Choosing a managed IT provider is a bigger decision than most firms treat it. The provider will hold administrator access to every system that touches privileged client data, and they become part of how you meet your duty of confidentiality. Price matters, but it should come after fit, scope and security.
Here is what a law firm should expect, and what to ask before signing.
The Core Service
At a minimum, a managed provider should deliver:
- Help desk with defined hours, response targets and a clear way to escalate urgent issues, such as a lawyer locked out an hour before a hearing
- Monitoring and patching for servers, workstations, network equipment and cloud services
- User lifecycle management: onboarding, offboarding and permission changes handled on a documented checklist
- Vendor management for internet, phone, printers and software, so you have one call instead of five
- Planning and budgeting, including a hardware refresh calendar and an annual technology roadmap
Security Should Not Be an Add-On
For a law firm, the line between "IT" and "security" barely exists. Expect the provider to address security as part of the base relationship, and ask specifically how they handle:
- Multi-factor authentication on email, remote access and administrative accounts
- Endpoint protection with someone watching the alerts around the clock, not only software installed and forgotten
- Email filtering, including impersonation and lookalike-domain protection
- Backup monitoring and restore testing
- Security awareness training and phishing simulations
- A written incident response process, including who calls whom and when
If a provider treats these as optional extras with separate quotes, understand what the base price is actually protecting.
Questions to Ask Any Candidate
About legal experience
- Do you support practice-management and document-management platforms such as Clio, NetDocuments or iManage?
- Are you familiar with client security questionnaires and outside counsel guidelines?
- Can you provide references from similarly sized firms?
About access and accountability
- Who on your team has administrator access to our systems, and how is that access protected and logged?
- Do your technicians use individual accounts, with MFA, instead of shared credentials?
- What happens to our data and access if we end the relationship?
About response and reporting
- What are your written response and resolution targets, and what happens when you miss them?
- Will we receive regular reports covering tickets, patch status, backup results and security events?
- Do we get a named point of contact and regular strategy meetings?
Understand the Contract
- Scope in plain language. What is included, what is billed hourly, and what counts as a project?
- Term and exit. Avoid auto-renewing multi-year terms with no way out. Make sure you own your documentation, licenses and credentials.
- Data handling and confidentiality. Look for confidentiality terms that fit the sensitivity of client information. Because Rule 5.3 addresses supervision of nonlawyer assistance, many firms treat IT vendors as part of that conversation.
- Insurance. Ask what liability and cyber coverage the provider carries.
Red Flags
- Reluctance to explain how they secure their own tools
- Vague answers about who responds after hours
- A pitch built entirely on fear, with no description of actual controls
- No documentation delivered at onboarding
- Pricing that is far below the market without a clear explanation of what is left out
Evaluate After Onboarding
The first ninety days reveal a lot. You should see a documented inventory of devices and accounts, a prioritized list of risks, and quick fixes completed. If you have to chase the provider for information, expect that to continue.
About Counsel Cyber
Counsel Cyber is a Dallas-based managed IT and cybersecurity provider that works with law firms. If you are comparing providers, including us, we are happy to share how we would approach your environment and answer these questions directly.