Nearly every conversation with a law firm starts the same way: "we have IT, we should be fine on security." Sometimes that is true. More often it is a category mistake. IT support and cybersecurity operations are related jobs, but they are different jobs. When an assumption gets made that the first one covers the second, the firm ends up with a gap that only shows up on the day a paralegal's mailbox does something strange or the document management server stops responding on a Friday afternoon during a closing.
This piece is not "your IT firm is bad." Most IT firms are excellent at what they do. This piece is about which job is which, when a law firm needs a specific security operation on top of its IT provider, and — importantly — how to tell whether the IT firm you already have is quietly covering it.
The direct answer
Your IT provider is probably not your security team. That is usually not their fault; the two roles have different training, different tools, and different hours. Some IT firms have added a real 24/7 security operations team and can produce insurance-grade evidence — most cannot. The way to tell is to ask a small number of specific questions and listen for a specific kind of answer. The questions are below.
What a general IT provider is built to do
A good IT firm handles the layer that keeps the firm operational day-to-day:
- Helpdesk for attorneys and staff — the paralegal cannot print, the conference-room display will not project, the front-desk phone system is down.
- Hardware procurement and refresh — attorney laptops, paralegal workstations, the document management server itself.
- Patching and routine maintenance — Windows updates, application updates, driver cleanup.
- Backups — the nightly job runs, the offsite copy syncs.
- Microsoft 365 or Google Workspace administration — user provisioning, mailbox forwarding, license changes.
- Wi-Fi, firewall, and network device management — the guest SSID, the attorney VPN.
- Document management and practice management system upgrades — service packs, version bumps, application updates.
- Vendor coordination — the DMS vendor, e-filing systems, the phone-system provider, the internet carrier.
Every one of those is real work. A law firm without a competent IT provider runs slower, breaks more often, and takes longer to recover from small problems. This is not the layer we are trying to displace.
What a security operation is built to do
A security operation is built for a different question: not "is it working?" but "is someone attacking it right now, and if so, what are we doing about it?"
The concrete pieces:
- 24/7 detection. A real security operations center reading endpoint and identity alerts around the clock — not software that fires notifications into an email inbox nobody watches after hours.
- Response. When something fires that looks real, the compromised workstation is isolated within minutes, the identity is disabled, and the incident is contained before it spreads to the document management server.
- Identity threat detection. Watching Microsoft 365 or Google Workspace sign-ins for adversary-in-the-middle phishing kits, mailbox rules that hide wire and escrow emails, OAuth-consent attacks, and token-replay activity — the identity-layer attacks that bypass MFA and enable closing-wire fraud.
- Security awareness training. Continuous phishing simulations calibrated for legal staff — closing-wire-redirect themes for paralegals, court-notice phishing for legal assistants, sealed-records hygiene for partners — and the click-rate trend a cyber-insurance carrier will ask about.
- Incident response coordination. When something happens: forensics coordination, breach-notification timing under ABA Formal Opinion 483 (notification to current clients whose material confidential information was affected), cyber-insurance claim support, and the client-facing communication.
- Written security plan and audit evidence. Audit-control logs, MFA-coverage reports, encryption attestation, training completion records, and the written incident-response plan — the evidence package a cyber-insurance underwriter, a matter-based client engagement, or a bar inquiry actually asks for.
These are operational security tasks. They are what a security team does, not what an IT team does. A general IT firm may configure some of these; very few operate them continuously.
Why the assumption fails: everyone assumes someone else is watching
The failure mode in a law firm is not usually a missing tool. It is a missing owner.
A paralegal or closing coordinator gets phished at 8pm on a Wednesday through an email that looks like it came from opposing counsel with updated wire instructions attached. An endpoint alert fires. The IT firm's ticket queue receives the notification. Nobody at the IT firm is on-call for it; their support hours are 8am to 6pm. Meanwhile the attacker has the paralegal's session token, sets an inbox rule that hides wire and escrow emails, and quietly swaps the routing on a Thursday-afternoon real-estate closing. Friday afternoon the closing funds move — to the attacker's account. Or, at another firm the same week: the DMS server is encrypted. Monday morning the firm cannot access matter files, meet deadlines, or work open matters.
By Monday morning either the closing funds are gone or the document management system is down. When the managing partner asks who was supposed to be watching, everyone points to someone else.
The alert was there. The tool worked. Nobody was watching it.
When your IT provider IS enough (honest read)
Some IT firms have genuinely built a security operation. Others have added a security bundle from a distributor and describe it that way. The words look identical on a website. The operational reality is different.
