Use a 100-Point MSP Scorecard Instead of Comparing Sales Presentations
A law firm should compare managed IT service providers using a 100-point scorecard across 10 categories: legal-industry experience, support, cybersecurity, disaster recovery, Microsoft 365, strategic planning, service scope, accountability, transition capability, and pricing.
For a 25–50 employee law firm, price should represent approximately 10–15 points of the final decision—not the entire decision. A proposal that is $20–$40 less per user each month may cost substantially more when it excludes after-hours support, cybersecurity monitoring, backup testing, vendor coordination, on-site service, or strategic planning.
The strongest provider should be able to show exactly how it will protect confidential information, support attorneys during urgent matters, restore critical systems, manage legal technology vendors, and provide measurable results.
Use the framework below to compare each MSP against the same requirements before selecting a provider.
1. Score Legal-Industry Experience: 15 Points
Law firms have technology requirements that differ from those of ordinary offices. Attorneys depend on email, matter documents, timekeeping, billing, legal research, court filing, secure communication, document production, and strict deadlines.
An MSP does not need to support only law firms, but it should understand legal workflows and the consequences of technology failure.
Questions to ask
- How many law firms do you currently support?
- What size are those firms?
- Which legal applications do you regularly manage?
- How do you support court filing and deadline-sensitive work?
- How do you coordinate with practice-management and document-management vendors?
- How do you protect confidential client and matter information?
- Can you provide relevant client references?
Scoring guidance
| Score | Evidence |
|---|---|
| 13–15 points | Demonstrated law firm experience, relevant references, documented legal workflows, and familiarity with major legal applications |
| 8–12 points | Professional-services experience with some law firm knowledge and a credible plan to support legal systems |
| 1–7 points | Generic business support with limited understanding of legal workflows or confidentiality requirements |
| 0 points | Cannot explain how legal IT differs from ordinary office support |
Red flag
Be cautious when a provider repeatedly describes all clients as interchangeable. A law firm should not need to teach its IT provider why a filing deadline, ethical wall, unavailable matter folder, or compromised client email requires urgent attention.
2. Score Help Desk and Emergency Support: 15 Points
The service desk is where attorneys and employees experience the MSP every day.
A proposal may contain impressive tools, but the relationship will fail if employees wait hours for help, repeatedly explain the same environment, or cannot reach a technician during an urgent evening or weekend problem.
Questions to ask
- Is support available 24/7?
- Does a live technician answer after hours?
- What qualifies as an emergency?
- What are your response targets by priority?
- What percentage of requests are resolved during the first interaction?
- Can you provide local on-site support?
- How are unresolved issues escalated?
- Will our employees receive status updates?
- Are after-hours calls included or billed separately?
- How do you measure client satisfaction?
Require response definitions
A “15-minute response” may mean that an automated email was sent, not that a technician began working on the problem.
Ask the provider to define:
- Acknowledgment time: When the request enters the system
- Human response time: When a technician communicates with the employee
- Work-start time: When troubleshooting begins
- Resolution time: When the user can work again
- Escalation time: When the issue moves to a more experienced resource
Scoring guidance
| Score | Evidence |
|---|---|
| 13–15 points | Live 24/7 support, clear response targets, documented escalation, local on-site capability, and measurable satisfaction reporting |
| 8–12 points | Strong business-hours support with defined after-hours escalation and reasonable on-site availability |
| 1–7 points | Unclear response definitions, limited staffing, or frequent reliance on callbacks and third parties |
| 0 points | No dependable method for obtaining urgent assistance outside normal business hours |
911 IT’s managed IT services include proactive management and access to live technical support around the clock.
3. Score Cybersecurity Capability: 15 Points
Cybersecurity should be evaluated as a coordinated operating system rather than a list of software products.
A credible MSP should address identity, devices, email, cloud applications, access, monitoring, employee behavior, vendors, backups, and incident response.
Minimum controls to evaluate
- Multi-factor authentication
- Phishing-resistant authentication for high-risk users
- Endpoint detection and response
- Managed security updates
- Email filtering and impersonation protection
- Microsoft 365 security monitoring
- Restricted administrator privileges
- Device encryption
- Security awareness training
- Phishing simulations
- 24/7 alert monitoring
- Incident response procedures
- Vendor-access controls
- Cyber insurance support
Questions to ask
- Who monitors security alerts after hours?
