From Outsourcing to Ownership
For the first three parts of this series, we looked backward.
We examined why American companies outsourced technology work to India, what that transition did to parts of the American IT career, and why India itself was never the real problem. Indian engineers and technology companies responded to enormous global demand. The deeper issue was an outsourcing model that increasingly separated the people who understood a business from the people who operated its technology.
Now we need to look forward. What if the American IT manager did not spend the next decade trying to recover the career structure that existed before outsourcing?
What if that IT manager became the MSP? And what if the opportunity were even larger? What if accountants, insurance professionals, attorneys, consultants, cybersecurity specialists, fractional executives, and other trusted advisers could participate in the same ecosystem—not by becoming network engineers, but by helping businesses understand and govern technology risk? The next chapter of American IT may not simply be about bringing jobs back. It may be about creating owners.
The IT Manager Already Has the Hard Part
Consider an experienced IT manager. Over 15 or 20 years, that person may have managed networks, cloud migrations, Microsoft 365, cybersecurity incidents, vendors, budgets, employees, backups, compliance requests, executive expectations, and countless emergencies.
But the most valuable thing they learned may not be technical. They learned how technology intersects with business. They know which systems actually matter. They understand the consequences when technology fails. They know how executives think about budgets, how employees use systems, how vendors behave, and how technical decisions affect operations. That experience has market value.
The U.S. Bureau of Labor Statistics reported a median annual wage of $175,140 for computer and information systems managers in May 2025 and projects employment in the occupation to grow 16% from 2025 through 2035.
The expertise is not disappearing. The question is who captures its value. Traditionally, the answer has been the employer. Perhaps another possibility deserves consideration.
What If Experience Became Equity?
Imagine an experienced IT manager deciding to start an MSP. Then comes the list. Remote monitoring. Endpoint protection. Backup. Email security. Ticketing. Documentation. Billing. Contracts. Insurance. Compliance capabilities. Vendor relationships. Technical support. Sales. Marketing. Possibly a security operations center. And while assembling all of that, somehow they also need customers. The obstacle is not necessarily technical ability. We are asking one person to recreate an entire technology company before effectively selling the first service. So perhaps we are asking the wrong question.
Instead of: How does an IT manager build an MSP?
Ask: What if much of the infrastructure of the MSP already existed?
The professional could bring what may be the hardest thing to manufacture at scale: the customer relationship.
Behind that relationship could sit a service-delivery platform providing technology, cybersecurity capabilities, specialists, automation, monitoring, documentation, support, and other infrastructure. The professional owns the conversation. The platform helps power the delivery. But how does that professional start the conversation? That is where Cyber Governance enters the model.
Stop Starting With Technology
For decades, much of the IT industry has started with products. Do you need a firewall? Endpoint protection? Backup? Microsoft 365? Vulnerability scanning? Those may all be legitimate needs. But they are not necessarily the first questions a business owner should answer. The first questions are different.
What does your company depend upon? What information must you protect? Who can access it? What happens if critical systems become unavailable? What requirements are customers placing on you? What does your cyber insurer expect? What regulatory or contractual obligations apply? Who is accountable for cybersecurity? Which risks has management accepted—and which risks does management not even know exist? Those are governance questions. And governance changes the conversation.
When NIST released Cybersecurity Framework 2.0, it added Govern as a sixth core function alongside Identify, Protect, Detect, Respond, and Recover. The change emphasized that cybersecurity belongs alongside enterprise risk, leadership, policy, legal obligations, and organizational accountability. Cybersecurity is no longer simply the responsibility of whoever configures the firewall. That creates an opportunity.
Millions of Businesses Need the Conversation
According to the SBA Office of Advocacy's 2025 profile, the United States had approximately 36.2 million small businesses, representing 99.9% of U.S. businesses and employing approximately 62.3 million people. Most cannot employ a CIO, CISO, cybersecurity department, compliance team, cloud team, and internal IT organization. Yet being small does not make their technology dependencies disappear. Neither does it make cyber risk disappear.
