Skip to main content
Express logo
Call
4.9154 reviewsOn site across Upstate New York, and wherever your other offices are
Attorneys reviewing documents around a conference table

Law firms, infrastructure side

Law firm IT support for everything but the law

Express IT Solutions runs the infrastructure side of law firms: the office network, Microsoft 365 and encrypted email, the environment your document and practice management systems run in, backups with tested restores, MFA on everything, access on a need-to-know basis, vendor remote access, monitoring. The law stays with your attorneys, the files stay behind the firm’s own access rules, and we say so before you ask.

The work runs from Syracuse, New York, where we have handled business IT since 2005. The same team keeps unstaffed peaker plants ready for start day for power plant clients across the country, from Upstate New York to California. A business where the deadline is set by a judge is familiar ground here, not a first.

Since 2005Remote first, a truck when it is notThe case files stay yours
21 yearsIn business, running IT since 2005
4.9From 154 public Google reviews
$65 to $99Published monthly plans, per user, in writing

Law firm IT support is the management of a law firm’s technology infrastructure: office networks, Microsoft 365 and encrypted email, the environment document management and practice management software runs in, backups with tested restores, multi-factor authentication, need-to-know access controls, vendor remote access and monitoring. The IT provider runs the infrastructure layer and implements the technical safeguards the firm’s confidentiality obligations call for, while the attorneys keep the matters, the clients and the professional judgment, and decisions about privilege and litigation holds stay with counsel.

The side of the firm nobody went to law school for

Every law firm runs on two kinds of work, and only one of them is billable. The professional side has partners, associates, paralegals and a docket that sets the pace. The other side, the server in the closet, the scanner feeding the document management system, the backup nobody has watched restore, the logins of people who left last year, belongs to whoever got stuck with it, usually the firm administrator or the partner who objected least.

You know how that ends because you have watched it happen. The brief is due at midnight and the machine holding the final version decides tonight is the night, or the internet drops with the e-filing half uploaded. A client gets an email about wiring closing funds, except it did not come from the firm; someone had been reading the mailbox for weeks and picked the right Tuesday. Then your practice management vendor’s support tech asks for remote access, and the fastest answer on hand is the password everybody shares, on the same network that holds every client file in the office.

None of that is negligence. It is arithmetic. A firm staffed to practice law has no hours left over for IT, so IT becomes a part-time job done between matters, and the gaps are where the problems grow. That holds for a two-partner office and a forty-lawyer firm with a branch in the next city alike. Closing that gap is what IT support for law firms means in practice, and the engagement runs on the same bones as our managed IT services.

Where the line is

Attorney IT support, on the infrastructure side of the practice

The practice belongs to the people admitted to it. How a matter is run, what the engagement letter promises, what is privileged and what gets produced, whether a hold applies and how far it reaches: those are counsel’s calls, and an IT company with opinions about them should worry you. We promise the opposite, and we put it in writing before anyone logs into anything.

What we take on is everything underneath the matter. The network and the firewall in front of it, Microsoft 365 and the retention rules behind the mail, backups and the proof they restore, multi-factor authentication on everything that holds client information, access that runs on need-to-know rather than convenience, the named accounts your software vendors use to get in, and the monitoring that notices trouble before a paralegal does. When the firm screens a lawyer off a matter, we build the technical side of that wall: the permissions, the groups and the logging that show the screen held. The security layer runs the way our cybersecurity practice runs it everywhere. Under the profession’s own rules, confidentiality is the lawyer’s duty: ABA Model Rule 1.6 expects reasonable efforts to prevent unauthorized access to client information, and the technology competence comment expects lawyers to understand the tools the practice runs on. The duty is the firm’s and stays the firm’s; the reasonable efforts are our trade, encryption, access controls, logging, tested backups, implemented and documented so the firm can show its work instead of describing it. Where our work meets your document management or practice management vendor’s, scope goes on paper first.

The same line holds where the untouchable layer is a tax return or a patient chart; the deadline cousin of this page is our accounting firm IT support, and the clinical version is our medical office IT support.

Runs the practice. Not ours.
Legal advice and strategyClient relationshipsPrivilege and ethics callsLitigation hold decisionsProfessional judgment

Your partners, your associates, your paralegals.

The boundary, kept deliberate
Everything around it. Ours.
Network and firewallMicrosoft 365 and encrypted emailBackups and restore testsMFA and access controlsVendor remote accessMonitoring

One accountable IT team, on one standard.

What our team handles at a law firm

Plain descriptions. The specifics come out on the first call anyway.

  • Email, Microsoft 365 and encrypted mail

    Email at a law firm is privileged correspondence moving through a commodity system, and it is where firms get breached more than anywhere else. Mailboxes, retention and security get set up for that reality: encryption for anything that should not travel in the clear, retention set for a firm that may someday have to produce its own records, alerts when a forwarding or inbox rule appears that nobody created on purpose, and mail defenses tuned for phishing dressed as opposing counsel, a court notice or a client with new wire instructions.

