Legal
Before choosing an IT provider, ask for at least 3 references from law firms comparable to yours in attorney count, practice areas, work model, and technology stack. Speak with firm leaders directly about response quality, cybersecurity, legal software support, recovery performance, communication, and whether the provider prevents problems rather than simply closing tickets.
In This Article
- Which legal-client references are most relevant to our firm?
- What should we ask legal-firm references about confidential information and cybersecurity?
- How do we verify support quality instead of accepting a polished testimonial?
- Which questions reveal whether an IT provider understands legal technology and business continuity?
- How should we conduct reference calls and compare the answers?
- Frequently Asked Questions
Which legal-client references are most relevant to our firm?

“John brought the right knowledge to my issue and resolved it in about a reasonable amount of time. I walked away confident the problem was actually fixed.”
The strongest reference is not necessarily the provider’s largest or most recognizable client. It is a law firm facing conditions similar to yours: a comparable number of attorneys and staff, similar reliance on Microsoft 365, a document management system, time-and-billing tools, remote work, and confidential client communications.
Ask for references from firms that resemble your operational reality. A litigation firm with courtroom travel, a real estate practice managing high-volume transactions, and a family-law firm handling sensitive client records can all have different support and security needs. Similarity makes the reference more useful than prestige.
For Norcross and greater Atlanta firms, also prioritize references from organizations that support multiple locations, hybrid attorneys, or clients across the I-85 corridor. Reliable connectivity, secure remote access, VoIP, and responsive onsite help can matter as much as a provider’s cybersecurity sales presentation.
Ask whether the reference firm has worked with the provider long enough to experience more than initial onboarding. A relationship of at least 12 months is usually more revealing because it can cover recurring maintenance, employee changes, security incidents, technology planning, and real support demand.
Takeaway: Request references that match your firm’s risk profile and daily workflow, not generic business testimonials.
What should we ask legal-firm references about confidential information and cybersecurity?
Start with the practical question: does the provider understand that a law firm’s information is not ordinary business data? References should be able to describe whether the provider protects attorney-client privilege, work product, conflict-check data, financial records, client portal access, and mobile communications without creating unnecessary friction for attorneys.
Ask how the provider handles phishing, compromised accounts, lost devices, ransomware concerns, and suspicious sharing activity. Do not settle for a vague answer that the provider “takes security seriously.” Ask what happened when a real concern arose, who communicated with leadership, and whether the firm understood the next steps.
References should also explain whether security recommendations were tied to the firm’s actual environment. Useful examples include conditional access, multi-factor authentication, mobile device management, backup protection, secure remote access, and permission reviews around matter-related files. The goal is thoughtful risk reduction, not a list of products.
Cyber liability underwriting and outside counsel guidelines increasingly make security conversations more specific. Ask whether the provider helped the firm prepare for questionnaires, document controls, or client security expectations, and whether recommendations were explained in business terms rather than dropped on the office as a technical checklist.
For firms evaluating local support, review how cybersecurity services for business environments connect security controls to practical attorney and staff workflows.
Takeaway: A worthwhile legal reference can describe how the IT provider protected sensitive information when the pressure was real.
Ask every reference whether the provider has supported the firm through at least 1 urgent security, outage, or recovery event.
How do we verify support quality instead of accepting a polished testimonial?
Ask references for specific examples of support interactions. Find out how the provider responded when an attorney could not access a document before a hearing, a practice-management platform stopped working, a new employee needed access quickly, or a network issue interrupted client calls. Details reveal more than a five-star rating.
Ask who owns communication during an incident. A dependable provider should keep the firm informed in language a managing partner, administrator, or office manager can use to make decisions. Silence, repeated handoffs, and unexplained delays are operational risks even when the technical problem is eventually solved.
Ask whether technicians communicate respectfully with users who are not IT specialists. Harold, a media client, described the experience this way: “Cain responds quickly, knows his stuff, and solves problems fast. He never makes me feel behind on technology.” That standard matters in a law office, where staff should be able to report issues early without embarrassment.
Also ask whether the provider follows up after resolving an issue. A permanent fix may require correcting an underlying configuration, updating documentation, training a user, or identifying a recurring pattern. Fast ticket closure is useful; preventing the same disruption from returning is more valuable.
For a clearer view of what proactive ongoing support can include, compare your expectations with managed IT services for small and mid-sized businesses.
Takeaway: The best references can point to concrete moments when the provider was responsive, clear, capable, and accountable.
