Break-Fix vs Managed IT: Which Model Fits Your Firm
Most Los Angeles law firms did not choose break-fix IT. They inherited it. A partner knew a good technician years ago, the arrangement worked, and nobody revisited it as the firm grew from six people to sixty. The invoices only arrive when something breaks, which feels disciplined and frugal.
The problem is that break-fix optimizes for the wrong variable. It minimizes visible spend while quietly maximizing exposure — to downtime, to ethics complaints, to failed client security questionnaires, and to the growing list of things your cyber insurer now expects you to have in place before they will pay a claim.
What Break-Fix Actually Buys You
Break-fix is a reactive model. You call when something is broken, a technician responds, the issue gets resolved, and you pay for the work performed. There is nothing dishonest about it. For a two-person practice with a handful of laptops and cloud-only applications, it can be entirely reasonable.
What break-fix does not buy is anything that happens before the break. No patch cadence. No backup verification. No endpoint monitoring. No offboarding checklist when a paralegal leaves for a competitor. No one is watching the environment on a Tuesday when nothing is on fire — and Tuesday is exactly when attackers prefer to work.
The Incentive Problem Nobody Names
The structural issue with break-fix is that your vendor gets paid when things go wrong. Nobody is accusing your technician of sabotage. But there is no financial mechanism rewarding them for the outage that never happened, the phishing email that got quarantined, or the ransomware that failed to execute because application allowlisting was in place.
Managed IT inverts that. Under a flat recurring agreement, every prevented incident is margin the provider keeps. Their interest and yours converge. That alignment — not the technology — is the actual product you are buying.
Where the Ethics Rules Have Landed
This is no longer purely an operations question for law firms. The ABA Model Rule 1.1 comment on technology competence obligates lawyers to keep abreast of the benefits and risks of relevant technology. ABA Formal Opinion 483 goes further, addressing a lawyer’s obligations after an electronic data breach — including the duty to monitor for intrusions and to notify affected current clients.
California practitioners should read those alongside the State Bar of California’s guidance on the confidentiality duty, which treats reasonable safeguards for client information as a professional obligation rather than an IT preference. “We only call someone when the server goes down” is a difficult position to defend to a disciplinary body after a breach.
The Comparison, Honestly Drawn
| Dimension | Break-Fix | Managed IT |
|---|---|---|
| Vendor incentive | Paid when systems fail | Paid to keep systems stable |
| Budget behavior | Unpredictable, incident-driven | Predictable, recurring |
| Patching and updates | Ad hoc, often deferred | Scheduled and documented |
| Backup verification | Assumed until tested by disaster | Routinely tested and logged |
| Security monitoring | None between calls | Continuous |
| Response to an outage | Queue position depends on availability | Governed by a service level agreement |
| Insurance questionnaires | Firm answers from guesswork | Provider supplies documented controls |
| Client security audits | Scramble per request | Standing evidence package |
| Staff onboarding/offboarding | Informal, easily missed | Defined, auditable process |
| Institutional knowledge | Lives in one technician’s head | Documented in a managed platform |
What Changed: Insurance and Client Audits
Two forces have made the break-fix position harder to hold, and neither is about technology preference.
First, cyber insurance underwriting tightened considerably. Carriers now ask specific control questions — multifactor authentication coverage, endpoint detection and response, immutable or offline backups, privileged access management — before binding or renewing. Answering those accurately requires someone who actually administers the environment. Guessing on an application is a coverage problem waiting to surface at claim time.
Second, corporate clients started auditing their outside counsel. If your firm handles work for financial institutions, healthcare organizations, or public companies, expect security questionnaires that map to recognized frameworks. The NIST Cybersecurity Framework 2.0 and the CIS Critical Security Controls are the two most common reference points. Those questionnaires assume a documented, continuously operated program. Break-fix produces neither documentation nor continuity.
The Real Cost Is Downtime, Not Invoices
The way to compare these models is not by looking at what you pay a vendor. It is by looking at what a lost day costs a firm that bills by the hour.
When a document management system is unavailable, associates cannot draft, partners cannot review, and filing deadlines do not move. That lost capacity is unrecoverable — you do not bill it later. Add the administrative drag of a security incident: forensic investigation, client notification, potential regulatory reporting, and weeks of partner attention diverted from client work. The FBI’s Internet Crime Complaint Center annual reports document the scale of reported losses from business email compromise and ransomware across sectors, and professional services firms are well represented in that data.
Against that, the qualitative tradeoff is straightforward. Break-fix converts IT into a variable cost you cannot forecast and cannot control. Managed IT converts it into a planned operating expense with defined response obligations. Most firms find the second easier to defend to a partnership committee, precisely because it is predictable.
When Break-Fix Is Still the Right Call
Honesty matters here. Break-fix remains defensible for a solo practitioner or a very small firm running entirely on well-configured cloud services, with no on-premises servers, no locally stored client files, and no clients imposing security requirements. If your entire technology footprint is a few laptops and a reputable cloud practice management platform with MFA enforced, a full managed agreement may be more structure than you need.
The threshold usually gets crossed at three points: when headcount grows past the point where everyone knows what everyone else has access to, when you take on a client who sends a security questionnaire, or when your insurance renewal asks a question you cannot answer confidently. Any one of those is the signal.
How to Evaluate a Managed Provider
Not all managed agreements are equal, and some are break-fix with a subscription wrapper. Ask pointed questions before signing.
Ask what is explicitly included versus billed separately — project work, after-hours response, and vendor coordination are common carve-outs. Ask for the response and resolution commitments in writing, tied to severity levels. Ask how backups are tested and how often you receive proof. Ask whether they will complete your cyber insurance application and client security questionnaires on your behalf, and whether they will stand behind those answers. Ask specifically about experience with legal practice software — document management, time and billing, court filing systems — because general business IT experience does not transfer cleanly.
Finally, ask what happens if you leave. A provider confident in their work will hand over documentation, credentials, and configuration without friction. One who cannot is selling you dependency, not management.
Making the Decision
The question is not whether break-fix or managed IT is cheaper on any given month. It is which model your firm can defend — to a client conducting an audit, to an underwriter reviewing a claim, and to a disciplinary body after an incident. Structure your decision around exposure and obligation, not around the last invoice you received.
If your firm has grown past the point where one technician’s memory is your disaster recovery plan, it is time to formalize. Map your actual technology footprint, identify where client data lives, and be candid about which controls you could evidence tomorrow if asked.
Los Angeles law firms deserve IT that is built around their ethical obligations, not around emergency phone calls. We Solve Problems helps firms move from reactive break-fix arrangements to documented, defensible managed IT programs — including the security evidence your clients and insurers now expect. Contact us to start the conversation.