Speak With An IT Professional Immediately. Call (312) 922-8600

Questions a Law Firm Should Ask Before Signing With an IT Provider in Chicago

20+ Years in Business Years in Business
100% HIPAA Certified Staff HIPAA Certified Staff
Microsoft Certified Partner Microsoft Certified Partner
98.2% Client Retention Rate Client Retention Rate

A managing partner interviewing IT vendors for a 30-attorney firm asked three candidates the same question: “How do you handle a compromised iManage login on a Friday afternoon?” Two gave a version of “we’d investigate and get back to you.” The third walked through lockout procedures, audit log review, and client notification timelines without hesitation. That one difference told the partner more than any pitch deck could.

Most law firms don’t find out their IT provider was the wrong fit until something breaks: a missed court deadline because remote access failed, a phishing email that got through because nobody was watching inboxes at 6 p.m., or a backup that turned out to have never been tested. By then, switching providers mid-crisis is its own headache. The better approach is asking the right questions before you sign, not after the first incident.

Below are the questions that actually separate a capable IT provider for law firms in Chicago from a generalist MSP that added “we work with law firms” to their website.

Does the Provider Have Real Experience With Law Firms, or Just a Client or Two?

Ask for specifics: how many law firm clients do they currently support, what size are those firms, and how long have they held those relationships? A provider with genuine legal industry depth will answer immediately with names of platforms, workflows, and compliance frameworks. A generalist will pivot to talking about their overall client count instead.

This matters because legal environments run differently than a typical small business. Attorneys need secure remote access that doesn’t slow them down before a filing deadline. Staff turnover means access needs to be provisioned and revoked correctly, every time. And the tools firms rely on, from time and billing systems to conflict checks, aren’t things a provider learns on the job without creating problems for your firm first. CTI Technology has worked with Chicago-area law firms for over 20 years and is listed in the Illinois State Bar Association Expert Directory under Information Technology and Computer Software, a distinction earned through recognition by the legal community, not a marketing claim.

Hear From Our
Happy Clients

Read Our Reviews

Do They Actually Support iManage, NetDocuments, or Whatever DMS You’re Running?

This is a pass or fail question, not a matter of degree. Ask the provider to walk through how they’ve handled a real migration or integration issue with your specific document management system. If the answer gets vague, that’s informative on its own.

Document management systems sit at the center of a law firm’s daily operations, and a provider who only has “general familiarity” with iManage or NetDocuments will be learning your firm’s most critical software during your first outage, not before it. The right provider should be able to speak to profile management, workspace security, integration with Outlook and Word, and how DMS access ties into your broader identity and access controls.

Do They Understand What ABA Rule 1.6 Actually Requires From a Technology Standpoint?

Your IT provider doesn’t need to be a lawyer, but they should be able to explain, without you prompting them, what “reasonable efforts” means under Model Rule 1.6(c) and how that translates into encryption, access controls, and breach notification procedures. According to the American Bar Association, Model Rule 1.1 requires lawyers to understand the benefits and risks associated with the technology used to deliver legal services, and Model Rule 1.6 obligates them to keep client information confidential regardless of how it’s stored or transmitted.

If a provider treats confidentiality as a generic IT security conversation rather than a professional responsibility issue specific to your firm’s ethical obligations, that’s a gap that shows up during a bar complaint or malpractice inquiry, not during a routine year of service.

What Does “24/7 Support” Actually Mean When You Call at 11 p.m.?

Ask directly: is there a live engineer answering, or does the call route to a ticket queue that gets addressed the next business day? “24/7 monitoring” and “24/7 support” are not the same commitment, and providers sometimes use the phrases interchangeably to sound more available than they are.

For a law firm, this distinction has real consequences. Court deadlines and client emergencies don’t confine themselves to business hours, and a compromised account discovered at 9 p.m. on a Thursday needs a response before Friday morning, not after. Ask what the provider’s actual after-hours staffing looks like and how quickly a real person picks up.

Is Pricing Per-Ticket, or Does It Discourage Staff From Reporting Problems Early?

Some IT providers still bill per ticket or per hour, which creates a quiet incentive for staff to avoid calling in small issues until they become bigger ones. An unlimited support model removes that friction, so a paralegal who notices something odd on their screen picks up the phone immediately instead of waiting to see if it resolves itself.

Ask how support is billed, what’s included in a flat monthly rate versus what triggers a separate project quote, and whether there are caps on ticket volume or response priority tiers that effectively function as a soft limit.

Have Their Backups Actually Been Tested, or Just Scheduled?

