Elevaire Systems
Why Law and Accounting Firms Outgrow Their MSP Faster Than Other Sectors
← Back to Insights
Industry Insightsprofessional servicesvendor managementIT strategygrowth-stage companies

Why Law and Accounting Firms Outgrow Their MSP Faster Than Other Sectors

Elevaire Systems·

A 60-person accounting firm and a 60-person marketing agency can run on the same managed service provider for years without either one noticing a gap. Then the accounting firm signs a new cyber insurance policy that requires a documented information security program, or a partner asks who is actually accountable for what happens if a client's trust account gets hit by a wire fraud scheme, and the gap becomes obvious. Law and accounting firms outgrow their MSP faster than almost any other sector in the 25 to 200 employee range, and it happens for reasons specific to what these firms handle, not because their MSP did anything wrong.

The moment the model breaks

A managed service provider is built to keep systems running: patching, monitoring, help desk tickets, backups, basic firewall management. That is genuinely valuable work, and most firms need it for the life of the business. What an MSP is not built to do is own a compliance program, negotiate with a practice management software vendor on the firm's behalf, or decide which cybersecurity controls the firm actually needs given the specific data it holds. Those are strategy and governance functions, not support functions.

For a generic professional services firm, that gap can sit unnoticed for a long time. For a law firm or accounting firm, it surfaces early because these firms carry two things most other growth-stage companies don't: legally privileged or federally regulated client data, and a body of professional and regulatory rules that treat technology decisions as compliance decisions, not IT decisions.

What law and accounting firms carry that other firms don't

Law firms hold client communications protected by attorney-client privilege, case files that can include medical records or financial disclosures, and client trust accounts governed by state IOLTA rules, where mishandling funds is a bar discipline matter, not just an accounting error. The American Bar Association's Model Rule 1.1 was amended in 2012 to add Comment 8, which states that competent representation now includes understanding "the benefits and risks associated with relevant technology." As of 2023, 39 states had adopted some version of that duty into their own rules of professional conduct. That is an ethical obligation attached to the firm's technology choices, not a general best practice.

Accounting and tax firms carry a parallel but distinct set of obligations. The FTC Safeguards Rule names "an accountant or other tax preparation service" directly as a covered financial institution, regardless of firm size, and requires a written, risk-assessment-based information security program with a designated Qualified Individual accountable for it. Since May 2024, firms covered by the rule must also report certain security incidents to the FTC. Separately, the IRS requires every paid tax preparer to follow Publication 4557's "Security Six" controls: antivirus and endpoint protection, firewalls, multi-factor authentication, encrypted backups, drive encryption, and a VPN for remote access. These requirements apply to a two-partner tax practice exactly as they apply to a 150-person firm.

None of this is optional, and none of it is something a general-purpose MSP is set up to interpret. A firewall vendor can sell you a firewall. Nobody at that vendor is going to tell you whether your current setup actually satisfies what the FTC or the IRS expects of your specific firm, because that requires reading the regulation and mapping it to your business, not configuring a device.

What it costs when nobody owns it

The exposure here is not abstract. The FBI's Internet Crime Complaint Center recorded more than $20.8 billion in reported losses across all categories in its 2025 Annual Report, a 26 percent increase over 2024. Business email compromise, the fraud pattern where an attacker impersonates a partner, client, or vendor to redirect a payment, accounted for roughly $3.05 billion of that total across nearly 24,800 incidents, an average loss of $123,000 per case, with 86 percent of the fraudulent payments moving by wire or ACH. Law firms and accounting firms are structurally attractive targets for this exact scheme: they move client funds routinely, correspondence about closings and disbursements is expected and unremarkable, and a single successful wire fraud against a trust account can trigger bar complaints and client lawsuits on top of the direct loss.

A firm this size doesn't need to imagine the cost. One BEC incident at the 2025 average loss figure is roughly what two to three years of dedicated, senior-level technology oversight would cost, and that is before counting the malpractice exposure, the client relationships damaged, and the hours partners spend managing the fallout instead of billing.

There is a second, quieter cost that shows up before any incident happens at all. Cyber insurance underwriters have tightened what they ask for at renewal across the industry, and firms that cannot produce documented evidence of specific controls, not just a verbal assurance that "IT handles it," increasingly face higher premiums, added exclusions, or an outright declined renewal. A managing partner finding this out during a 30-day renewal window, with no one able to produce the documentation on short notice, is a common and entirely avoidable position to be in.

