ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Law Firm Help Desk Metrics Worth Asking Your IT Provider For

The help desk and security metrics a managing partner can request from an IT provider each quarter, and how to read them without technical expertise.

3 min readBy Counsel Cyber Team

Many firm leaders receive an IT invoice and little else. If nothing is going wrong, the lack of information feels fine. When something does go wrong, it becomes clear that no one was measuring how well the service was working.

You do not need to read logs to manage IT well. You need a short, regular report with the right numbers. Here are the metrics worth requesting, what they tell you and what to do when they look off.

Help Desk Metrics

Ticket volume and categories

How many requests came in, and what were they about? A spike in password resets might point to an authentication problem. Many printer tickets might mean it is time to replace the printer. Recurring issues are signs of underlying causes worth fixing.

First response time

How quickly does someone acknowledge a request? Compare this to the response targets in your agreement.

Time to resolution

How long until the problem is solved? Averages can hide outliers, so ask for the longest-open tickets as well. A request that has been open for six weeks deserves attention.

First-contact resolution

What share of issues are resolved on the first call or chat? A higher rate usually means skilled staff and good documentation.

User satisfaction

Short post-ticket surveys give you direct feedback. Pay attention to comments, not just scores. An attorney who says the help desk "does not understand deadlines" is telling you something.

Security and Maintenance Metrics

Patch compliance

What percentage of computers and servers are fully patched, and how many are overdue by more than a set number of days? Ask about critical updates specifically.

Endpoint protection coverage

How many devices are protected and reporting? Compare that number to your headcount and device list. A mismatch indicates unmanaged machines.

MFA coverage

How many accounts have MFA enabled? Target is every account. Ask for the exceptions list and the plan to close it.

Security alerts and incidents

How many alerts were raised, how many were real and what happened with each? Even a quiet quarter should include a summary of what was monitored.

Phishing and training

If your provider runs awareness training or phishing simulations, ask for completion rates and click rates by group, and how people who click are coached.

Backup and Recovery Metrics

  • Backup success rate across systems for the period
  • Failed or missed backups and how they were resolved
  • Last restore test date, what was restored and how long it took
  • Storage and retention status

A report that says only "backups successful" without a test record is missing the part that matters most.

Asset and Account Hygiene

  • Device inventory: Age and condition of computers, and which are due for replacement.
  • User accounts: New hires, departures and whether departed users were disabled on time.
  • Administrator accounts: Who has elevated access and when it was last reviewed.
  • Licenses and renewals: What is coming due, and what is unused.

How to Use the Report

Hold a quarterly review

Thirty minutes with the provider, the firm administrator and a partner is enough. Review trends, open issues and upcoming projects.

Ask good follow-up questions

  • What changed since last quarter, and why?
  • What is the biggest risk you see right now?
  • What should we budget for next year?
  • Which recommendations have we declined, and what risk does that leave?

Keep a decision log

Record the recommendations you approve or defer. If a deferred item later contributes to an incident, you will have a clear record of the decision, which is also useful to insurers and clients.

Beware of Vanity Metrics

Large numbers of blocked attacks look impressive but may measure noise. Prefer metrics that tie to your risk: coverage gaps, speed of response, time to patch and recovery readiness.

Supervision Duties

ABA Model Rule 5.3 concerns supervision of nonlawyer assistance, and outside IT providers are part of that picture. A routine report review is one concrete way to show reasonable supervision.

Keep the Format Simple

One or two pages with trends over time is better than a thick packet. If your provider cannot or will not report on these basics, that is useful information too.

Counsel Cyber provides quarterly reporting to law firm clients covering these areas in plain language. If you would like to see what a useful report looks like, we can share a sample format.