
IT SUPPORT FOR LAW FIRMS
Managed IT and cyber security for Christchurch law firms
A law firm relies on technology across almost every part of the working day, from email, documents and matter systems through to billing, client communication and the services staff need to complete their work. When support is slow, problems move between suppliers without being resolved, or nobody has a clear view of the wider environment, partners and practice managers end up spending time coordinating IT that should already be under control.
The arrangement should be much simpler than that. Staff should know where to go when they need help, urgent issues should be prioritised properly, other technology providers should be dealt with directly, and partners should only be drawn into decisions that genuinely need their involvement.
ITstuffed provides managed IT and cyber security for law firms across Christchurch and Canterbury. We look after the day-to-day environment, security, Microsoft 365, backups, users, devices and technology planning, with the aim of giving the people running the firm much less IT to manage themselves.
Reviewing your firm's current IT arrangements?
If support has become difficult to deal with, you are concerned about security, or you have considered changing provider but do not want the handover to become another project for the partners, tell us what has prompted the review.
Prefer to choose a time? Book a 15-minute IT Fit Check
Your IT provider should reduce the amount of IT the firm has to manage
Most law firms rely on a mix of Microsoft 365, practice and matter-management systems, internet and network services, computers, printers, security products, backups and specialist platforms. Different suppliers may be responsible for different parts of that environment, but somebody still needs to maintain a clear view of how it all fits together.
When that ownership is missing, the work tends to come back to somebody inside the firm.

Partner and practice-manager time should not disappear into support
A support issue might begin with a staff member who cannot access something and end with several providers trying to establish whose system is responsible.
That should not require a partner or practice manager to keep the issue moving. Your IT provider should investigate the environment they manage, speak directly with other suppliers where necessary and remain involved until the next action and responsibility are clear.
The same principle applies to routine administration. User accounts, licensing, device replacements, software access and staff changes are all small tasks individually, but they consume a surprising amount of management time when nobody owns them consistently.
The firm's information and financial workflows need careful protection
Law firms hold sensitive personal and commercial information, often alongside communications involving significant financial transactions. The New Zealand Law Society continues to warn firms about phishing, business email compromise and other attacks targeting legal practices, particularly where client funds or commercially sensitive information are involved.
That makes cyber security part of the firm's wider operating environment rather than a product installed on the computers.
Email protection, identity security, endpoint protection, patching, backups, web protection, user awareness and sensible processes around sensitive requests all address different parts of the risk. None removes the need for judgement when something unusual happens.
Changing IT provider should not become another project for the partners
Staying with an IT provider because changing sounds worse than the current arrangement is understandable.
There may be years of accumulated access, documentation, licensing, supplier relationships and knowledge sitting with the incumbent provider, and the staff still need to work while all of that moves across.
A managed transition will still require some involvement from the firm. Decisions need to be made and authority has to come from somewhere. What the partners should not need to do is understand the technical configuration themselves or coordinate the handover between the incoming and outgoing providers.
Email and payment instructions deserve a process behind the technology
Email security can filter a great deal of unwanted and malicious traffic, but law firms also deal with communications where the consequence of trusting the wrong message can be significant.
The New Zealand Law Society has warned lawyers about scams involving compromised or impersonated email accounts and fraudulent payment instructions. Its guidance recommends care around unexpected communications and verification of important details rather than relying on the appearance of an email alone.
Technology should make those attacks harder and give the firm better visibility when something is wrong. The firm's own procedures still matter, particularly where somebody is being asked to change payment details, disclose sensitive information or take an action that would be difficult to reverse.
Your IT provider should be managing the whole environment
Managed IT is broader than a helpdesk.
The provider needs enough understanding of the environment to support staff properly, identify when something is deteriorating, maintain the security controls behind the firm and give management a useful view of what should happen next.
Issues should also have a clear owner. A routine user request and a firm-wide system outage are not the same problem and should not be treated with the same priority. Once something has been handed over, the firm should be kept informed without a partner having to repeatedly ask what is happening.
Support and operations
- Day-to-day IT support
- Microsoft 365
- Computers and devices
- Networks and connectivity
- User onboarding and offboarding
- Vendor coordination
Security and continuity
- Endpoint and identity protection
- Email and web security
- Patching and vulnerability management
- Backup and recovery
- Security awareness
- Incident response
Planning and management
- Technology roadmap
- Device lifecycle planning
- Microsoft licensing
- Security improvements
- Projects and system changes
- Budget planning and Business Technology Reviews
What one Christchurch law firm wanted from its next IT provider
“I really value our relationship. You don’t only look after our IT, you look after us as a business, and me personally.”
Case study
The firm had five staff when we first started working with them and had reached the point where the partner wanted to leave a large national IT provider. His frustration was not based on one catastrophic failure. It came from having to repeatedly follow up support and administrative issues himself, with little continuity between the people involved.
His biggest concern about moving was the handover.
We took responsibility for dealing with the outgoing provider and worked through close to 100 onboarding checks once we had access to the environment. That review found a third-party backup that had become disconnected and had not been tested, Microsoft 365 licensing that needed attention and security that was fairly basic.
We have now worked with the firm for around four years. It has grown to seven staff, the original findings have been worked through, and the partner spends far less time managing routine IT than he did when we first met.
Experience from environments where reliability matters
Several members of our technical team worked in healthcare and hospital environments before joining or founding ITstuffed.
In a law firm, technology needs to support work that is often deadline-driven and commercially sensitive. Changes need to be planned carefully, and when something does need attention, staff should be able to keep working without becoming responsible for managing the technical response.

