ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX · Serving TX, AR, LA, OK & KS
(737) 325-2520

Budgeting for Law Firm IT: Where the Money Should Go

A practical framework for budgeting law firm IT: running costs, security, hardware cycles, projects and reserves, with questions to ask before approving spend.

3 min readBy Counsel Cyber Team

Technology budgets at small and mid-size law firms are often set by looking at last year's number and adding a bit. That approach tends to underfund the unglamorous items, such as security tools and hardware replacement, until something breaks. A more useful way is to divide spending into categories, understand what each buys, and plan for the lumpy costs ahead of time.

This post offers a framework rather than specific dollar figures, since costs vary widely with firm size, practice area and location.

Step 1: Separate the categories

Run: keeping the lights on

These are recurring costs: managed IT or help desk fees, licenses for Microsoft 365, practice management, document management, phones and internet service. They scale with headcount and are fairly predictable.

Protect: security and resilience

Security tools and services include email filtering, endpoint detection and response, 24/7 monitoring, MFA, backup and disaster recovery, security awareness training, and periodic testing or assessments. Many firms understate this line because it is spread across invoices.

Replace: hardware lifecycle

Laptops, desktops, servers, firewalls, switches and access points wear out and fall out of vendor support. Spreading replacement across years avoids a painful single-year spike. A common practice is to plan a multi-year cycle for workstations and to treat unsupported devices as security risks.

Grow: projects

Migrations, new office build-outs, software rollouts and automation initiatives are one-time or periodic. Keep a list of candidate projects and rank them by value and risk reduction.

Reserve: the unexpected

Set aside a contingency for emergencies, such as a failed device, an urgent security fix or an incident deductible.

Step 2: Build a technology inventory

You cannot budget what you have not listed. Record devices with purchase dates and warranty status, software with renewal dates and seat counts, and contracts with terms and notice periods. Your IT provider should be able to supply this.

Step 3: Look for waste

  • Unused licenses. Departed staff and unused add-ons keep billing.
  • Overlapping tools. Several products doing the same job, perhaps after a vendor bundle changed.
  • Shadow IT. Subscriptions bought on credit cards by individuals.
  • Redundant vendors and contracts that auto-renewed unnoticed.

Redirect savings to underfunded priorities.

Step 4: Fund security deliberately

Rather than a flat percentage, work from risk. Ask what the firm's most likely and most damaging events are, such as ransomware, wire fraud and account takeover, and whether controls are in place for each. Insurers and clients increasingly expect baseline controls like MFA, monitoring, tested backups and training. The cost of those controls is usually modest compared with the cost of an incident, including downtime, notification and reputational damage.

Step 5: Plan hardware replacement

Create a schedule from the inventory: which devices reach end of life in each of the next three to five years, and what that costs. Check vendor support lifecycles for operating systems and firewalls. Running unsupported systems may also affect insurance and client questionnaires.

Step 6: Treat cloud costs as variable

Per-user subscriptions rise with headcount and with feature tiers. Review renewals ahead of time, check whether add-on licenses such as AI assistants justify their price, and ask for annual terms only where the discount is meaningful.

Step 7: Compare options fairly

When evaluating a new tool or provider, look at total cost of ownership: licenses, implementation, training, ongoing management and the cost of leaving. The lowest sticker price is rarely the lowest total.

Step 8: Connect to the firm's strategy

Budget conversations go better when tied to outcomes: faster intake, fewer interruptions, stronger client trust, lower insurance risk. Present a short plan to partners with options and consequences, such as what happens if a project is deferred.

Questions to ask before approving spend

  1. What risk or inefficiency does this address?
  2. What happens if we do nothing?
  3. What is the full multi-year cost?
  4. Who will own it after launch?
  5. How will we know it worked?

Review quarterly

Compare actual spending to plan, adjust as headcount changes and update the project list. An annual technology review with your IT provider, held before the firm's budget cycle, keeps surprises low.

Counsel Cyber builds technology roadmaps and budgets with law firms, including inventory, security gap analysis and a multi-year replacement plan. If you are preparing next year's numbers, we can help you structure them.