IT management at a professional services firm has exactly one job description: the technology works on the days the work is worth the most, and it doesn't become the reason anything is slow. Everything else, the hardware refresh schedule, the vendor contracts, the argument about which laptop, is subordinate to that. A firm that measures its IT any other way ends up with a tidy asset inventory and a network that goes down on April 12th.
Most small firms don't decide how to handle IT. They accumulate it. A partner who is good with computers becomes the help desk, a nephew set up the server, someone's cousin does the website, and the arrangement holds until the week it very publicly doesn't. That's not a criticism, it's just what happens when nobody's actual job is technology and the work always comes first.
This guide is the deliberate version. What IT is responsible for at a firm your size, the three models for getting it (plus the fourth one you're probably running by accident), what a technology stack for a small firm should contain, how to make hybrid work function without opening holes, what to budget, and how to pick a partner without ending up in a contract you resent.
What IT is actually responsible for
Ask a firm owner what IT does and you'll usually hear "fixes things." That's reactive IT, and it's the most expensive kind, because the cost isn't the repair bill. It's the six people who couldn't work while it was broken, during a week when their hours were worth the most they'll be worth all year.
The honest job list at a professional firm has six items. Keep systems available, especially in the seasons that matter. Keep client data secure and the firm's compliance obligations satisfied. Make sure work can happen from wherever people are working this year. Keep the software your practice runs on current, connected, and licensed. Make sure a hardware failure or a ransomware event is a bad day rather than an extinction event. And be the person who says no, calmly, when someone wants to install something with terms nobody read.
Notice that only one of those is about fixing things. The rest are about preventing the fixing, which is why "we call someone when it breaks" produces a firm that is always slightly broken. What that looks like practice by practice is in what actually matters in IT support for accounting firms and, for the other side of the profession, what a law firm should expect from its IT support.
The ways firms get IT help
Four arrangements, and one of them isn't a decision.
The partner who is good with computers
Nearly universal in firms under twenty people, and the true cost is invisible because it never appears on an invoice. Take the partner's billing rate, multiply by the hours a month they spend on printer drivers and password resets and researching whether the backup is running, and put that number in front of the partnership. It is reliably larger than the cost of the thing they were avoiding. (Nobody budgets for this, by the way. It just quietly comes out of the practice.)
The second cost is worse and harder to see. That partner is doing IT at an amateur level, which means the security decisions, the backup design, and the vendor terms are all being made by someone whose actual expertise is somewhere else entirely. The gaps don't show up until they show up.
Hiring someone
Works at scale and rarely below it. A firm of fifteen cannot keep a capable IT person busy or interested, and a capable IT person will not stay somewhere the work is fifteen laptops and a printer. You end up with either an overqualified person who leaves in a year or an underqualified one who becomes a single point of failure with all the passwords. Somewhere north of forty or fifty people, the math turns and an in-house hire starts making sense, usually alongside outside help for the specialist work.
Managed IT
A firm handles your technology for a monthly fee: monitoring, patching, help desk, security tooling, and usually a stated response time. The economics work because they spread specialists and tooling across many clients, so you get a security person and a network person and a Microsoft 365 person without employing any of them.
The variance between providers is enormous, and the thing to check is whether they understand professional services. A provider whose other clients are dental offices will not know why the second week of April is different, will schedule maintenance during it, and will treat your practice management platform as unfamiliar software. Ask directly how many accounting or law firms they support and what their change freeze policy is during filing season. The answer tells you almost everything.
Fractional IT leadership
The least understood option and often the right one. Managed services handle the doing. Fractional leadership handles the deciding: what to buy, what to retire, how to sequence a migration, whether the vendor's proposal is reasonable, what the three-year plan is. A few days a month of someone senior, who is on your side of the table when a salesperson is in the room.
Firms that need this are usually the ones growing past the point where accumulated decisions still hang together, or the ones about to do something consequential like a merger, an office move, or replacing the practice management system. What it looks like week to week is in what fractional IT management looks like for a small firm.
What most firms actually land on
Managed services for the daily operation, fractional leadership for the decisions, and one person internally who owns the relationship and knows where things are. That last role is small and matters more than it sounds, because a managed provider with no internal counterpart drifts, and nobody notices for a year.
