What Co-Managed IT Actually Means for Piqua Businesses
Co-managed IT is a working arrangement where COMNEXIA operates alongside your existing internal IT staff. Your team keeps control of the systems and relationships they know best. COMNEXIA fills the gaps: after-hours coverage, security tooling your in-house person may not have licensed, and structured processes that keep audit trails clean. For a Piqua manufacturer, a Miami Valley auto group, or a professional services firm that has one or two IT employees but no security engineer on staff, this model closes real exposure without replacing the people already doing good work.
This is not a handoff. It is a defined split of responsibilities, documented in writing at onboarding, so nothing falls between the cracks.
The Security Layer Your Internal IT Team Likely Does Not Have
COMNEXIA leads every co-managed engagement with endpoint security before touching anything else. That means deploying SentinelOne EDR across managed endpoints, with behavioral AI detection running continuously, not just at scheduled scan windows. Alongside that, we configure Microsoft Entra ID conditional access policies so that a technician logging into your ERP from an unmanaged personal device triggers a block or step-up MFA, not a silent pass-through.
Specific controls we implement and document:
- SentinelOne EDR installed and reporting to a centralized console your IT staff can view with read access
- Microsoft Entra ID conditional access policies scoped by user risk, sign-in risk, and device compliance state
- DNS-layer filtering through Cisco Umbrella to block C2 callback traffic before it reaches the endpoint
- Patch management via NinjaOne, with separate patch rings for servers and workstations and a documented rollback procedure for failed updates
Your internal IT staff gets visibility into all of it. We share the dashboard, not just a monthly summary.
How This Works for Miami Valley Auto Dealerships
Auto dealers running CDK Global, Reynolds and Reynolds, or Dealertrack face a compliance clock. The FTC Safeguards Rule (16 CFR Part 314), as updated and in effect since June 2023, requires dealerships to maintain a written information security program with specific technical controls: encryption of customer data in transit and at rest, multi-factor authentication for systems containing customer financial information, continuous monitoring, and annual penetration testing or vulnerability assessments.
Most dealership IT setups in the Piqua and greater Dayton area are one person managing DMS integrations, the phone system, and every workstation ticket simultaneously. That person is not running a vulnerability scanner or reviewing Entra ID sign-in logs at 11 PM. COMNEXIA handles those specific Safeguards Rule technical requirements under the co-managed model:
- Documenting the access control inventory required under the Rule’s Section 314.4(e)
- Running quarterly vulnerability scans against DMS-connected systems using Tenable or a comparable credentialed scanner
- Configuring encryption for customer records stored in network shares or synced to Microsoft 365 using Microsoft Purview Information Protection sensitivity labels
- Providing written security event reports your dealer principal can show a Safeguards Rule auditor
Your internal IT contact keeps handling CDK or Reynolds day-to-day. COMNEXIA owns the compliance controls.
What the Onboarding Process Looks Like
COMNEXIA uses a documented onboarding checklist, not a verbal walkthrough. Within the first two weeks of a co-managed engagement, we complete:
- Asset discovery across all endpoints using NinjaOne’s agent deployment, producing a named device inventory with OS versions, patch status, and last-seen timestamps
- Review of existing Microsoft 365 tenant configuration, including legacy authentication protocol status (legacy auth should be blocked), admin account MFA enforcement, and mailbox audit logging
- Establishment of a shared ticketing queue in our help-desk platform so both COMNEXIA engineers and your internal staff log work in one place, eliminating the “I thought you handled that” problem
- A written RACI matrix (Responsible, Accountable, Consulted, Informed) signed by both parties defining who owns patching, who owns security alerts, and who handles end-user password resets
Nothing in the first 90 days requires a truck roll to Piqua. Discovery, configuration, and policy deployment happen remotely.
Monthly Reporting Your Leadership Can Read
Every month, co-managed clients receive a report covering patch compliance percentage by device group, SentinelOne alert volume and disposition, Entra ID risky sign-in events reviewed, and open versus closed help-desk tickets by category. This is not a marketing document. It is the record your operations manager or dealer principal needs to verify that contracted controls are actually running.
Talk to COMNEXIA About Co-Managed IT in Piqua
COMNEXIA has been delivering managed IT and security services for 35 years, with deep experience supporting auto dealerships navigating DMS integrations and FTC Safeguards Rule requirements. If your Piqua-area business has internal IT staff but needs security engineering, compliance documentation, or after-hours coverage built around them rather than replacing them, call (877) 600-6550 to schedule a scoped discovery call.