Choosing a Managed IT Provider for Your Law Firm: 11 Questions That Go Beyond the Sales Pitch

By

Take three managed IT proposals, cover up the company names and read the first few pages. There’s a good chance they’ll sound remarkably similar. Cybersecurity. 24/7 support. Microsoft 365. Backups. Cloud. Strategic guidance. Maybe a promise to be “proactive” for good measure. None of those things is unimportant. They’re just not particularly useful for figuring out what it will actually be like to work with the provider.

For a law firm, the better evaluation starts one level deeper. Who takes responsibility when a problem crosses multiple vendors? What does 24/7 support actually mean? Can the provider show how its own security controls are tested? And after you hire them, how much technology coordination is still going to land on the firm administrator, COO or internal IT team? Those are the questions that start separating one managed service provider (MSP) from another.

Start with fit, not the service list

1. Can the provider demonstrate that it understands firms like yours?

Plenty of MSPs can say they serve law firms. Ask what that means. How many clients are similar to your firm in size, application mix and internal IT structure? Which document management, practice management and legal-specific applications does the team routinely encounter? Can the provider give you a reference from a firm whose environment actually resembles yours?

This matters because the issue isn’t simply whether an MSP recognizes the names of your applications. Law firms increasingly operate across interconnected systems, repositories and cloud services, and that technology complexity can create its own operational burden.

Legal specialization alone does not guarantee a good fit. Comparable experience, technical capability and a clear understanding of how your people work are much better tests.

2. Where does the provider’s responsibility stop and yours begin?

This is especially important for firms with internal IT. A fully managed model may make sense when an outside provider will own most day-to-day technology operations. A co-managed arrangement can work better when the firm already has capable internal resources but needs additional coverage, security expertise, project capacity or escalation support.

The ABA’s technology research found that 56% of respondents at firms with 10-49 attorneys turn first to internal technical staff when problems arise, rising to 96% at firms with 100 or more attorneys. Before signing, clarify who owns Microsoft 365, security, procurement, vendor management, user onboarding, projects and long-term planning. You do not want to discover six months later that you are paying an MSP and still serving as a referee.

3. What happens when a problem crosses multiple vendors?

Ask for an example, not a promise. If an attorney cannot open a document and the issue could involve Microsoft 365, the document management system, a plug-in or the desktop environment, who coordinates the investigation? Who opens tickets with the other vendors? Who communicates with the user? Most important, who stays accountable until the problem is resolved?

That question has become more relevant as law firms work across a mix of SaaS applications, desktop software and cloud environments. The MSP does not have to own every application. Your firm should not have to own every escalation.

Ask for evidence, not security buzzwords

4. What can the provider show you about its own security controls?

A row of security logos should prompt more questions, not end the conversation. SOC 2, ISO 27001, the NIST Cybersecurity Framework and PCI DSS all serve different purposes. For example, SOC 2 is an independent CPA assurance report covering specified controls and criteria within a defined scope. It is not a blanket security certification.

When a provider presents a report, certification or framework, ask:

  • What exactly is it?
  • What services and systems are in scope?
  • How current is the evidence?

You do not need to become an auditor. You do need to know whether the proof actually supports the claim being made.

5. Can the provider support the security requirements your firm has to answer for?

The administrator’s security job often extends beyond deciding whether multifactor authentication is turned on. Your clients may send security questionnaires. A cyber insurer may request information about controls. Firm leadership may want evidence around Microsoft 365, endpoint security or administrative access. Someone has to know where that information lives and who is responsible for maintaining it.

Ask whether the MSP can provide clear documentation of the controls it manages, identify responsibilities that remain with the firm and support requests for security evidence without sending you on a scavenger hunt across five vendors.

Microsoft 365 deserves particular attention because protecting access is only one layer. Microsoft’s current guidance describes using identity, device and risk signals to make access decisions, and firms should also understand how suspicious activity is monitored after authentication.