The stack, in the order it should be built
Technology decisions at small firms get made one panic at a time, which is how you end up with three places to store documents and no agreement about which is real. Build it in layers instead, from the bottom.
Identity first. One directory, one login per person, MFA on everything, and a defined process for granting and removing access. This is the foundation for everything above it, and it's the layer that makes onboarding and offboarding a checklist instead of an archaeology project.
Email and collaboration. For nearly every small firm this means Microsoft 365 or Google Workspace, and the choice matters less than the configuration. The mistake to avoid is buying the cheapest tier, then discovering the retention controls, device management, and advanced threat protection you assumed you had live one tier up.
Practice management. The system of record for clients, matters or engagements, deadlines, time, and billing. Everything else should connect to it rather than duplicate it, and the day a firm gives up on that principle is the day the data starts disagreeing with itself.
Documents. One place. With a naming convention, retention rules, and a client portal so that sensitive documents stop travelling as email attachments. Firms fight this and lose years to it.
Communications. The phone system belongs in the stack, not off to the side with the furniture, because it's the layer clients touch most. Cloud phones that follow people, route by rule, and produce data about what you missed are a different category of tool than the box in the closet. Our cloud PBX service covers that layer, and the full decision is in our guide to business phone systems.
Security and backup underneath all of it. Endpoint protection, filtering, monitoring, and a backup you have restored from. Treated as a layer rather than a product you bought once, which is the argument we make at length in our cybersecurity guide for firms.
One rule governs every purchase after the first year: it has to connect to what you already run. A tool that doesn't integrate creates a manual handoff, and manual handoffs are where firms lose the time they bought the tool to save. The full build order, with the questions to ask at each layer, is in how to build a technology stack for a small professional services firm.
Hybrid work, done without holes
Most firms now run some mix of office and home, and most of them built that setup in a hurry during a week when the priority was "make it work by Monday." The temporary version is still running at a lot of firms, which is worth saying plainly.
The version that holds up has a few properties. Firm-owned and firm-managed devices wherever possible, because you cannot enforce encryption, patching, or remote wipe on a machine you don't control, and the family laptop with the shared login is a genuinely bad place for client data. Cloud-first applications so that the office network stops being a chokepoint, since the alternative is a VPN that everyone hates and half the staff bypasses. Access based on identity rather than location, because "on the network" hasn't meant "trusted" for a long time. And a home network standard that at least covers the basics, which mostly means the router's default admin password and firmware nobody has thought about since installation.
Then the human part: people at home make security decisions alone, without the colleague who would have said "that email looks off." The compensating control is a habit of checking with someone, which only exists if you build it deliberately. The equipment and configuration details are in the best office IT setup for secure hybrid work.
The office network and the closet nobody opens
Every firm has a closet. In it there is a switch from a decade ago, a router the ISP left, a cable that's been unplugged for years, and often a server running an operating system the manufacturer stopped patching a while back. It works, so nobody touches it. It also has no monitoring on it, guest Wi-Fi that shares a network with the file server, and an admin password that three former employees still know.
The fix is not exotic. Segment the network so guests and smart devices can't reach anything that matters, put the infrastructure behind proper credentials with MFA, replace what's out of support, and get monitoring in place so a failing drive announces itself before it announces itself loudly. If you'd rather have it designed properly once, that's what our secure network design service is for.
Staying up on the days it matters
Continuity planning at a small firm doesn't require a binder. It requires answers to two questions, in writing, for each critical system: how long can we be without this, and how much recent work can we afford to lose. Those two numbers determine what you buy, and firms that skip them buy backup products by price and find out the difference during an outage.
Then test. A restore test once a quarter, timed. A failover test for the phones. A "what if the office is inaccessible for a week" conversation that produces a real answer rather than a shrug. The most useful thirty minutes an IT provider will ever spend with you is the one where they try to restore something in front of you and it doesn't work, because that's cheaper on a Tuesday in September than during an incident.
And a seasonal rule worth adopting formally: a change freeze during your busy period. No migrations, no version upgrades, no swapping the firewall in March. Whatever needs doing gets done before the season or after it. Firms learn this rule the hard way roughly once.
What to budget, and how to think about it
Percentage-of-revenue rules of thumb are worth very little at small-firm scale, because a firm of eight with heavy compliance obligations and a firm of eight doing simple bookkeeping have completely different needs and identical revenue percentages. Build the number from the list instead.
