A 25-attorney firm in the Loop has one IT manager. On a typical Tuesday, she resets a partner’s MFA, fixes a NetDocuments sync error on a paralegal’s laptop, and fills out the cyber questionnaire for the firm’s malpractice renewal. Meanwhile, nobody is reviewing the sign-in alerts from Microsoft 365. Nothing is wrong with her work. The firm has simply given one person a job that needs a team.
The question of managed IT vs. co-managed IT for law firms comes down to a simple choice. You can hand your whole IT function to an outside partner, or you can keep internal staff and bring in a partner to cover what they can’t. This guide is for managing partners and firm administrators who need to decide which model fits. It covers who owns what, how cost works, what each model means for your ABA confidentiality obligations, and which model fits your firm’s size.
The Real Difference Is Who Answers for the Outcome
Managed IT means an outside provider runs your entire technology environment for a flat monthly fee. That covers the help desk, security monitoring, patching, backups, Microsoft 365 administration, vendor coordination, and long-term planning. You have no internal IT staff. The provider is your IT department, and it is accountable for the whole outcome, from a stuck printer to a suspicious login at 2 a.m. CTI’s managed IT services follow this model, with unlimited support and a dedicated account manager who runs quarterly business reviews.
Co-managed IT means your firm keeps one or more internal IT people, and an outside partner fills defined gaps. The split is negotiated. Often the internal person keeps onsite support, the legal applications, and relationships with attorneys. The partner takes the 24/7 monitoring, security tooling, patching, after-hours coverage, and project capacity. Your team keeps control of key decisions. The partner adds depth and removes single points of failure. CTI has written in detail about how this works in co-managed IT for Chicago law firms.
Managed IT vs. Co-Managed IT for Law Firms: Side by Side
| Area | Fully Managed IT | Co-Managed IT |
| Help desk | Provider handles all user support, unlimited | Split: internal staff often take onsite and attorney-facing issues, provider takes overflow and after-hours |
| Security | Provider owns the full stack: MFA, Conditional Access, endpoint protection, email security, SOC monitoring and response | Provider usually owns 24/7 monitoring, detection, and response; internal staff own policy decisions and day-to-day enforcement |
| Projects | Provider plans and delivers migrations, upgrades, and rollouts | Shared: provider adds hands and specialized skills for large projects; internal staff lead or coordinate |
| Vendor management | Provider coordinates with DMS, practice management, ISP, and phone vendors | Typically internal staff, who know the vendor contacts and contract history |
| Legal software administration | Provider supports DMS, practice management, and e-discovery tools | Usually internal staff, with provider backup |
| Cost structure | Flat per-user monthly fee (CTI’s range is 200–400 per user per month) | Internal salaries plus a partner fee scoped to the functions you hand off |
| Best fit by firm size | Solo practitioners to roughly 50 users with no dedicated IT staff | Firms with at least one IT employee, commonly 30 users and up |
| Compliance coverage (ABA Rule 1.6(c), client confidentiality) | One party documents and maintains every control, so evidence of “reasonable efforts” lives in one place | Coverage is only complete if a written responsibility matrix closes the gaps between the two teams |
Firm-size ranges are rules of thumb. A 15-person firm with a strong IT hire can run co-managed well. A 70-person firm whose IT person just left may be better served by full management while it rebuilds.
Your Ethics Duties Stay the Same Under Either Model. The Proof Changes.
ABA Model Rule 1.6(c) requires lawyers to make reasonable efforts to prevent unauthorized access to or disclosure of client information. Illinois adopted the same duty in its own Rule 1.6(e). Model Rule 5.3 adds that lawyers must supervise nonlawyer help, and its commentary makes clear that this includes outside service providers who handle client information.
In practice, outsourcing IT does not outsource your ethical responsibility. Whether you choose managed or co-managed IT, the firm must be able to show that someone reasonable was watching. That means MFA was enforced, patches were applied, backups were tested, and suspicious activity was investigated.
The stakes are going up. The ABA Journal reported in March 2026 that BakerHostetler’s incident response team handled nearly twice as many law firm cyber incidents in 2025 as it did the year before. Attackers target firms because they hold privileged communications, M&A details, and personal data for many clients in one place.
The two models create different compliance risks:
- Managed IT puts every control in one provider’s hands. Your job is due diligence: confirm the provider understands legal confidentiality, can produce documentation for client security questionnaires and cyber insurance applications, and reports to you on a regular schedule. CTI’s ABA Rule 1.6 guide for Illinois law firms covers what that documentation should include.
- Co-managed IT puts controls in two places, and breaches often start where responsibilities meet. If the internal IT manager assumes the partner reviews Conditional Access exceptions and the partner assumes the firm does, nobody reviews them. A co-managed contract without a written responsibility matrix for every security control is a liability waiting for a trigger.
Legal Software Is Often What Decides It
Generic IT comparisons skip this factor, but for law firms it often settles the question. Firms run specialized platforms, and those platforms need someone who understands how lawyers use them.