- Can you isolate a compromised computer immediately?
- Can you disable a suspicious account?
- Which security tools are included in the monthly fee?
- Which controls require additional licensing?
- How do you verify that every device is protected?
- How are high-risk findings reported to leadership?
- What happens during a confirmed incident?
- Are incident-response services included?
- How do you coordinate with cyber insurance and outside counsel?
Ask for evidence
The provider should be able to show sample reports such as:
- Device-security coverage
- Patch status
- Microsoft 365 risk findings
- Administrative access reviews
- Security-training participation
- Open risk register
- Incident escalation records
Scoring guidance
| Score | Evidence |
|---|---|
| 13–15 points | Layered controls, 24/7 monitoring, documented response, measurable coverage, recurring risk reviews, and clear leadership reporting |
| 8–12 points | Solid technical safeguards with some monitoring or governance limitations |
| 1–7 points | Primarily antivirus and firewall management with limited identity, cloud, training, or response capability |
| 0 points | Security responsibilities are unclear or largely transferred to individual employees |
Review cybersecurity services for examples of layered protection, threat monitoring, phishing prevention, and incident-response support.
4. Score Backup and Disaster Recovery: 10 Points
Do not award full points because a proposal includes “backup.” Determine whether the provider can restore usable systems and information within the firm’s required timeframe.
Questions to ask
- Which servers, applications, and cloud services are protected?
- How frequently are backups created?
- Is at least one copy isolated or immutable?
- Are backup administrator credentials separate?
- Who investigates failed jobs?
- How long are backups retained?
- How quickly can critical systems be restored?
- How often do you conduct real restoration tests?
- Will we receive written test results?
- Who validates that restored information is usable?
Require recovery objectives
Each critical system should have:
- Recovery Time Objective: The maximum acceptable downtime
- Recovery Point Objective: The maximum acceptable amount of recent data loss
A provider cannot responsibly promise recovery without understanding these two numbers.
Scoring guidance
| Score | Evidence |
|---|---|
| 9–10 points | Protected local and cloud data, isolated copies, documented recovery objectives, recurring restoration tests, and written results |
| 6–8 points | Reliable backups with reasonable monitoring but limited system-level testing or continuity planning |
| 1–5 points | Backup jobs are monitored, but restoration capability and recovery times remain unclear |
| 0 points | No recent evidence that critical information can be restored |
Explore business continuity services for backup, disaster recovery, continuity planning, and recovery testing.
5. Score Microsoft 365 and Cloud Expertise: 10 Points
Microsoft 365 is often the law firm’s identity platform, email system, collaboration environment, and gateway to other applications. It should not be managed as a basic mailbox subscription.
Questions to ask
- How do you secure Microsoft 365 identities?
- Do you manage Conditional Access?
- How do you protect administrator accounts?
- How do you govern SharePoint, OneDrive, and Teams?
- How do you control external sharing?
- How do you monitor suspicious sign-ins and mailbox rules?
- How do you review licensing?
- How do you manage former employee data?
- How do you review third-party application access?
- How is Microsoft 365 information recovered?
Evaluate tenant ownership
The law firm should retain appropriate ownership and recovery control of its Microsoft 365 tenant, domains, subscriptions, and information.
The MSP may administer the environment, but it should not create dependency by retaining exclusive control.
Scoring guidance
| Score | Evidence |
|---|---|
| 9–10 points | Advanced identity, security, collaboration, governance, monitoring, licensing, and recovery capability |
| 6–8 points | Strong day-to-day administration with some limitations in governance, security, or strategic cloud planning |
| 1–5 points | Primarily creates users, resets passwords, and assigns licenses |
| 0 points | Cannot explain how it protects or governs Microsoft 365 beyond default settings |
Review cloud services for Microsoft 365 integration, cloud management, migration, secure access, and ongoing support.
6. Score Strategic Planning and vCIO Services: 10 Points
A managed IT provider should not spend the entire relationship reacting to support requests.
Strategic service should connect technology decisions to growth, security, budgeting, staffing, office changes, client requirements, and risk.
