Plenty of firms run without dedicated IT support and get away with it for years. The machines work, email flows, and the occasional problem gets solved by whoever in the office is best with computers. From the inside it looks like a sensible saving.
What makes law firms different is not that they have more outages. It is that the same incident carries consequences other businesses do not face. An IT failure at most companies is an operational cost. At a firm it can be a professional-conduct matter, an insurance problem, and an evidentiary one simultaneously, and none of those appear in a downtime calculation.
This is not an argument that every firm needs a full outsourced arrangement. It is an accounting of what the risk actually consists of, so the decision gets made on real numbers.
1. Technology Competence Is a Professional Obligation
Start here, because it is the exposure most often treated as somebody else’s department.
Confidentiality is not merely good practice for a firm, it is an ethical duty enforced by bar associations, regulators, and your malpractice insurer. The ABA Model Rules require lawyers to make reasonable efforts to prevent unauthorised disclosure of client information, and the duty of competence is generally understood to extend to understanding and managing the technology risks involved. The practical consequence is significant: a breach that a reasonable safeguard would have prevented can be a professional-conduct issue in addition to a civil liability.
That changes who owns the problem. “Our IT was not set up properly” is a mitigation in most industries and something closer to an admission in this one. It also changes the standard, because reasonable efforts is measured against what competent firms do, which moves over time as controls become standard.
Which is why the arrangement matters less than whether somebody is accountable for it. A firm with a documented, reviewed setup is in a defensible position. A firm relying on whoever is good with computers has no record of having made reasonable efforts, even if the setup happens to be sound. Our guide to what to look for in managed IT services for law firms covers what that accountability looks like in practice.
2. Downtime Is Priced in Billable Hours
Most businesses count an outage in lost productivity, which is a soft number. A firm counts it in billable hours, which is not.
The arithmetic is unforgiving. Take a twenty-attorney firm at a few hundred dollars an hour and a single lost day runs into the tens of thousands in billings that cannot be recovered, because the hours do not exist to be billed later. Then add the part nobody counts: it takes people a surprisingly long time to fully re-engage with detailed work after an interruption, so an outage costs more than the minutes the systems were actually down.
Two features make firms worse off than the raw number suggests. The work is deadline-bound, so time lost cannot always be shifted. And it is concentrated in expensive people, meaning an outage affecting ten attorneys costs several times what the same outage costs a company with ten administrative staff.
Set that against the cost of support and the comparison usually resolves quickly. A single serious incident a year tends to exceed the annual cost of the arrangement that would have prevented it, which is the calculation our overview of help desk support for law firms works through.
3. Your Cyber Insurance Now Requires Attestations
This one has changed recently and catches firms out.
Carriers have moved from asking general questions to requiring specific controls. Current renewals commonly want evidence of multi-factor authentication on every account, endpoint detection and response deployed on servers as well as laptops, and immutable backups with a documented restore test.
The risk is not only being declined at renewal. It is answering the application inaccurately. If you attest to a control you do not actually have in place everywhere, a claim can be denied on the basis of misrepresentation, which means you have been paying premiums for coverage that will not respond when you need it. That is a worse position than being uninsured, because you planned around protection you did not have.
Answering these questions accurately requires someone who knows the current state of every account and every server, not a best guess. Firms discover the gap at claim time, which is the most expensive moment. The controls themselves are also where a managed security arrangement earns its keep, since managed security services exist precisely to keep that evidence current rather than reconstructed annually.
4. Filing Deadlines Do Not Accept Excuses
Fourth is the exposure that has no equivalent in most industries. A retailer losing a day loses a day of sales. A firm losing the wrong day can miss a court-imposed deadline, and courts are not obliged to care that your document system was unavailable.
This is a narrow risk that is severe when it lands. It also concentrates predictably, since filing activity clusters around known dates, which means the cost of an outage is not uniform across the calendar. An hour of downtime on a quiet afternoon and an hour on a filing deadline are the same outage and very different events.
Practically, this argues for two things beyond general reliability: knowing how quickly you could restore access to matter documents specifically, and having a tested way for attorneys to work when the primary system is unavailable. Both are ordinary requirements that go unexamined until they are needed.
5. Legal Hold Turns Routine Cleanup Into a Problem
The last exposure is the subtlest and the one most likely to be created by well-meaning automation.
Standard IT hygiene says that when someone leaves, you disable the account, archive the mailbox, and reclaim the licence. That is correct almost everywhere. At a firm, if that person’s mailbox contains material relevant to a matter under a preservation obligation, the routine cleanup is exactly the wrong action, and it is the kind of thing that gets done automatically by anyone competent who has not been told.
The same applies to retention generally. Matter data has retention requirements that outlast employment, client relationships, and often the software the data was created in. A firm without deliberate retention configuration is either deleting things it should keep or keeping everything indefinitely, and the second is a liability too, because material you still hold is material that can be requested.
Getting this right needs the IT arrangement and the firm’s obligations connected. Somebody must know which departures are ordinary and which are not, which requires a channel between practice management and whoever administers the systems. Our note on Microsoft 365 management for law firms goes further into the retention and sharing side of that platform specifically.
What Firms Usually Get Wrong About the Decision
Two framing errors show up repeatedly.
The first is treating this as a purchase rather than an accountability question. The useful question is not which provider to hire, it is who is answerable for confidentiality controls, insurance attestations, restore capability, and retention. Sometimes the right answer is internal, particularly at larger firms, and the model matters less than the absence of a gap. A co-managed arrangement suits firms that have internal capability but want the security and continuity pieces covered properly.
The second is comparing the cost of support against a normal year. Support is not priced against the year where nothing happens. It is priced against the ethics complaint, the denied claim, the missed deadline, and the spoliation argument, all of which are low-probability and high-consequence. That is the same reasoning a firm applies to its own malpractice coverage, which no partner would drop on the grounds of not having needed it recently.
If you want a straight assessment of where your firm currently stands on those five exposures, our managed IT services team does exactly that review, and our note on choosing a provider for firms in New Jersey covers what to ask. Book a free strategy call and we will start with your insurance attestations, since that is usually where the largest undiscovered gap sits.
Frequently Asked Questions
Is IT security really an ethics issue for a law firm?
Yes. Confidentiality is an ethical duty rather than only a business preference, and the duty of competence is generally understood to extend to managing technology risk. A breach that a reasonable safeguard would have prevented can therefore raise a professional-conduct question alongside civil liability.
How should a firm calculate the cost of downtime?
In billable hours rather than productivity, since those hours cannot be recovered later. Multiply affected fee earners by their rate by the hours lost, then allow extra for how long detailed work takes to resume after an interruption, and weight it by whether the outage lands near a filing deadline.
What controls do cyber insurers ask law firms to confirm?
Commonly multi-factor authentication on every account, endpoint detection and response on servers as well as laptops, and immutable backups with a documented restore test. Attesting to a control you do not actually have everywhere risks a claim being denied for misrepresentation.
Why is offboarding riskier at a law firm?
Because standard cleanup can destroy material subject to a preservation obligation. Disabling the account, archiving the mailbox, and reclaiming the licence is correct almost everywhere, and is exactly wrong when that mailbox holds matter material under legal hold.
Does a small firm need a full managed IT arrangement?
Not necessarily. The requirement is that somebody is accountable for confidentiality controls, insurance attestations, restore capability, and retention, and can show it. Smaller firms often start with a co-managed arrangement covering the security and continuity pieces while keeping day-to-day support internal.