Daniel
Before founding ITstuffed, Daniel worked as a registered nurse and paramedic.
His healthcare background still influences how he approaches priorities, risk and the responsibility that comes with looking after systems other people rely on.

David
David spent nearly 20 years maintaining radiation therapy systems in major New Zealand hospitals, including Christchurch Hospital.
His work required careful maintenance, documentation and change management around technology that could not be treated casually.

John
John has around 20 years of IT experience, including IT and administration work within a major European hospital.
He also volunteers with Hato Hone St John's Major Incident Support Team.
That background is useful because our engineers are used to working in environments where systems need to be reliable, changes need to be thought through properly, and people cannot afford to spend their day sorting out IT.
Specialist legal systems should not leave your practice manager in the middle
Your practice-management and legal platforms have their own specialist support teams, and there will be times when they are the people who need to make the final change.
Our role is to manage the environment around those applications and work with the vendor when the boundary is unclear.
If a problem involving Actionstep, LINZ or another service also touches Microsoft 365, a workstation, user access, the network, a printer or another part of the environment we manage, we can investigate our side and deal directly with the relevant supplier.
One of the law firms we support uses both Actionstep and LINZ as part of its day-to-day work. When a new employee starts, we prepare their account and computer, make sure the systems we manage are ready for them and check that their required access is working on the device. The firm itself needs to arrange the LINZ login, but once that has been issued we make sure it is working properly in the employee's environment.
We take the same approach with the firm's other technology suppliers. Responsibilities and dependencies should be clear, and where an issue crosses between providers, we deal directly with the people involved rather than leaving the practice manager to pass technical information back and forth.
Protecting client information needs more than antivirus
The Law Society's guidance on cyber security recognises the sensitivity of the personal and commercial information held by legal practices and specifically addresses threats such as phishing, ransomware and business email compromise. Its cloud guidance also reinforces the firm's responsibility to protect client information when systems and data are hosted externally.
For the environment we manage, security is therefore handled across several layers.
The controls themselves matter, but so does maintaining them. Security software that was installed years ago, a backup nobody has restored from and user access that has accumulated over several staff changes are not things we want to discover for the first time during an incident.
That can include:
- endpoint protection;
- Microsoft 365 and identity security;
- email filtering;
- web protection;
- multi-factor authentication;
- vulnerability management and patching;
- backups and recovery;
- staff security-awareness training;
- monitoring and alerting;
- incident response.
Technology planning should happen before a decision becomes urgent
A managed IT relationship changes over time.
People join and leave. Computers age. Microsoft changes licensing and services. Practice-management software develops. Security requirements change. A new office, acquisition or new area of practice can introduce requirements that were not relevant a year earlier.
Those changes should feed into a technology plan rather than appearing as a series of unrelated invoices and urgent decisions.
For managed clients on the appropriate service, Business Technology Reviews provide a structured opportunity to look at what has changed in the firm, what is coming up and what should be budgeted for. That can include:
- device replacement;
- Microsoft 365 changes;
- security improvements;
- software and vendor projects;
- network and connectivity work;
- backup and recovery;
- business continuity;
- cyber-insurance requirements;
- expected technology expenditure.
The partners still make the commercial decisions. Our role is to give them enough information to make those decisions before the timing is forced on them.