Expected deliverables
- A 12–36 month technology roadmap
- An annual IT budget
- A three-year equipment replacement plan
- A cybersecurity risk register
- Quarterly business reviews
- Microsoft 365 licensing reviews
- Vendor and contract planning
- Major project plans
- Backup test results
- Written action items with owners and dates
Questions to ask
- Who will serve as our strategic advisor?
- How often will we meet?
- What written deliverables will we receive?
- Will you build a three-year roadmap?
- Will you help prepare our annual budget?
- How do you prioritize risks?
- How do you track unresolved recommendations?
- Is vCIO service included in the monthly fee?
- How will you measure roadmap progress?
Scoring guidance
| Score | Evidence |
|---|---|
| 9–10 points | Named advisor, quarterly meetings, written roadmap, budget planning, risk register, and measurable follow-through |
| 6–8 points | Recurring planning meetings and recommendations with limited budgeting or written documentation |
| 1–5 points | Occasional sales or account-management meetings presented as strategy |
| 0 points | No structured technology-planning process |
7. Score Service Scope and Vendor Coordination: 10 Points
Most law firms depend on multiple technology vendors. When a problem crosses email, internet, phones, legal software, scanning, or hosting, employees should not be forced to coordinate every vendor themselves.
Determine what is included
Ask whether the monthly agreement covers:
- Help desk support
- After-hours assistance
- On-site service
- Server and network management
- Microsoft 365 administration
- Cybersecurity tools
- Backup monitoring
- Employee onboarding and offboarding
- Vendor coordination
- Quarterly planning
- Documentation
- Minor projects and changes
Determine what is excluded
Common exclusions may include:
- Major projects
- Office moves
- Cloud migrations
- New computer installations
- Cabling
- Compliance assessments
- Incident response
- Data recovery
- After-hours project work
- Third-party license costs
Exclusions are not automatically unreasonable. They must be visible enough to compare the real cost of each proposal.
Ask who owns the problem
When a legal application stops communicating with Microsoft 365, will the MSP contact the application vendor and remain involved, or will it tell the attorney to call the vendor?
A strong provider should coordinate technical issues through resolution, even when another company must perform part of the work.
Scoring guidance
| Score | Evidence |
|---|---|
| 9–10 points | Broad, clearly defined scope with vendor ownership, local support, and transparent exclusions |
| 6–8 points | Good core coverage with several understandable exclusions or limited vendor coordination |
| 1–5 points | Narrow support scope that leaves firm employees coordinating multiple providers |
| 0 points | The proposal is too vague to determine what the firm is buying |
8. Score Reporting and Accountability: 5 Points
The MSP should demonstrate results through reports that leadership can understand.
Useful measurements
- Human response times
- Resolution times
- Recurring support issues
- Employee satisfaction
- Device-security coverage
- Patch status
- Backup success and restoration tests
- Open cybersecurity risks
- Equipment approaching replacement
- Roadmap progress
Questions to ask
- Which reports will we receive monthly and quarterly?
- Can we see a sample report?
- How do you identify recurring problems?
- How do you document recommendations we decline or postpone?
- How will we escalate a service concern?
- Who is responsible for correcting missed service targets?
Scoring guidance
| Score | Evidence |
|---|---|
| 5 points | Clear operational and strategic reporting with named owners, deadlines, and trend analysis |
| 3–4 points | Useful service reports with limited business-impact or roadmap reporting |
| 1–2 points | Primarily ticket counts and tool-generated reports without analysis |
| 0 points | No consistent reporting or accountability process |
9. Score Onboarding and Transition Capability: 5 Points
The quality of onboarding often predicts the quality of the long-term relationship.
A provider should have a documented process for taking responsibility without leaving gaps in support, security, backups, or access.
Questions to ask
- How long does onboarding typically take for a firm our size?
- Who manages the transition?
- What information will you request?
- How do you verify Microsoft 365 and domain ownership?
- How do you replace the prior provider’s security tools?
- How do you prevent gaps in backup coverage?
- Will you coordinate directly with the outgoing provider?
- How will employees learn the new support process?
- What will be completed in the first 30, 60, and 90 days?
