Few firm administrators enjoy the question "what should we be spending on IT?" Prices vary widely, vendors present them differently and it is easy to compare unlike things. The goal of this guide is not to give you a number. Any number quoted without knowing your headcount, systems and risk profile would be a guess. The goal is to give you a framework so that when proposals arrive, you can compare them honestly and budget without surprises.
Start with what you are paying for today
Before looking at new quotes, add up your current total cost of technology, including the items nobody labels as IT.
- The monthly fee to any outside IT provider or consultant.
- Software subscriptions: Microsoft 365, practice management, document management, e-signature and research tools.
- Security tools bought separately: antivirus, email filtering, backup, password managers.
- Hardware refresh and repairs.
- Internet and phone services.
- Staff time spent on IT by an office manager or attorney.
- Emergency or hourly work billed in the past year.
That last item is the telling one. Firms with low monthly bills often spend heavily on unplanned work.
Common pricing models
Per user per month
The provider charges a flat amount per person. This scales easily as you hire. Ask what counts as a user and whether part-time staff or shared mailboxes are included.
Per device
Pricing follows the number of workstations, servers and mobile devices. Useful if you have many devices per person, less so if you have few.
Tiered or bundled packages
Several service levels, typically differing in security stack and support hours. Compare what is actually inside each tier, because the labels vary.
Hourly or break-fix
You pay as problems occur. This looks cheap until something fails. It also gives the provider little incentive to prevent issues and rarely includes proactive security monitoring.
The cost categories to include in any proposal
- Help desk and administration. Hours, response targets and after-hours coverage.
- Security. MFA, endpoint detection and response, email security, backup, training and incident response.
- Onboarding or transition fees. Often a one-time cost to document and standardize your environment.
- Projects. Migrations, office moves, new hires and hardware refresh, which are often billed separately.
- Licensing. Whether software is included, resold at cost or passed through at a markup.
- Compliance support. Help with client security questionnaires and cyber insurance applications.
Questions that prevent surprises
- What is explicitly not included in the monthly fee?
- How are after-hours emergencies billed?
- Is incident response included, or billed hourly if a breach occurs?
- What increases can we expect at renewal?
- Are there fees for adding or removing users?
- Who pays for hardware, and how is refresh scheduled?
Plan the hardware cycle
Laptops, firewalls, switches and servers wear out. Spreading replacements across several years avoids a large single-year hit. Ask your provider for an inventory with ages and a proposed replacement calendar, then fold it into your annual budget.
Budget for risk, not just operations
A security incident has costs that never appear in an IT budget: downtime, forensic work, client notification, lost billable hours and possible premium increases. Cyber insurance can help with some of these, but policies have conditions, and carriers increasingly expect controls such as MFA and tested backups. Spending on prevention is generally easier to predict than spending on recovery.
Compare apples to apples
Create a simple side-by-side list of what each proposal includes, using the six categories above. Mark each item as included, extra or absent. A provider that appears cheaper often turns out to omit security monitoring, training or after-hours support, which you would then have to buy elsewhere.
Ask about value, not only price
A good provider should offer regular reports, an annual technology review and a roadmap tied to your firm's plans. If a provider only appears when something breaks, that tells you something about the relationship.
How Counsel Cyber can help
Counsel Cyber provides managed IT and cybersecurity for law firms with clear scopes and predictable pricing. If you have proposals in hand or want help building next year's technology budget, we are glad to go through them with you.