Which questions reveal whether an IT provider understands legal technology and business continuity?
Legal IT support must extend beyond laptops and password resets. Ask references whether the provider could support or coordinate with the firm’s practice-management, case-management, document management, e-discovery, time-and-billing, and secure client portal platforms. The provider does not need to own every application, but it should know how to troubleshoot across vendors.
Ask what happens if the firm loses access to files, email, phones, or its office network. A reference should be able to explain whether the provider had documented recovery priorities, communicated clearly during disruption, and restored the systems that mattered most to client service and deadlines.
Backup is only useful if recovery is possible and understood. Ask whether the provider regularly discusses recovery expectations, account access, remote-work contingencies, and business continuity planning with firm leadership. Avoid providers whose only answer is that backups exist somewhere.
Ask about onboarding and offboarding as well. Legal firms need reliable access changes when attorneys, paralegals, contractors, and staff join or leave. Weak offboarding can leave old accounts, devices, documents, or client information exposed long after an employment change.
| Reference topic | Question to ask | Strong answer sounds like |
|---|---|---|
| Legal applications | Did the provider understand your practice and document workflows? | They coordinated with vendors, identified the source of issues, and protected daily work. |
| Recovery | What happened during an outage, data issue, or security concern? | They communicated priorities, restored critical services, and documented next steps. |
| Remote work | Can attorneys work securely from home, court, and client sites? | Access is secure, reliable, and practical rather than overly restrictive. |
| Account controls | How are hires, departures, and permissions handled? | Changes are prompt, documented, and aligned with least-privilege access. |
Explore how data backup and recovery planning can support resilient access to the information your firm depends on.
Takeaway: Ask references whether the provider protected the firm’s ability to serve clients, not merely its hardware.
How should we conduct reference calls and compare the answers?
Do not email a generic questionnaire and treat a few positive replies as due diligence. Schedule short calls with a managing partner, firm administrator, operations leader, or another person who experiences both strategic guidance and day-to-day support. Give each person room to answer candidly.
Use the same core questions for each reference, then compare responses side by side. Look for consistency in communication, support ownership, security maturity, legal-software awareness, and planning. One glowing reference is encouraging; three references that independently describe the same strengths are stronger evidence.
- Ask the provider for 3 legal-client references, including one comparable in size and complexity to your firm.
- Request contacts who can discuss both leadership-level planning and everyday support, not only the original buyer.
- Ask for one example of an urgent incident, one recurring problem, and one proactive improvement.
- Listen for specifics: timelines, communication, decision-making, and the lasting result.
- Ask what the reference wishes it had known before starting the relationship.
- Document answers using the same criteria before comparing providers.
Be alert to a provider that supplies only references from unrelated industries, only brand-new customers, or only contacts who cannot discuss security and service experience. That does not automatically disqualify a provider, but it limits what you can verify.
A legal IT relationship should be measured by trust over time. Madhav, a professional-services client, said, “John brought the right knowledge to my issue and resolved it in about a reasonable amount of time. I walked away confident the problem was actually fixed.” Confidence in the lasting resolution is the point of your reference call.
Takeaway: Compare evidence from structured conversations, not marketing claims or isolated online reviews.
Frequently Asked Questions
How many legal-client references should we request from an IT provider?
Request at least 3 legal-client references whenever possible. One should resemble your firm in size, technology needs, and work model. Ask for contacts who have worked with the provider for at least 12 months and can discuss support, cybersecurity, communication, planning, and an actual operational challenge.
What should a law firm ask an IT provider’s references about cybersecurity?
Ask how the provider responded to phishing, suspicious account activity, ransomware concerns, lost devices, or accidental file sharing. Ask whether recommendations protected attorney-client privilege and work product without burdening attorneys. Strong references provide specific examples of communication, response ownership, preventative improvements, and business impact.
Should we only ask for references from other law firms?
Legal-client references should be your first priority because they reveal familiarity with confidential records, document workflows, court-related mobility, and practice software. References from healthcare, financial, or other regulated organizations can add useful context, but they should not replace evidence that the provider understands a law firm’s day-to-day realities.
What is a red flag during an IT provider reference call?
A red flag is a reference that offers only broad praise but cannot describe a real support event, security concern, communication process, or lasting improvement. Other concerns include repeated surprises in billing, unclear ownership during outages, poor follow-up, disrespectful support interactions, and no proactive technology planning with leadership.