Require a written onboarding plan
The plan should include:
- Discovery and inventory
- Credential transfer
- Documentation transfer
- Security-tool deployment
- Backup verification
- Help desk launch
- Employee communication
- Provider-access removal
- Initial risk report
- First strategic review
Scoring guidance
| Score | Evidence |
|---|---|
| 5 points | Structured 30–90 day plan, named project manager, security and backup validation, and controlled provider handoff |
| 3–4 points | Credible transition plan with limited detail or reporting |
| 1–2 points | Informal onboarding dependent on the outgoing provider’s documentation |
| 0 points | No clear process for preventing service or security gaps |
10. Score Pricing and Contract Terms: 5 Points
Price matters, but it should be compared after normalizing the services included in each proposal.
Managed IT for a 25–50 employee law firm may be presented as:
- A per-user monthly fee
- A per-device monthly fee
- A fixed organizational fee
- A base fee plus usage charges
- A hybrid of recurring and project costs
Create a three-year cost comparison
For each provider, calculate:
- Monthly managed-service fees
- Required security licenses
- Backup costs
- Microsoft 365 costs
- Onboarding fees
- On-site charges
- After-hours charges
- Project estimates
- Annual price increases
- Contract termination costs
Questions to ask
- What is included in the recurring fee?
- Which services are billed separately?
- Are after-hours emergencies included?
- Are on-site visits included?
- How are projects defined?
- How often can pricing increase?
- What is the initial contract term?
- Does the agreement renew automatically?
- What notice is required to terminate?
- What happens to our data, licenses, and documentation when the agreement ends?
Scoring guidance
| Score | Evidence |
|---|---|
| 5 points | Transparent, predictable pricing with clear scope, exclusions, increases, ownership, and termination terms |
| 3–4 points | Generally clear pricing with several variable charges or contract limitations |
| 1–2 points | Low headline price but substantial uncertainty about exclusions and additional fees |
| 0 points | Proposal cannot be converted into a credible three-year cost estimate |
Use This 100-Point MSP Comparison Table
| Evaluation category | Maximum points | Provider A | Provider B | Provider C |
|---|---|---|---|---|
| Legal-industry experience | 15 | |||
| Help desk and emergency support | 15 | |||
| Cybersecurity capability | 15 | |||
| Backup and disaster recovery | 10 | |||
| Microsoft 365 and cloud expertise | 10 | |||
| Strategic planning and vCIO | 10 | |||
| Service scope and vendor coordination | 10 | |||
| Reporting and accountability | 5 | |||
| Onboarding and transition | 5 | |||
| Pricing and contract terms | 5 | |||
| Total | 100 |
A provider scoring below 70 should generally require significant clarification. A score of 80 or higher may indicate a strong candidate, provided the MSP satisfies all mandatory legal, security, ownership, and recovery requirements.
Do not allow a high total score to hide a critical failure. For example, a provider should not be selected when it cannot demonstrate backup recovery or emergency support, even if it performs well in less critical categories.
Create Five Mandatory Pass-or-Fail Requirements
Before comparing total scores, establish requirements every provider must satisfy.
A law firm might require:
- Live emergency support available 24/7
- Documented cybersecurity monitoring and response
- A successful backup restoration process
- Firm ownership of critical accounts and information
- A written onboarding and transition plan
A provider that fails one of these requirements should not advance solely because it offers a lower price.
Compare Service Agreements Line by Line
Two proposals may use the same service names while providing substantially different coverage.
Create a side-by-side matrix for:
- Support hours
- Response targets
- On-site support
- Device management
- Microsoft 365 administration
- Cybersecurity tools
- Security monitoring
- Employee training
- Backup services
- Recovery testing
- Vendor coordination
- vCIO meetings
- Project labor
- After-hours work
- Compliance assistance
- Incident response
Clarify unlimited support
“Unlimited support” may exclude:
- On-site visits
- After-hours assistance
- Projects
- New device setups
- Legal software problems
- Vendor coordination
- Security incidents
- Data recovery
Ask the provider to define unlimited support with examples of included and excluded requests.
Compare Three Common MSP Models
Low-cost reactive provider
This model may offer basic remote assistance and monitoring at a low monthly rate.
It may be appropriate for organizations with internal technical leadership, limited security requirements, and tolerance for variable project costs.
Common limitations include:
- Limited after-hours support
- Minimal strategic planning
- Separate cybersecurity charges
- Limited recovery testing
- Little legal-industry experience
- Variable on-site costs
Tool-focused managed service provider
This model includes monitoring, endpoint tools, patching, backup, and a help desk.
