How Law Firms Should Evaluate an IT Provider
Choosing an IT company is hard when you’re not technical — and harder still for a law firm, where the wrong answer can compromise matter confidentiality and the ABA Model Rule 1.1 duty of technology competence. In southern Nevada that choice also has to survive real-estate closings, e-filing calendars, and the way a Henderson or Las Vegas docket actually moves. You can’t evaluate a provider’s technical skills directly, so you’re left judging based on how they make you feel — which is exactly how bad providers stay in business.
Here’s how to evaluate an IT company using questions any partner or office manager can ask, with answers you can verify.
Questions to ask before signing
”What does your onboarding process look like?”
A good provider has a documented process: inventory your equipment, audit your security, document your network, set up monitoring, configure backups. They should be able to describe this step by step.
Red flag: “We’ll just remote in and take a look.” That’s break/fix disguised as managed services.
”How will I know what you’re doing each month?”
You should get regular reporting — what was monitored, what issues were resolved, what patches were applied, what the backup status is. This isn’t optional. If they can’t show you a sample report, they’re not tracking it.
Red flag: “You’ll know we’re doing our job because nothing will go wrong.” That’s not accountability, that’s a trust exercise.
”Who do I call when something breaks?”
You should get a direct number or email that reaches a technician who knows your environment. Ask what the average response time is.
Red flag: “You’ll submit a ticket through our portal and someone will get back to you.” That’s fine for routine requests, but if your server is down, you need to talk to a human now.
”What’s included and what costs extra?”
Get this in writing. Some providers include everything in a flat fee. Others have a base fee with hourly charges for “out of scope” work. Both models can work, but you need to know which one you’re signing up for.
Red flag: Vague language about what’s included. If they can’t give you a clear list, expect surprise invoices.
”What security tools do you deploy?”
They should be able to name specific products: which endpoint protection, which email security, which backup solution. “We use best-in-class tools” is a non-answer.
Red flag: They can’t name their security stack, or they don’t include security in their managed services offering. Security bolted on as an upsell means it’s not part of their standard practice.
”What happens if we want to leave?”
Your data, your documentation, your passwords — all of it should come with you. Ask specifically about offboarding. A confident provider isn’t worried about this question.
Red flag: Long-term contracts with no exit clause, or any suggestion that “it would be complicated to transition away.”
What good service looks like in practice
Once you’re working with a provider, here’s what separates good from adequate:
- They know your environment. When you call, they don’t ask what kind of server you have. They already know.
- Problems get caught before you notice. You get an email saying “we noticed your backup failed and fixed it” — not a call from you saying “something seems wrong.”
- Reports are regular and understandable. Monthly or quarterly, in plain language, showing what happened and what’s coming.
- They push back. A good provider tells you when your idea is bad, when your equipment needs replacing, and when you’re underinvesting in security. They’re an advisor, not a yes-man.
The bottom line
You don’t need to understand networking to evaluate an IT company. You need to evaluate their process, their communication, their transparency, and their willingness to be held accountable.
If your current provider can’t answer these questions clearly, it might be time to have a different conversation.