The recurring side: per-user software licensing, your support arrangement, security tooling, backup, connectivity, and phones. The periodic side: hardware on a refresh cycle, which for laptops means roughly every three to four years and should be staggered so you're replacing a few each year instead of all of them in a single miserable quarter. Then a contingency line, because something will break that nobody predicted, and firms without a contingency line make that decision badly under pressure.
The mistake to avoid is treating IT purely as overhead to be minimized. Some of it genuinely is. But the document automation, the phone system, and the practice management platform are capacity, and capacity is the constraint on a professional firm's revenue. Cutting there to save a monthly fee is how firms end up hiring instead, which costs more and is harder.
What changes as the firm grows
The right answer moves with headcount, and firms usually notice about a year late. Three rough thresholds are worth knowing in advance.
Under ten people. Almost everything can be cloud services and good laptops. Skip the server entirely if you still can. The main risks are that nobody owns security decisions and that the whole operation depends on one person's memory. A light managed arrangement plus MFA everywhere covers most of it, and the cost is genuinely small.
Ten to twenty-five. The stage where accumulated decisions start to conflict. Two document repositories, a spreadsheet doing a job software should do, onboarding that takes a week because nobody wrote down the steps. This is where the accidental IT arrangement breaks, and where the firm should get deliberate about identity, access, and documentation. It's also the stage where an outside pair of eyes pays for itself fastest, because the problems are structural rather than technical.
Twenty-five to sixty. Now you need process. Change control so upgrades don't surprise anyone, formal onboarding and offboarding, a real asset inventory, and somebody internal who owns the relationship with your provider. Multiple offices, if you have them, force decisions about standardization that a single office can defer forever. That standardization problem is as much an operations question as a technology one, and we treat it as such in our firm operations guide.
The failure pattern is the same at every threshold. The firm keeps running the arrangement that worked at the previous size, because changing it is a project and there's always client work. Then something breaks in a busy week and the change happens under pressure, at the worst price, with the wrong provider, chosen in four days.
Choosing a provider without regretting it
Ask these before you sign. How many firms like ours do you support, specifically in accounting or law. What's your policy on changes during tax season or trial weeks. What's the guaranteed response time, and is it in the contract or the brochure. Who actually answers when we call, and what happens at 8pm on April 14th. Do we own our documentation and licenses if we leave. What's the contract term and the exit process.
The red flags are consistent. Long lock-in with an unpleasant exit. Vagueness about response times. A provider who won't put you in touch with a client in your profession. Recommendations that all happen to be products they resell. And the big one: an unwillingness to explain things in language you understand, which is almost never about complexity and almost always about not wanting you to evaluate the answer.
If you want a structured way to work out what you need before the first call, we keep a simple IT checklist for growing professional firms for exactly that.
The mistakes that cost the most
Waiting for the break. Reactive IT costs more than proactive IT and firms compare the wrong two numbers, the monthly fee against nothing, instead of against the downtime it prevents.
Running hardware to failure. The six-year-old workstation is not saving money. It's costing an hour a week in slowness and it will fail during the week you can least afford it, because that's the week it's working hardest.
Buying tools nobody adopts. Software bought without asking the people who'll use it becomes a line item with a renewal date. Run an audit once a year of what you pay for versus what's actually in use, and cancel the rest.
Treating security as separate from IT. They're the same function with two invoices. The unpatched server is both an IT issue and a security incident waiting for a scanner to find it.
Documenting nothing. Where things are, who the vendors are, what the passwords protect, how the network is laid out. When the person holding all of it in their head leaves, the firm pays for the rediscovery. Write it down, keep it current, and store it somewhere that survives the server it describes.
Where this leaves you
Good IT at a professional services firm is nearly invisible. Nothing breaks in March, new people are productive on day one, the laptop that died is replaced by lunch, and nobody in the partnership has a strong opinion about any of it because nobody has had to. That state is achievable at fifteen people and it isn't expensive. It just requires deciding, once, who owns the technology instead of letting the answer stay "whoever noticed."
Start with the closet, the backup, and the access list of people who've left. Those three will occupy an afternoon and will tell you most of what you need to know about where you stand.

