Industries

IT for law firms that have to prove it.

Ohio’s rules of professional conduct do not ask whether you meant to protect client information. If something gets out, they ask what you actually had in place beforehand. Iconium runs those safeguards, keeps the record, and can hand you the evidence when a client, an insurer or a disciplinary inquiry asks for it.

1.6(c)
The rule behind this page
24/7
Threat monitoring
Under 2 hrs
First response, business hours
$0
Trip charges

What actually goes wrong in a law firm

Not “downtime is expensive.” These are the specific failures that turn an IT problem into a professional one.

The ones that cost money

  • Business email compromise during a closing or a settlement disbursement, where the altered wire instructions are the whole point of the attack
  • Ransomware on the file share holding a decade of matter folders
  • A document management system down on the afternoon of a filing deadline

The ones that cost more than money

  • A conflicts database nobody can reach before taking on a new client
  • Privileged material readable by staff who have no business in that matter
  • A departing associate leaving with a copy of a client file

What Ohio actually requires

Two rules do most of the work here, and neither is about technology for its own sake.

Rule 1.1, Comment [8] — competence

A lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology.

Rule 1.6(c) — confidentiality

“A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of or unauthorized access to information related to the representation of a client.”

The word carrying the weight is reasonable. Comment [18] says plainly that unauthorized access is not by itself a violation where the lawyer made reasonable efforts to prevent it, and it lists what reasonableness turns on: the sensitivity of the information, the likelihood of disclosure if additional safeguards are not used, the cost of those safeguards, and the difficulty of implementing them.

Read that in reverse and it tells you what a firm actually needs on the bad day: not a promise that nothing could ever happen, but a record of what was running when it did.

The safeguards we run, and what each one answers

Every item below is part of the standard monthly rate, not an upsell tier. The grouping maps to the reasonableness factors above rather than to a vendor’s product categories.

Keeping sensitive material narrow

  • Encryption in transit and at rest
  • Access controls, reviewed rather than set once
  • Email security and quarantine
  • DNS and web content filtering

Making disclosure less likely

  • Multi-factor authentication and identity hardening
  • Application allow-listing
  • Dark web credential monitoring
  • Security awareness training and simulated phishing

Catching it when it starts

  • Managed detection and response, 24/7, independent of our support hours
  • Patch and vulnerability management

Getting the firm back to work

  • Backup verification and recovery testing, not just backup
  • Unlimited help desk, under two hours to first response in business hours
  • Onsite when remote will not do it, included in the rate

Underneath all of it sits the part firms actually get asked for: audit evidence collection, plus quarterly technology planning so the answer to “when did you last review this” is a date rather than a shrug.

Where our responsibility stops

Most providers imply the opposite, so it is worth saying out loud.

  • We operate the controls and produce the evidence. We are not your lawyers and we do not opine on whether your efforts satisfy Rule 1.6(c). That judgment stays with the firm.
  • We do not sell an attestation, a certification or a seal. Nobody can certify a firm compliant with a rule of professional conduct, and a provider offering to is telling you something about themselves.
  • Your practice management, document management and e-discovery vendors keep their own support responsibilities. We manage the environment those applications run in and coordinate with them; we do not replace them.
  • The client relationship, the ethical duty and the decision about what risk is acceptable are all yours. We make them informed decisions rather than blind ones.

What it costs

The same published rates apply to a law firm as to anyone else: $163 per user, $19 per computer, $100 per server, $17 per mailbox and $179 per additional location, per month. A fully equipped seat is $199 all in. No minimum, no setup fee, no automatic annual escalator. See the full pricing page — there is no form in front of it.

We support firms across Northeast Ohio and the Greater Houston area, including co-managed arrangements where a firm already has internal IT.

Questions law firms ask us

No, and be wary of anyone who says they can. Rule 1.6(c) places the duty on the lawyer, not on a vendor, and it asks for reasonable efforts rather than a certificate. What we do is operate the safeguards that make those efforts real, and keep the records that show they were running on the date in question. Whether that meets the standard for a given matter is a judgment for the firm, and if it ever came to it, for a disciplinary body.

We manage the environment those applications depend on: the endpoints, the identities, the network, the backups and the security controls around them. Where a vendor supports the application itself, we coordinate with that vendor rather than displacing them, and we handle the parts they will not touch. Tell us what you run on the first call and we will be specific about where the line falls.

Detection and response run 24/7 and do not wait for business hours, so the first action to isolate affected machines is not sitting in a queue until morning. Recovery then depends on something most firms assume and few verify: that the backups actually restore. We test restores rather than trusting a green checkmark, which is the difference between a bad week and a closed firm. We will also tell you plainly what was reachable, because that question is coming from your client and your insurer.

We can tell you exactly what is deployed and show you the evidence behind each answer, which is usually the hard part of that form. The answers themselves go in over the firm’s signature, not ours, because the insurer is contracting with you. Firms find this is also where gaps surface, and it is a better place to find them than in a claim.

No. There is no seat minimum and no monthly minimum, so a three-person firm pays for three people. The obligations in Rule 1.6(c) do not scale down with headcount either, which is why small firms are frequently the ones with the widest gap between what is required and what is running.

Client transitions happen, and we plan for a clean one. We never withhold data or client intellectual property, and we work with your incoming provider to make the handover orderly. A firm that holds your files hostage at the end of a relationship was never really protecting them.

Yes. Mixed environments are normal in firms, and Macs are covered at the same per-computer rate as anything else.

Onboarding typically runs about a week. Contract terms are twelve, twenty-four or thirty-six months, and there is no onboarding or setup fee.

Want to know what your firm would actually look like?

Call (440) 991-9980 or book a thirty minute call. We will tell you plainly where your current setup sits against the factors in Comment [18], including the parts that are already fine.

See also: every industry we serve and our written answers to the questions clients ask most.