6. What will recovery actually look like for your firm?

“Your data is backed up” is a starting point. Ask which systems would be restored first. Who determines those priorities? How are restores tested? Who communicates with attorneys and staff? When was the provider’s recovery process last tested and what changed as a result?

NIST’s current incident response guidance connects preparation, detection, response and recovery rather than treating backup as a standalone activity. Your firm does not need a universal recovery-time number pulled from an MSP brochure. It needs recovery expectations that reflect the systems your attorneys and staff actually depend on.

Find out how the relationship works after the sale

7. What happens after someone opens a support ticket?

Most MSPs will gladly tell you their response time. Ask what happens next. How are issues prioritized? When does a ticket escalate? What happens when the first technician cannot solve it? How are recurring problems identified instead of repeatedly closed as individual tickets? That last question matters. The ABA found that technology problems sometimes hurt productivity for 47% of respondents and “often” or “sometimes” affected 56% of respondents at firms with 10-49 attorneys.

Ask what reporting you will receive on recurring issues, escalation trends and resolution. A useful MSP should be able to tell you when ticket No. 14 is no longer a support problem and has become an underlying technology problem.

8. What exactly happens when you switch providers?

Ask the prospective MSP where transitions typically get difficult. What happens when the outgoing provider’s documentation is incomplete? Who identifies applications or vendor relationships nobody documented? How are administrative credentials transferred and verified? Who deals with cleanup that surfaces 30 or 60 days after cutover?

The technical inventory matters: users, endpoints, applications, licenses, security tools, backups and vendors all need to be accounted for. But so does the human side. Attorneys and staff need to know what is changing, where to get support and what they need to do differently. A provider that has done this repeatedly should be able to describe the messy parts, not just promise an easy transition.

9. How predictable will your IT budget actually be?

Instead of asking which proposal has the lowest monthly fee, pressure-test the price. What happens when you add 10 attorneys? Open another office? Replace hardware? Need an after-hours project? Increase cloud storage? Add security services? Migrate a major application? Ask what is included in recurring fees, what becomes a project and what triggers additional charges. Also clarify ownership of documentation, administrative credentials and transition assistance if the relationship eventually ends.

Your counsel can advise on specific contract terms. From an operational standpoint, the goal is to understand where the budget can move before it does.

Look at what happens over the next several years

10. How will the provider turn what it learns about your firm into better technology decisions?

Almost every MSP promises some form of technology guidance. Ask what that actually produces. Will recurring support issues influence the technology roadmap? Will the provider identify redundant applications or aging systems? How will upcoming projects and security investments be reflected in budgeting?

And here is a useful test: Will they ever tell you not to buy something? The same applies to AI. The MSP should not decide how attorneys use AI in legal work, but IT has a role in managing approved tools, access, security and the underlying technology environment. As AI use spreads beyond formal pilots, those responsibilities are becoming harder to separate from everyday technology management.

11. How will you know a year from now whether the relationship is working?

Define success before the contract is signed. Depending on your firm, that might include fewer recurring issues, better resolution trends, fewer escalations, more predictable budgeting, progress on security priorities or more capacity for internal IT. The exact measurements matter less than agreeing on them and reviewing them regularly.

Ask who will sit down with your firm to review performance, how often those conversations happen and what changes when something is not working. References and case studies are useful during selection, but ongoing accountability is what tells you whether you chose well.

A good MSP should reduce what your firm has to manage

The strongest provider may not have the lowest price, the longest service list or even the most law firm logos on its website. The best fit is the provider that understands your environment, makes responsibilities clear and can show how it performs when technology gets complicated. Ultimately, one question cuts through much of the sales language: Will this relationship reduce the amount of technology coordination your firm has to carry, or simply give you another vendor to manage?

If you are comparing providers, it can also be useful to see how other law firms have approached similar decisions. Afinety’s law firm case studies look at provider transitions, ongoing support and technology changes across firms with different needs.