HD Tech - SecurITy Delivered
Back to Blog
Managed IT

Co-Managed IT for Law Firms in Orange County

By Tom Hermstad · HD Tech

Co-Managed IT for Law Firms in Orange County

What is co-managed IT for law firms, and do Orange County practices actually need it?

Co-managed IT for law firms pairs your existing internal IT person or team with an outside managed services partner — giving them around-the-clock monitoring, cybersecurity depth, and backup coverage they can't realistically provide alone. For Orange County law firms navigating ABA Rule 1.6, CCPA/CPRA, and a rising wave of phishing and ransomware attacks, it's the difference between an overwhelmed IT generalist and a fully staffed, always-on IT operation — without replacing the person you already trust.


By Tom Hermstad, Founder & CEO, HD Tech Serving Orange County law firms | hdtech.com


Is your IT person the problem — or is the workload just too big for one person?

If your firm has an internal IT person — or even a small team — they're probably good at what they do. They know your systems. Your attorneys trust them. They keep the lights on.

But here's the reality: keeping the lights on is no longer enough.

Phishing is now the top cybersecurity concern for 50% of law firms, outranking ransomware and insider threats. Four in ten law firms self-report experiencing a security breach, with 8% losing or exposing sensitive data. And ransomware attacks against law firms continue to climb, with a significant and growing number of incidents compromising legal records each year.

Your IT person cannot watch for threats at 2 a.m. on a Tuesday. They can't simultaneously manage a partner's printer issue, respond to a phishing alert, and document your data-mapping practices for CCPA compliance. Nobody can do all of that alone.

One IT generalist — no matter how talented — isn't a seasoned security operation. That's not a failure. That's math.

Co-managed IT solves this without disruption — by extending your team, not replacing it.


What does ABA Rule 1.6 actually require from your IT setup?

ABA Model Rule 1.6 requires lawyers to take reasonable measures to prevent unauthorized disclosure of client information — and that duty now explicitly covers electronic security.

ABA Formal Opinion 477R goes further. It states that depending on the sensitivity of the matter, attorneys may need to implement special security precautions: encryption, stronger access controls, and documented vendor oversight.

Practically, this means your firm must:

  • Understand the nature of current cyber threats
  • Know where client data lives — and who can access it
  • Use reasonable, documented security measures
  • Train staff on information security practices
  • Conduct due diligence on every technology vendor

That last point matters. When you work with HD Tech through our co-managed IT services, you get a documented, auditable security partner — not just a break-fix vendor. That's the kind of vendor relationship ABA guidance expects you to have.


California privacy law adds another layer your IT person can't carry alone

Orange County law firms subject to CCPA/CPRA face a separate compliance burden. If your firm generates over $25 million annually or handles data on 100,000 or more California residents or households per year, CCPA/CPRA applies.

Attorney-client privileged data is often exempt. But non-privileged personal data — website visitors, job applicants, HR records, marketing leads — remains in full scope, with 45-day deadlines on consumer rights requests, access controls, breach notification, and data-mapping requirements.

One IT person managing daily support tickets does not have the bandwidth to own this. A co-managed IT arrangement distributes the load — your internal person stays focused on the firm's day-to-day, while HD Tech handles continuous monitoring, access logging, and compliance documentation.


What are the real financial stakes for firms without mature cybersecurity?

It's not if, it's when — and the cost of waiting is steep. Ransomware demands against law firms have reached staggering levels in recent cases, and a meaningful share of ransomware attacks on legal firms have resulted in lawsuits — with plaintiffs prevailing or obtaining settlements in the vast majority of those cases.

Cyber insurance helps, but carriers increasingly require documented controls — backups, multi-factor authentication (MFA — requiring users to verify identity through a second method beyond a password), and incident response plans — before issuing or renewing coverage. Co-managed IT is how many firms build and maintain those controls.

You don't get a second chance at a first breach. The time to build the program is now.


How co-managed IT actually works for Orange County law firms

This is where firms often get confused. Co-managed IT is not outsourcing your IT department. It's adding depth behind your existing person.

Here's what that looks like in practice through HD Tech's Cyber Lifeguard Standard™:

  • Around-the-clock threat monitoring — HD Tech watches your network continuously. Your IT person gets alerts and backup during off-hours, not silence.
  • Fast help desk response — Attorneys and staff reach a live technician quickly. Your internal IT person isn't the only person between a frustrated partner and a resolution.
  • Security projects — Firmware updates, vulnerability assessments, MFA rollouts, ABA 1.6 alignment documentation. The work that never makes it to the top of the queue actually gets done.
  • Flat monthly fee — Predictable costs. No surprise invoices. No overtime billing when a ransomware event hits at 11 p.m.
  • Shared tools and visibility — Your IT person sees everything HD Tech sees. They stay in control. They just aren't doing it alone.

For a sense of how other Orange County professional service firms approach this, our managed IT services for law firms page covers the full picture. And if you're thinking about recovery time commitments alongside day-to-day coverage, RPO and RTO planning for professional firms in Orange County is worth reading before you evaluate any IT partner.

