Most visitors decide in 5 seconds whether they understand what you do. Ours is a free, no-pressure look at your site.

Behind the ScenesMSPCultureHow-To

Day in the Life — MSP Owner Servicing Law Firms

Patryk Stanczak, Founder & CEOFebruary 17, 20268 min read
GH

Geek Heros War Stories

5:00 AM — The Dashboard Check

My alarm goes off at 5:00 AM. Before coffee, before brushing my teeth, before anything — I check the monitoring dashboards on my phone. This isn't discipline; it's paranoia that's become habit.

The dashboard shows the real-time status of every system we manage across all of our law firm clients. Green means healthy. Yellow means attention needed. Red means something is wrong right now. This morning: all green except one yellow — a backup job at a family law firm took longer than usual overnight. Not a failure, just slow. I make a mental note to check the backup repository size; it might need expansion.

By 5:15 AM, I've scanned the overnight security alerts. Our EDR platform flagged two events — both false positives (a legitimate software update that triggered a behavioral detection). I verify, dismiss them, and make coffee.

This morning routine takes about 15 minutes. It's the most important 15 minutes of my day, because it tells me whether the next 14 hours will be planned work or crisis management. Today, it's planned work. That's a good day.

7:00 AM — Microsoft 365 Migration Planning

First meeting of the day: a planning session with a 40-person litigation firm that's migrating from an on-premise Exchange server to Microsoft 365. This is a project we've done dozens of times, but every firm is different. This firm has partners who've been using Outlook the same way for 15 years and are deeply suspicious of change.

The meeting covers the migration timeline (we do it over a weekend to minimize disruption), the training plan (we schedule 30-minute small-group sessions because attorneys won't sit through a 2-hour webinar), and the communication strategy (the managing partner will send a firm-wide email explaining why the migration is happening and what to expect).

The most important part of the meeting is managing expectations. I explain that for the first week after migration, there will be questions. Lots of questions. "Where did my folders go?" "Why does my calendar look different?" "Why can't I find the email I filed in 2019?" We have answers for all of these, but the first week is always bumpy. Setting that expectation now prevents panic later.

10:00 AM — Security Awareness Training

I'm on-site at a 20-person estate planning firm, running a security awareness training session. This is one of my favorite parts of the job, because it's where you can see the lightbulb moments happen in real time.

Today's session covers phishing identification. I show real phishing emails we've collected (with sensitive information redacted) and walk the staff through the red flags: mismatched sender domains, urgent language designed to bypass critical thinking, links that go to unexpected URLs, requests for credentials or financial information.

The best moment comes when a legal assistant raises her hand and says, "Wait — I got an email exactly like that last week. I clicked the link but didn't enter anything. Should I be worried?" We discuss it, check her account, verify nothing was compromised, and use it as a teaching moment for the whole group.

Security awareness training isn't a one-time event. It's an ongoing program. But sessions like this — interactive, relevant, using real examples from the legal industry — are dramatically more effective than the typical corporate training video that everyone clicks through without watching.

12:00 PM — New Client Network Assessment

Lunch is a protein bar eaten while driving to a prospective client's office. They're a 30-person personal injury firm that's been unhappy with their current IT provider and reached out after reading one of our blog posts about phishing simulations.

The network assessment is methodical. I connect our scanning tools and spend about 90 minutes collecting data: network topology, device inventory, software versions, security configurations, backup status, user account permissions, and firewall rules.

While the scans run, I walk through the office. I'm looking at physical security too: server room access (who has the key?), clean desk policies (any sensitive documents left out?), USB ports (any unauthorized devices connected?), and general infrastructure condition.

Initial observations: their firewall is two firmware versions behind, three workstations are still running Windows 10 past end-of-life, and the "server room" is actually a corner of the break room behind a folding screen. I take notes. I'll compile everything into a formal assessment report this week.

