Your Law Firm’s IT Didn’t Break Overnight. That’s Exactly Why It’s a Problem.
The managing partner of a small Bozeman law firm has never had a data breach. She is careful with client files. She uses a password she considers strong. Her staff does not click suspicious emails, at least not that she knows of. From where she sits, the firm’s technology is fine. It works. Nobody is complaining.
What she does not know: a paralegal who left the firm twenty-two months ago still has an active email login. The document management software running on the back-office server has not received a security update in over a year because no one realized updates had to be applied manually. Client intake forms flow into a personal Google Drive account that a former associate set up in 2020 because it was the fastest solution at the time. And the managing partner’s own laptop, the one she uses for everything including reviewing settlement documents at home, has never been enrolled in any centralized device management or monitoring system.
None of this happened because anyone was careless. It happened because the firm grew around the technology that was available when each decision was made, and nobody had the time or the mandate to go back and govern it. This is not a crisis. It is something quieter and harder to see: a slow accumulation of ungoverned systems, lapsed access controls, and unreviewed configurations that have been quietly building exposure for years.
If your Bozeman law firm has more than two attorneys and has been operating for more than three years without a structured IT review, there is a high probability your firm looks more like this than you realize. This article explains how inherited IT happens, what it means under the ABA’s current interpretation of your ethical obligations, and what addressing it actually involves for a firm that does not want to rebuild its technology from scratch.
How Inherited IT Happens at Small Law Firms
Inherited IT is not a technical term. It is a pattern that emerges from a simple reality: small law firms make technology decisions one problem at a time, and those decisions accumulate without any governing architecture.
It starts at the beginning. A firm is founded or a solo practice opens. The attorney buys a laptop, sets up a Microsoft 365 account, and finds a document management tool that fits the budget. A paralegal joins and gets their own account. A part-time receptionist gets added to the email system. Someone sets up a shared drive because emailing documents back and forth stopped working. A cloud backup service gets added after a scary moment with a failing hard drive.
Each decision was reasonable. None of them was made with any thought about how it would connect to or interact with what comes next. And critically, none of them came with a decommissioning plan. When the paralegal leaves, their account persists because the managing partner does not know that offboarding requires an explicit step in the admin portal. When the document management tool gets replaced, the old one stays connected to the network because nobody logged in to revoke its access. When the associate who set up the Google Drive leaves, the firm loses track of what was stored there.
Over time, the firm’s IT environment becomes a layered record of every decision and every departure, every tool that was added and never fully removed. The attorney at the center of it experiences none of this as a problem because everything still works. The exposure is invisible until it is not.
For a broader look at what these invisible costs add up to across a small business’s IT footprint, the hidden IT cost breakdown for small businesses is worth reading alongside this one.
What the ABA Actually Means by “Reasonable Efforts” in 2026
ABA Model Rule 1.6(c) requires attorneys to make reasonable efforts to prevent the unauthorized disclosure of or unauthorized access to client information. That language has been in place for years. What has changed is how “reasonable” is being defined as the threat environment evolves and as regulators and malpractice insurers look more closely at small firm security postures.
ABA Formal Opinion 483, the most substantive guidance the bar has issued on breach response, makes clear that the obligation to protect client data is not satisfied simply by avoiding a known breach. Attorneys are expected to proactively establish policies and technical controls, not merely react when something goes wrong. The duty to supervise, under Rules 5.1 and 5.3, extends that obligation to the systems and vendors the firm uses to handle client information, including cloud storage providers, document platforms, and IT support arrangements.
In practical terms, “reasonable efforts” in 2026 means something closer to: multi-factor authentication on every account that touches client data, documented offboarding procedures that revoke access when staff depart, a reviewed and current incident response plan, encrypted storage for sensitive client files, and some form of ongoing monitoring that would detect unauthorized access before a breach becomes a disclosure obligation. For a small firm running on inherited IT, most of those elements are absent, not because of negligence, but because no structured process ever put them in place.
The bar association does not prescribe specific technology. What it does require is that an attorney be able to demonstrate, if asked, that they took competent steps to understand the risks and implement proportionate controls. An IT environment that has never been formally reviewed, that includes active credentials belonging to departed staff, and that relies on unmonitored personal cloud accounts for client data would struggle to meet that standard under any reasonable interpretation of current guidance.
This is also where malpractice insurance intersects with the ethics question. Insurers are increasingly asking about multi-factor authentication, endpoint protection, and incident response plans during renewal. Firms that cannot answer those questions clearly are seeing higher premiums or coverage gaps that would leave them exposed in exactly the scenario the coverage is supposed to address.
The Five Systems Most Small Firms Have Never Properly Secured
Inherited IT concentrates in predictable places. Across small and mid-sized law firms, the same five categories of systems consistently turn up ungoverned during an IT review, and each one represents a distinct type of exposure.
Email accounts with no offboarding process. Every person who has ever worked at your firm and had a firm email address is a potential access point if their credentials were never formally revoked. In Microsoft 365 and Google Workspace environments, inactive accounts remain valid login targets until an administrator explicitly disables or removes them. Most small firms have no documented process for doing this when someone leaves, which means departed staff, terminated contractors, and former associates may still be able to log in and access firm email today.
Unmanaged personal devices used for firm work. Attorneys and paralegals who check firm email on personal phones or work from personal laptops at home are accessing client data on devices the firm has never enrolled, configured, or monitored. If that device is lost, stolen, or compromised by malware, the firm has no ability to remotely wipe it, no visibility into what data was stored locally, and no record of what client files may have been exposed.
