Illustration of a dog in a suit weighing cybersecurity protection against hackers on a justice scale in a courtroom.

What Questions Should a Law Firm Ask Before Switching IT Providers?

August 01, 2026

Ask These 15 Questions Before Moving Your Law Firm to a New IT Provider

Before switching IT providers, a law firm should evaluate 15 areas: service quality, response times, cybersecurity, Microsoft 365, backups, legal software, compliance, documentation, account ownership, pricing, onboarding, employee communication, vendor coordination, offboarding, and long-term technology planning.

A 25–50 employee law firm should expect a structured transition to take approximately 30–90 days, depending on the condition of its systems, the quality of existing documentation, the number of applications and locations, and the cooperation of the outgoing provider.

The objective is not merely to replace one help desk with another. A successful transition should reduce risk, protect client information, preserve access to critical systems, and establish clear accountability from the first day of service.

1. Why Are We Considering a Change?

Begin by documenting the business reasons for switching. Without clearly defined goals, the firm may select a new provider that recreates the same problems under a different contract.

Common reasons law firms consider changing IT providers include:

  • Slow or inconsistent responses
  • Recurring issues that never receive a permanent fix
  • Difficulty reaching a live technician
  • Unexpected invoices and unclear project charges
  • Insufficient cybersecurity
  • Poor communication during outages
  • Limited Microsoft 365 expertise
  • No strategic planning or technology roadmap
  • Weak documentation
  • Concerns about backup and disaster recovery
  • Lack of experience with legal workflows
  • Inadequate support for remote attorneys

Create a list of the five most important improvements the firm expects from a new provider. Make each one measurable where possible.

For example, replace “We want better service” with:

  • Employees must be able to reach a live technician 24/7.
  • Critical issues must receive an initial response within a defined period.
  • Recurring problems must receive root-cause analysis.
  • Firm leadership must receive a quarterly technology and security review.
  • Backup restoration must be tested and documented regularly.

2. Does the New Provider Understand How Our Law Firm Works?

Legal technology supports time-sensitive and confidential work. A provider should understand how technical problems affect court filings, client communications, document access, billing, legal research, remote work, and case deadlines.

Ask the prospective provider:

  • How many law firms of our size do you support?
  • Which legal applications have your technicians encountered?
  • How do you handle an issue involving a third-party legal software vendor?
  • How do you support attorneys working after normal business hours?
  • How do you protect confidential client information?
  • Can you describe a transition involving a similar professional-services firm?
  • Can you provide an appropriate client reference?

The provider does not need to be the developer of every legal application. It should be capable of supporting the identities, computers, servers, networks, permissions, cloud systems, and vendor relationships surrounding those applications.

Relevant experience should be demonstrated with examples rather than a general statement that the company supports “all industries.”

3. What Support Experience Will Attorneys and Staff Receive?

A firm should understand exactly what happens after an employee requests help.

Ask the provider to explain:

  • How support requests can be submitted
  • Whether a live technician answers the phone
  • Which hours are covered
  • Whether after-hours support costs extra
  • How urgent requests are identified
  • How tickets are escalated
  • When on-site service is provided
  • How users receive progress updates
  • Who reviews unresolved or recurring issues

Request written response standards

Terms such as “fast,” “priority,” and “responsive” can mean different things to different providers. The agreement should define priority levels and the expected initial response for each one.

A critical issue might include:

  • A firm-wide outage
  • A suspected security incident
  • Inability to access a court filing system near a deadline
  • Loss of access to a critical legal application
  • A failed internet connection affecting the entire office
  • Widespread inability to send or receive email

Also ask whether the service target covers only acknowledgment or actual work toward resolution. An automatic message saying that a ticket was received is not the same as a technician beginning an investigation.

Review the provider’s managed IT services to compare help desk availability, proactive monitoring, on-site support, and strategic planning.

4. What Cybersecurity Controls Will Be Implemented?

Switching providers is an opportunity to identify security gaps that may have accumulated over time. The new provider should perform a documented assessment rather than assuming the current configuration is secure.

Ask whether the proposed service includes:

  • Multi-factor authentication
  • Endpoint detection and response
  • Email filtering and impersonation protection
  • Microsoft 365 security management
  • Disk encryption
  • Restricted administrative access
  • Operating-system and application patching
  • Vulnerability management
  • Security awareness training
  • Phishing simulations
  • Backup monitoring
  • Incident response planning
  • 24/7 security alert monitoring

Ask how existing security tools will be replaced

The outgoing provider may remove its security, monitoring, backup, and remote-support tools when the relationship ends. The incoming provider should schedule replacement tools so devices are not left unprotected during the transition.

