Many firms hear from their IT provider only when something breaks or a renewal arrives. That leaves partners making decisions about security, spending and risk with very little information. A recurring technology review, held quarterly for most firms, fixes that. It takes about an hour and gives leadership a regular view of what is happening.
This post outlines an agenda and the questions worth asking.
Who should attend
- A managing partner or designated technology partner
- The firm administrator or office manager
- The account lead from your IT provider, ideally someone who knows your environment
- Occasionally, the partner responsible for risk or ethics matters
Suggested agenda
1. Service performance
Ask for a summary of support activity:
- Ticket volume and common categories
- Response and resolution times against targets
- Repeat issues, which signal a root cause that has not been fixed
- Satisfaction feedback from staff
Questions: What is generating the most tickets? Are any people or offices having a worse experience? What are we doing about repeat problems?
2. Security posture
This is the most important section for a law firm. Look for:
- MFA coverage: what percentage of accounts is enforced, and what exceptions exist
- Endpoint protection status and alerts handled
- Phishing reports and results of simulations
- Patch compliance and anything outstanding
- Administrator accounts and recent changes
- Vulnerabilities found and fixed
- Any security incidents or near misses
Questions: What are the top three risks right now? What changed since last quarter? What would you fix first if budget were no issue?
3. Backup and recovery
- Results of recent backups and any failures
- The latest restore test, with date, scope and outcome
- Whether recovery goals are still realistic given data growth
Question: If our main system failed this morning, how long until we are working again, and how do you know?
4. Users, devices and licenses
- Joiners and leavers processed
- Accounts that have not been used recently
- Device age and refresh planning
- License counts versus use, so you are not paying for unused seats
- Software nearing end of support
5. Projects and roadmap
- Status of current projects
- Upcoming renewals and expirations
- Recommended initiatives, with reasons, estimated cost and priority
- Alignment with firm plans such as new hires, an office move or a merger
6. Compliance and client expectations
- Open client security questionnaires and cyber insurance renewal timing
- Policy updates needed, including AI use
- Training schedule and completion rates
- Vendor review status
7. Budget
- Spending to date versus plan
- Anticipated costs for the next two quarters
- Items that could be deferred and the risk of deferring them
Reports to request
- A one-page dashboard with consistent metrics from quarter to quarter
- A list of open risks with owners and target dates
- A summary of changes made to the environment
- An inventory of hardware and software, updated
Signs of a healthy relationship
- The provider brings issues before you ask
- Recommendations come with reasons and alternatives, not only a price
- Bad news is delivered promptly and plainly
- You can see progress on the same items over time
Signs of trouble
- Reviews are cancelled or become sales presentations
- Reports are vague or change format each time
- Questions get jargon in response
- Recommendations arrive only when a renewal is near
Keep a record
Capture decisions and action items, with names and dates, and review them at the start of the next meeting. These notes also help demonstrate to insurers and clients that the firm oversees its technology, consistent with its supervisory responsibilities.
Start with Counsel Cyber
If your current provider does not offer a regular review, we can run a one-time assessment and show you what a useful report looks like.