In-House IT vs a Managed Provider for LA Law Firms
The Three Things You’re Actually Comparing
When a firm crosses roughly the point where the office manager can no longer be the de facto IT department, the conversation almost always gets framed as a hiring decision: do we bring someone on, or do we outsource? That framing hides the real question. What actually differs between the two models is not who cuts the check — it’s coverage, security depth, and continuity, and those three things fail in very different ways.
Coverage is availability: which hours, which locations, which systems, and how fast someone with the right authority can act. Security depth is the range of specialized functions your environment needs — identity administration, endpoint detection and response, vulnerability management, backup verification, email security, log retention — and whether each is genuinely owned or merely assumed. Continuity is what happens when the person who knows everything gets sick, gets recruited away, or leaves on bad terms three days before a trial.
A good in-house hire beats a bad managed provider. A good managed provider beats a good solo in-house hire on all three dimensions above, because those dimensions are about bench depth, not talent. And for most firms in the ten-to-eighty-attorney range, the strongest configuration is neither one alone. The honest analysis below should let you tell which situation you’re in.
Coverage: The Hours a Law Firm Actually Runs On
Law firms do not run on business hours. They run on filing deadlines, depositions that start early, closings that end late, document productions over the weekend, and partners who work from home after dinner. An in-house generalist covers a workweek. The practice covers considerably more than that.
The gap shows up in specific, predictable places. A partner cannot get into the document management system at 9 p.m. the night before a hearing. A brief needs to go out and the e-filing session keeps timing out. An associate’s laptop dies on a Sunday during trial prep. None of these are exotic incidents — they’re routine, and they’re all outside a single employee’s coverage window. Firms with one internal person usually solve this informally: the IT person answers texts at night, unpaid, until they burn out and leave. That’s not a coverage model. It’s a resignation on a delay timer.
The second coverage gap is planned absence. Vacation, jury duty, parental leave, conferences, and illness are all normal, and each one leaves the firm with no IT function at all unless someone else is on the hook. A managed provider’s core structural advantage is that coverage is a roster, not a person: after-hours and weekend response, a documented escalation path, and a second and third technician who can read the same documentation and pick up the same ticket.
The third gap is the one firms notice last. A single generalist spends most of their week on interrupt-driven work — password resets, printer mappings, onboarding a new paralegal, a Zoom that won’t share screen. That work is real and it has to be done, but it means the strategic work never gets done. Patching slips. Backup restores go untested for a year. The security roadmap becomes a document that gets updated the week before the insurance renewal. The failure isn’t competence; it’s that one person cannot be both the help desk and the security program.
Security Depth: One Generalist Is Not a Security Team
Law firms are unusually attractive targets because they aggregate other people’s secrets: deal terms before announcement, settlement positions, unreleased creative material, personal information about clients and adverse parties. Attackers know it, and the attack patterns are well documented. Verizon’s 2025 Data Breach Investigations Report found a human element in roughly 60% of breaches, third-party involvement in 30% (double the prior year), and ransomware present in 88% of breaches at small and mid-sized organizations. The dominant threats are phishing, stolen credentials, and unpatched software — not zero-days.
The defenses that address those threats are individually unglamorous and collectively broad. Consider what a competent modern law firm environment requires someone to actually own, week over week:
- Identity and access: conditional access policies, blocking legacy authentication, phishing-resistant MFA, privileged account separation, quarterly access reviews. CISA reports that enabling multifactor authentication makes an account 99% less likely to be hacked — but only if it’s enforced everywhere, including on service accounts and legacy mail protocols.
- Endpoint detection and response with someone watching it. An EDR console that nobody monitors at 2 a.m. is a very expensive log file.
- Vulnerability and patch management against a real standard. CISA’s Binding Operational Directive 22-01 requires federal agencies to remediate vulnerabilities in the Known Exploited Vulnerabilities catalog within two weeks for recently assigned CVEs and within six months for older ones. That’s a defensible benchmark to hold your own IT function to, whoever provides it.