Cloud storage accounts outside firm control. Google Drive, Dropbox, and OneDrive accounts set up by individual staff members for convenience represent a category of data storage the firm typically does not know about, cannot audit, and cannot recover if the account owner leaves or loses access. Client documents stored in personal cloud accounts are, from an ABA compliance standpoint, being held in an environment the attorney cannot supervise or control.
Practice management or document software running without updates. Software that is not actively maintained receives no security patches. Vulnerabilities in unpatched software are among the most reliably exploited attack vectors in any industry. In law firms, practice management software and document management systems that run on local servers are frequently months or years behind on patches because updating them requires deliberate administrative action that never gets scheduled.
No monitored backup with a tested restore process. Many small firms have a backup of some kind. Far fewer have a backup that is monitored for completion, stored in a location isolated from the primary network, and tested for restorability on any regular basis. A backup that has never been tested is not a recovery plan. It is an assumption.
Understanding how each of these gaps affects your overall network security posture is the first step toward knowing where to focus remediation effort.
Why Fixing This Does Not Mean Starting Over
The most common reason small law firms delay addressing inherited IT is the assumption that doing so means a disruptive overhaul that replaces everything, costs a significant amount, and takes the firm offline for days. That assumption is almost always wrong.
Remediating inherited IT is not a replacement project. It is a remediation sequence. The goal is not to build a new IT environment from scratch. It is to bring the existing environment up to a governed, monitored, and defensible standard without disrupting the workflows the firm depends on. For most small firms, that work happens in phases, starting with the highest-risk gaps and moving systematically through the rest.
The first phase is almost always an access audit: identifying every active login credential, email account, and cloud storage connection, then revoking everything that should not still be active. This does not require new software or new hardware. It requires administrative access to the accounts your firm already has and a structured process for reviewing them.
The second phase is enabling multi-factor authentication across every system that touches client data. In Microsoft 365 and Google Workspace environments, MFA is included in the subscription your firm is already paying for. Enabling it is a configuration step, not a procurement decision. The same applies to most practice management platforms and document management systems. The protection exists in the tools you are already using. It just has not been turned on.
The third phase is device management: enrolling firm devices and establishing a policy for how personal devices can access firm data. Modern mobile device management tools are built into Microsoft 365 and can be configured without purchasing additional software in most cases.
Each phase is incremental. None of them requires the firm to stop working, replace its core systems, or invest in a completely new technology stack. What they do require is someone with the knowledge and the mandate to execute them methodically, which is exactly what a managed IT services relationship provides.
What a Managed IT Partner Does That a Break-Fix Tech Cannot
Many small Bozeman law firms have a relationship with a local IT person who helps when something stops working. That relationship has real value for immediate troubleshooting. It has no value for the problem this article is describing, because inherited IT is not a break. It is an absence of structure, and break-fix support has no mandate or process for building structure.
A break-fix technician responds to incidents. They come in when the printer stops working, when an email account gets locked out, when a laptop will not start. They solve the immediate problem and leave. They are not responsible for reviewing the firm’s overall access control posture, auditing whether departed staff still have active credentials, monitoring whether backups are completing successfully, or flagging that a piece of software has fallen months behind on patches. That work only happens if someone has an ongoing mandate and a systematic process for doing it.
Complete IT management for a law firm means that the ungoverned accumulation of systems stops accumulating. Access gets reviewed. Patches get applied. Backups get tested. When a staff member leaves, the offboarding checklist runs automatically. When new software gets added, it goes through a standard provisioning process that connects it to the firm’s security baseline rather than adding another ungoverned layer.
It also means that when a malpractice insurer asks whether the firm has MFA enabled and monitored endpoint protection in place, the answer is documented and verifiable, not a guess. And when a client’s engagement letter or outside counsel guidelines include provisions about data security practices, the firm can respond with actual evidence rather than reassurance.
For Bozeman law firms that have grown around the technology available at each moment rather than the technology that serves the firm’s long-term security posture, the path forward is not a crisis response. It is a structured review followed by a methodical remediation sequence managed by a partner with the knowledge and the mandate to execute it. The cybersecurity information page covers the full scope of what that looks like in practice.
It is also worth considering how a compromised IT environment intersects with backup and business continuity planning. If client files are spread across personal cloud accounts and an unmonitored local server, recovery from any kind of incident, whether a ransomware attack, a hardware failure, or a departing employee who deletes shared files, depends on a backup strategy that most small firms have never formally built.
The Firm You Are Running Is Not the Firm Your IT Was Built For
The practice you are managing today is almost certainly larger, more complex, and more digitally dependent than the one your current IT environment was designed to support. That gap is not unusual. It is the natural result of growth happening faster than infrastructure governance, which is exactly how inherited IT accumulates in every firm that has ever focused on serving clients first and technology administration second.
Closing that gap does not require a wholesale technology replacement or a disruption to the firm’s daily operation. It requires a structured look at what you actually have, a clear-eyed assessment of where the exposure lives, and a remediation sequence executed by a partner who understands both the technical requirements and the professional obligations that make this more than an operational question for a law firm.
Entre works with law firms across Bozeman and throughout the region to bring inherited IT environments up to a governed, secure, and ABA-defensible standard without overhauling what already works. The law firm services page covers the specific ways Entre supports legal practices, from access management and endpoint monitoring to backup infrastructure and incident response planning.
If you want to understand your firm’s current exposure before an insurer or a bar complaint makes the question urgent, the IT and cybersecurity readiness quiz takes five minutes and gives you a structured picture of where the gaps are. Or contact Entre directly to have a direct conversation about your firm’s specific IT environment and what bringing it up to standard actually involves.


