Predictable monthly IT costs
Managed IT works best when routine support and management are part of an agreed ongoing service rather than a new purchasing decision every time somebody needs help.
Our managed services are provided for a fixed monthly price based on the agreed service.
That gives the firm a predictable operating cost for the day-to-day management of its IT and allows staff to raise support requests without management first deciding whether the issue is worth another hourly invoice.
Project work or other items outside the agreed managed-service scope are discussed separately.
What we manage for law firms
Day-to-day IT support
Staff have access to an IT team for the issues that interrupt their work, with requests prioritised according to impact and urgency.
Microsoft 365
We manage user accounts, licensing and the Microsoft 365 services used for email, files, collaboration and security.
Computers and devices
Devices are monitored, maintained and patched, with lifecycle planning used to identify equipment approaching replacement.
Cyber security
Security is managed across devices, identities, email, web access, patching and user awareness rather than relying on one product.
Backup and recovery
Backups are monitored and recovery forms part of the wider continuity discussion.
Backup testing matters because the presence of a backup product does not, by itself, prove that information can be restored when needed.
Networks and infrastructure
We manage and monitor the network and related infrastructure covered by the managed service.
Vendor coordination
Where an issue involves another technology or software provider, we deal directly with them where appropriate rather than handing the coordination back to the firm.
Staff onboarding and offboarding
Accounts, access and devices can be prepared before somebody starts and removed through a defined process when they leave.
Incident response
If a security incident occurs, we can assist with containment, technical investigation, remediation and coordination with other specialists where required.
Technology planning
Regular reviews help management look beyond the current support queue and maintain a roadmap for the environment.

SMB1001 Gold
ITstuffed holds SMB1001 Gold certification and uses the framework as part of the way we manage our own cyber security.
Frequently asked questions
Do you support Actionstep, LINZ and other legal software?
We support the wider environment those applications rely on and work directly with specialist software providers where the issue crosses between systems.
We do not pretend to replace the vendor's own application support.
If a problem involves the computer, network, Microsoft 365 environment, user access or another system we manage, we can investigate that part and coordinate with the relevant provider.
How difficult is it to change IT providers?
There is work involved in changing provider because access, documentation, licensing, backups, devices, security and vendor relationships all need to be understood and transferred.
The firm should expect to answer questions and make decisions where its authority is required. It should not need to manage the technical handover itself.
Our law-firm case study follows a real transition where the partner's biggest concern was precisely how much disruption and involvement the change would require.
What if our current IT provider has most of the passwords and documentation?
That is common in provider transitions.
Part of onboarding is establishing what documentation exists, obtaining the required access from the outgoing provider and identifying gaps as the environment is reviewed.
Incomplete documentation may mean some things require additional investigation, which is another reason we work through the environment methodically rather than assuming the handover material is complete.
How do you protect confidential client information?
There is no single security product that protects every part of a law firm's environment.
We use multiple controls across accounts, devices, email, web access, patching, backup and staff awareness and maintain those controls as part of the managed service.
The New Zealand Law Society also publishes guidance for practices on protecting client information and managing cyber risks.
What happens when somebody joins the firm?
We can prepare the user's account, computer and required access before their first day once we have the information we need.
In the law firm featured in our case study, the final staff-facing part of onboarding normally takes around 15 minutes after the technical preparation has already been completed. During that session we make sure the employee can sign in, set up MFA, introduce the password manager and security-awareness training and check access to systems including Actionstep and LINZ.
Can you work with our other technology suppliers?
Yes.
No IT provider controls every system a law firm uses. Where another supplier is responsible for a particular application or service, we can work directly with them and provide the technical information required from the environment we manage.
How do you prioritise urgent problems?
Requests are prioritised according to impact and urgency.
A problem affecting one staff member is different from an issue preventing the whole firm from accessing an important system, and an active security incident is treated differently from a routine support request.
Do you provide onsite support?
Yes, where onsite work is appropriate and included within the relevant service arrangement.
A large amount of modern IT support can be completed remotely, but onsite work still makes sense for some infrastructure, project and user requirements.
Do you only work with larger law firms?
No.
The more relevant question is whether the firm wants its technology actively managed and wants to reduce the amount of routine IT work sitting with partners, managers or staff internally.
Reviewing your firm's IT support?
You may be spending too much time following up the current provider, questioning whether security and backups are being managed properly, or considering a change but concerned about what the transition would involve.
Tell us what has prompted the review and we will get in touch.
You do not need to prepare a technical inventory of the firm before contacting us.
Start the conversation
Prefer to choose a time? Book a 15-minute IT Fit Check
Based in Christchurch and working with law firms across Canterbury.