Where the MSP model runs out of runway

None of this is a knock on the MSP relationship itself. The mismatch is about scope, not competence. An MSP's contract typically covers keeping the network up and responding to tickets. It typically does not cover:

  • Deciding whether the firm's practice management platform (a Clio, an iManage, a CCH Axcess, a Karbon) is the right long-term fit, or negotiating the renewal
  • Writing and maintaining the written information security program the FTC Safeguards Rule requires
  • Evaluating whether the firm's current controls would actually satisfy a cyber insurance underwriter's questionnaire before a policy lapses
  • Deciding how much of the technology budget goes to security versus new tooling versus infrastructure refresh, and defending that allocation to the partners
  • Owning a vendor risk register for every SaaS tool a paralegal or a staff accountant has signed up for without anyone in IT knowing

At 25 employees, a managing partner can hold most of this informally. At 75 to 150 employees, with multiple practice groups or service lines, informal ownership stops working. Something falls through, usually quietly, until an insurance renewal, a bar audit, or an incident forces the question.

What closes the gap

This is where fractional IT leadership fits, and it is worth being precise about what that means. Elevaire Systems does not replace a firm's MSP. The MSP keeps the lights on. Fractional IT leadership makes sure the lights are pointed in the right direction: setting the technology roadmap, owning the compliance program, evaluating and managing the MSP and every other vendor relationship, and giving the partners a single accountable person to answer to when the insurer, a regulator, or a client asks hard questions.

For a law or accounting firm specifically, that means someone who can translate ABA Rule 1.1, the FTC Safeguards Rule, and IRS Publication 4557 into an actual, documented program rather than a folder of vendor invoices, and who sits between the partners and the MSP so neither side has to guess what the other needs. That is a leadership function. It was never realistic to expect a break-fix support contract to deliver it.

Frequently Asked Questions

How much does fractional IT leadership cost compared to hiring a full-time CIO?

A full-time CIO at a firm this size typically commands a total compensation package well into six figures once salary, bonus, and benefits are included, and that person still needs a budget for tools and support staff. Most law and accounting firms in the 25 to 200 employee range don't have enough strategic technology work to justify that as a full-time role, which is exactly why the position usually goes unfilled and the gap persists. Fractional IT leadership provides senior-level strategic ownership at a fraction of that fixed cost, scaled to the actual hours a firm this size needs, which is usually a matter of days per month, not a full-time role.

Will this replace our current MSP?

No. Your MSP continues handling day-to-day support, monitoring, and infrastructure. Fractional IT leadership sits above that relationship: setting strategy, managing the MSP as a vendor, and owning the compliance and risk decisions that a support contract was never designed to cover.

Do we actually need this if we've never had a security incident?

The absence of an incident is not evidence of a working program. The FTC Safeguards Rule and IRS Publication 4557 apply regardless of your loss history, and cyber insurers increasingly require proof of specific controls before binding or renewing a policy. Firms usually discover the gap during an underwriting questionnaire or a bar audit, not because something already went wrong.

What does getting started actually look like?

It typically starts with an assessment of your current technology environment, your MSP relationship, and your compliance posture against the rules that actually apply to your firm, followed by a prioritized roadmap. Elevaire Systems offers a free consultation to walk through where your firm stands before any engagement begins.

Is this only for law firms with in-house data, or does it apply to smaller practices too?

Firm size doesn't change the regulatory obligations. A two-partner tax practice is bound by the same IRS Security Six requirements as a 150-person firm, and a small firm typically has fewer internal resources to cover the gap, which makes dedicated oversight more valuable per dollar spent, not less.

How does this work if we have multiple offices or practice groups?

Fractional IT leadership is built for exactly this kind of complexity. One accountable person can standardize security controls, vendor relationships, and compliance documentation across practice groups or locations that would otherwise each develop their own inconsistent approach, which matters most at firms where a litigation group, a transactional group, or a separate tax practice have each quietly picked their own tools without anyone reconciling the risk across all of them.

Ready to Put This Into Practice?

Schedule a free consultation and let's talk through what this means for your organization specifically.

Schedule a Free Consultation