ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Help Desk Reports Worth Reading: Metrics for Law Firm IT

Which IT metrics deserve a managing partner's attention? A short list of help desk and security measures that show whether your provider is delivering.

3 min readBy Counsel Cyber Team

Many firms receive a monthly IT report that no one opens. It is a stack of ticket counts and charts that look busy, and it tells you very little about whether the technology is healthy or the firm is safe. A good report is short, honest and tied to decisions. A managing partner or administrator should be able to read it in five minutes and know whether to worry.

This guide lists metrics worth asking for, what each tells you and how to read them without getting lost in numbers. None of these require specialized knowledge to understand.

Service metrics

Response time and resolution time

Response time is how long before someone begins work on a ticket. Resolution time is how long until it is solved. Ask for both, by priority level. Averages can hide problems, so request the longest times as well. One ticket that took three weeks tells you more than a comfortable average.

First-contact resolution

The share of requests solved on the first interaction. A high figure suggests competent front-line support. A low one may mean tickets bounce between people.

Ticket volume and trends

Rising volume could mean growth, a failing system or a recurring problem. Ask your provider to identify the top five repeat issues and what is being done about them. Fixing root causes should reduce volume over time.

User satisfaction

Short post-ticket surveys give a qualitative signal. Ask for the comments, not just the score.

After-hours performance

Law firms have urgent needs on weekends and before filing deadlines. Ask how many after-hours requests occurred and how quickly they were handled.

Security metrics

These matter even more for a law firm than ticket speed.

  1. MFA coverage: the percentage of accounts with MFA enforced, and a list of exceptions with reasons.
  2. Patch status: how many devices are missing critical updates and for how long.
  3. Endpoint protection coverage: the number of devices with active, reporting security agents compared with the total.
  4. Backup success and restore tests: the success rate of recent backups and the date and result of the last restore test.
  5. Phishing and training: training completion rate, simulation results and report rate.
  6. Security alerts and incidents: what was detected, what action was taken and how long it took.
  7. Privileged accounts: the number of administrator accounts and any changes.
  8. End-of-life systems: devices or software no longer receiving vendor security updates.

Asset and lifecycle metrics

  • Hardware age: devices approaching replacement, which feeds your budget.
  • License usage: paid licenses with no active user, a source of savings and a sign of orphaned accounts.
  • Warranty and support dates for key equipment.

Strategic items

A report should also look ahead.

  • Upcoming renewals and expirations.
  • Recommended projects with estimated costs and risk reduction.
  • Open risks that the firm has accepted, with names and dates.

If the report never contains recommendations, you may have a vendor who only reacts.

How to read the report

  1. Look for changes since last month rather than absolute numbers.
  2. Ask about exceptions. Zero exceptions usually means no one looked.
  3. Pick one or two items each month to dig into.
  4. Check consistency. Do the numbers match what people in the office say?
  5. Record decisions made in response, so the report becomes a record of oversight.

Model Rule 5.3 addresses supervision of nonlawyer assistance, and the ABA has discussed vendors in this context. Regularly reviewing reports and asking questions is one concrete way to show that supervision is real.

Red flags in reporting

  • Reports consisting only of ticket counts.
  • Metrics that never change.
  • Reluctance to share raw data or explain methodology.
  • No mention of security or backups.
  • Surprises discovered by the firm before the provider reports them.

Meeting rhythm

A monthly report and a quarterly review meeting are a good cadence. In the quarterly meeting, discuss trends, risks, the roadmap and the budget. An annual meeting should revisit scope, service levels and renewal terms.

Ask for a sample first

When evaluating providers, request an anonymized sample report. If it's unclear to you, it will likely be unclear in practice.

How Counsel Cyber can help

Counsel Cyber provides managed IT clients with a plain-language monthly report and quarterly review covering service and security measures. If you would like to see what that looks like, we are happy to share a sample.