Most law firms sign their first managed IT agreement the same way they sign a copier lease: skim the price, glance at the term, and file it. The problem is that an IT contract defines who is responsible when a server fails at 4:45 p.m. before a filing deadline, or when an attorney's mailbox is compromised. Those are not copier-level risks.
This post walks through what a managed IT contract for a law firm should spell out, so you can compare proposals on substance rather than on the monthly number alone.
Scope: what is actually covered
"Managed IT" can mean anything from a help desk that answers the phone to a full team that owns your network, security and vendor relationships. Ask for the scope in writing and look for each of these:
- Help desk hours, channels (phone, chat, email) and whether after-hours or weekend support for deadline emergencies is included or billed separately
- Onsite versus remote support, and how quickly someone can physically reach each of your offices
- Which devices, users and applications are covered, including personal phones used for firm email
- Whether line-of-business tools such as your practice-management platform and document management system are supported or only "the network underneath them"
- Onboarding and offboarding of attorneys and staff
If something is excluded, the contract should say so. Vague language like "reasonable support for business applications" is where disputes start.
Response and resolution targets
A good agreement states how fast the provider will respond and, ideally, how fast they aim to resolve issues by priority level. A server outage or suspected compromise should rank above a request for a second monitor. Ask what happens when targets are missed. Credits are common; the more important question is whether the provider reports on performance so you can see patterns over time.
Security responsibilities
For a law firm, security cannot be an optional add-on that nobody owns. Confirm which of these the provider handles, and which remain with you:
- Multi-factor authentication on email, remote access and administrator accounts
- Endpoint protection with someone watching the alerts, not just software installed on laptops
- Email filtering and impersonation protection
- Patching of operating systems and third-party software on a defined schedule
- Backup monitoring and periodic restore testing
- Security awareness training and phishing simulations
- Incident response: who you call, how fast they engage, and whether that work is included or billed hourly
ABA Model Rule 5.3 addresses a lawyer's responsibility for nonlawyer assistance, which the ABA has applied to outside technology vendors. Your contract is where you document how that supervision works in practice. Confirm the details with your state bar.
Data ownership, access and confidentiality
Your client files and the credentials to your systems belong to the firm. The contract should say that plainly. Look for:
- A confidentiality clause that covers client information the provider's technicians may encounter
- A statement that the firm owns all data and holds administrator-level access to its own environment
- Limits on who at the provider can access your systems, and whether access is logged
- Notification terms if the provider itself has a security incident
- Whether the provider carries its own cyber and professional liability insurance
Documentation and visibility
You should receive, and keep, a current network diagram, an inventory of hardware and software, a list of administrator accounts, and records of license renewals. If the provider holds this knowledge only in their heads, you are locked in regardless of what the contract says.
Term, pricing and exit
Per-user pricing is common and easy to budget. Watch for what falls outside it: projects, hardware, after-hours work, travel to remote offices, and security tools billed separately. Then read the termination section carefully.
- How long is the initial term, and does it auto-renew?
- How much notice is required to leave?
- Will the provider hand over documentation, passwords and data in an orderly way, and is there a fee for that transition?
A provider confident in its service has little reason to make leaving difficult.
Questions worth asking before you sign
- Who will be my day-to-day contact, and who covers when they are out?
- Can I speak with a law-firm client of similar size?
- How do you handle a request at 6 p.m. the night before a hearing?
- What does your quarterly or annual review with the firm look like?
Next step
If you already have an agreement and want a second opinion, Counsel Cyber is glad to review it against what a firm your size should expect, and to point out gaps without any obligation to switch.