Most firms sign a managed IT agreement once and revisit it only when something breaks. That is a mistake, because the contract determines what you get when something goes wrong at 4:45 on the day a filing is due. A good agreement for a law firm is specific about scope, response, security and exit. A vague one leaves everything to goodwill.
Here is what to look for before you sign or renew.
Scope of services
What is included
List the services in plain terms: help desk, patching, endpoint management, backup monitoring, email security, user onboarding and offboarding, vendor liaison for software like practice-management platforms, and periodic security reviews. Ask what counts as a project and what counts as routine support. Hidden project fees are one of the most common sources of frustration.
What is excluded
Every agreement has exclusions. Read them for items you assumed were covered: line-of-business applications, after-hours support, travel to a branch office, hardware procurement, or remediation after a security incident.
Response and resolution commitments
- Defined response times by severity, such as a server outage versus a password reset.
- Support hours, including whether after-hours or weekend coverage exists for deadline-driven work.
- How incidents are escalated and who at the provider is accountable.
- How performance is reported to you, ideally with a regular review.
Be cautious about promises of "resolution" in a fixed time for every issue. Response is something a provider controls. Resolution sometimes depends on third parties.
Security responsibilities
A firm needs clarity about who does what. Ask the provider to state in writing:
- Whether they provide or manage multi-factor authentication, email filtering, endpoint detection and response and security awareness training.
- Whether security alerts are monitored around the clock or only during business hours.
- How quickly they will notify you of a suspected incident.
- How they protect their own access to your systems, since an IT provider's tools are a high-value target.
- Who handles incident response and whether it is included or billed separately.
Confidentiality and supervision
ABA Model Rule 5.3 addresses a lawyer's responsibility for nonlawyer assistance, and outside IT providers frequently see client information. The agreement should include confidentiality terms, restrict who at the provider can access your data, require staff to be vetted and trained, and address what happens to your data if the relationship ends. Ask whether the provider will complete the security questionnaires your clients and insurers send, because those requests are increasingly routine.
Data ownership, documentation and exit
- You own your data, your domain names, your licenses and your administrative credentials.
- The provider documents your network, passwords (in a shared vault you can access) and configurations.
- There is a reasonable termination clause, a transition-assistance commitment and no punitive fee for retrieving your own information.
If a provider will not hand over administrator access or documentation on request, treat that as a red flag.
Pricing structure
Per-user pricing is common and usually easy to budget. Ask what changes the price: new devices, new locations, added applications or higher security tiers. Understand renewal terms and whether the price auto-escalates.
Red flags
- Reluctance to put response times in writing.
- No mention of cybersecurity in the agreement at all.
- Sole reliance on a single technician with no backup coverage.
- A refusal to share references from other professional-services firms.
Questions to ask in the sales conversation
Sales conversations tend to focus on features. Steer yours toward how the provider behaves when things go wrong. Ask who will actually answer the phone, how many technicians know your environment, and how the provider handled its last serious incident for another client, without names. Ask how often your account is reviewed and who prepares those reviews. A provider that welcomes these questions is usually one that has good answers.
Next steps
Read your current agreement with a highlighter and mark every point on this list that is missing. Bring the gaps to your provider, or to a prospective one, and ask for clear answers in writing. Counsel Cyber is happy to review an existing IT agreement with you and explain, without obligation, where it leaves your firm exposed.