Your IT firm may already have you covered if all of these are true:
- They operate — not merely resell — a managed endpoint detection and response service on every workstation AND the document management server, with a real 24/7 security operations team behind it.
- They can produce, on request, the audit-control logs, MFA-coverage report, and identity-monitoring evidence a cyber-insurance underwriter wants for a renewal application.
- They have a documented incident-response process specific to your firm, including who they call at your firm at 2am and how they coordinate with your cyber-insurance carrier and, for confidentiality-triggered incidents, your ethics counsel.
- They have a written engagement agreement with the firm covering confidentiality of client matter files, least-privilege access to firm systems, and prompt breach-notification duties back to the firm.
- They carry appropriate cybersecurity insurance and errors-and-omissions coverage themselves.
If all five are true and you can verify them, you may not need a separate security firm. If any are unclear, the security layer is not owned — the firm is uncovered even if the IT relationship is excellent.
Questions to ask your IT provider (bring these to your next review)
The point of these questions is not to trap anyone. It is to find out what is being operated on the firm's behalf and what is not, so any gaps can be assigned to someone before the gap becomes an incident.
-
"Is there a security operations center monitoring our endpoints 24 hours a day, or is it software that runs unattended after your business hours?" A yes-there-is-a-team answer should name the team and the escalation path.
-
"If a workstation starts behaving like an active ransomware intrusion at 2am on a Saturday, who acts, how fast, and what do you do first?" The answer should describe automatic isolation within minutes, not "we'd see it Monday and call you."
-
"Can you produce the audit-control logs, MFA-coverage report, and identity-monitoring evidence our cyber-insurance renewal will ask for?" The answer should be "yes, here are samples from last quarter," not "we'd have to check."
-
"Do you have a written engagement agreement with us covering confidentiality of client matter files, least-privilege access to firm systems, and prompt breach-notification duties back to the firm?" Any vendor with remote access to systems that hold privileged matter files needs a written engagement covering confidentiality and scoped access. "We've been with you for years, we're trusted" is not the same as a written agreement.
-
"Do you monitor our Microsoft 365 or Google Workspace tenant for identity attacks — session-token theft, adversary-in-the-middle sign-ins, malicious inbox rules — not just email spam filtering?" The answer should distinguish identity threat detection from anti-spam. Most IT firms provide the second and not the first. This is the layer that catches closing-wire-fraud attempts before the money moves.
-
"When you deploy patches, do you have a documented SLA for critical CVEs, and do you specifically track the CISA Known Exploited Vulnerabilities list?" The answer should be a written policy, not "auto-update is on."
If the answers on any of these are hesitant or unclear, the security layer for that specific piece is unowned. That does not mean firing anyone. It means naming who owns it going forward.
Co-managed is the healthy model
The mental model most firms default to — one firm, all of it — is not the model that works best for security. It is a leftover from an era when small offices had a single IT contact and everything technical went through that person.
The model that works now is co-managed. Your IT firm keeps the firm operational — the layer they are excellent at. A security firm operates the detection, response, identity monitoring, awareness training, and evidence layer — the layer they are excellent at. The two coordinate: when a security incident touches an IT-owned system, the two firms work together. When an IT change might affect the security posture, the two firms coordinate the change.
No one gets fired. The firm pays for two functions instead of one because those functions are actually two things. Total cost is often closer than partners expect to what a single do-everything provider would charge for comparable depth, because each specialist runs its own layer more efficiently than a generalist can run both.
What we do
Obsidian Ridge is a managed security firm, not an IT MSP. We coordinate with the IT firm the law firm already has — we do not replace them. Our program is managed detection and response, identity threat detection, and security awareness training, operated end-to-end for the firm with the written security plan, cyber-insurance readiness support, and Formal Opinion 483-aligned incident response coordination attached. Deeper on the legal context: the law firm cybersecurity page.
If a cyber-insurance renewal is the pressure point that surfaced this whole question, the Cyber Insurance Readiness Sprint is the fixed-scope engagement — from $1,500, delivered in 7 business days — that turns the questionnaire into a paperwork step instead of a scramble.
If you want the broader tool-and-service-model taxonomy before the co-managed conversation with your IT firm, the MDR vs EDR vs MSSP vs SOC-as-a-service decision tree is the buyer-side companion piece.
Next step
If this article named a gap you already suspected, the practical next step is either the free carrier questionnaire — score the firm yourself first — or the Cyber Insurance Readiness Sprint if the renewal or an active matter's evidence request is already on the calendar.
Last updated
July 28, 2026. We refresh this content as the threat landscape and tools evolve.