Fire Your IT Guy If He Says This
Geek Heros War Stories
Your IT Provider Should Make You Safer, Not More Vulnerable
Not all IT providers are created equal. Some are genuinely competent, proactive, and invested in your firm's security. Others are coasting — collecting monthly fees while your infrastructure deteriorates and your risk exposure grows.
The problem is that most managing partners and office administrators don't have the technical background to evaluate their IT provider's competence. You trust them because they showed up, fixed things a few times, and speak with confidence. But confidence isn't competence, and some of the most confidently stated IT advice is dangerously wrong.
Here are six statements that should trigger an immediate conversation — or an immediate search for a new provider.
Red Flag #1: "You Don't Need MFA — It's Too Complicated"
What they're really saying: "I don't want to deal with the support tickets that come with rolling out MFA, so I'm going to convince you it's unnecessary."
The truth: Multi-factor authentication is the single most effective security control you can implement. Microsoft's own data shows that MFA blocks 99.9% of automated account compromise attacks. It's not optional. It's not "nice to have." It's the absolute minimum baseline for any organization that handles sensitive data.
Yes, there's a brief adjustment period when you first deploy MFA. Staff will have questions. Some will grumble. But a competent IT provider handles the rollout smoothly, provides clear instructions, and manages the transition in a way that minimizes disruption. An incompetent one avoids it entirely because they don't want to deal with it.
If your IT provider told you that you don't need MFA, they are either incompetent or lazy. Either way, your client data is at risk.
Red Flag #2: "Your Antivirus Is Enough"
What they're really saying: "I installed Norton/McAfee/whatever three years ago and I don't want to spend time or money upgrading to a real endpoint protection solution."
The truth: Traditional signature-based antivirus has been inadequate for years. Modern threats use polymorphic malware, fileless attacks, living-off-the-land techniques, and zero-day exploits that antivirus signatures will never catch. What you need is EDR — Endpoint Detection and Response — which uses behavioral analysis, machine learning, and real-time monitoring to detect and respond to threats that antivirus misses.
Every major cyber insurance carrier now requires EDR as a condition of coverage. If your IT provider is still telling you that antivirus is sufficient, they're either uninformed about current threat landscapes or they're avoiding the cost and complexity of deploying a proper EDR solution.
Red Flag #3: "We'll Fix It When It Breaks"
What they're really saying: "I don't do proactive monitoring or maintenance. I wait for things to fail, and then I charge you emergency rates to fix them."
The truth: This is the "break/fix" IT model, and it should have died a decade ago. Reactive IT management means your systems degrade slowly until they fail catastrophically — usually at the worst possible time (court filing deadline, trial preparation, month-end billing).
Proactive IT management includes continuous monitoring of system health, performance, and security. It means patching vulnerabilities before they're exploited, replacing hardware before it fails, and resolving issues before users even notice them. It costs more per month than having no one monitor anything, but it costs dramatically less than emergency service calls, data recovery, and lost productivity.
A provider who only shows up when things break has no incentive to prevent things from breaking. Think about that.
Red Flag #4: "Backups? We Have One Somewhere"
What they're really saying: "I set up a backup at some point in the past, I'm not sure if it's still running, and I've never tested whether it actually works."
The truth: Backups that aren't verified are not backups. They're hopes. We've encountered firms whose "backup" was an external hard drive that hadn't been connected in months. We've seen backup software that had been failing silently for weeks. We've seen backup repositories that were stored on the same server they were supposed to be backing up — which means if the server fails, the backups fail with it.
A proper backup strategy follows the 3-2-1-1-0 rule: three copies, two media types, one offsite, one immutable, zero errors in verification testing. Your IT provider should be testing full restores monthly and providing you with verification reports. If they can't tell you exactly when the last successful backup was, where it's stored, and how long a full recovery would take — you don't have backups.
Red Flag #5: "Compliance Isn't Really Our Thing"
What they're really saying: "I don't understand your industry's regulatory requirements, and I don't want to learn."
The truth: If you're a law firm, compliance IS your thing, which means it has to be your IT provider's thing too. ABA Model Rule 1.6 requires reasonable efforts to protect client data. Cyber insurance applications require specific technical controls. If your firm handles healthcare-related cases, HIPAA compliance adds another layer of requirements.
A generic IT provider who "doesn't do compliance" is leaving you exposed to regulatory penalties, insurance claim denials, bar complaints, and malpractice liability. Your IT provider doesn't need to be a lawyer, but they need to understand the compliance landscape for your industry and ensure that your technology meets the requirements.
Red Flag #6: "We Don't Need to Document Anything"
What they're really saying: "I keep everything in my head, and if I get hit by a bus, good luck figuring out your own network."
The truth: Proper IT documentation includes network diagrams, asset inventories, configuration records, password management (in an encrypted vault, not their personal memory), license tracking, and procedures for common tasks. If your IT provider walks out the door tomorrow — whether they quit, retire, or get fired — you should be able to hand that documentation to a new provider and have a smooth transition.
If your current provider can't produce comprehensive documentation of your environment on request, you're locked into a dependency relationship. That's not a partnership; it's a hostage situation.
What to Do Next
If your IT provider has said any of these things, it doesn't necessarily mean you need to fire them today. But it does mean you need to have a very direct conversation about their approach, their capabilities, and their willingness to meet the security and compliance requirements of a law firm.
If that conversation goes poorly — if they're defensive, dismissive, or insist that you're overreacting — then yes, it's time to make a change. Your client data, your ethical obligations, and your firm's future are too important to leave in the hands of someone who thinks antivirus is enough and backups are optional.
Not sure if your IT provider is up to standard? [Get a free site audit](#assessment) — we'll evaluate your current security posture and give you an honest, no-pressure report on where you stand.
Get Your Free Site Audit
Find out where your firm stands on security, compliance, and IT performance — at no cost.