One of our long-standing law firm clients put it plainly:

"Careful attention to detail, solution-oriented services and implementation and fair pricing. We have worked with HD Tech for many years now and are extremely satisfied with their professionalism and capabilities." — Greg Burnight, Principal, APC, Curtis & Burnight, Seal Beach


Frequently Asked Questions

No. Trust, yet verify. That's exactly what Co-Managed IT let's you do with your internal IT team. Co-managed IT is designed to support your existing IT staff, not replace them. Your internal person stays in place and keeps their relationships with partners and staff. HD Tech adds continuous monitoring, security depth, and project capacity behind them — so they can focus on the work only they can do.

ABA Rule 1.6 requires lawyers to take reasonable measures to prevent unauthorized disclosure of client information, including electronic security measures. ABA Formal Opinion 477R further specifies that firms may need encryption, stronger access controls, and documented vendor oversight depending on the sensitivity of the matter. Co-managed IT directly supports this compliance posture by providing documented, auditable security practices.

Yes, if your firm meets the applicable thresholds — over $25 million in annual revenue or handling data for 100,000 or more California residents or households. Non-privileged personal data like HR records, marketing leads, and job applicant information falls in scope, with strict deadlines and documentation requirements that often exceed what one IT generalist can manage.

HD Tech's help desk is staffed to connect attorneys and staff with a live technician quickly — not a ticket queue or a callback window. For a firm where billable time is always at stake, that response speed matters.

HD Tech uses a flat monthly fee model. You know exactly what you're paying each month, with no surprise invoices for after-hours incidents or project work that runs long. Predictable IT costs are easier to budget and easier to justify to firm leadership.


If your internal IT team is stretched thin on cybersecurity, compliance, or after-hours coverage — and you're not ready to hand everything over to an outside firm — co-managed IT may be exactly the model you've been looking for. Start with a conversation. Book your free Discovery Call and find out where your gaps actually are.


{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "Organization",
      "@id": "https://hdtech.com/#organization",
      "name": "HD Tech",
      "legalName": "HD Tech, LLC",
      "url": "https://hdtech.com",
      "logo": {
        "@type": "ImageObject",
        "@id": "https://hdtech.com/#logo",
        "url": "https://hdtech.com/images/hdtech-logo.png",
        "width": 512,
        "height": 512,
        "caption": "HD Tech"
      }
    },
    {
      "@type": "WebSite",
      "@id": "https://hdtech.com/#website",
      "url": "https://hdtech.com",
      "name": "HD Tech",
      "publisher": { "@id": "https://hdtech.com/#organization" },
      "inLanguage": "en-US"
    },
    {
      "@type": "WebPage",
      "@id": "https://hdtech.com/blog/co-managed-it-law-firms-orange-county/#webpage",
      "url": "https://hdtech.com/blog/co-managed-it-law-firms-orange-county",
      "name": "Co-Managed IT for Orange County Law Firms | HD Tech",
      "isPartOf": { "@id": "https://hdtech.com/#website" },
      "breadcrumb": { "@id": "https://hdtech.com/blog/co-managed-it-law-firms-orange-county/#breadcrumbs" },
      "inLanguage": "en-US"
    },
    {
      "@type": "BreadcrumbList",
      "@id": "https://hdtech.com/blog/co-managed-it-law-firms-orange-county/#breadcrumbs",
      "itemListElement": [
        { "@type": "ListItem", "position": 1, "name": "Home", "item": "https://hdtech.com" },
        { "@type": "ListItem", "position": 2, "name": "Blog", "item": "https://hdtech.com/blog" },
        { "@type": "ListItem", "position": 3, "name": "Co-Managed IT for Law Firms", "item": "https://hdtech.com/blog/co-managed-it-law-firms-orange-county" }
      ]
    },
    {
      "@type": "BlogPosting",
      "@id": "https://hdtech.com/blog/co-managed-it-law-firms-orange-county/#article",
      "mainEntityOfPage": { "@id": "https://hdtech.com/blog/co-managed-it-law-firms-orange-county/#webpage" },
      "headline": "Co-Managed IT for Orange County Law Firms",
      "description": "Orange County law firms with internal IT staff are stretched thin on cybersecurity and ABA compliance. Co-managed IT extends your team without replacing it.",
      "image": {
        "@type": "ImageObject",
        "url": "https://hdtech.com/images/blog/co-managed-it-law-firms-orange-county.webp",
        "name": "Co-Managed IT for Orange County"
      }
    }
  ]
}
co-managed IT for law firms
Tom Hermstad, President of HD Tech

Tom Hermstad

President & CMO, HD Tech

Tom Hermstad has led HD Tech since 1995, building one of Southern California's most trusted managed IT and cybersecurity firms. He specializes in helping Orange County businesses eliminate IT headaches and stay ahead of evolving cyber threats — in plain English.

Need Help With Your IT?

Get a free, no-pressure IT health check. We'll show you exactly where you're exposed — in plain English.