Posted on

5 Managed IT Services Risks Law Firms Miss Until Renewal

Two law firm professionals reviewing a managed IT services agreement at a conference table

Law firms should expect a managed IT services provider to own five things in writing: administration of the practice systems a matter runs on, a confidentiality obligation that names subcontractors, a response commitment written in billable-time terms rather than ticket tiers, the documentation a client security questionnaire asks for, and a defined offboarding process. Most firms evaluate a provider on the first ninety days, when onboarding attention is high and nothing has broken yet. The obligations above rarely get tested until year two, which is also when the contract renews. We wrote this from the renewal conversations we sit in, where the gap between what a firm assumed and what the agreement actually says becomes expensive.

Overview: What This Article Covers, and Who It Is For

Written for managing partners, firm administrators, and operations directors at firms of roughly five to two hundred people, where nobody holds a full-time IT title and the provider relationship is the IT department.

  • The systems that carry a matter are not generic office software. Conflict checks, matter intake, document management, and time and billing each fail differently, and a provider who treats them as ordinary applications will be learning on your deadline.
  • Confidentiality is a professional duty that does not delegate. A firm keeps the ethical obligation to clients no matter who administers the servers, so the contract has to carry the obligation forward to the provider and to anyone the provider subcontracts.
  • Downtime in a firm is measured in billable time and court dates. A severity table written for general business does not distinguish a filing deadline from a slow printer.
  • Client security questionnaires arrive without warning. Corporate clients and insurers ask for access reviews, patch records, training logs, and retention settings, and those answers cannot be assembled after the request lands.
  • The exit terms decide how much leverage the firm has. Data export format, credential handover, and transition support belong in the agreement signed at the start, not negotiated once the relationship has soured.

Why Managed IT Services Relationships Sour in Year Two, Not Year One

Managed IT services for law firms almost always look strong in the first quarter, because onboarding is the phase where a provider assigns its most attentive people and every request is new enough to feel urgent. What changes later is not effort, it is exposure. By month fourteen the firm has hit a real outage, taken on a corporate client with a security addendum, lost the technician who knew the matter intake workflow, and started thinking about renewal.

Our team sees the same pattern across firms of different sizes. The agreement was scoped against a list of covered devices and a response-time table, both of which describe activity rather than obligation. Nobody wrote down who is accountable when the document management system will not open a matter file at four in the afternoon, or what the provider owes the firm when a client asks for proof of a quarterly access review.

That gap is not usually anyone’s bad faith. It is that legal practice creates duties a general business contract has no reason to mention, and a firm evaluating providers is comparing monthly fees and coverage hours because those are the numbers on the page. A good starting position is our guide to what law firms should look for in a managed IT provider, which covers the selection stage. This article covers the five things that decide whether the choice holds up.

Risk 1: Nobody Owns the Systems a Matter Actually Runs On

A law firm runs on a stack that general managed IT services contracts rarely name: a conflict-check database, matter intake, a document management system with strict version control, time and billing, court e-filing portals, and often a practice management platform stitching several of those together. Each fails in a way that stops legal work rather than slowing it.

The capability a firm needs here is not troubleshooting, it is standing with the platform vendors. Knowing which support tier can move a stuck e-filing submission, telling a vendor-side outage from a local one before an hour of billable attention is spent proving it, and having handled the same failure on the same version six months ago. That standing takes time to build and does not transfer when a technician changes jobs.

A provider with real legal depth answers questions about platforms in particulars: which document management and practice management systems they administer today, how many firms run each, and the escalation path when the vendor is the problem. A provider without it answers with response-time averages, which is an answer to a different question. Our team’s own view is that a firm should ask for that platform list in writing during evaluation, because it is the one claim that is easy to verify later and easy to overstate up front. The way to test it quickly is a structured vetting call rather than a proposal review, and we walk through that in our note on how to vet a managed IT security provider in about thirty minutes.

Risk 2: Confidentiality Written Into the Contract, Not Assumed

Client confidentiality is a professional obligation that stays with the firm and its lawyers regardless of who administers the systems holding client files. Model rules on confidentiality and on supervising nonlawyer assistance both point the same direction: a firm has to take reasonable steps to see that anyone with access to client information handles it consistently with the firm’s own duties. Delegating administration does not delegate the duty.

What that means practically is that the agreement has to do work. Our team looks for four things in a firm’s provider contract, and we rarely find all four. First, a confidentiality clause that covers client information by name rather than a generic business-data clause. Second, a list of the provider’s staff who hold administrative access, reviewed on a schedule instead of at onboarding. Third, disclosure of subcontractors, including offshore support, with the same obligation flowing through to them. Fourth, an incident notification commitment with a stated timeframe, because a firm may carry its own duty to notify affected clients.

Holding both sides honestly: outsourcing does widen the number of organizations touching client data, which is a real increase in exposure that a firm should not talk itself out of. It also replaces an informal understanding with an enforceable, insured obligation and usually with better monitoring than a small firm runs alone. Credential exposure is one place where the monitoring difference shows up plainly, which is why we treat dark web monitoring for law firms as part of the baseline rather than an upsell. Neither model is safer by default. The written obligation is what makes the outsourced one manageable.

Risk 3: A Response Commitment Written in Billable Time

Downtime at a law firm is not a productivity problem measured in lost hours, it is a problem measured in billable time and calendar dates that do not move. An attorney who cannot open a matter file is not slowed, they are stopped, and the hour is not recoverable the way a delayed internal report is. A missed e-filing window can carry consequences no service credit addresses.

That reframing changes what a firm should require in the agreement. A ticket queue that resolves issues in order of arrival treats a document management outage and a failing desk phone as comparable, because from the queue’s side they are. What a firm needs instead is a triage definition written in its own terms and agreed before it is needed: which failures stop legal work, which slow it, which are inconvenient, and what happens within what window for each. Filing deadlines and hearing dates deserve their own tier.