Document management systems such as iManage and NetDocuments hold the firm’s core work product. They require matter-centric security, ethical walls, correct profiling, and careful integration with Outlook and Microsoft 365. A misconfigured ethical wall is a confidentiality failure, not just an IT ticket.
Practice management and billing platforms such as Clio, PracticePanther, Aderant, or Elite 3E touch time entry, trust accounting, and client records. When they go down, billable time stops.
E-discovery and litigation support tools such as Relativity, Everlaw, or on-premises review platforms bring large data volumes, chain-of-custody concerns, and secure transfer with opposing counsel and vendors.
Here’s how legal software shapes the decision. If your internal IT person is the one who truly understands your DMS configuration and your litigation support workflow, that knowledge is hard to replace. A co-managed model keeps it in the firm while offloading work that doesn’t need firm-specific context, such as patching, monitoring, and after-hours alerts. If no one inside the firm owns these platforms, your managed IT provider must be able to support them directly. Ask any prospective provider which DMS and practice management systems it supports today, and ask for law firm references. CTI’s law firm software buyer’s guide is a useful reference if you’re also re-evaluating the platforms themselves.
Three Firms, Three Answers
Solo or small firm with no IT staff: Choose managed IT
A 6-attorney family law practice in Naperville has a firm administrator who “handles the computers” between payroll and conflicts checks. Security settings came from whoever set up Microsoft 365 years ago. No one has tested a restore from backup.
This firm needs fully managed IT. There is no internal team to share work with, and making a non-technical administrator responsible for Rule 1.6(c) compliance is unfair to that person and risky for the partners. A flat monthly fee turns an unpredictable cost into a line item. The firm also gets 24/7 coverage it could never staff itself. This is the scenario CTI’s IT services for law firms are built around.
Mid-size firm with one overwhelmed IT person: Choose co-managed IT
This is the Loop firm from the opening. The IT manager is capable and knows the firm’s iManage setup inside and out, but she is doing the work of three people. When she takes vacation, the firm hopes nothing breaks.
Co-managed IT keeps her institutional knowledge and relationships with attorneys in place. The partner takes the 24/7 security monitoring, patch management, backup verification, overflow help desk tickets, and project help for the next Microsoft 365 or server migration. She gets a team behind her. The firm removes its biggest single point of failure. The partners also get documented, continuous security coverage that one person can’t provide.
The alternative is hiring a second IT employee. That doubles payroll, still doesn’t produce round-the-clock monitoring, and leaves two generalists where the firm needs specialists.
Larger firm with an IT department that needs security depth: Choose co-managed security
A 120-attorney firm has a director of IT, two support technicians, and a litigation support analyst. Daily operations are handled well. What the team lacks is dedicated security staff: analysts who watch alerts overnight, hunt threats, and respond within minutes. Meanwhile, client outside counsel guidelines and security questionnaires keep getting stricter.
This firm needs a narrow co-managed arrangement focused on security. That usually means an outsourced security operations center with managed detection and response, periodic penetration testing, and strategic security guidance. The internal team keeps everything it does well. Building an in-house SOC with 24/7 staffing is out of reach for most firms this size, and co-managed security closes that gap for a fraction of the cost.
Compare the Cost of Building It, Not What You Pay Today
Firms often compare a managed IT quote to what they spend on IT now. That comparison misleads, because current spending usually leaves real gaps uncovered: after-hours monitoring, tested disaster recovery, documented security controls, and a backup for the one person who knows the passwords.
A fairer comparison asks what it would cost to build the same coverage internally. That includes salaries and benefits for enough staff to cover nights, weekends, and vacations; security tools such as endpoint detection, email filtering, and SIEM licensing; and the time senior staff spend managing all of it.
Managed IT at CTI runs $200 to $400 per user per month, depending on the complexity of the environment. Co-managed pricing depends on scope. You pay for the functions you hand off, and you keep paying your internal team. For firms with a strong IT employee, that combination usually costs less than adding a second or third hire and delivers more coverage.
The Verdict: Managed IT vs. Co-Managed IT for Law Firms
If your firm has no dedicated IT staff, choose managed IT. Solo practices and small firms, roughly up to 50 users, get full coverage, predictable costs, and one accountable party for ABA Rule 1.6(c) compliance.
If your firm has one or two IT employees who are stretched thin, choose co-managed IT. Keep their knowledge of your legal software and your attorneys. Hand off 24/7 monitoring, patching, backups, overflow support, and project capacity.
If your firm has an IT department but no dedicated security team, choose co-managed security. Add a SOC with managed detection and response, and keep daily operations in-house.
Under either model, require a written responsibility matrix and regular reporting. Your confidentiality obligations don’t transfer to a vendor. What you need is proof that every control has an owner and that someone is checking.
If you aren’t sure which model fits, start with an assessment of where your environment stands today. CTI works with Chicago-area firms under both models, and our law firm IT services page explains how we support legal teams. To talk through your firm’s situation, book a strategy call or call us at (312) 922-8600 in Chicago or (847) 888-1900 in the suburbs.
Why Is CTI Technology The Best Choice For IT Services In The Chicagoland Region?

Years in Business
Microsoft Certified Partner
Client Retention Rate