Many law firms sign a managed IT agreement the way they sign a copier lease: skim the price, confirm the term, and file it away. The trouble is that an IT provider will have administrator access to nearly everything the firm owns, including privileged client files. The agreement is where you decide what that access means, what you can expect, and how you leave if things go badly.
This guide walks through what a managed IT agreement for a law firm should address, in the order most administrators find useful.
Scope: what is in and what is out
Services included
The agreement should name the services plainly. Typical items are help desk support, device management and patching, server and network monitoring, Microsoft 365 administration, backup management, and security tooling. Watch for vague phrases such as "all reasonable IT support." Ambiguity is where billing disputes begin.
Services excluded or billed separately
Ask what triggers extra charges: projects, office moves, after-hours work, hardware procurement, onboarding of new attorneys, and incident response. Request a rate sheet for anything outside the monthly fee.
Covered users and devices
Confirm how the provider counts users and devices, how additions are billed, and whether personal devices that access firm email are covered.
Service levels you can measure
A service level agreement should define response and resolution targets by priority. For example, a firm-wide outage should be treated differently from a single user's printer problem.
- Response time: how quickly someone starts working on the issue.
- Resolution target: how quickly the issue should be fixed, where feasible.
- Hours of coverage: business hours only, or extended hours for trial weeks and filing deadlines.
- Escalation path: who you call when the help desk is not resolving a problem.
Ask what remedies exist when targets are missed. Credits are common. At minimum, you should receive regular reporting against the targets.
Security responsibilities in writing
For a law firm, this section matters most. The agreement should state which security controls the provider manages and who is accountable for each.
- Multi-factor authentication configuration and enforcement.
- Patch management timelines for operating systems and applications.
- Endpoint detection and response, including who monitors alerts and during what hours.
- Email security configuration.
- Backup monitoring and periodic restore testing.
- Security awareness training.
- Incident response: who leads, what the provider will do, and whether it is included in the fee.
If the provider offers "security" as a bullet point with no detail, ask for specifics. A provider that cannot describe what it monitors is probably not monitoring much.
Confidentiality and access terms
Because the provider can reach privileged data, the agreement should include confidentiality obligations that are at least as strong as your own. Model Rule 5.3 addresses a lawyer's responsibility for nonlawyer assistance, and ABA guidance has discussed supervising outside vendors. Reasonable steps often include:
- A written confidentiality clause covering client information.
- A requirement that provider staff are background-checked and use individual accounts, not shared credentials.
- Restrictions on subcontracting without your consent.
- Provisions for data return and deletion at termination.
- Notification of any security incident affecting your data, within a defined time frame.
Insurance and liability
Ask the provider what professional liability and cyber coverage it carries and request a certificate. Read the limitation of liability clause carefully. Many agreements cap damages at a few months of fees, which may bear no relationship to the harm a breach could cause. You may not be able to remove the cap entirely, but you should understand it and discuss it with your own counsel.
Documentation and ownership
The agreement should say that you own your data, your domain names, and your licenses, and that the provider will deliver administrator credentials and network documentation on request. Firms sometimes discover at termination that the provider holds the only copy of key passwords or that licenses are registered in the provider's name.
Term, renewal and exit
- Check the initial term and auto-renewal language. Calendar the notice window.
- Confirm termination rights for cause, such as repeated missed service levels or a security failure.
- Require a reasonable transition period with cooperation.
- Ask what the provider charges for offboarding assistance.
Questions to ask before you sign
- Who will actually work on our account, and what is their experience with law firms?
- How do you handle a client questionnaire or insurance application that asks about our controls?
- What is your own security posture, and can you share it?
- When did you last test your own incident response?
- May we speak with two current law firm clients?
A final word
A good managed IT agreement reads like a division of responsibility, not a menu of tools. If you would like a second opinion on a proposal you have received, Counsel Cyber is happy to review it with you and point out gaps, whether or not you end up choosing us.