The FBI's 2025 Internet Crime Report recorded more than one million complaints of suspected internet crime and reported losses exceeding $20 billion. Verizon's 2025 Data Breach Investigations Report found ransomware present in 44% of the breaches it reviewed and reported that ransomware was disproportionately represented among breaches affecting smaller organizations.
Small businesses increasingly depend on sophisticated technology while facing sophisticated threats and growing contractual, insurance, compliance, and governance expectations. Someone needs to help close that gap. Historically, we assumed that someone must be an MSP. Perhaps that definition is too narrow.
The Trusted Professional Already Has the Meeting
Think about the people surrounding a small-business owner. The accountant understands the company's finances. The attorney understands contracts and legal obligations. The insurance adviser understands risk transfer. The business consultant understands operations. The IT provider understands technology. The compliance professional understands regulatory requirements. The fractional CFO understands financial controls. These professionals possess something technology companies spend enormous amounts trying to acquire: Trust.
They also have access. The accountant does not have to cold-call the owner. The owner already calls the accountant. The attorney does not need to manufacture a reason for a meeting. The insurance adviser does not need to explain why risk matters. This suggests an entirely different way of thinking about the distribution of technology and cybersecurity services.
They Don't Need to Become Cybersecurity Engineers
This distinction is critical. The CPA should not configure firewalls. The attorney should not operate endpoint detection systems. The insurance professional should not run a SOC. The business consultant should not troubleshoot printers. Their professional boundaries and areas of competence remain important. Their role is different. They can recognize when a governance conversation needs to happen.
An accountant may encounter information-security obligations. An attorney may encounter cybersecurity and privacy requirements in contracts. An insurance professional may discover missing controls during a cyber-policy discussion. A consultant may identify technology dependencies threatening business continuity.
An MSP may discover that technical problems actually require management decisions. Each sees a different piece. Cyber Governance can provide a common framework connecting those pieces.
Cyber Governance Becomes the Front Door
This is the concept behind the CyberGovernance Portal model we are developing at netPulz. Instead of asking: What product can I sell this company? The professional begins with: What does this organization need to govern?
That conversation identifies requirements. Requirements expose gaps. Gaps create remediation. Remediation creates projects. Projects can create managed services. Managed services create recurring relationships. The progression becomes:
Trusted Professional → Cyber Governance → Requirements → Gaps → Solutions → Managed Services → Recurring Revenue
That is fundamentally different from selling another cybersecurity product.
The IT Manager Becomes the First Entrepreneur
Now return to the American IT manager. Imagine someone who spent 20 years running corporate technology. Instead of competing for another director position, that person could potentially advise several small and midsize businesses. Not as an employee. As an owner.
Cyber Governance becomes the entry point. Behind the adviser can sit an ecosystem providing managed IT, cybersecurity, cloud services, compliance assistance, monitoring, specialists, remediation resources, and other capabilities. The IT manager does not need 30 employees on day one.
They need customers. They need credibility. They need a repeatable methodology. They need delivery infrastructure. And they need to be able to tell a prospective client: "Let's determine what your business actually needs before we start selling you technology."
But Why Stop With the IT Manager?
Now the model becomes much larger. Suppose a CPA introduces CyberGovernance to business clients. An insurance adviser introduces it during risk discussions. A fractional CFO uses it while evaluating operational exposure. An attorney identifies governance deficiencies while reviewing contracts. A cybersecurity consultant uses it as the framework for an engagement.
A retired CIO uses it to build a fractional technology practice. An existing MSP uses it to move conversations from the help desk to executive management. Different professions. Different expertise. Different relationships.
One common problem: Businesses need help understanding and governing technology risk.
The professional does not need to deliver every service discovered through that process. That is what the ecosystem is for.
From Reseller Channel to Professional Ecosystem
Technology companies traditionally organize channels around products:
Vendor → Distributor → Reseller → Customer.
Cyber Governance suggests another possibility. Organize the ecosystem around the customer. Around that customer might sit an IT adviser, accountant, attorney, insurance professional, compliance specialist, cybersecurity professional, fractional executive, and MSP. Each sees the organization from a different perspective. Cyber Governance becomes the common table.