- Backup that is immutable, off-tenant, and restore-tested. Microsoft 365 retention is not backup. If your only copy of a matter folder lives in the same tenant as the account an attacker just compromised, you do not have a backup.
- Email security, security awareness training, log retention, and incident response — including audit log retention long enough to reconstruct what happened. IBM’s 2025 Cost of a Data Breach Report puts the U.S. average breach cost at $10.22 million against a global average of $4.44 million, with a mean time to identify and contain of 241 days. Short log retention is how a firm ends up unable to prove what an intruder did or didn’t take.
No single hire covers all of that at depth, and the market makes the hire harder every year: the 2024 ISC2 Cybersecurity Workforce Study estimated a global shortfall of about 4.8 million cybersecurity professionals. In Los Angeles specifically, a strong generalist who can also do security work is competing for attention against studios, streamers, aerospace, health systems, and the Westside startup market. Firms that do hire well often lose that person inside two years — and the departure resets the security program, not just the help desk.
This is where the structural argument for a managed provider is strongest. You aren’t buying more hours. You’re buying access to specialization your firm cannot justify employing full-time: someone who does nothing but identity, someone who does nothing but threat detection, someone who does nothing but backup and recovery.
The AI Wrinkle: Copilot Exposes Your Permissions Debt
Every firm is now being pitched AI — drafting assistants, deposition summarizers, Microsoft 365 Copilot. Here is the practical security consequence that gets skipped in the demo: AI assistants inherit the permissions of the user running them. If your file shares and SharePoint sites have accumulated a decade of over-broad permissions — the “everyone can access” folder, the departed partner’s site nobody locked down, the ethical wall that exists on paper — an AI assistant will cheerfully surface all of it in response to a plain-language question. Conflicts and confidentiality problems that were previously protected by obscurity become one query away.
Cleaning that up is a project: permission inventory, sensitivity labeling, retention policy, ethical wall enforcement inside the document management system, and a written policy on which tools may touch client data. It is exactly the kind of work that never happens when your one IT person is answering the phone all day, and exactly the kind of work a provider should be bringing to you before you turn Copilot on rather than after.
Continuity: The Single Point of Failure Nobody Budgets For
Run this test at your next partner meeting. Ask: if our IT person did not answer the phone tomorrow, who has the global administrator credentials for our Microsoft tenant, who controls the domain registrar, who can authorize a restore, and where is that written down?
If the answer is “they’d know,” you have a continuity problem regardless of how good they are. In-house IT concentrates operational knowledge in one head by default. That’s not a character flaw — documentation is the first thing that gets deferred when one person is doing three jobs. But the consequences are severe and asymmetric: a disputed departure can leave a firm locked out of its own systems, and the recovery is slow, expensive, and occasionally requires counsel.
A managed provider’s continuity advantage is contractual and procedural rather than heroic. Credentials live in a documented, access-controlled vault. Runbooks exist because a second technician has to be able to work the ticket. Onboarding and offboarding follow a checklist rather than institutional memory. Vendor relationships — your DMS, your practice management platform, your carrier, your ISP — are held by an organization, not a person.
The flip side is real and you should weigh it: a provider can also be a single point of failure if the relationship is thin, if you have no named engineer who knows your practice, or if the contract makes it hard to leave. Ask before you sign: who specifically is assigned to us, what happens at offboarding, do we own our documentation and our tenant, and can we export everything without a fight? A provider that hesitates on tenant ownership or documentation portability is telling you something important.