A backup that runs on schedule but has never been tested for successful restoration is not a real backup, it’s an assumption. Ask the provider how often they test restoration, what your recovery time objective would be in a ransomware scenario, and whether backups are isolated from the primary network so an attacker who compromises your systems can’t also encrypt or delete your recovery point.

This question matters more than it used to. Ransomware groups increasingly steal data before encrypting it, which means a clean backup alone no longer guarantees you avoid a breach notification obligation, even if you never pay a ransom. Law.com reported that legal organizations in 2025 faced everything from direct breaches to impersonation attacks and third-party legal tech compromises affecting hundreds of thousands of records, a reminder that the exposure isn’t limited to a firm’s own systems.

Do You Get a Dedicated Account Manager, or Only a Help Desk Queue?

A provider that’s purely reactive support will keep you stable, but it won’t help you plan. Ask whether managed clients are assigned a dedicated Account Manager separate from day-to-day service desk staff, and how often that person meets with your firm for strategic reviews.

CTI Technology’s managed clients get a dedicated Account Manager who runs quarterly Technology Business Reviews covering environment health, emerging cyber risk trends, and budget planning, on top of the unlimited help desk support. That structure exists because a law firm’s technology needs change as it grows, adds practice groups, or opens a second location, and those decisions shouldn’t be made reactively in the middle of a support ticket.

What Certifications and Credentials Actually Back Up Their Claims?

Ask for specifics rather than accepting general assurances. Do they hold a HIPAA Seal of Compliance, relevant for firms handling health-related matters or personal injury cases? Are they a Microsoft Solutions Partner? Are they listed by a bar association or recognized within the legal community, as opposed to only claiming legal industry experience on their own website?

CTI Technology holds the HIPAA Seal of Compliance from Compliancy Group, is a Microsoft Solutions Partner, and appears in the ISBA Expert Directory. Credentials alone don’t guarantee good service, but their absence, combined with vague answers to the questions above, is a reliable warning sign.

What Happens in the First 30 Days After You Sign?

A provider should be able to describe onboarding in concrete terms: environment assessment, documentation of your current setup, deployment of security tools, and a timeline for stabilizing anything that’s been neglected. If the answer is vague or rushed, that’s often a preview of how they’ll handle ongoing service.

Most firms that switch providers come in with some combination of excessive admin permissions, unmanaged accounts from former employees, insufficient endpoint protection, or backup policies that were never actually tested. A structured onboarding process should surface and fix these issues within the first 15 to 30 days, not leave them undiscovered until an audit or an incident forces the question.

Making the Decision

None of these questions are difficult for a provider who actually does this work. That’s the point. The gap between a provider who’s spent years in legal IT environments and one who hasn’t is visible in how specifically, and how quickly, they answer.

Whether your firm is based in the Loop, out toward Schaumburg, in Naperville, or anywhere else in the Chicagoland area, the standard shouldn’t change. For a deeper look at what to evaluate before switching or selecting a provider, CTI Technology’s IT guide for Chicago law firms breaks down the most common technology gaps firms face, and our cybersecurity consulting page covers how we approach risk assessment for legal environments specifically.

If you’re not sure how your current provider would answer these questions, or you’re evaluating options for the first time, CTI Technology offers a complimentary consultation to walk through your firm’s specific environment. You can also review our IT consulting services for law firms for a more detailed look at how we structure that evaluation.

Share This Story, Choose Your Platform!
no-photo

Aaron Kane

CEO of CTI Technology
Aaron Kane is the CEO of CTI Technology, a Chicago-based IT services provider helping businesses navigate technology with confidence. With expertise in IT strategy, infrastructure, cloud solutions, and voice technologies, Aaron focuses on helping organizations improve efficiency, strengthen operations, and make smarter technology decisions. Under his leadership, CTI Technology has continued to grow while maintaining a strong focus on service and long-term client relationships.
Connect with Aaron on Linkedin

Why Is CTI Technology The Best Choice For IT Services In The Chicagoland Region?

quotes
“Great pricing, even better service. Highly recommended!”
Great pricing, even better service. Highly recommended!”
Guido Arquilla
stars
quotes
“Great IT company for our business! Highly recommended.”
“Great IT company for our business! Highly recommended.”
Brian Coli
stars
quotes
“CTI is a great company and I would not trust my IT services to anyone else.”
CTI is a great company and I would not trust my IT services to anyone else.
Jenny Wagner
stars

CTI Technology Tips & Articles

Check Out Our Technology Insights
Call Now Button