Request a written deployment sequence covering:

  1. Inventorying existing tools
  2. Confirming replacement licenses
  3. Installing new protection
  4. Verifying that every device is reporting
  5. Removing obsolete or conflicting software
  6. Testing alerts and response procedures

Explore cybersecurity services to understand the protections that should be coordinated during onboarding.

5. How Will Microsoft 365 Be Transferred and Secured?

The firm should retain ownership and administrative control of its Microsoft 365 tenant. The IT provider may administer the environment, but the account should belong to the law firm rather than to the provider.

Before switching, confirm:

  • The legal name associated with the tenant
  • Who controls the global administrator accounts
  • Which provider relationships and subscriptions are active
  • How licenses are purchased and billed
  • Which domains are connected
  • Whether emergency administrator accounts exist
  • Where administrative credentials are stored
  • Which applications have access to Microsoft 365 data

The new provider should review:

  • Multi-factor authentication coverage
  • Conditional Access policies
  • Administrator roles
  • Legacy authentication
  • Mailbox forwarding
  • External sharing
  • SharePoint and OneDrive permissions
  • Inactive accounts
  • Former employee access
  • Mobile-device access
  • Audit logging and security alerts
  • Retention and recovery settings

Review cloud services for help managing Microsoft 365, identity security, remote work, cloud migration, and collaboration.

6. Can the New Provider Prove That Our Data Can Be Recovered?

Do not assume that existing backups are complete, usable, or transferable. The outgoing provider may own the backup appliance, software license, cloud repository, or management account.

Ask both providers:

  • Who owns the backup hardware and subscriptions?
  • Where is backup data stored?
  • Which servers, applications, and cloud platforms are protected?
  • How long is data retained?
  • Are backup copies isolated from production credentials?
  • When was the last successful restoration test?
  • Will historical backups remain available after termination?
  • What happens to backup data when the old contract ends?

Complete a restoration test during onboarding

The incoming provider should not rely solely on a successful status displayed in backup software. It should restore selected files, mailboxes, databases, or systems and verify that the recovered information is usable.

The test report should document:

  • What was restored
  • The date of the test
  • The recovery source used
  • How long recovery took
  • Whether the restored information opened correctly
  • Any problems discovered
  • Required corrective actions

Learn more about business continuity services and how backup, disaster recovery, and continuity planning work together.

7. How Will Legal Applications and Vendors Be Handled?

Create an inventory of every important application and vendor before the transition begins.

The list may include:

  • Practice-management software
  • Document-management systems
  • Timekeeping and billing platforms
  • Legal research databases
  • Electronic court filing services
  • Accounting and payroll systems
  • Document scanning and production tools
  • VoIP phone services
  • Internet and telecommunications providers
  • Website and domain providers
  • Cloud storage and collaboration tools
  • Electronic signature platforms
  • E-discovery systems

For each vendor, record:

  • The primary contact
  • The account owner
  • The support number
  • The contract or renewal date
  • The administrative login
  • The number of licenses
  • The system dependencies
  • The escalation procedure

Ask whether the new MSP will contact and coordinate with vendors on the firm’s behalf. This prevents attorneys and administrators from acting as intermediaries during technical disputes.

8. What Compliance and Insurance Requirements Must Be Preserved?

A transition should not disrupt controls promised to clients, insurers, courts, regulators, or business partners.

Before changing providers, gather:

  • Cyber insurance applications and policy requirements
  • Client security questionnaires
  • Outside counsel guidelines
  • Relevant engagement requirements
  • Security policies
  • Risk assessments
  • Incident response plans
  • Business continuity plans
  • Training records
  • Vulnerability reports
  • Backup test reports
  • Open remediation plans

Ask the incoming provider to identify which controls it will operate, which controls remain the firm’s responsibility, and what evidence will be produced.

Do not let documentation disappear

The firm should retain copies of historical reports and evidence, even when the outgoing provider created them. These records may be relevant to an insurance renewal, client review, audit, incident investigation, or contractual obligation.

