Industries

IT, cybersecurity and practice management for US law firms

Law firms hold some of the most sensitive information any organization handles, and clients expect it to stay confidential. We run and secure the technology behind your practice and help you manage matters, documents and billing in one place.

Challenges we see

Small and mid-sized law firms and in-house legal departments face IT problems that carry professional as well as business risk:

  • Confidential files in too many places. Client documents live in document management systems, email, shared drives, personal devices and file-sharing links, often without consistent access controls.
  • Wire fraud and impersonation. Real estate closings and trust account transfers attract email compromise attacks that redirect funds.
  • Ransomware. A locked file server can halt a practice and expose privileged material.
  • Disconnected practice tools. Matter management, time entry, billing, trust accounting, calendars and document assembly often run as separate systems.
  • Remote court and client work. Lawyers work from courthouses, client offices and home, and need secure remote access and reliable video.
  • Deadlines that do not move. Statutes of limitation and court dates make downtime more than an inconvenience.

How Promatics helps

Our managed IT services give your firm one accountable provider, including direct coordination with your practice management, document management and telecom vendors. Coverage typically includes:

  • A fully remote, 24/7 help desk for managed-service clients, with priorities and response targets set in the service agreement.
  • System design and networking for offices and remote lawyers, with secure remote access and backup internet links.
  • Software license management across practice, document and productivity applications.
  • Hardware procurement and inventory, with encrypted laptops and a record of where every device is.
  • Cabling and phone systems for office moves and expansions.
  • On-site systems maintenance where your service agreement includes on-site work.
  • A layered cybersecurity stack aligned with recognized frameworks such as the NIST Cybersecurity Framework, including multi-factor authentication, endpoint detection and response and privileged access control. See cybersecurity services.

Email security adds impersonation protection, link and attachment scanning and payment-change verification procedures. We configure Microsoft 365 so matter files are organized with the right permissions and retention, and backup and disaster recovery keeps tested, restorable copies of client files. A virtual CIO provides strategic assessments, gap analysis and project management, and helps you answer the technology questions in client security questionnaires and insurance applications.

The legal edition of Prometheus ERP is designed from a legal practice perspective to help you see the big picture. It brings together the resources your departments need: matters, email, litigation, legal spend, document and contract management, e-billing and reporting, outside collaboration and calendars. It includes:

  • Billable and non-billable expense tracking.
  • Multiple document upload, download, versioning and sorting.
  • Case status dashboards, cases by stage, revenue reports and more.
  • Customizable invoices and detailed billing with terms, discounts and fees.

Prometheus is scalable, so it can grow with your firm, and it can be deployed on-premises or in a US cloud region.

US regulatory and operating context

  • Confidentiality and competence. The ABA Model Rules of Professional Conduct, and the state bar rules based on them, require lawyers to protect client information and to keep up with the benefits and risks of relevant technology (Model Rule 1.1 comment on technology competence, and Rule 1.6(c) on reasonable efforts to prevent unauthorized disclosure). Choices about cloud storage, remote access and outsourcing IT should support those duties.
  • Bar and ABA guidance. The ABA and many state bars publish ethics opinions and guidance on cloud computing, cybersecurity and working with technology providers, including questions to ask about where data is stored and who can access it.
  • Trust accounting and records. State bar rules set detailed requirements for client trust (IOLTA) accounting and record retention, so systems holding these records need reliable backups and access controls.
  • Privacy and breach notification. Every state has a breach notification law that can apply to personal information held by a firm, and some state privacy laws and the FTC Act may also be relevant. Clients in regulated sectors, such as health care and finance, may also impose contract requirements.
  • Attorney-client privilege. Privilege and work-product protection depend on keeping client communications confidential, so access controls, retention settings and vendor agreements deserve the same attention as any other firm policy.

This is general information, not legal advice. Your state bar's rules and guidance are the authoritative source for your obligations.

Services for legal

Talk to us about your firm

Tell us about your practice areas, how your team works and which systems hold client files. We will suggest a practical first step.