2:00 PM — The Printer Call

My phone rings. It's the office manager at one of our long-time clients — a small family law practice. She's frantic.

"The printer won't print. The attorneys need documents for a 3:00 PM filing. Can someone come right now?"

I pull up the printer's remote management dashboard while she's still talking. Status: offline. I check the network — the printer's IP address isn't responding. I ask her to check if the printer is turned on. It is. I ask her to check the cable. "What cable?" I describe the ethernet cable — the one that connects the printer to the network jack in the wall.

Silence. Then: "Oh. It's not plugged in. The cleaning crew must have knocked it out last night."

She plugs it in. The printer comes online. Documents start printing.

Total resolution time: 4 minutes. This is probably 30% of all "emergency" printer calls. I'm not complaining — it's part of the job, and she needed those documents. But it's a reminder that not every IT crisis is a cyber attack. Sometimes it's just a cable.

4:00 PM — BCDR Plan Development

Back at my desk, I'm writing a Business Continuity and Disaster Recovery plan for a mid-size commercial litigation firm. This is detailed, technical work that requires concentration — which is why I schedule it for late afternoon when the urgent calls typically slow down.

The BCDR plan covers everything: recovery time objectives (how fast each system needs to be back online), recovery point objectives (how much data loss is acceptable), backup architecture (what gets backed up, where, how often), disaster scenarios (ransomware, hardware failure, natural disaster, insider threat), and step-by-step recovery procedures for each scenario.

I'm also documenting the testing schedule. We'll conduct a full recovery test quarterly, simulating a complete system failure and verifying that every critical system can be restored within the defined timeframes. The first test is scheduled for next month.

This plan is 28 pages long when finished. It's not glamorous work. Nobody's going to frame it on their wall. But when the 2 AM call comes — and it will, eventually — this document is the difference between a four-hour recovery and a four-day catastrophe.

6:00 PM — Compliance Checklist Review

End of the day, and I'm reviewing a client's cyber insurance renewal application. The carrier is asking 47 specific questions about the firm's security posture: Do you have MFA? Do you have EDR? Do you have immutable backups? Do you have an incident response plan? Do you conduct regular security training?

Because we manage this firm's IT, I can answer every question with confidence and provide evidence to support each answer. MFA enabled on all accounts — here's the configuration report. EDR deployed on all endpoints — here's the deployment summary. Immutable backups with monthly testing — here's the most recent test result.

This is the part of the job that doesn't make for exciting storytelling, but it's critically important. A properly completed insurance application — backed by evidence — gets better coverage at lower premiums. An incomplete or inaccurate application can result in claim denials when the firm needs coverage most.

8:00 PM — Winding Down (Sort Of)

Dinner with my family, then one more check of the monitoring dashboards. All green. The backup job that was slow this morning completed successfully — just a larger-than-usual data set. No action needed.

I scan my email one more time. A client's attorney sent a message at 7:45 PM asking about a slow application. It's not urgent, but I send a quick reply acknowledging the issue and letting him know we'll look at it first thing tomorrow. Response time matters — even when the issue isn't critical, the client knowing that someone is paying attention makes a difference.

Tomorrow: another assessment, another training session, probably another printer. And maybe — hopefully not, but maybe — a 2 AM call that makes all of the preparation worth it.

Why This Matters

I share this not to complain — I genuinely love this work — but to illustrate what proper managed IT looks like from the inside. It's not just fixing things when they break. It's the 5 AM dashboard checks, the BCDR plans, the compliance reviews, the phishing simulations, and the patience to talk someone through a printer cable at 2 PM.

If your IT provider doesn't do most of what I described in this post, ask yourself: what are they actually doing between your emergency calls?

Curious what proactive IT management looks like for your firm? [Get a free site audit](#assessment) and experience the difference.

Get Your Free Site Audit

Find out where your firm stands on security, compliance, and IT performance — at no cost.

Related Articles

Ready to see where your brand stands?