A managed IT agreement defines what you can expect when something breaks, when something is attacked and when you eventually want to leave. Many firms sign a standard template with a price and a vague list of services, and only learn what is missing after a problem occurs.
Law firms have particular needs: confidentiality duties, deadline-driven work, specialized software and clients who ask pointed security questions. Here are the elements to look for in an agreement, whether you are choosing a provider or renewing one. Have your own counsel review any contract before you sign.
Scope of services
Vague scope causes disputes. Look for specifics.
- Help desk hours and how to reach support after hours and on weekends, including for urgent deadlines.
- Which devices, users, locations and applications are covered.
- Whether on-site visits are included and how they are billed.
- Management of cloud services such as Microsoft 365 and practice management platforms.
- Procurement, vendor management and project work: included or billed separately?
- Which items are explicitly excluded.
Service levels
A service level agreement describes how quickly the provider will respond and resolve issues.
- Response and resolution targets by severity, such as a server outage versus a password reset.
- How severity is defined, and who decides.
- Whether targets apply around the clock or only in business hours.
- What remedies exist if targets are missed, such as credits or escalation rights.
Beware of promises phrased only as "best effort."
Security responsibilities
This is where many agreements are thin. Spell out who does what.
- Patch management, with timelines for critical updates.
- Endpoint protection and monitoring, and whether a security operations team watches alerts around the clock.
- Email security and MFA management.
- Backup, restore testing and disaster recovery, with recovery objectives.
- Vulnerability scanning and remediation.
- Security awareness training.
- Incident response: who leads, who is called, and whether the retainer is included or billed hourly.
If security is described only as "antivirus," ask questions.
Confidentiality and data handling
Because the provider will have broad access, the agreement should include:
- A confidentiality commitment that covers client information.
- Limits on how the provider may use your data.
- Background screening of technicians with access.
- Rules for subcontractors.
- A breach notification commitment with a stated timeframe.
ABA Model Rule 5.3 addresses supervising nonlawyer assistance, and the ABA has discussed vendors in this context. These clauses help you demonstrate reasonable oversight.
Access and accountability
- A list of administrative accounts the provider holds, with MFA required.
- Logging of administrator activity.
- Your firm's ownership of all domains, licenses, credentials and documentation. You should never have to ask permission to see your own admin passwords.
- Change management for significant modifications.
Reporting and meetings
Ask for regular reports, perhaps monthly, covering tickets, patch status, backup results, security alerts and open risks. Schedule a quarterly business review where someone looks beyond tickets and talks about planning and budget.
Pricing and billing
- Per-user, per-device or flat-fee structure, and what triggers changes.
- Annual increases, and any caps.
- Charges outside scope or after hours.
- Costs of onboarding and new-hire setup.
- Licensing pass-through terms for Microsoft 365 and other software.
Make sure you can predict your bill.
Term, renewal and exit
- Contract length and automatic renewal terms, including how much notice is needed to cancel.
- Termination for cause, such as repeated missed service levels or a security failure.
- Transition assistance: documentation, credentials, handoff to a new provider and how that is priced.
- Return or deletion of your data, with written confirmation.
A good provider makes departure orderly, because it is confident you will stay for the service.
Liability and insurance
Read the limitation of liability clause. Ask whether the provider carries professional liability and cyber coverage, and how that interacts with your own cyber policy. Understand what happens if the provider's error leads to a loss.
Questions to ask in the sales process
- Which other law firms do you support, and how big are they?
- Who will be my primary technician and escalation contact?
- How do you respond to a ransomware incident?
- May we see a sample report and a sample contract?
- How do you secure your own environment?
Closing thought
Counsel Cyber is a managed IT and cybersecurity provider for law firms. Whether you are considering us or reviewing your current agreement, we are glad to walk through this list with you and point out gaps.