ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

What a Managed IT Contract for a Law Firm Should Actually Cover

Before you sign with a managed IT provider, check these contract items: scope, response times, security duties, data ownership, and how you can leave.

3 min readBy Counsel Cyber Team

A managed IT agreement is a long-term relationship with a company that will have the keys to your firm's email, documents, and client data. Many firms sign the first proposal that fits the budget and discover the gaps only during a crisis: a ransomware weekend when "security" turns out to be an add-on, or a renewal when they learn they cannot get their own passwords and documentation back.

Reading the contract carefully, and asking the right questions before signing, protects you more than any single technical control.

Scope: what is and is not included

Vague phrases like "full support" and "proactive monitoring" mean nothing until they are defined. Ask for a list.

  • Help desk: hours, channels (phone, email, chat), and whether after-hours emergencies are included
  • Onsite visits: included or billed, and travel terms across your offices
  • Devices and users covered: laptops, phones, printers, servers, and what happens when you add people
  • Cloud services: Microsoft 365 administration, practice-management tools, document management, and who is the point of contact with each vendor
  • Projects: what counts as project work, such as migrations, office moves, and new-hire waves, and how they are priced

Service levels that mean something

A service level agreement should state response and resolution targets by priority.

  1. What counts as critical, such as a firm-wide outage or a suspected breach
  2. The response time for each level, and whether it is measured from ticket creation or from a human reply
  3. What remedies apply if targets are missed
  4. How performance is reported, and how often

Be cautious of response-time promises with no consequence attached.

Security responsibilities, spelled out

For a law firm, security cannot be an afterthought. Ask the provider to state in writing who handles:

  • Multifactor authentication and conditional access
  • Endpoint protection and monitoring, and who responds at 2 a.m.
  • Patching schedules and exceptions
  • Email security and anti-phishing
  • Backup, off-site copies, and restore testing
  • Security awareness training
  • Incident response: who leads, who calls your insurer, and what is billed separately

Under ABA Model Rule 5.3, lawyers have supervisory responsibilities over nonlawyer assistance, which commonly includes outside vendors. Your contract should support, not undermine, your ability to supervise.

Data, access, and ownership

Who owns what

The contract should state that your data, your accounts, and your licenses belong to the firm. Watch for arrangements in which the provider holds the Microsoft 365 tenant or software licenses in its own name.

Administrative credentials and documentation

You should be able to obtain current network diagrams, admin credentials held in escrow or a shared vault, and asset inventories on request, not only after a dispute.

Confidentiality and personnel

Ask about background checks for staff with access, confidentiality obligations in the agreement, and whether subcontractors are used. Ask whether access to your environment is logged and limited by role.

Commercial terms

  • Pricing model: flat per user, per device, or tiered, and exactly what changes it
  • Term and auto-renewal: many contracts renew automatically for a year unless you give notice weeks in advance
  • Price escalators: annual increases and how they are capped
  • Hardware and licensing: whether you buy or lease, who owns it at the end
  • Liability and insurance: the provider's liability cap, and whether it carries professional liability and cyber coverage. Ask your broker how the provider's coverage interacts with yours.

Exit terms

The most overlooked clause is the one about leaving. Insist on:

  • A reasonable termination right, including for repeated service failures
  • A defined transition period with continued service
  • Delivery of credentials, documentation, and data in usable form
  • A cap on or clear pricing for transition assistance

A provider confident in its service has no reason to hold you hostage.

Red flags

  • Refusal to share a sample report or a reference from another professional-services client
  • No written incident response process
  • Security tools sold as optional extras that any law firm would need
  • No clear answer on who owns the admin accounts
  • Pressure to sign quickly

Getting a second look

Counsel Cyber is happy to read a competing proposal or your current agreement and tell you plainly what it does and does not cover, even if you do not hire us. If you are comparing providers, a short checklist review can save a lot of grief later.