In-House vs. Managed vs. Co-Managed: A Side-by-Side
| Dimension | Solo In-House Generalist | Managed Provider | Co-Managed (Internal + Provider) |
|---|---|---|---|
| Coverage hours | Business hours; after-hours depends on goodwill | Contracted after-hours and weekend response with defined escalation | Internal for daytime concierge; provider for nights, weekends, and overflow |
| Absence and turnover | No coverage during PTO, illness, or after resignation | Roster-based; a second technician picks up the same ticket | Either side can absorb the other’s gap |
| Security specialization | Generalist breadth, limited depth in identity, EDR, and detection | Access to specialists your firm couldn’t employ full-time | Internal owns apps and users; provider owns security stack |
| Monitoring and response | Alerts reviewed when there’s time | Continuous monitoring with defined response commitments | Provider monitors; internal coordinates the firm’s response |
| Patch and vulnerability cadence | Slips first when help desk volume spikes | Scheduled, reported, measurable against a standard | Provider enforces cadence; internal manages practice-app exceptions |
| Backup and restore testing | Frequently untested until it’s needed | Verified restores on a documented schedule | Provider tests; internal validates matter-level recovery |
| Documentation and credential custody | Concentrated in one person’s head | Centralized, access-controlled, portable if you insist on it | Shared vault with dual custody |
| Knowledge of your practice | Deep — knows the partners, the matters, the quirks | Varies; depends on onboarding and industry fit | Best of both if the internal role is scoped well |
| Compliance and insurance evidence | Ad hoc, assembled at renewal | Reporting and attestation artifacts produced as a routine deliverable | Provider supplies artifacts; internal owns the narrative |
| Cost profile | Fixed salary plus unpredictable tooling, training, and emergency spend | Predictable recurring commitment; project work scoped separately | Predictable base with a smaller internal footprint |
| Scaling with headcount | Degrades as attorney count and offices grow | Absorbs growth without a hiring cycle | Scales without re-founding the IT department |
What Los Angeles Makes Different
Some of this analysis is universal. Parts of it are not, and the LA-specific parts tend to be the ones that bite.
Geography is a coverage tax. A firm with offices in Century City and Downtown, plus attorneys working from the Valley and the South Bay, cannot rely on one person physically walking to desks. Two site visits in a day can consume most of a workday in traffic. Remote-first support with well-defined onsite escalation is not a compromise here — it’s the correct design.
Court deadlines are hard deadlines. Los Angeles Superior Court requires electronic filing for represented parties in civil matters. An outage at 4 p.m. on a filing day is not a help desk ticket; it’s a potential malpractice event. That changes what “acceptable response time” means and should be written into whatever service commitment you sign.
Regional disruption is a scheduled event, not a tail risk. Public safety power shutoffs, wildfire smoke and evacuation zones, and seismic risk all mean your firm should be able to operate with the office inaccessible — not in theory, but tested. That means cloud-hosted or replicated document systems, laptops rather than desktops, softphones, and a communication tree that works when email is down. Ask when your firm last ran that test end to end.
Entertainment and media clients raise the bar. Firms with studio, label, talent, or production clients routinely receive outside counsel guidelines and vendor security questionnaires with specific technical requirements: encryption standards, access controls on pre-release material, breach notification windows, sometimes restrictions on where data may be stored or which subcontractors may touch it. Answering those accurately requires evidence, and the firms that lose work over them usually lose it because nobody could produce the evidence — not because the controls were absent.
What Insurers, Clients, and California Law Will Ask You to Prove
Whichever model you choose, you will be asked to demonstrate controls to at least four audiences: your cyber insurer at renewal, your clients through their guidelines and questionnaires, your regulators, and — if something goes wrong — opposing counsel and possibly a court.
California’s breach notification statute requires notice without unreasonable delay, and breaches affecting more than 500 California residents must also be reported to the California Attorney General, where the submission becomes publicly searchable. For firms that meet the CCPA’s applicability thresholds, the statute also creates a private right of action for breaches of certain unencrypted personal information, with statutory damages of $100 to $750 per consumer per incident — a figure that scales alarmingly against a class action plaintiff list. Encryption at rest and in transit is not just hygiene; it is a specific statutory posture.
