum is moving towards co-managed enterprise networks
Enterprises shouldn’t have to choose between control and capability.
For decades, enterprise IT wrestled with whether to build and operate capabilities internally or outsource.
Outsourcing promised scale, expertise and simplicity. Insourcing promised control, visibility and responsiveness. As technology, economics and management thinking changed, the pendulum swung between the two.
Enterprise networking followed the same pattern. When we founded Coevolve, we argued that the question itself was outdated.
Modern networking and security technologies have fundamentally changed what enterprises and their providers can see, control and automate. The choice no longer needs to be between handing over the keys or doing everything yourself.
The more pertinent question for MNCs is: What should the enterprise own, and what should its provider operate?
Why enterprises historically outsourced network operations
As the first swing towards outsourcing gathered momentum, many multinational enterprises effectively adopted a “give us the keys” approach. Simply because outsourcing was the most practical model while they focused on their core business.
Building equivalent capabilities internally required specialist expertise, global operational coverage and relationships with providers across numerous countries. A large global telco could offer all of that within a single managed service.
The trade-off was control.
Customers accepted limited visibility, change-request queues and provider dependencies as part of the arrangement. If something needed changing, you raised a ticket. If something broke, you called the provider.
That model solved problems for a time but it was based on making compromises. Those compromises became more pronounced in the cloud era (from 2010 on). The mistake is assuming that the same division of responsibilities remains optimal today.
The problem isn’t that fully managed networking failed. It’s that the technology moved on faster than the operating model.
Software-defined networks brought network management back in house
Over the past decade, the pendulum has swung back as enterprise networking became software-defined. Infrastructure became programmable. Policies could be changed centrally. APIs made integration and automation possible. Visibility improved dramatically.
As a consequence, enterprise IT teams changed too. They became more sophisticated technology buyers and operators. Understandably, many wanted greater control. So, the pendulum began swinging back.
But DIY creates its own challenges.
Having the technical ability to operate something doesn’t necessarily mean doing so is the best use of scarce enterprise talent. Someone needs to monitor environments around the clock, investigate alerts, coordinate vendors, implement changes and respond when something fails at 2am.
For MNCs those responsibilities multiply across technologies, countries and time zones. The organisation seemingly gains control, but it can also inherit considerable operational complexity.
Why traditional managed network services models are obsolete
The technology changed. Why hasn’t the operating model? This is the contradiction I find interesting. Almost every layer of enterprise networking has changed.
Hardware became software-defined. Private telco circuits gave way to internet and cloud connectivity. Command-line configuration moved towards APIs and orchestration. Networking and security converged. Basic monitoring evolved to observability, analytics and automation.
Yet frequently enterprise IT and procurement teams framed the operating-model decision in remarkably binary terms, just like the prior decades, asking, “Do we manage it ourselves, or do we outsource it?”
Essentially enterprises inherited these models designed for an earlier era.
Modern technology makes that distinction increasingly unnecessary as today’s platforms can provide clients and managed service providers with access to the same environment. Permissions can be granular. Guardrails installed and changes automated. APIs allow different systems and organisations to work together.
The customer no longer needs to sit on the outside of a “black box”. Indeed, I wrote of this dynamic in an article in 2017, three years into the Coevolve mission.
Now the opportunity for a different division of labour is a tangible, well-defined path.
The third model: What is co-management
A strong co-managed operating model deliberately allocates responsibilities according to who is best positioned to perform them. The enterprise might retain ownership of architecture principles, security policy, business priorities, risk decisions and strategic change.
The provider might take responsibility for 24×7 monitoring, routine changes, incident response, carrier and vendor coordination, platform expertise, lifecycle management and operational automation.
Other areas – optimisation, major changes, resilience planning and architecture evolution and governance – are better performed collaboratively.
The precise dividing line will differ by organisation, technology environment and operating footprint. The point is that the boundary is designed rather than inherited. Defined on the back on vast real world experience. Co-management isn’t splitting the workload 50:50, but rather allocating each responsibility to the party best equipped to perform it.
That allows the enterprise to retain control where its business context matters while accessing specialist capabilities where scale and expertise matter. The objective isn’t outsourcing more. Nor is it outsourcing less. It is designing a better operating model.
How AI is changing enterprise network management
AI adds momentum to this shift. Many operational activities performed manually today shouldn’t simply move between an enterprise and its provider. They should in fact disappear.
Alert triage, anomaly detection, configuration validation, event correlation, routine remediation, reporting and analysis are all becoming increasingly automatable.
All of this has significant implications for managed services. Historically, managed service providers often created value by assembling teams of people to perform operational tasks at scale. Increasingly, value should come from combining engineering expertise with data, software, automation and accumulated operational knowledge.
That changes the economics, but more importantly it changes what each party should be doing. Enterprise teams should spend more time on decisions requiring business context, risk judgement and strategic thinking. Providers should increasingly automate the repetitive operational work and apply specialist expertise to the exceptions that require it. My co-founder explored this shift in greater detail in a previous article in our Future of Global Enterprise Networks series.
There is a simple principle here: Automate the operational. Preserve human control of the consequential.
How should CIOs evaluate network operational models
Perhaps we therefore need to change the question. Instead of asking: “Should we outsource our network?” CIOs should ask:
- Where should control sit?
- Which decisions genuinely require internal business context and judgement?
- Which activities benefit from specialist expertise, scale and 24×7 capability?
- Which operational activities shouldn’t be performed by either party because they can now be automated?
- Where would shared visibility and collaboration produce a better outcome than either organisation working independently?
Those questions lead to a different conversation from the traditional outsourcing debate. They start with the outcome and work backwards towards the operating model required to deliver it.
The future of enterprise network management
In the first article in this series, I argued that competitive advantage in enterprise networking has moved away from infrastructure ownership towards operating model, software, automation and outcomes.
That shift has implications for how enterprises choose to operate network and security in the future. The evolution isn’t simply from outsourced to DIY. It is towards something more nuanced: intelligently shared and increasingly automated.
The risk MNCs need to avoid is incremental optimisation. Renegotiating connectivity contracts or improving the terms of an inherited outsourcing model may deliver savings, but it doesn’t answer the more important question: is the underlying model still right?
CIOs, IT teams and procurement should challenge the architecture, sourcing model and division of responsibilities rather than simply replicating the RFPs of the last decade. Engage new voices in your deliberations and start with the outcomes in mind, not the inherited model.
Enterprises shouldn’t have to choose between control and capability. The optimal operating model must give them both.