Coverage is the second half. A single provider technician assigned to the account cannot cover the hours a firm actually works, and firms work evenings before filings. Ask how after-hours escalation functions in practice, who answers at seven in the evening, and whether that person can reach the document management vendor. Where a firm already has internal help, a co-managed arrangement often fits better than full outsourcing, though it introduces its own boundary problems that we cover in our piece on co-managed IT mistakes.

Risk 4: Evidence a Client Security Questionnaire Will Ask For

Corporate clients, insurers, and opposing counsel’s protective orders increasingly ask firms to document their security posture, and the request usually arrives with a deadline attached to a matter the firm wants. The questions are consistent: when was the last user access review, what is the current patch status with dates, who completed security awareness training, how long are logs retained, and how is vendor access governed.

The expensive gap is almost never a missing control. It is a control that exists and cannot be proven. Access reviews happen informally when someone remembers. Patching is current with no record of when it was applied. Log data rolls off after thirty days because nobody set the retention window. A confident description of good practice is not evidence, and the moment the record is needed is exactly when it cannot be created after the fact.

This is where the two arrangements diverge quietly. A capable internal person often does the work correctly and documents it lightly, because documentation competes with the next interruption. A provider working under a contract usually produces documentation as a byproduct, because a reporting obligation exists. The test works on either: ask for those five records this week and see what arrives within a day. A firm comparing providers should also ask whether questionnaire support is included in the fee or billed as project work, since the answer changes the real cost. Our roundup of managed IT providers serving law firms is a reasonable place to see how that support is usually packaged.

Risk 5: The Exit Terms Nobody Read at Signing

Offboarding is the clause a firm signs without reading and needs at the worst possible moment. When a relationship ends, the firm needs its data in a usable format, administrative credentials for every system, current network and system documentation, and enough transition support that the incoming provider is not reconstructing the environment from scratch while matters continue.

Four questions decide how that goes, and all four are cheaper to settle at signing. In what format and on what timeline will client data be returned, and at whose cost. Who holds the top-level administrative credentials for the firm’s tenant, domain, and platform accounts during the relationship, because a firm that does not hold its own domain registration has less leverage than it thinks. What documentation is maintained and handed over. And how much transition assistance is included rather than billed hourly at a moment of low goodwill.

Our position is that a firm should own its own tenant and domain registrations outright and grant the provider administrative access, rather than the reverse. Providers who work this way are usually comfortable saying so. If a provider resists, that answer is itself information worth having during evaluation rather than at renewal. A firm reviewing its current managed IT services agreement can start with the offboarding section alone and learn a great deal in ten minutes.

Frequently Asked Questions

What should law firms expect from managed IT services at a minimum?

A firm should expect documented administration of its practice systems, a written confidentiality obligation covering client information and subcontractors, a triage definition that recognizes filing deadlines, security documentation available on request, and defined exit terms. Coverage hours and device counts describe activity rather than obligation, so a firm that compares only those numbers is comparing the least decisive part of the offer.

Does outsourcing IT transfer a firm’s confidentiality duty to the provider?

No. The duty of confidentiality and the duty to supervise nonlawyer assistance stay with the firm and its lawyers. A contract makes the provider responsible for stated safeguards and gives the firm enforceable recourse, but responsibility for the firm’s obligations to clients does not move. Any provider suggesting otherwise is describing something that does not exist.

How much do managed IT services cost for a law firm?

Most providers price per user per month, with tiers based on included services rather than device counts alone. The figure that matters more is what falls outside the fee: security questionnaire support, after-hours escalation, platform vendor liaison work, and offboarding assistance are commonly billed as projects. Ask for the exclusions list before comparing monthly rates between two providers.

Can a firm keep internal IT staff and still use a provider?

Yes, and for firms above roughly forty people it is often the arrangement that holds up best. The internal person handles day to day support, workflow, and attorney-facing work, while the provider carries after-hours coverage, monitoring, platform escalation, and the documentation trail. The arrangement works when the boundary is written down rather than assumed.

How do we tell whether a provider genuinely understands legal work?

Ask which document management and practice management platforms they administer today and how many firms run each. Ask how they define a filing-deadline incident and what the response commitment is. Ask how confidentiality and subcontractor disclosure appear in their standard agreement. Particular answers indicate real experience, and general answers about response times indicate a generalist.

The Team Behind This Guidance

Mindcore has spent years supporting law firms and other organizations where a systems failure carries consequences beyond lost productivity, including professional obligations that follow the client relationship rather than the technology. That work shapes how we read these agreements: not as a services comparison, but as five obligations somebody has to hold.

Matt Rosenthal, Chief Executive Officer at Mindcore, has made the same point with legal clients for years, which is that the provider relationship should be judged on what it does in a bad week rather than what it promises in a good one. Our role is to help a firm see those five obligations clearly and decide which belong inside the firm, including the times when the honest recommendation is to keep more of the work internal.

Talk Through Your Firm’s Five Answers Before You Renew

Reading the five risks together, the useful pattern is not a size threshold, it is timing. Every one of them is inexpensive to settle while a firm is choosing a provider and expensive to settle once a matter is on the line. A firm that walks into a renewal knowing which of the five its current agreement actually covers is negotiating from a different position than one working from the monthly fee and a sense that things have been mostly fine.

If two or three of those came back unanswered, that is the normal starting point and it is workable. The fastest way forward is a short conversation about how your firm runs today, which platforms carry a matter, and where your security documentation currently lives.

Book a free strategy call and our team will walk the five obligations with you and tell you plainly which parts belong with a provider and which belong inside your firm.

Related Posts

Matt Rosenthal