The fraud exposure is equally concrete. The FBI’s 2024 Internet Crime Report logged 859,532 complaints and more than $16.6 billion in reported losses, with California leading all states in both complaint volume and reported losses. For law firms, the highest-frequency version of this is wire fraud on client trust funds — a compromised or spoofed email thread that changes settlement or escrow wiring instructions. The control that stops it is procedural (out-of-band verbal verification against a known-good number, no exceptions, no matter who is asking) and technical (mail flow rule auditing, impersonation protection, alerting on inbox forwarding rules). Someone has to own both halves.
The practical test of any IT model is whether it produces evidence on demand: a current asset inventory, MFA enforcement reports, patch compliance against the KEV catalog, restore test results with dates, security awareness training completion, and a written incident response plan that names your breach coach, your carrier’s hotline, and who is authorized to declare an incident at 11 p.m.
A Scorecard You Can Run This Week
Run this against your current setup — internal, outsourced, or neither. Every item is answerable in under an hour, and the pattern of answers tells you which model you need.
- Restore test. Ask for the date of the last successful restore of a full matter folder and a partner’s mailbox, and how long it took. “We have backups” is not an answer.
- Bus factor. Name every person who holds global admin in your Microsoft tenant and who controls the domain registrar. If it’s one person and no vault, that’s your top risk.
- MFA reality check. Not “do we have MFA” but “which accounts are exempt, and why.” Exemptions are where compromises live.
- Patch evidence. Ask for a report showing which endpoints are behind and by how long, measured against a published standard.
- Log retention. How many days of sign-in and audit logs can you actually produce? Compare that to how long breaches typically go undetected.
- Offboarding proof. Pick the last person who left. Verify their accounts, mobile access, and third-party logins are actually terminated.
- After-hours path. What number does a partner call at 9 p.m. on a Sunday, and what is the committed response time in writing?
- Insurance alignment. Pull last year’s cyber application and verify every attested control is still true today. Misattestation is a coverage denial waiting to happen.
- Client guidelines. Pull the two most demanding outside counsel guidelines you’ve signed and check whether you can currently evidence compliance.
- Strategic backlog. Ask your IT function what security work has been deferred for more than ninety days. The length of that list is the clearest signal of whether one person is enough.
If items 1, 2, 4, and 5 come back weak, you have a depth problem, and adding help desk hours won’t fix it. If item 7 is the only failure, you may need coverage rather than a wholesale change. If items 9 and 10 fail, you have a capacity problem that will get worse with every attorney you add.
Making the Change Without Breaking the Practice
The transition is where firms get hurt, so sequence it deliberately.
Before anything else, take custody of the assets: confirm the firm — not an individual, not a vendor — owns the Microsoft tenant, the domain registration, and the documentation. Get credentials into a firm-controlled vault with at least two partners holding break-glass access.
During evaluation, insist on a written assessment before a contract rather than after. Any provider worth hiring will tell you what’s broken, in what order it should be fixed, and what they will and won’t cover — in writing, with named response commitments. Ask what happens the first time a filing deadline collides with an outage. Ask who your assigned engineer is and how often they’ll be on site.
During transition, keep your internal person if you have one, and rescope the role rather than eliminating it. The best co-managed arrangements give the internal person the work they’re actually good at and that a provider can’t replicate — knowing the partners, owning the practice management and document systems, sitting in on matter intake, being the human face of technology — while the provider takes monitoring, patching, backup verification, identity governance, and after-hours. That’s usually the configuration that fits a growing firm best: enough internal presence that technology feels attentive, enough external depth that nothing critical rests on one person’s memory.
Whatever you choose, the deliverable is the same: coverage that matches how the firm actually works, security depth that maps to how firms actually get breached, and continuity that survives one person’s departure. Pick the model that produces evidence for all three.
We Solve Problems is a Los Angeles managed IT provider with deep experience supporting law firms and entertainment-industry professional services — managed IT, cybersecurity, Microsoft 365, and compliance, delivered as a co-managed partnership or a full outsourced function depending on what your firm actually needs. If you want an outside read on where your current setup has coverage gaps, security depth gaps, or a bus-factor problem, get in touch with us and we’ll walk your firm through the scorecard above.