Consider a 75-person manufacturer. A governance review might discover that the company lacks an incident-response plan, faces new cyber-insurance requirements, needs to answer a customer's security questionnaire, has weaknesses in Microsoft 365, has never seriously tested recovery, gives vendors excessive access, and has never clearly assigned cybersecurity accountability.
Traditionally, those issues might be discovered separately over several years by several professionals. Governance connects them. The result is something more useful than another product proposal.
A roadmap. And a roadmap can create years of meaningful work.
Local Knowledge Becomes Valuable Again
Outsourcing demonstrated the economic value of distance. Governance demonstrates the value of proximity—not necessarily physical proximity, but business proximity.
Knowing the owner matters. Knowing the industry matters. Understanding which application cannot be offline for four hours matters. Knowing that one customer represents a large portion of revenue matters. Understanding how the company actually operates matters. A remote engineer can be extraordinarily capable. But technical capability and business intimacy are different assets. The future model can use both.
Global talent can provide specialized expertise. Automation can perform repetitive work. AI can accelerate analysis. Security operations can happen remotely. Cloud platforms can centralize infrastructure. The trusted professional remains close to the customer. That is not a rejection of globalization. It is a different division of labor.
Stop Trying to Recreate the Old IT Department
The outsourcing debate often focuses on restoration. How do we bring the jobs back? Some may return. Others will not. Technology does not move backward. AI, cloud computing, automation, global talent, remote operations, and managed services will continue changing how work gets done. Trying to recreate the corporate IT department of 1998 is not a strategy for the next decade.
A more interesting question is: What businesses can experienced professionals build because technology delivery itself has become distributed? The same forces that allowed corporations to outsource technology can allow an individual entrepreneur to access capabilities that once required a large company. The corporation used outsourcing to gain scale. The entrepreneur can use shared infrastructure to gain independence.
From Employee to Owner
Imagine the IT manager who survived reorganizations, trained offshore teams, migrated systems to the cloud, handled cybersecurity incidents, absorbed budget cuts, and adapted repeatedly. Perhaps the conclusion of that career does not have to be another corporate job search. Perhaps twenty years of experience can become the foundation of a company.
Five customers. Then ten. Then twenty. Recurring revenue. Specialization. Reputation.
Eventually employees—or perhaps an increasingly capable network of partners and platforms. Something the professional owns. And the opportunity extends beyond IT.
America has accountants, consultants, cybersecurity professionals, insurance advisers, attorneys, former executives, MSPs, and industry specialists serving millions of businesses that increasingly need help navigating technology risk. Those professionals do not all need to become technology companies. They need a way to participate in the conversation. Cyber Governance can become that bridge.
Turning the Outsourcing Model Inside Out
There is an interesting symmetry here. For decades, large corporations asked: How much of our technology organization can we externalize? That question helped create the global outsourcing industry. Now the independent professional can ask: How much of the infrastructure required to operate my own technology business can I externalize?
The corporation outsourced infrastructure to gain scale. The entrepreneur can use shared infrastructure to gain independence. The machinery that once helped consolidate technology work into enormous providers may now help distribute entrepreneurship outward. This series began by asking what outsourcing did to American IT. Jobs were displaced. Career ladders changed. Technology work became globally distributed. History does not owe us the restoration of the world that existed before those changes.
The better question is what we build next.
Outsourcing taught us that technology work could be separated from the company.
The next chapter may be discovering that technology entrepreneurship can be separated from the infrastructure required to deliver it.
The American IT manager becoming the MSP is only the beginning. The larger opportunity is enabling trusted professionals to become the front door to CyberGovernance, technology services, and long-term business relationships. For thirty years, we talked about where the work went.
Perhaps it is time to talk about who can own the work next.
________________________________________
Coming Next — Part 5: The Independence: The One-Person MSP Can Become a Real Business
The opportunity is one thing. Building the business is another. In Part 5, we move from theory to economics: customers, recurring revenue, margins, delivery, specialization, scale, and ultimately business value. How does one professional gain the capabilities of a much larger organization without building one from scratch?And can decades of IT experience be converted not simply into another paycheck—but into an asset the professional actually owns? That is where we go next.

