Managed IT agreements tend to look similar on the surface: a monthly fee, a promise of help desk support, and a list of tools. The differences that matter are in the details, and they only become obvious on a bad day. For a law firm, where client confidentiality and deadlines drive everything, it pays to read the agreement with a specific set of questions in mind.
This is a buyer's guide for managing partners and firm administrators. It is not legal advice, and your own counsel should review any contract before you sign it.
Scope: what is and is not included
Ask for a plain-language list of what the monthly fee covers. Typical inclusions are help desk support, patching, monitoring, antivirus or endpoint protection, and vendor coordination. Then ask what falls outside it.
- Are new-hire onboarding and departures included, or billed per project?
- Is on-site support included, and how often?
- Are office moves, new-server projects and software upgrades quoted separately?
- Does the fee cover all devices, or only a stated number of seats?
Ambiguity here is where surprise invoices come from.
Response and resolution times
Most agreements state a response time, which only means someone acknowledged your ticket. Ask about resolution targets by priority as well. A hearing the next morning and a printer jam should not share a queue. Ask how after-hours emergencies are handled and whether there is a direct number for urgent legal-deadline problems.
Security responsibilities
This is where law firm agreements most often fall short. "We install antivirus" is not a security program. Ask specifically:
- Is there 24/7 monitoring of endpoints, and who responds when an alert fires at 2 a.m.?
- Who manages multi-factor authentication, email filtering and phishing protection?
- Is security awareness training included?
- What is the process and who is called if a breach is suspected?
- Does the provider maintain its own security controls, such as MFA on its administrative tools?
Your provider has privileged access to every system in the firm. ABA Model Rule 5.3 addresses a lawyer's responsibility for nonlawyer assistance, and the ABA has discussed vendor oversight in its opinions on cybersecurity. Confirm with your state bar how that applies in your jurisdiction, but at a minimum you should know what your provider does with its access and how it protects it.
Data ownership and confidentiality
Ask who owns the documentation, the credentials and the configuration. You should hold the administrator credentials to your own systems and own the network documentation. Request a confidentiality clause that covers client data the provider may see, and ask whether any subcontractors or offshore staff can access your environment.
Backup and recovery commitments
Do not accept "backups are included" at face value. Ask what is backed up, how often, where the copies are stored, whether any are immutable, and how often restores are tested. Ask for stated recovery time targets.
Reporting and meetings
A good provider reports on what it did, not just what it sold. Ask for a regular summary of tickets, patch status, security alerts and risks, and a periodic strategy conversation about the technology budget for the coming year.
Term, pricing changes and exit
- How long is the initial term, and does it auto-renew?
- How much notice is required to cancel, and are there termination fees?
- Can fees increase mid-term, and by how much?
- If you leave, what transition help is provided, and will credentials and documentation be handed over promptly?
The exit clause matters most when you are least happy, so read it first rather than last.
Red flags
- A provider that will not put response times in writing.
- Reluctance to share the administrator credentials or documentation.
- No mention of security responsibilities beyond antivirus.
- No experience with the legal software you use, such as Clio, NetDocuments, iManage or Microsoft 365.
- Pressure to sign quickly.
A simple way to compare proposals
Put each provider's proposal side by side and score a short list: scope clarity, security coverage, response commitments, legal-industry experience, data ownership, and exit terms. The cheapest monthly price rarely wins once these are weighed.
Counsel Cyber works only with law firms, and we are happy to review an existing agreement or a competing proposal and point out gaps in plain English, whether or not you end up working with us.