A managed IT agreement defines who is responsible for what when something breaks, and for a law firm, when something leaks. Too many small firms sign a one-page order form built around a monthly price per user and discover later what it did not cover. A little care before signing avoids a lot of friction afterward.
This is a guide for firm administrators and partners reading proposals. It is not legal advice, and your own counsel should review any contract.
Scope: What Is Actually Included?
Ask for a plain list of covered services, and for what is explicitly excluded.
- Help desk hours and channels, including after-hours and emergency support
- Which devices, locations and users are covered
- Patching and updates for workstations, servers and network equipment
- Management of Microsoft 365 and other cloud platforms
- Support for practice-management and document systems, and whether vendor-specific issues are included
- Onboarding and offboarding of users
- Projects, such as office moves or migrations, and how they are priced
Vague phrases like "all IT needs" invite disputes. Specific lists prevent them.
Service Levels That Mean Something
Look for measurable commitments.
- Response times by severity, such as how quickly a down server is acknowledged versus a password reset.
- Resolution targets where practical.
- Hours of coverage and whether emergencies outside business hours are included.
- Remedies if targets are missed, such as credits.
Response is not resolution. Ask how each is measured and reported.
Security Responsibilities in Writing
For a law firm this is the heart of the agreement. Security should not be a vague promise.
- Which security tools are included, and who monitors alerts? Is monitoring around the clock, or only business hours?
- Who enforces multi-factor authentication and manages access reviews?
- How are patches prioritized, and how quickly are critical ones applied?
- Who manages email security, including DMARC and filtering?
- Are backups monitored and restore tests performed, and how often?
- What is the incident response process, and is it included or billed separately?
Clarify what remains the firm's responsibility. A provider cannot force staff to avoid risky behavior, but it can be clear about shared duties.
Confidentiality and Data Handling
Your provider will have privileged access to systems that hold client information. Under Model Rules 5.1 and 5.3, lawyers have supervisory responsibilities over nonlawyer assistance, and ABA Formal Opinion 477R and others discuss reasonable safeguards. Reflect that in the contract.
- A confidentiality clause covering client data and a commitment to limit access to those who need it
- Background screening and training of technicians
- Rules on subcontractors and where your data may be stored or accessed
- Obligations if the provider itself suffers a breach, including notification timing
- Clear statement that client data remains the firm's property
Reporting and Transparency
You should not need to ask for visibility. Look for:
- Regular reports on tickets, patch status, backup results and security events
- Periodic reviews, such as quarterly business meetings
- An inventory of assets and accounts that you can request at any time
- Access to your own documentation, such as network diagrams and credentials, held in a way you control
Insurance and Liability
Ask what insurance the provider carries, including cyber and professional liability. Read limitation-of-liability language carefully, since many agreements cap damages at a small multiple of monthly fees. Have counsel weigh in on whether the limits are acceptable.
Term, Pricing and Changes
- What is the contract length, and is there auto-renewal?
- How are price increases handled?
- How are users added or removed during the term?
- What are the rates for work outside scope?
Exit Provisions
The time to plan a divorce is before the wedding. A good agreement spells out:
- How much notice is required to terminate
- What happens to your data, accounts and documentation
- Whether the provider will cooperate with a transition, and at what cost
- How credentials and administrative control are returned to you
The firm should always hold ownership of its domain, Microsoft 365 tenant, and key administrative accounts, never the provider alone.
Red Flags
- Reluctance to put security commitments in writing
- No reporting beyond an invoice
- No answer to "who monitors alerts at 2 a.m.?"
- Claiming to fix everything for a very low per-user price
- No experience with legal workflows or confidentiality duties
Counsel Cyber is happy to review a proposal from any provider, including ourselves, and explain what it covers and what it leaves out. If you have an agreement coming up for renewal, bring it and we can go through it together.