ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Help Desk Metrics a Law Firm Should Ask Its IT Provider to Report

Learn which help desk and security metrics a managing partner should request from an IT provider, and how to read them without getting lost in jargon.

3 min readBy Counsel Cyber Team

Many firms pay a managed IT provider every month and receive little visibility in return. The help desk is busy, tickets get closed, and nobody outside the IT relationship can say whether service is good. Asking for a short, regular report changes that. The right metrics let a managing partner or administrator judge responsiveness, spot recurring problems and confirm that security work is actually being done.

This guide lists the measures worth requesting and explains how to interpret each.

Service responsiveness

Time to first response

How long between a user submitting a ticket and a technician acknowledging it? Look at the average and at the slowest tickets. A good average can hide a few that sat for days.

Time to resolution

How long until the problem is actually fixed? Break this down by priority. A locked-out attorney before a hearing should be resolved faster than a request for a new monitor. Compare actual results against the targets in your agreement.

First-contact resolution

What share of tickets are solved on the first interaction? A higher number usually means users are not bounced around, though very complex issues will legitimately take longer.

Reopened tickets

Tickets reopened because the fix did not last suggest rushed or incomplete work. A rising count deserves a conversation.

Backlog and aging

How many tickets are open and how old are the oldest? A steadily growing backlog suggests understaffing.

User experience

Satisfaction ratings

Many ticketing systems send a short survey after closure. Ask for the scores and, more importantly, read the comments on low-rated tickets.

Top recurring issues

If the same printer, VPN or login problem produces dozens of tickets, that is a root-cause problem worth a project, not more tickets.

Tickets by person or department

Heavy requesters may need training or better equipment. Be careful to use this to help staff, not to blame them.

Security and maintenance metrics

Responsiveness is only half of managed IT. Ask also for:

  1. Patch compliance. What share of devices has the latest critical updates, and how many are overdue?
  2. Endpoint protection coverage. How many devices run the protection agent, and are any offline or unprotected?
  3. MFA coverage. What share of accounts has MFA enforced, and which do not?
  4. Backup success and test results. Were jobs successful, were any missed, and when was the last restore test?
  5. Security alerts and response. How many alerts were raised, how many were real, and how long did response take?
  6. Phishing simulation and training results. Click rates, reporting rates and completion.
  7. Privileged accounts. Who holds administrator rights, and has the list changed?
  8. End-of-life systems. Which devices or software are no longer supported by their vendors?

NIST Cybersecurity Framework 2.0 can be a helpful mental model here, since it groups activities into functions such as identify, protect, detect, respond and recover. A good report touches each.

Asset and lifecycle information

  • An up-to-date inventory of computers, servers, network devices and licenses
  • Warranty and replacement dates
  • Software license counts compared to actual use
  • A forecast of upcoming hardware replacement costs

This turns the annual technology budget from a surprise into a plan.

Financial transparency

Ask for a summary of billed hours or projects outside the flat fee, and compare against the agreement. Unexpected charges should be explained.

How to read the report

  • Look at trends over several months, not a single data point.
  • Ask what changed when a number moves sharply.
  • Focus on a handful of metrics rather than dozens.
  • Pay attention to what is missing. If the provider cannot report on MFA coverage or backup tests, they may not be tracking them.

Set up a regular meeting

A monthly dashboard and a quarterly strategic conversation work well for most small and mid-size firms. The quarterly meeting should address risks, upcoming projects, budgets and any incidents, and it should involve a partner who can make decisions.

What good looks like

A provider with healthy service will give you concise reports, own up to misses, show improvement over time and connect their work to your firm's risks. A provider that resists reporting, or only offers generic numbers, may be concealing weaknesses.

Link to your duties

Model Rule 5.3 concerns supervision of nonlawyer assistance, which includes outside providers. Regular reporting is one practical way to oversee the people who hold the keys to your systems. Confirm specifics with your state bar.

Counsel Cyber provides law firms with plain-English monthly reports covering service and security measures, and we are happy to show a sample or review the reports you receive today.