What to Ask Before You Hire an IT Company for Your Law Firm
Geek Heros War Stories
Why This Matters More Than You Think
Choosing an IT provider for your law firm isn't like choosing one for an accounting firm or a dental practice. The stakes are fundamentally different. Your IT provider will have access to attorney-client privileged communications, litigation strategy documents, financial records, and personally identifiable information for hundreds or thousands of clients.
If they get it wrong, the consequences aren't a slow afternoon — they're malpractice claims, bar complaints, regulatory fines, and client trust that takes years to rebuild.
Here are the 10 questions you should ask before signing anything — and what the right answers sound like.
Question 1: Do You Specialize in Law Firms?
Why it matters: Law firms have unique technology requirements that generic IT providers don't understand. Practice management software, document management systems, e-filing requirements, trust accounting rules, and ethical obligations under ABA Model Rules are all foreign to a provider who primarily supports retail stores and medical offices.
The right answer: "Yes, law firms are our primary focus. We understand matter workflows, billing integrations, document retention requirements, and compliance obligations specific to legal practice."
Red flag: "We support all kinds of businesses." This means they'll be learning your industry on your dime.
Question 2: What's Your Average Ticket Response Time?
Why it matters: When an attorney can't access a document 30 minutes before a court filing deadline, a slow response time isn't acceptable.
The right answer: A specific number backed by data. "Our average first response time is under 30 minutes during business hours, and we handle standard tickets in order of urgency with transparent updates."
Red flag: "We get to things as quickly as we can." No SLA, no accountability.
Question 3: Do You Carry Errors & Omissions (E&O) Insurance?
Why it matters: If your IT provider makes a mistake that results in a data breach, you need to know they have insurance to cover the damages.
The right answer: "Yes, we carry E&O insurance with [specific coverage amount]. We can provide a certificate of insurance upon request."
Red flag: "We've never had anyone ask about that."
Question 4: What Happens When You Can't Fix Something?
Why it matters: Every IT provider will eventually encounter a problem they can't solve. What matters is their escalation process.
The right answer: "We have established escalation procedures with all major vendors. When an issue exceeds our first-line capabilities, we escalate within 2 hours and manage the vendor relationship on your behalf."
Red flag: "We'd probably refer you to the vendor." This means you'll be stuck playing telephone between your IT provider and your software vendor.
Question 5: Do You Help with Cyber Insurance Compliance?
Why it matters: Cyber insurance requirements have become dramatically more stringent. Your IT provider should be proactively ensuring that your technology meets carrier requirements.
The right answer: "Yes. We maintain documentation for all security controls that cyber insurers require: MFA deployment records, EDR status reports, backup verification logs, incident response plans, and training completion records."
Red flag: "That's really between you and your insurance company."
Question 6: How Do You Handle After-Hours Emergencies?
Why it matters: Court deadlines don't respect business hours. Ransomware attacks hit at 2:00 AM.
The right answer: "We have a defined after-hours emergency process. Critical issues are responded to within [specific timeframe]. We have on-call engineers available 24/7 for true emergencies."
Red flag: "You can leave a voicemail and we'll get back to you in the morning."
Question 7: What Legal Software Do You Support?
Why it matters: Your practice management system, document management platform, and billing software are mission-critical applications.
The right answer: "We support a wide range of legal software platforms and we learn your exact software stack during onboarding. During your free site audit, we document every tool your firm relies on so our team can support it from day one."
Red flag: If they have to Google your practice management software, they're not the right fit.
Question 8: How Do You Handle Onboarding?
Why it matters: The transition from one IT provider to another is one of the most critical — and risky — periods for a law firm.
The right answer: "We follow a structured onboarding process that typically takes 2-4 weeks. It includes a complete infrastructure audit, security deployment, staff training, and a parallel support period."
Red flag: "We can have you up and running by next week." If onboarding is too fast, corners are being cut.
Question 9: What Reporting Do We Get?
Why it matters: You should be able to see exactly what your IT provider is doing — and not doing.
The right answer: "You receive monthly reports covering all key metrics: tickets opened and resolved, average response times, security posture status, backup verification results, and patch compliance. We also provide quarterly strategic reviews with your leadership team."
Red flag: "We'll let you know if there's a problem." No proactive reporting means no accountability.
Question 10: What's Your Contract Structure?
Why it matters: Some IT providers lock firms into long-term contracts with heavy early termination fees.
The right answer: "Our standard agreements are annual, which allows us to properly implement and maintain security infrastructure. We offer month-to-month billing with a slight premium for flexibility. There are no hidden fees."
Red flag: "We require a 3-year commitment with a 50% early termination fee."
Why Generic MSPs Fail Law Firms
The pattern is consistent: a law firm hires a well-reviewed generic MSP. For the first few months, things seem fine. But then the cracks appear. The paralegal calls about a practice management integration that broke — the MSP has never seen the software. The attorney needs help with document management permissions — the MSP doesn't understand matter-based access control. The managing partner asks about ABA compliance documentation — the MSP has no idea what ABA Model Rule 1.6 requires.
Each of these incidents doesn't just waste time — it erodes confidence. The firm starts working around their IT provider instead of through them. Shadow IT proliferates. Security gaps widen. And the firm ends up in a worse position than before.
What the Right Provider Looks Like
The right IT provider for your law firm should feel like an extension of your team. They should understand your practice areas, your workflows, and your compliance obligations without needing them explained. They should proactively manage your security posture. They should attend quarterly reviews with your leadership, audit your technology spend, and plan your IT roadmap — not just fix things when they break.
At Geek Heros, we answer all 10 of these questions with confidence because law firms are all we do. Ready to see the difference? Contact us for a free site audit and we'll show you exactly what proper law firm IT looks like.
Get Your Free Site Audit
Find out where your firm stands on security, compliance, and IT performance — at no cost.