  • Office and conference-room network

    Switches, firewall, Wi-Fi and cabling, built so the guest network your clients use in the conference room never touches the side that holds their files. Everything labeled and documented, so the next person in the server closet is not doing archaeology.

  • The environment your document and practice management systems run in

    The DMS and the practice management system belong to their vendors, hosted or local, and we do not pick them for you. Everything they depend on is ours: the server down the hall or the connection to the vendor’s cloud, the workstations, the scanners feeding the file, the printers the filings come out of, and the backups behind anything local. When the vendor’s support line says the problem is on your end, that ticket is ours, and we work it with them instead of leaving a paralegal to translate.

  • Access controls, conflicts walls and need-to-know

    Confidentiality is an access problem before it is anything else. Everyone who touches client information works from a named account, access runs on need-to-know rather than convenience, and when the firm screens someone off a matter, the wall gets a technical side to match the ethical one: permissions, groups and logging that show it held. Which people can reach which matters stops being a guess and becomes a record.

  • Backups, restore tests and litigation holds

    The matter files, the DMS store, the email archive: that is the firm’s memory, and some weeks it is evidence. Retention runs on the schedule the firm sets, and restores get tested on a calendar instead of assumed. When counsel issues a litigation hold, the decision and its scope are counsel’s; our part is making the systems obey it, suspending the deletions that would otherwise keep running, preserving what counsel names, and documenting what was done and when.

  • Accounts, MFA and the turnover problem

    Associates leave, laterals arrive with their matters, and staff churns at the front desk, and every one of those moves is an access decision. Everyone gets a named account with multi-factor authentication; when someone leaves, access ends and you get that confirmed in writing. Vendor support techs get the same treatment: named, logged, shut off after the session. And we come to the office for the work a remote session cannot do: hardware swaps, cabling, a new office brought online. All of Upstate New York, within 50 miles of Syracuse no questions asked, and farther by planned visit, including travel by air.

Front of a wall mounted UniFi equipment rack installed by Express IT: a gateway, two switches with status screens lit, and a rack power distribution unit, beneath a labeled Cat 6 keystone.
A UniFi rack our team built and runs: gateway, switches and rack power, under a labeled Cat 6 drop. Our own installation, our own photo.
IT technician installing a network switch in a server rack.
Rack work, cabling and hardware swaps are part of the job.

Practical automation for the front office

Law firms are drowning in AI pitches, most of them aimed at the legal work itself, which is exactly where a careful firm does not want a vendor experimenting. The same team that runs this IT practice runs an AI practice, and at a firm the honest use for it is the paperwork around the matter: intake turned into structured records before the consult, the document chasing that eats a paralegal’s week, status questions answered without pulling anyone off billable work. One caution comes free: client information pasted into public AI tools has left the building, so the firm needs an AI policy before it needs an AI vendor, and what we build runs inside systems the firm controls. We scope one workflow, build it, connect it to the systems you already run, secure it and watch it after launch. Nothing drafts, advises or files, and if a workflow is not worth automating, you will hear that on the first call. The full picture is on our AI agents and workflow automation page.

Tell us what keeps failing at the firm. The first conversation is free and specific.

Due at 11:59 p.m.

Deadline IT: the court does not care why the file would not upload

A tax practice gets one season and eight forgiving months. A law firm’s deadlines arrive all year, one matter at a time: a filing due at midnight, discovery responses due Friday, a closing that funds on the first. In an ordinary week, a switch that needs the occasional reboot or a workstation with moods is an annoyance. The night something is due, the same faults get priced in missed deadlines and apology calls, and the court’s clock does not stop for any of them.

Deadline IT is not a different service. It is the same service with the calendar taken seriously: disruptive work in announced windows, never on a machine the night before it files; workstations, accounts and backups proven on a schedule instead of assumed; monitoring that reports trouble while it is still small. That preparation is where legal IT services either earn their keep or get found out. We keep unstaffed peaker plants ready for a start order on the same discipline, hunting quiet failures in quiet weeks so they stop being discoveries; a firm that files at midnight is the same problem in a suit. We will not promise nothing can break the night something is due; we make sure that night starts on equipment that has been proven and stays watched.

Getting a firm through its deadlines is a calendar, not heroics.

  1. Maintenance in windows, never on filing night. Patching, upgrades and swaps run after hours, on a schedule the firm sees before anything moves, and never on a machine with a deadline attached.
  2. Proven, not assumed. Restore tests on a calendar, workstations kept current, spares staged, so the final draft is never trapped on the one machine nobody has looked at since spring.
  3. Monitoring that phones home. A disk filling up, a backup quietly failing, a certificate about to expire: caught at breakfast, not at 11:40 p.m. with the exhibit half uploaded.

One standard across your offices

Firms spread out, by merger, by a lateral group, by a satellite office near a courthouse. The acquired practice arrives with its own server, its own backup tool, its own password spreadsheet and a retiring partner who knew where everything was. Every office goes onto the same monitoring, the same backup standard and the same helpdesk, so the whole firm behaves like one office with long hallways. How that works across locations is written up on our multi-site IT support page.

