Free Resource · guide

What Should a Managed IT Agreement for a Law Firm Include?

A managed IT agreement for a law firm should put the essentials in writing: exactly what is covered, how fast support responds, how client confidences are protected, which security controls the provider implements and documents, how backups and data return work, and how the relationship ends. You read contracts for a living. Apply the same scrutiny to the one governing every client file your firm holds.

Attorneys spend their days marking up other people’s contracts, then sign IT agreements that would never survive their own redline. The document governing access to every client file, every privileged communication, and every deadline-critical system in the firm deserves at least the scrutiny you bill for. Here is what to demand before signing with any provider, ours included.

One caveat up front, and you already know it: this is practical guidance from an IT provider that supports law firms, not legal advice.

Does the agreement define scope, or just gesture at it?

You would never let a client sign a services agreement where the services are “support.” Yet that is what most managed IT proposals amount to. The agreement should enumerate what the monthly rate covers:

  • Which people, including of counsel, contract attorneys, and remote staff
  • Which devices, and law firms should count carefully here, because attorneys often run a desktop plus a laptop that travels to court
  • Servers and hosted systems, named
  • Email tenants and mailboxes
  • Network equipment, firewalls, and the office’s connection to the world
  • Your practice systems, in the sense that matters: the servers and workstations they run on, the backups behind them, and coordination with their vendors when a problem sits inside the application

That last point deserves precision. No IT provider operates your case management or document system the way your paralegals do, and one who claims to should worry you. What the contract can and should commit to is the environment those applications depend on, and direct vendor coordination so your staff never plays telephone between a help desk and a software company while a filing waits.

Ambiguity in a contract favors the drafter. The provider drafted this one.

What response can you actually enforce?

“We’re very responsive” is puffery, and you would strike it from any agreement a client brought you. The document should state:

  • Support hours, and what happens outside them
  • How your people reach a human, not just a ticket portal
  • How priorities are assigned, and where “the document system is down and our response is due at five” ranks
  • A stated response expectation for each priority level
  • The escalation path when the first response doesn’t resolve it

Be realistic about what you are asking for. Honest providers commit to response expectations and measured typicals rather than guaranteed fix times, because nobody can guarantee when a hardware failure resolves. What you should refuse to accept is a contract with no numbers at all. As a reference point, Braintek typically answers the phone in about 60 seconds and responds to emailed tickets in roughly 2 hours. Your provider’s numbers can be different. They cannot be absent.

How does the agreement protect client confidences?

Your duty of confidentiality does not pause because a third party administers your systems. The provider’s technicians can read anything on them, which makes the agreement’s confidentiality terms as important as any engagement letter your firm signs. Look for:

  • A confidentiality obligation binding the provider and every employee who touches your environment, wherever they sit
  • A commitment that firm and client data will not be used or disclosed outside of delivering the service
  • Access controls and logging, so you can answer the question “who at the vendor can see our files, and when did they”
  • Security on the provider’s own remote access tools, since those tools are a door into every matter you have

Then ask about breach notification. If the provider detects or suspects an incident touching your systems, the agreement should obligate them to tell you within a stated timeframe, describe what they know, and cooperate fully with your investigation, your insurer, and whatever notification duties fall on the firm. Those duties stay with you either way. What you are contracting for is speed and candor when it matters.

Ask any prospective provider where their support staff work and how access is governed. Braintek’s teams are in Houston, DFW, and the Philippines, and every technician operates under the same confidentiality obligations and logged access regardless of location. Whatever answer you get, it belongs in the contract, not in a reassuring email that binds no one.

Which security controls will they implement, and will they prove it?

Two forces now demand documentation from law firms: corporate clients sending outside counsel guidelines and security questionnaires, and cyber insurers whose applications double as audits. When either arrives, “our IT company handles that” is not an answer anyone accepts.

The agreement should name the controls the provider implements and maintains, at minimum MFA, encryption, endpoint protection, email security, patching, and monitoring, and should commit the provider to producing evidence: the reports and documentation showing each control exists and works. That paperwork is what fills out the client questionnaire and the insurance renewal. If supplying it is not a written deliverable, it is a future invoice.

This is one of the places two identically priced quotes quietly diverge, and one of the reasons to compare inclusion lists before rates. Our law firm IT support page describes how we structure these controls for a practice, and our pricing page shows the rate structure they live inside.

What do the backup and data return clauses actually say?