It may provide strong day-to-day operations but vary in strategic planning, law firm expertise, incident response, and vendor ownership.
Strategic legal IT partner
This model combines daily support with cybersecurity, recovery, Microsoft 365, legal-vendor coordination, local assistance, and long-term planning.
It will usually cost more than basic reactive service because the scope includes prevention, monitoring, accountability, and executive guidance.
The correct model depends on what the firm expects the provider to own.
A Practical Comparison for a 35-Employee Law Firm
Consider a Salt Lake City law firm comparing three providers.
Provider A: Lowest monthly price
- $125 per user per month
- Business-hours remote support
- After-hours support billed separately
- Basic antivirus
- Backup monitoring without quarterly restoration tests
- No formal vCIO roadmap
- On-site service billed hourly
Provider B: Mid-range general MSP
- $180 per user per month
- 24/7 call center
- Endpoint protection and patching
- Microsoft 365 administration
- Annual planning meeting
- Quarterly file-restoration tests
- Limited law firm experience
Provider C: Legal-focused strategic provider
- $225 per user per month
- Live 24/7 technical support
- Local on-site service
- Layered cybersecurity and active monitoring
- Microsoft 365 security management
- Quarterly recovery testing
- Legal application coordination
- Quarterly vCIO meetings
- A 12–36 month technology roadmap
Normalize the annual cost
For 35 users, the headline annual managed-service fees would be approximately:
| Provider | Monthly fee | Annual base fee |
|---|---|---|
| Provider A | $4,375 | $52,500 |
| Provider B | $6,300 | $75,600 |
| Provider C | $7,875 | $94,500 |
Provider A appears to save $42,000 annually compared with Provider C. However, the firm must add the cost of cybersecurity, after-hours support, on-site labor, recovery testing, strategic planning, and internal time spent coordinating vendors.
The comparison should also estimate the operational value of faster support, reduced downtime, stronger security, predictable projects, and documented recovery.
Apply the scorecard
| Provider | Score | Result |
|---|---|---|
| Provider A | 54/100 | Low price but significant support, security, and recovery gaps |
| Provider B | 75/100 | Credible general provider requiring clarification on legal workflows and strategic planning |
| Provider C | 91/100 | Highest base cost but strongest alignment with the firm’s complete requirements |
This example does not mean the most expensive provider always wins. It demonstrates why proposals must be normalized before leadership makes a decision.
Verify Claims Through References and Demonstrations
Do not rely entirely on proposal language.
Ask references specific questions
- How quickly can you reach a technician?
- What happens during an after-hours emergency?
- Does the MSP communicate clearly?
- Has it successfully handled a serious outage or security event?
- Does it coordinate effectively with other vendors?
- Does it provide useful strategic recommendations?
- Have monthly costs matched expectations?
- What would you change about the relationship?
Request demonstrations
Ask the provider to demonstrate:
- The employee support process
- The escalation process
- A sample security report
- A sample quarterly business review
- A sample technology roadmap
- A sample backup test report
- The onboarding project plan
A demonstration reveals whether the provider has an established operating process or is creating answers specifically for the sales meeting.
What Law Firm Clients Value in an MSP
Customer feedback collected by 911 IT repeatedly emphasizes outcomes that matter during an MSP comparison:
- Fast access to a real technician
- Patient and understandable assistance
- Responsibility through final resolution
- Knowledge of the client’s complete environment
- Proactive recommendations
- Local support when remote service is insufficient
- Confidence that critical information is protected
- A team that feels like an internal IT department
One legal-services client described relying on 911 IT for email, legal research, electronic court filing, and document access. The client emphasized the importance of reaching a live technician who remained involved until the problem was resolved.
Another client valued having one technology team understand its IT, phones, cloud services, and related vendors. That familiarity reduced repeated explanations and improved coordination.
These experiences demonstrate that an MSP should be evaluated through actual employee and leadership outcomes—not only through its tool list.
20 Questions to Ask Every Finalist
- How many law firms of our size do you support?
- Which legal applications does your team regularly manage?
- Can an employee reach a live technician 24/7?
- What is your human response time for a critical issue?
- Who monitors cybersecurity alerts overnight?
