The in-house IT versus outsourced managed IT services decision at a law firm is usually settled on headcount economics, one salary compared against one monthly fee. That comparison is easy to build and it answers the wrong question, because a firm is not buying a quantity of support. It is buying coverage across the hours it actually works, standing with the platforms a matter depends on, and continuity when one person leaves. Our team runs this comparison with firms several times a year, and the five gaps below are the ones that decide it in practice. None of them are visible in a cost model, and four of them get worse rather than better as a firm grows past a single hire.
Overview: What This Article Covers, and Who It Is For
Written for managing partners, firm administrators, and operations leads at firms of roughly ten to two hundred people who are either about to make a first IT hire or reconsidering an existing provider.
- Coverage is arithmetic, not effort. One person cannot staff the evenings before a filing, a Saturday close, vacation weeks, and a normal work week at the same time, and no amount of commitment changes that.
- Escalation standing with legal platforms takes years to build. Knowing which support tier at a document management vendor can move a stuck matter is worth more in an outage than general troubleshooting skill.
- A security program is broader than one generalist’s job. Monitoring, patch discipline, identity controls, and credential exposure work are separate functions that a single help-desk-focused hire rarely covers together.
- Documentation decides what a firm can prove to clients. Access reviews, patch dates, and training logs are what corporate clients and insurers ask for, and they are the first thing to slip when one person is interrupted all day.
- Continuity risk concentrates in whoever holds the knowledge. When the sole internal technician resigns, the undocumented workflow knowledge leaves in the same week.
Why the Headcount Comparison Misleads Law Firms
Managed IT services for law firms get compared to an internal hire on a spreadsheet with two columns, and the spreadsheet is not wrong so much as incomplete. Salary, benefits, payroll tax, tooling, training, and recruiting sit on one side. A monthly per-user fee sits on the other. Whichever total is lower appears to win, and for a firm under about seventy-five people the provider column is usually lower before any of the harder questions are asked.
What the two columns cannot show is shape. A firm’s technology demand is not distributed evenly across a work week. It clusters before filing deadlines, during trial preparation, at month end when billing runs, and in the evenings when attorneys are finishing work that has to be filed the next morning. A model that compares annual cost to annual cost treats forty hours of Tuesday-afternoon availability as equivalent to availability at seven in the evening before a deadline, and those are not equivalent to a firm.
Our own position, which we say plainly to firms who ask: the cost comparison is worth building, and it should be the second thing you build. The first is an honest map of when your firm needs help and what it needs help with. A firm that maps that first often finds the answer is neither model alone. For the selection-stage questions that follow this decision, our guide to what law firms should look for in a managed IT provider picks up where this article ends.
Gap 1: The Hours a Single Hire Structurally Cannot Cover
Coverage is the gap that arithmetic settles rather than judgement. A full-time internal technician works a standard week, takes vacation, gets sick, and attends training. A law firm files documents in the evening, runs weekend trial preparation, and closes billing at month end regardless of who is available. One person cannot be present for all of it, and a firm that plans as though they can has accepted an uncovered window without deciding to.
The uncomfortable version of this question is what happens at seven in the evening when the document management system will not open a matter file and the filing is due at nine the next morning. With a single internal hire, the honest answer is usually a phone call to a personal mobile and hope. With a provider, the answer should be a defined escalation path, and a firm should test it during evaluation rather than assume it. Ask who answers at that hour, what their authority is, and whether they can reach the platform vendor directly.
Holding the other side of this fairly: an internal person’s presence has real value that coverage math misses. They see which conference room is used for depositions, they know which attorney will not report a problem until it is severe, and they can walk down the hall. That proximity is genuinely hard for a remote team to replicate, and firms that outsource everything sometimes lose it and feel the loss. The strongest arrangements we see keep that proximity and buy the coverage, which is what a co-managed IT arrangement is for.
Gap 2: Escalation Standing With the Platforms a Matter Runs On
Legal work runs on platforms a firm does not control: document management with version history that matters evidentially, practice management, time and billing, court e-filing portals, and a conflict-check database. When one of those fails, the useful skill is not diagnosis, it is knowing whose problem it is and who can move it.
That standing is built through repetition. A technician who has escalated the same document management interface failure three times knows which support tier can act, what evidence the vendor asks for, and how long the vendor takes. A technician meeting it for the first time spends an hour establishing what is already known elsewhere, and at a law firm that hour is billable attention that does not come back. An internal hire builds this standing over years and it becomes genuinely valuable, but it lives in one head and covers only the platforms your firm happens to run.
A provider’s advantage here is exposure across many firms, which turns a novel failure into a known one. The limitation is real and worth naming: a generalist provider without legal depth learns your platforms at your expense, and plenty of providers claim legal experience on a web page without administering a single legal platform. This is the one claim easiest to verify during evaluation. Ask which document management and practice management systems they administer today, how many firms run each, and what happens when the vendor is the problem. A structured call surfaces that quickly, and we walk through the format in our note on how to vet a provider in about thirty minutes.
Gap 3: A Security Program Is Several Jobs, Not One
Law firms hold settlement terms, deal documents, medical records in personal injury matters, and privileged strategy, which makes them a target out of proportion to their size. A security program that matches that exposure is a set of separate ongoing functions: identity and access controls, patch discipline across every endpoint, monitoring that someone actually watches, backup restoration testing, phishing resistance training, and credential exposure work.
A single internal hire whose day is consumed by help desk tickets and attorney requests rarely runs all of those well, not through any lack of skill but because the interruptions win. The security work is important and never urgent, so it slips behind the printer that stopped working, and the firm’s posture drifts without anyone deciding to let it. That is the pattern we see most often at firms with one technician and good intentions.