The new provider should not claim that the firm is “compliant” without knowing the applicable requirements. It should help implement, test, and document technical controls identified by the firm and qualified counsel.

9. Who Owns Our Accounts, Domains, Documentation, and Equipment?

Ownership should be clarified before the firm gives notice to its current provider.

The law firm should have appropriate control over:

  • Domain registrations
  • DNS accounts
  • Microsoft 365
  • Cloud platforms
  • Software subscriptions
  • Internet and phone accounts
  • Firewall and network equipment
  • Backup data
  • Encryption recovery keys
  • Website and hosting accounts
  • Security and administrative documentation

Some equipment or licenses may legitimately belong to the outgoing provider under a service agreement. Identify those items early so replacements can be ordered before service ends.

Request a complete documentation package

The transition package should contain:

  • Network diagrams
  • Device inventories
  • IP address and configuration records
  • Vendor contacts
  • License information
  • Administrative credentials
  • Backup configurations
  • Security policies
  • Support history
  • Known issues
  • Warranty information
  • Internet and telecommunications details

Credentials should be transferred using a secure method rather than ordinary email or an unencrypted spreadsheet.

10. What Will the New Service Actually Cost?

Compare the complete scope rather than the headline monthly price.

Ask whether the monthly agreement includes:

  • 24/7 help desk support
  • Local on-site service
  • Remote monitoring and maintenance
  • Cybersecurity tools
  • Security alert response
  • Microsoft 365 administration
  • Backup and recovery
  • Employee training
  • Vendor coordination
  • Quarterly planning
  • Technology budgeting
  • Incident response

Also request a written list of exclusions, including:

  • Onboarding fees
  • Hardware purchases
  • Software licenses
  • Office moves
  • Cabling
  • Cloud migrations
  • After-hours project work
  • Major remediation
  • Compliance assessments
  • Penetration testing

Calculate the first-year total

Compare each provider using this formula:

Monthly service fees × 12 + onboarding + expected projects + hardware + licenses = estimated first-year cost.

A provider with a lower recurring fee may cost more after security subscriptions, projects, after-hours support, and excluded services are added.

11. What Happens During the First 30, 60, and 90 Days?

Ask for a written onboarding plan with phases, owners, deadlines, and deliverables.

Days 1–30: Discovery and stabilization

  • Collect documentation and credentials
  • Inventory users, devices, applications, and vendors
  • Deploy support and monitoring tools
  • Verify cybersecurity coverage
  • Review Microsoft 365 administration
  • Confirm backups are running
  • Address critical access and security risks
  • Introduce the new support process to employees

Days 31–60: Assessment and remediation

  • Complete a detailed security assessment
  • Review network and cloud configurations
  • Test backup restoration
  • Remove inactive accounts
  • Correct missing patches and security tools
  • Standardize documentation
  • Review legal application dependencies
  • Prioritize technical debt

Days 61–90: Planning and optimization

  • Present the technology roadmap
  • Create an equipment lifecycle plan
  • Establish a technology budget
  • Finalize incident response procedures
  • Schedule recurring security training
  • Define quarterly reporting
  • Review service performance
  • Confirm remaining project priorities

The exact sequence may differ, but the provider should be able to explain how it will move from discovery to stabilization and then to long-term improvement.

12. How Will Employees Be Prepared for the Transition?

A technically successful transition can still feel unsuccessful when employees do not know how to obtain help.

Before the service launch, communicate:

  • The date the new provider becomes responsible
  • The support phone number
  • The support email or portal
  • How to identify an urgent request
  • When on-site service is available
  • How employees can verify a technician’s identity
  • What software or icons may appear on computers
  • Whether employees must complete any enrollment steps

The incoming provider should offer a brief orientation for attorneys and staff. This can take 15–30 minutes and should focus on practical actions rather than technical details.

Address change fatigue

Employees may resist a new process, especially if they have worked with the same technician for years. Explain the reasons for the change, the improvements expected, and how feedback will be collected.

During the first month, the provider should monitor support patterns and identify users who need additional assistance.

13. How Will the Outgoing Provider Be Managed?

The transition should remain professional and documented. Firm leadership should review the current agreement before giving notice.

Confirm:

  • Required notice periods
  • Termination fees
  • Automatic renewal provisions
  • Ownership of equipment and licenses
  • Data return and deletion requirements
  • Offboarding assistance
  • Final invoicing
  • Tool removal dates
  • Credential-transfer procedures

Ask the incoming provider to coordinate technical details directly with the outgoing provider while keeping the firm informed.