- Can you isolate a compromised device immediately?
- Which cybersecurity tools are included?
- How often do you test backup restoration?
- Will we receive written recovery results?
- How do you secure Microsoft 365?
- Will the firm retain ownership of all critical accounts?
- How do you coordinate with legal software vendors?
- Who provides local on-site support?
- What will our quarterly strategy meetings include?
- Will you prepare a 12–36 month technology roadmap?
- What services are excluded from the monthly fee?
- How do you handle projects and after-hours work?
- What happens during the first 30, 60, and 90 days?
- How will we measure your performance?
- What happens to our data and documentation when the agreement ends?
Red Flags When Comparing MSPs
Be cautious when a provider:
- Competes almost entirely on price
- Cannot provide relevant references
- Uses “24/7” to describe voicemail or an answering service
- Cannot define response and resolution times
- Treats antivirus as a complete cybersecurity program
- Cannot show a recent recovery-test report
- Does not ask about legal workflows
- Cannot explain Microsoft 365 tenant ownership
- Does not provide a written onboarding plan
- Calls a sales meeting a quarterly business review
- Will not identify exclusions clearly
- Requires the firm to coordinate every outside vendor
- Provides no process for ending the relationship
- Promises zero downtime or complete security
- Pressures leadership to sign before technical discovery
Frequently Asked Questions
How many MSPs should a law firm compare?
Three qualified finalists usually provide enough variation for a meaningful comparison without creating an unmanageable review process. Each provider should respond to the same requirements and scorecard.
Should the law firm choose the lowest-priced MSP?
Not automatically. Compare the total three-year cost, included services, operational risks, support quality, cybersecurity, recovery capability, and internal time required to manage exclusions.
What should managed IT cost for a law firm?
A 25–50 employee law firm may encounter pricing from approximately $100–$275 per user per month, depending on service scope, security, support hours, cloud management, backup, on-site coverage, and strategic guidance.
Is 24/7 support necessary for a law firm?
It is valuable when attorneys work outside ordinary business hours, travel, face court deadlines, or require urgent access to email and matter information. Confirm that 24/7 means access to a qualified technician rather than only message intake.
How important is law firm experience?
Legal experience reduces the learning curve around confidentiality, matter access, legal applications, filing deadlines, document workflows, vendor coordination, and attorney expectations. Evaluate demonstrated experience rather than marketing language alone.
Should cybersecurity be included in managed IT?
Core security controls should be integrated with IT operations. The agreement should identify which tools, monitoring, training, assessments, and incident-response services are included and which require additional fees.
How can a firm verify disaster recovery?
Request a real restoration test and written results showing what was restored, how long it took, whether the information was usable, and whether the approved recovery target was met.
What contract length is reasonable?
Contract terms vary. Evaluate the initial period, automatic renewal, termination notice, price increases, service obligations, transition assistance, data return, license ownership, and documentation transfer.
Should the MSP own the firm’s domain or Microsoft 365 tenant?
The firm should retain appropriate organizational ownership and recovery control. The MSP may administer these systems through approved access but should not be the only party capable of controlling or recovering them.
How long should MSP onboarding take?
A 25–50 employee law firm should often plan for 30–90 days. The schedule depends on documentation quality, provider cooperation, application complexity, security gaps, and whether equipment or backup systems must be replaced.
Select the MSP That Produces the Best Complete Outcome
A law firm should compare providers across 10 measurable categories:
- Legal-industry experience
- Help desk and emergency support
- Cybersecurity capability
- Backup and disaster recovery
- Microsoft 365 and cloud expertise
- Strategic planning
- Service scope and vendor coordination
- Reporting and accountability
- Onboarding capability
- Pricing and contract terms
The winning proposal should not merely provide the lowest monthly number. It should provide the clearest evidence that the provider can protect confidential information, support urgent legal work, restore critical systems, coordinate vendors, and guide the firm’s technology decisions over the next 12–36 months.
911 IT provides law firms with live 24/7 support, legal IT experience, managed cybersecurity, Microsoft cloud expertise, tested business continuity, proactive vCIO planning, predictable managed services, and local on-site assistance.
Explore our managed IT services, review our cybersecurity services, learn about business continuity, or schedule a 10-minute discovery call to compare your current IT arrangement against a complete managed-services framework.