Word for word from public Google reviews. Names as the reviewers published them.

“Express provides excellent service, we’ve been with them for years. They are always responsive to whatever issues we might have. Great work, always totally pleased.”

Dave Kamp, public Google review

“I have always had good experiences with this team. They listen to the problem and take the time to go over it with you if you need or want them to. Very good experience and reasonable.”

Sue Kazel, public Google review

Straight answers for partners and firm administrators

The questions we actually get asked.

Can you make our firm compliant with the bar’s rules?

No, and no vendor can; the ethics duties belong to the lawyers. ABA Model Rule 1.6 expects reasonable efforts to prevent unauthorized access to client information, and the technology competence comment expects lawyers to understand the benefits and risks of the tools they practice with; neither duty can be handed to a contractor. What an IT provider can honestly do is supply the reasonable efforts: encryption, multi-factor authentication, need-to-know access controls, logging, tested backups, implemented and documented so the firm can show its work if a client or a carrier ever asks. That is the part we do, and we put in writing which part is whose.

Will you sign our confidentiality agreement?

That is the right question, and a vendor that hesitates has answered it. A firm’s duty of confidentiality follows client information to every vendor who can reach it, which is why bar guidance on outsourcing expects firms to bind outside providers in writing. An IT provider with access to your systems sits squarely in that category, so confidentiality terms belong on paper before work starts, and that is how engagements are set up here: terms in writing, reviewed with the partner who owns the decision, before anyone logs into anything.

A litigation hold just landed. What is your part?

The implementation, never the decision. Whether to hold, which matters it covers, whose mailboxes and which date ranges: that is counsel’s call, full stop. Once counsel directs the scope, our part is making the systems obey it: suspending the automatic deletion and retention jobs that would otherwise keep running, placing the named mailboxes and file stores on preservation settings, and documenting what was preserved, when, and on whose instruction. When the hold lifts, the same steps run in reverse, on paper. A hold that exists only in a memo is a hope; the settings are what make it real.

Our document management system is cloud-hosted. Is there anything left for you to do?

Plenty. The application belongs to its vendor and the hosting belongs to the host; everything the session rides on is ours: the internet connection and the firewall, the workstations and scanners, identity and MFA, email and its retention, and the local files that never made it into the hosted system. When the vendor’s support line says the problem is on your end, we pick up that ticket and work it with them instead of leaving a partner to referee.

Wire fraud keeps hitting real estate and trust closings. What actually stops it?

A verification procedure the firm never skips, backed by technical controls that make the setup harder. The attack is patient: a compromised mailbox, a quiet inbox rule hiding the real thread, then swapped wire instructions days before a closing, sent from an address everyone trusts. The technical half is ours: multi-factor authentication on every mailbox, defenses tuned for the impersonation mail firms actually receive, alerts when a new forwarding or inbox rule appears, encrypted email for instructions that should not travel in the clear. How to check your own tenant for the inbox rule trick is written up in our Microsoft 365 inbox rule fraud walkthrough. The procedural half is the firm’s, and no technology replaces it: wire instructions get confirmed by a call to a number already on file before money moves, every time, no matter how senior the name on the email.

What does law firm IT support cost?

Hourly for project work, or a flat monthly rate for full coverage, with the price in writing before work starts. Our published plans run $65, $80 and $99 per user per month; what each includes is on the MSP packages page. Firm specifics, like a satellite office near the courthouse or a conflicts wall that needs building, get priced in the first conversation.

Our firm administrator handles IT now. How does this work with them?

As a team, not a replacement. Co-managed is a normal arrangement here: your administrator keeps what they are good at, often the practice management system and the way the firm actually works, and we carry the rest, monitoring, backups, security and the helpdesk depth one person cannot provide the week three matters heat up at once. Who owns what goes on paper, so nothing falls between two chairs.

We have offices in two cities. Does that change anything?

No, that is an arrangement we expect. Firms grow by merger and lateral moves, and each acquired practice tends to arrive with its own server, its own backup tool and its own password spreadsheet. Every office goes onto the same monitoring, the same backup standard and the same helpdesk, so the whole firm behaves like one office with long hallways. The multi-location version of this page is our multi-site IT support page.

Book a scoping call

A few fields now, a straight recommendation on the call.

We call before we email, so this is the fastest way to get an answer.
Where the written reply goes.
It tells us how far out you are, so we can answer properly.
A sentence is plenty. It saves a round trip.

Your details go to our Fayetteville office. We use them to get back to you, and we do not sell or share them.

Tell us about the firm.

How many attorneys and offices, whether your document and practice management systems are hosted or on a server down the hall, and what failed last month. That is enough for a straight recommendation and a price in writing, usually from the first conversation.

Fayetteville office511 East Genesee St, Suite 8A
Fayetteville, NY 13066
Syracuse office120 Madison St, Suite 1000
Syracuse, NY 13202
CoverageRun from Syracuse NY since 2005. On-site across Upstate New York, and farther by plan.