If you manage a law firm's IT relationship, you probably receive some kind of monthly report. It may list the number of tickets opened and closed, a few charts, and a note that everything is "on track." Reports like this are easy to produce and hard to act on. The right metrics, by contrast, tell you whether your attorneys and staff are being helped, whether problems are shrinking, and whether you are getting what you pay for.
Here are the measurements worth asking for, how to interpret them, and the traps to avoid.
Metrics that matter
First response time
This measures how long it takes from the moment a person submits a request until a human begins working on it. Attorneys feel this one acutely, because the silent period is when frustration builds. Ask for the median and the longest wait, not just an average, since averages hide the worst experiences.
Time to resolution
Track how long it takes to close tickets, broken down by priority. A password reset and a failed server do not belong in the same average. Ask for resolution times by category so you can see where delays cluster.
First-contact resolution
What share of issues are solved on the first call or chat? A higher rate usually signals a capable help desk and good documentation. A low rate may mean frequent handoffs, which frustrate users and consume billable time.
Repeat tickets and root causes
If the same user, device or application generates the same ticket over and over, the real problem has not been fixed. Ask your provider to identify the top five recurring issues each quarter and propose permanent fixes. This metric turns the help desk from a repair service into an improvement engine.
Backlog age
Count how many tickets have been open for more than a set number of days. A small, stable backlog is normal. A growing one suggests understaffing or tickets waiting on decisions that no one owns.
User satisfaction
Short surveys sent after a ticket closes, with one question and an optional comment, give you direct feedback. Pay particular attention to written comments from attorneys. A rating alone is less informative than a sentence about what went wrong.
Onboarding and offboarding speed
For a law firm, these are critical processes. Track how long it takes to give a new attorney a working laptop, accounts and access to the right systems, and how quickly access is removed when someone leaves. Delays in onboarding cost productive time. Delays in offboarding are a security risk.
Security-related metrics to ask for
Help desk reporting should not stop at convenience. Ask for these as well:
- Patch compliance: the share of devices fully updated, with a list of exceptions.
- MFA coverage: the number of accounts without MFA, ideally zero.
- Open security alerts: how many were investigated, how quickly, and what was done.
- Backup success and test results: not just job completion, but restore tests.
- Phishing reports: how many suspicious emails staff reported and how fast they were reviewed.
These numbers show whether the provider is doing the preventive work that the monthly fee is supposed to cover.
Reading the numbers wisely
Beware of vanity metrics
A high count of closed tickets looks impressive, but it may only reflect a noisy environment. Fewer tickets over time is often a better sign than more.
Segment by group
Look at results for litigation attorneys during trial weeks, for the accounting team near month-end, and for remote users. A good overall average may hide poor service to the people with the tightest deadlines.
Compare to the agreement
Your service level agreement defines targets. Ask for results against those targets, not against numbers the provider chose for the report.
Combine with conversation
Metrics do not replace talking to your people. A ten-minute chat with a few attorneys each quarter will often tell you more than a dashboard.
A simple monthly review format
- One page of metrics, with trend lines compared to the previous quarter.
- The top recurring problems and the plan to fix each one.
- Security metrics summary.
- Upcoming projects, renewals and risks.
- A short list of decisions needed from the firm.
Keep it short enough that busy partners will read it.
Our approach
Counsel Cyber reports on both service and security measures for the law firms we support, and we are happy to explain every number we show. If your current reports leave you unsure whether you are getting good service, we can review a sample report with you and suggest what to ask for next.