Do not terminate service too early

Maintain sufficient overlap to transfer documentation, deploy replacement security tools, verify backups, and test support procedures. A rushed termination can leave the firm without access, monitoring, security coverage, or vendor information.

However, avoid paying indefinitely for two full services. The transition plan should identify a target date when the incoming provider assumes primary responsibility.

14. What Risks Could Delay the Transition?

A provider should identify obstacles during discovery rather than surprising the firm after the contract begins.

Common transition risks include:

  • Missing or inaccurate documentation
  • Unknown administrative passwords
  • Accounts owned by a former employee
  • Domains controlled by a third party
  • Unsupported servers or workstations
  • Failed or incomplete backups
  • Unlicensed software
  • Unmanaged personal devices
  • Obsolete network equipment
  • Incomplete cybersecurity deployment
  • Uncooperative outgoing vendors
  • Complex legal application dependencies

Request a risk register that identifies:

  • The issue
  • The potential business impact
  • The person responsible
  • The proposed solution
  • The target completion date
  • The estimated cost

This helps partners distinguish immediate transition requirements from improvements that can be scheduled later.

15. What Strategic Value Will the New Provider Deliver?

The transition should produce more than a different support phone number. Ask how the provider will help the firm improve technology over the next one to three years.

A strategic provider should help with:

  • Annual IT budgeting
  • Computer and equipment lifecycle planning
  • Cybersecurity roadmaps
  • Microsoft 365 optimization
  • Cloud and remote-work strategy
  • Vendor and license reviews
  • Business continuity planning
  • Office moves and expansion
  • Technology due diligence for mergers
  • Quarterly leadership reporting

Ask to see a sample quarterly business review. It should communicate business risks, trends, decisions, budgets, and priorities—not simply display the number of tickets closed.

The 30-Item Law Firm IT Transition Checklist

Use this checklist before approving the switch:

  1. Document the five primary reasons for changing providers.
  2. Define measurable expectations for the new relationship.
  3. Review the current contract and notice requirements.
  4. Confirm the outgoing provider’s offboarding obligations.
  5. Inventory all users and devices.
  6. Inventory all legal and business applications.
  7. List every technology vendor and account owner.
  8. Confirm ownership of the firm’s domain.
  9. Confirm ownership of Microsoft 365.
  10. Identify all administrative accounts.
  11. Collect network diagrams and system documentation.
  12. Identify provider-owned hardware and licenses.
  13. Verify that backups are currently operating.
  14. Complete a backup restoration test.
  15. Plan replacement of security and monitoring tools.
  16. Review multi-factor authentication coverage.
  17. Review former employee and vendor access.
  18. Identify unsupported hardware and software.
  19. Collect cyber insurance and client security requirements.
  20. Create a list of open security and compliance findings.
  21. Approve the 30-, 60-, and 90-day onboarding plan.
  22. Assign a transition leader within the law firm.
  23. Establish a secure credential-transfer process.
  24. Notify employees of the new support procedure.
  25. Schedule an employee orientation.
  26. Establish a technical overlap period.
  27. Test the new help desk before final cutover.
  28. Verify that every device reports to the new provider.
  29. Schedule the first quarterly strategy review.
  30. Confirm that final documentation belongs to the firm.

A Practical Transition Example for a 35-Employee Law Firm

Consider a Salt Lake City law firm with 35 employees, one office, several remote attorneys, Microsoft 365, a cloud practice-management system, a document server, and an outsourced IT provider.

The firm is changing providers because support responses are inconsistent, invoices are unpredictable, and leadership has not received evidence that backups can be restored.

During discovery, the incoming provider finds:

  • Five former employee accounts are still active.
  • Several users do not have multi-factor authentication.
  • The domain is registered through an account controlled by the outgoing provider.
  • The backup system has not been restoration-tested in the last year.
  • Eight laptops are approaching the end of their supported life.
  • No written incident response plan exists.

The provider divides the work into three groups.

Immediate: Secure the domain, disable inactive accounts, enforce MFA, deploy endpoint protection, and verify backups.

First 60 days: Test recovery, replace unsupported devices, document vendors, review Microsoft 365, and create the incident response plan.

First 90 days: Present a three-year technology budget, conduct employee training, run an incident-response exercise, and establish quarterly reporting.

