ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

What to Expect in a Quarterly IT Business Review for Law Firms

A good IT provider meets with you regularly. Here is the agenda, the reports and the questions that make a quarterly review worth a partner's time.

3 min readBy Counsel Cyber Team

Many firms have a managed IT provider they speak to only when something breaks. That is a missed opportunity. A quarterly technology business review, often shortened to QBR, is a scheduled conversation where the provider reports on what happened, what is coming and what the firm should decide. Done well, it gives partners visibility and catches problems while they are still cheap to fix. Done badly, it is a slide deck of ticket counts.

This post describes what a useful review includes, so you can ask for it if you do not have one or improve the one you have.

Who should attend

At minimum: a partner or the managing partner, the firm administrator and the provider's account lead and security representative. Keep it to an hour. Rotate other attendees in when topics require them, such as a practice group leader when discussing a new system.

The agenda

1. Service performance

Ask for plain figures: how many tickets were opened and closed, how quickly they were first answered and resolved, which issues recurred and how that compares with the agreement. Recurring issues are the interesting part, because they point to a root cause worth fixing. Ask for the most frequent complaint and what is being done about it.

2. Security posture

This should be the longest section for a law firm. Look for:

  • Patching status: which devices and servers are behind, and why.
  • Endpoint protection coverage and alerts that required action.
  • MFA coverage, including any exceptions and who approved them.
  • Email security: blocked threats, phishing reports from staff and DMARC status.
  • Vulnerabilities found and remediated or accepted.
  • Security awareness training completion and phishing simulation results.
  • Any incidents or near misses, with what was learned.

The numbers matter less than the trend and the explanation of exceptions.

3. Backup and recovery

Request the results of the last restore test, any failed jobs and whether recovery objectives are still being met. Ask when the next test is scheduled and what is being tested.

4. Access and accounts

Review a list of accounts added and removed since the last meeting, administrator accounts, shared mailboxes and contractor access. Compare with the firm's staff list. This single exercise often exposes forgotten accounts.

5. Changes and projects

Cover completed work, projects in progress and anything delayed. Include changes made in the environment, such as new software, configuration changes or vendor swaps.

6. Hardware and software lifecycle

Ask which devices are approaching end of life or end of support and what replacement costs to plan for. Operating systems and applications that no longer receive security updates should be flagged clearly.

7. Budget and roadmap

Look ahead twelve months. Which renewals are coming, which licenses are unused, which upgrades are recommended and what are the priorities and rough costs? A good provider helps you avoid surprises and shows reasoning, not just a shopping list.

8. Compliance and client requirements

Discuss pending cyber insurance renewals, client security questionnaires and any contract commitments. Ask the provider to help assemble the evidence you will need.

9. Risks and decisions

End with a short list of risks the provider recommends addressing, with options and consequences, and decisions needed from the firm. Record who owns each.

Documents to request

  1. A written report delivered before the meeting.
  2. A risk register with dates and owners.
  3. Updated network and system documentation.
  4. Meeting notes and action items.

Keeping these also supports your supervision responsibilities under Rule 5.3 and gives you a record to show carriers and clients.

Signs the review is working

  • You hear about problems before you experience them.
  • Recommendations come with reasons and costs.
  • Action items from last time are closed or explained.
  • Partners can answer questions about firm technology without calling IT.

Signs it is not

  • Mostly charts of ticket volumes.
  • No security discussion.
  • Vague answers on exceptions.
  • No documentation afterward.

A closing note

The point of a review is accountability in both directions. The provider reports honestly, and the firm makes timely decisions. Counsel Cyber holds quarterly reviews with every managed firm and is glad to share a sample report format. If your current reviews feel thin, we can show you what a full one looks like.