“Backups are included” would not survive your redline as a client’s counsel, and it should not survive as the client. The agreement should specify what is backed up, including email and the data behind your practice systems, how often, how long backups are retained, where copies live outside your office, whether restores are tested, and who is watching when a backup job fails. Check the retention window against your own file retention obligations; a provider’s default of 30 or 90 days may be far shorter than what your policies assume.

Then the clause that matters most on the worst day: data ownership and return. The agreement should state plainly that the firm owns all firm and client data, that administrative credentials and documentation belong to the firm, and that on termination everything comes back, in a stated format, on a stated timeline, at a stated cost, with the provider deleting its copies after handoff. You should leave with everything you arrived with plus everything created since, and the outgoing provider should be obligated to cooperate with the incoming one.

Exit terms are cheapest to negotiate when nobody is leaving. If a provider bristles at discussing them during courtship, believe what that tells you.

When should a firm walk away?

Some findings end the negotiation rather than shape it:

  • The provider will not put scope, response expectations, or exclusions in writing
  • Data ownership and return terms are missing, vague, or “handled case by case”
  • No confidentiality language exists until you request it
  • The contract is silent on breach notification
  • Auto-renewal with a punishing termination clause and no offboarding commitments
  • They will not show you their standard terms until late in the process

That last one is a useful early filter. We publish our client terms at braintek.com/legal so you can read them before the first meeting, which is exactly the posture you would want from anyone holding your clients’ files. Terms shown up front are harder to quietly change later.

Who does this for law firms in Houston and DFW?

Braintek has supported Texas businesses since 2002, with local teams in Houston and DFW. Fully managed support fits firms of roughly 10 to 50 people; larger firms usually do better co-managed, with internal IT handling the day to day while we cover security, projects, and escalations. If your firm is comparing agreements, or suspects the current one would not survive its own review, book a discovery call or send the contract over. We will tell you plainly what is covered, what is missing, and what to demand in writing.

Want a second set of eyes on an IT agreement?

Send us the proposal or contract your firm is reviewing. We'll mark up what's vague, what's missing, and what to demand in writing before you sign, whether or not you ever work with us.

By submitting, you agree to be contacted by Braintek about your inquiry.

FAQs

Who owns the firm's data if we fire our IT provider?

The firm does, and the agreement should say so without qualification. It should also state how data comes back on exit, in what format, how fast, and at what cost, plus when the provider deletes its copies. A provider who won't commit to data return in writing is showing you exactly how the breakup will go.

What response commitments should the agreement contain?

Whatever numbers the provider will sign, not whatever adjectives the salesperson used. "Responsive" and "unlimited" are not commitments. As a reference point, Braintek typically answers phone calls in about 60 seconds and responds to emailed tickets in roughly 2 hours. Those are measured typicals rather than guarantees, and other providers will differ. What matters is that their numbers appear in the document.

Should the agreement address attorney-client privilege and confidentiality?

Yes. Your provider's technicians can see everything on your systems, including privileged material. The agreement should bind the provider and every employee to confidentiality, state that firm and client data will not be used or disclosed outside the service, and describe how technician access is controlled and logged.

Will the provider supply the security documentation our clients and insurer demand?

Only if the agreement says so. Corporate clients now send outside counsel security questionnaires, and cyber insurance applications ask for evidence of MFA, backups, and monitoring. If producing that documentation isn't a written deliverable, expect to pay separately when the questionnaire lands the week an engagement is on the line.

What is normally excluded from a managed IT agreement?

Major projects like server migrations or office moves, hardware, software licensing, cabling, and after-hours project work are commonly billed outside the monthly rate. Exclusions are normal. Exclusions you first meet on an invoice are not, so get the list in writing and compare scopes before you compare prices.

What should make a firm walk away from an IT contract?

A provider who resists writing down scope, response expectations, or data return terms. Silence on breach notification. A confidentiality clause they have to draft after you ask. Any answer to "how do we leave" that starts with "that never comes up." You would tell a client to walk from a contract like that, so take your own advice.

How much does managed IT cost for a law firm?

As context, Braintek's managed IT runs about $150 to $250 per device per month plus $15 to $35 per mailbox, with shared mailboxes free and Microsoft licensing billed separately. Any provider's rate only means something once you can hold it against a written inclusion list.

Ready for IT that just works?

Book a no-pressure discovery call. We'll review your setup and show you exactly where you stand.