At 8:15 on a Monday morning, everything looks normal. Attorneys are opening files, staff is moving matters forward and no one is thinking about IT risk. A few hours later, a critical vendor is down, the person who knows the workaround is unavailable and no one is certain which alternative process has actually been approved.
Nothing about the firm’s environment appeared risky that morning. No breach alert was flashing and no system had been failing for weeks. The exposure was quieter: too much dependence on one platform, knowledge concentrated with one person and a recovery plan that had never been tested under real pressure.
That is where managing partners can misread IT risk. Stable systems create confidence, but they do not necessarily prove that the firm is prepared for disruption. The larger concern may be the collection of exceptions, workarounds and hidden dependencies that have gradually become part of how the firm operates.
When “Working” Gets Mistaken for “Prepared”
The most reassuring thing about a hidden weakness is that it rarely interrupts the workday. An aging application can keep opening files, a backup job can continue reporting success and an informal workaround can move matters forward, even when each has become a potential point of failure. Because no one is complaining and the work is still getting done, leadership has little reason to question what is happening beneath the surface.
Availability and resilience are not the same thing. Availability tells leaders that the technology environment is functioning today, while resilience shows whether the firm can restore the people, systems and workflows it depends on after an outage, failed update or vendor disruption.
An ABA report on law firm cybersecurity found that only 34% of respondents said their firms had an incident response plan. Even among firms with 50 to 99 attorneys, just 54% reported having one in place.
The same research cautions firms against treating a successful backup report as proof that recovery will work, recommending periodic test restores instead. Recovering files is only part of the equation. Attorneys also need functioning devices, access to critical applications and a clear process for continuing client work while the broader environment is restored.
For managing partners, the better question is not simply whether the firm has backups or a written response plan. It is whether the organization has proved that its most important work can continue when a familiar system, process or provider is suddenly unavailable.
When Technology Risk Gets Delegated Away
A capable internal IT team or outside provider can manage systems, implement controls, monitor threats and support users. What it cannot do is decide how much risk the firm is willing to accept, which exceptions are worth carrying or how much disruption is tolerable when a key system becomes unavailable.
Those are leadership decisions because they affect client service, revenue, professional obligations and the firm’s reputation. They also require trade-offs that extend beyond the technical details, including whether to replace an aging platform, fund a more resilient recovery model or continue relying on a vendor that has become difficult to replace. The ABA’s guidance on technology competence reinforces that distinction by stating that lawyers should understand the benefits and risks associated with relevant technology.
Managing partners do not need to know how every control works, but they should understand what the firm depends on, where material exceptions exist and whether anyone has verified the assumptions behind those decisions. Clear technology governance establishes who advises, who decides and who is accountable when the firm accepts an exception or postpones an investment. Delegating technical work is sensible. Delegating awareness of the business risk is not.
When Cybersecurity Becomes the Whole Risk Conversation
Cybersecurity deserves serious attention, but it is not the only way technology can create business risk. A failed migration, prolonged vendor outage, poorly adopted platform or undocumented workflow can interrupt client service without involving a cyberattack.
Technology risk can also show up through:
- Vendor concentration that leaves the firm with no practical alternative when a platform goes down
- Important processes that depend on one employee’s knowledge
- Poor adoption of systems the firm has already paid to implement
- Data and communications spread across disconnected repositories
- Inadequate training that leads users to create their own workarounds
Fragmentation creates another layer of exposure. When documents, communications and processes are spread across multiple products from multiple vendors, each with different workflows and ownership roles, the environment becomes harder to support and easier to misunderstand. Thomson Reuters has noted that technology can improve productivity but can also significantly complicate a firm when related functions are handled by disconnected products and providers.
For a law firm, the practical question is not only whether information is protected. Leadership also needs to understand whether attorneys and staff could keep working if a core application, device fleet or outside provider became unavailable at the worst possible time.
When Insurance Creates False Comfort
Cyber insurance can help absorb part of the financial impact of an incident, but it does not transfer the entire burden. The firm still has to restore systems, communicate with clients, manage deadlines, redirect staff and leadership time and rebuild confidence after the disruption.
Coverage also does not guarantee that every cost, delay or business consequence will be absorbed. Policies have limits, exclusions and conditions, while applications commonly require firms to describe the controls they have in place. Those answers need to reflect the firm’s actual environment rather than the controls leadership assumes are operating.
Insurance remains an important part of risk management, but it is a financial backstop rather than a recovery strategy. A policy cannot reopen a blocked workflow, complete a filing or make an untested response plan work under pressure.
When Security Gets Blamed for Friction
Lawyers and staff sometimes find work-arounds for controls that make routine work unnecessarily difficult. Personal accounts, unauthorized tools and one-off exceptions often begin as practical attempts to complete a task, then become part of the firm’s operating environment without formal review.
That does not mean stronger security always creates more friction. Well-designed controls can make approved tools easier to use, standardize access, reduce recurring support issues and eliminate uncertainty about where information belongs. Poorly designed restrictions create workarounds, while thoughtful design reduces the need for them.
Current NIST guidance treats the user experience as part of effective authentication, including the ability to recover when credentials or authenticators are lost. Security is more sustainable when people can understand the process and complete their work without inventing an alternate path.
For leadership, the better question is not whether security slows people down. It is whether the firm has designed its controls around the way legal work actually happens, and then trained users well enough that the approved path is also the practical one.
Better Visibility Leads to Better Decisions
Managing partners do not need to become technologists, but they do need enough visibility to separate confidence from evidence. A useful review should help leadership answer questions such as:
- What could prevent the firm from serving clients tomorrow even if its data remained intact?
- Which critical processes depend on one person, application or vendor?
- When did the firm last prove it could restore priority workflows rather than simply recover files?
- Which temporary exceptions have quietly become permanent?
The goal is not to eliminate every technology risk. It is to understand which risks the firm is carrying, who owns them and whether the organization is prepared when normal operations stop being normal.
Afinety helps law firms evaluate those questions across technology, security and business continuity, then turn the answers into practical priorities. To discuss where hidden exposure may exist within your firm, contact our team.