This phased approach allows the firm to correct urgent risks without attempting every improvement during the first week.

What Legal Clients Value During IT Support

Feedback from 911 IT clients repeatedly highlights five qualities that matter during a technology transition and the relationship that follows:

  • Reaching a real person when assistance is needed
  • Receiving a fast response
  • Working with patient technicians who explain the solution
  • Having one team take ownership of interconnected systems
  • Feeling that the provider functions as part of the internal team

One legal-services client described relying on 911 IT for email, court filing systems, legal research tools, document access, and other essential attorney workflows. The client emphasized the value of speaking with a live technician and receiving remote assistance until the issue was resolved.

Another legal-industry client valued having one team understand its IT, phone, and hosting environment. That familiarity reduced the need to explain the company’s systems repeatedly and helped minimize downtime.

Those outcomes should be built into the selection and onboarding process rather than left to chance.

Red Flags Before Switching Providers

Pause the process when the incoming provider:

  • Prepares a final proposal without assessing the environment
  • Cannot describe its onboarding process
  • Promises a zero-risk transition
  • Does not ask about legal applications or client requirements
  • Cannot explain how existing security tools will be replaced
  • Does not verify Microsoft 365 ownership
  • Assumes backups work without testing them
  • Has no plan for obtaining documentation
  • Cannot identify who will lead the transition
  • Does not provide written pricing and exclusions
  • Expects the firm to coordinate every vendor
  • Will not commit to returning documentation and credentials later

Frequently Asked Questions

How long does it take to switch IT providers?

A 25–50 employee firm should generally plan for a 30–90 day transition. A well-documented cloud-based environment may move faster, while multiple locations, aging servers, missing passwords, security gaps, and complex applications can extend the timeline.

Should we tell our current provider before selecting a new one?

Review the existing agreement first and select the incoming provider before issuing final notice. The law firm should understand notice periods, renewal terms, ownership, offboarding requirements, and transition risks before beginning the formal change.

Will employees experience downtime?

A properly planned transition should minimize disruption. Some brief interruptions may be required when changing security tools, network equipment, accounts, or applications. The provider should schedule these changes, communicate them in advance, and prepare a rollback procedure.

Can the old provider withhold passwords?

The answer depends on account ownership and the existing agreement. The law firm should retain appropriate control over its essential business accounts and documentation. Disputes should be addressed through firm leadership and qualified counsel rather than through unsafe technical workarounds.

Do we need to replace all of our equipment?

No. The new provider should inventory and assess existing equipment. Devices that remain supported, secure, reliable, and suitable for the firm’s needs may continue in service. Unsupported or high-risk equipment should receive a prioritized replacement plan.

Should both providers overlap?

A limited overlap is useful for documentation transfer, tool deployment, backup verification, and problem escalation. The period should have a defined purpose, owner, and completion date.

Who should lead the transition inside the law firm?

Assign one internal decision-maker, typically a firm administrator, operations leader, managing partner, or technology committee representative. That person should coordinate approvals, communication, access, vendors, and priorities.

What should be completed on the first day?

The new provider should have access to essential systems, a current contact list, the ability to receive support requests, deployed management tools, confirmed escalation procedures, and a plan for urgent security or operational issues.

When should we evaluate whether the transition was successful?

Review progress at approximately 30, 60, and 90 days. Evaluate support responsiveness, device coverage, security improvements, documentation, recovery testing, employee feedback, open risks, and progress against the onboarding plan.

Switch Providers With a Plan, Not a Leap of Faith

A law firm should not remain with an underperforming IT provider solely because changing feels risky. The greater risk may be continuing with slow support, untested backups, unclear account ownership, weak security, and no strategic plan.

A successful transition follows a repeatable process:

  1. Define the business reasons for changing.
  2. Inventory accounts, systems, applications, and vendors.
  3. Protect ownership of critical assets.
  4. Verify security and recovery.
  5. Use a written 30-, 60-, and 90-day onboarding plan.
  6. Measure the new provider against specific outcomes.

911 IT provides live 24/7 assistance, local on-site support, managed cybersecurity, Microsoft cloud expertise, business continuity, vendor coordination, and proactive technology planning for Utah businesses.

Explore our managed IT services, review our cybersecurity services, or schedule a 10-minute discovery call to plan a controlled transition from your current provider.