Many firm leaders receive an IT invoice and little else. If nothing is going wrong, the lack of information feels fine. When something does go wrong, it becomes clear that no one was measuring how well the service was working.
You do not need to read logs to manage IT well. You need a short, regular report with the right numbers. Here are the metrics worth requesting, what they tell you and what to do when they look off.
Help Desk Metrics
Ticket volume and categories
How many requests came in, and what were they about? A spike in password resets might point to an authentication problem. Many printer tickets might mean it is time to replace the printer. Recurring issues are signs of underlying causes worth fixing.
First response time
How quickly does someone acknowledge a request? Compare this to the response targets in your agreement.
Time to resolution
How long until the problem is solved? Averages can hide outliers, so ask for the longest-open tickets as well. A request that has been open for six weeks deserves attention.
First-contact resolution
What share of issues are resolved on the first call or chat? A higher rate usually means skilled staff and good documentation.
User satisfaction
Short post-ticket surveys give you direct feedback. Pay attention to comments, not just scores. An attorney who says the help desk "does not understand deadlines" is telling you something.
Security and Maintenance Metrics
Patch compliance
What percentage of computers and servers are fully patched, and how many are overdue by more than a set number of days? Ask about critical updates specifically.
Endpoint protection coverage
How many devices are protected and reporting? Compare that number to your headcount and device list. A mismatch indicates unmanaged machines.
MFA coverage
How many accounts have MFA enabled? Target is every account. Ask for the exceptions list and the plan to close it.
Security alerts and incidents
How many alerts were raised, how many were real and what happened with each? Even a quiet quarter should include a summary of what was monitored.
Phishing and training
If your provider runs awareness training or phishing simulations, ask for completion rates and click rates by group, and how people who click are coached.
Backup and Recovery Metrics
- Backup success rate across systems for the period
- Failed or missed backups and how they were resolved
- Last restore test date, what was restored and how long it took
- Storage and retention status
A report that says only "backups successful" without a test record is missing the part that matters most.
Asset and Account Hygiene
- Device inventory: Age and condition of computers, and which are due for replacement.
- User accounts: New hires, departures and whether departed users were disabled on time.
- Administrator accounts: Who has elevated access and when it was last reviewed.
- Licenses and renewals: What is coming due, and what is unused.
How to Use the Report
Hold a quarterly review
Thirty minutes with the provider, the firm administrator and a partner is enough. Review trends, open issues and upcoming projects.
Ask good follow-up questions
- What changed since last quarter, and why?
- What is the biggest risk you see right now?
- What should we budget for next year?
- Which recommendations have we declined, and what risk does that leave?
Keep a decision log
Record the recommendations you approve or defer. If a deferred item later contributes to an incident, you will have a clear record of the decision, which is also useful to insurers and clients.
Beware of Vanity Metrics
Large numbers of blocked attacks look impressive but may measure noise. Prefer metrics that tie to your risk: coverage gaps, speed of response, time to patch and recovery readiness.
Supervision Duties
ABA Model Rule 5.3 concerns supervision of nonlawyer assistance, and outside IT providers are part of that picture. A routine report review is one concrete way to show reasonable supervision.
Keep the Format Simple
One or two pages with trends over time is better than a thick packet. If your provider cannot or will not report on these basics, that is useful information too.
Counsel Cyber provides quarterly reporting to law firm clients covering these areas in plain language. If you would like to see what a useful report looks like, we can share a sample format.