Where a provider genuinely helps is in the functions that benefit from being someone’s scheduled job rather than someone’s spare hour: monitoring, patch reporting, restoration tests on a calendar, and watching for firm credentials appearing in breach data, which is why we treat dark web monitoring for law firms as baseline work rather than an add-on. The fair counterpoint is that outsourcing adds an organization with administrative access to privileged material, which widens exposure. That trade is manageable through the contract, and it is a trade rather than a free improvement.
Gap 4: What the Firm Can Actually Prove to a Client
Corporate clients, cyber insurers, and protective orders increasingly ask firms to document their security posture, and the request usually arrives attached to a matter the firm wants to keep. The questions are consistent: when was the last user access review, what is the current patch status with dates, who has completed security awareness training, how long are logs retained.
The gap is rarely a missing control. It is a control that works and cannot be evidenced. A capable internal technician often does the right thing and records it lightly, because writing it down competes with the next interruption and the knowledge lives with them anyway. A provider operating under a contract usually produces documentation as a byproduct, because a reporting obligation exists and reports are how they demonstrate value.
Neither model produces evidence by accident. The practical test runs on both: ask for those four records this week and see what arrives inside a day. If assembling them takes a fortnight, the firm has the gap regardless of who holds the work, and it will have it again the next time a client asks. A firm choosing between models should ask directly whether questionnaire support is inside the fee or billed as project work, since that answer changes the real comparison. Our roundup of managed IT providers serving law firms shows how that support is usually packaged.
Gap 5: What Happens the Week Your Technician Resigns
Concentration risk is the gap firms acknowledge last, usually because the internal hire is performing well. When one person holds the administrative credentials, the vendor relationships, the knowledge of which integration breaks after which update, and the informal record of what was configured and why, their resignation removes all of it at once. The replacement search takes months in a tight market, and the interim period lands on an office manager.
The mitigation is not distrust, it is documentation and access hygiene, and both are cheap while the person is still there. Our team’s standing advice to firms with a single technician: make sure the firm itself holds the top-level administrative credentials for its tenant, domain registration, and platform accounts, keep a current system inventory that someone other than the technician can read, and know which vendor relationships would need rebuilding. A firm that cannot answer those three is running a continuity risk it has not priced.
A provider changes the shape of this risk rather than removing it. Staff turn over at providers too, and a firm can find itself with a new account technician who knows nothing about its environment. The difference is that the documentation and vendor relationships usually sit with the organization rather than the individual, so the loss is a nuisance instead of an event. Firms running a hybrid model should read our piece on co-managed IT mistakes, because a blurred boundary between internal and provider responsibility recreates the same single-point risk in a new place.
Frequently Asked Questions
Which fits a law firm better, in-house IT or outsourced managed IT services?
For most firms under roughly seventy-five people, an outsourced provider covers more of the real requirement than a single hire, because coverage hours, platform escalation standing, and a documented security program are hard for one person to hold together. Above roughly a hundred attorneys, internal staffing at genuine depth becomes workable, and the decision shifts from staffing to which functions stay specialized.
At what size should a law firm hire its first internal IT person?
The trigger is usually workload shape rather than a headcount number. A firm with steady daily attorney-facing demand, custom workflows, and multiple offices tends to need someone in the building, while a firm whose demand comes in bursts around deadlines gets more from coverage than from presence. Many firms make the first hire for proximity and keep a provider for coverage and security.
Is a hybrid or co-managed model actually cheaper?
Rarely cheaper than either model alone, and often better value. A firm pays for an internal person and a reduced provider scope, so the line-item total sits between the two, while coverage and documentation improve. The arrangement earns its cost when the boundary is written down, and it wastes money when both sides assume the other owns monitoring.
What does an internal IT hire actually cost a law firm beyond salary?
Total cost includes benefits and payroll tax, recruiting, the tooling and licensing an individual still needs, training to keep current, and coverage for the hours and weeks that person is not available. Firms comparing models should also account for the work that will still be outsourced, since a single hire seldom covers monitoring, after-hours escalation, and security documentation alone.
How do we test whether a provider genuinely understands legal work?
Ask which document management and practice management platforms they administer today and how many firms run each, how they define a filing-deadline incident and their response commitment for one, and what their escalation path is when the platform vendor is at fault. Particular answers indicate experience, and general answers about average response times indicate a generalist.
The Team Behind This Guidance
Mindcore has spent years supporting law firms and other organizations where a systems failure carries professional consequences rather than only lost productivity, including firms that run internal staff, firms that outsource entirely, and firms that split the work. That range is why we treat this as a coverage question instead of a staffing preference.
Matt Rosenthal, Chief Executive Officer at Mindcore, has made the same argument with legal clients for years, which is that a firm should decide this on what its week actually looks like rather than on what the category is supposed to cost. Our role is to help a firm map that week honestly and then choose, including the times when the right recommendation is to hire internally and buy less from us.
Map Your Firm’s Week Before You Decide
Read together, the five gaps point at one conclusion that a cost model cannot produce: this decision is settled by when your firm needs help and what it needs help with, and only then by what each option costs. A firm that knows its own demand shape can buy precisely, whether that means a hire, a provider, or a boundary drawn between them. A firm working from a salary figure and a monthly fee is guessing at the part that matters.
If two or three of those gaps are currently uncovered, that is the ordinary starting point and it is straightforward to fix. The useful next step is a short conversation about how your firm runs, which platforms carry a matter, and where your evenings and deadlines actually fall.
Book a free strategy call and our team will map your coverage against the five gaps and tell you plainly which parts belong to a hire, which belong to a provider, and which you can leave alone. If a firm would rather review the scope of a full managed IT services engagement first, that is a reasonable place to start.

