| Generic MSP | PK Tech | |
|---|---|---|
| IT Fundamentals | ||
| Day-to-day IT support during business hours | ||
| Procurement and installation of business-class workstations, servers, network equipment, and cloud solutions | ||
| 24/7/365 IT support availability | ||
| Audited annually by a third party for security controls (SOC 2 Type II) | ||
| Properly insured for comprehensive coverage of breaches, extortion, and mistakes | ||
| 15+ years of Microsoft partnership and expertise | ||
| Generic IT Support vs. PK Tech | ||
| Experts in helping law firms comply with required regulations, such as ABA Model Rules of Professional Conduct and state bar cybersecurity guidelines | ||
| Responsive IT support when court deadlines leave no room for downtime | ||
| Successful track record of hosting and managing legal practice management software in Microsoft Cloud | ||
| Works well with internal IT managers as their backup, escalation point, and security advisor | ||
| 15+ years supporting confidentiality and uptime-critical professional firms | ||
Why PK Tech for my Legal Services firms?
Protect client information, Reduce downtime, Support your legal team
PK Tech helps law firms maintain secure, efficient, and reliable technology environments.
A Message to Legal Services Firms
We know Legal Services firms.
IT Support Built for Law Firms -- We have supported law firms since our founding. We understand the operational demands of legal practice, the sensitivity of client data, and what it takes to keep attorneys and staff productive. When you evaluate us, you will find a provider with a documented security posture, defined processes, and a track record in your industry.
A Vendor Your Firm Can Trust and Verify -- Our SOC 2 Type II attestation, issued by an independent third-party auditor, gives your firm documentation to satisfy ABA Rule 1.6 obligations around reasonable efforts to protect client data. Most IT providers cannot offer that.
Security Aligned to Your Compliance Obligations -- The type of client data your firm handles determines which regulations apply to you. Firms working with healthcare clients may fall under HIPAA. Those handling consumer financial data may fall under the FTC Safeguards Rule. California-based clients can bring CCPA into scope. We assess your practice and align your IT environment to the regulations that actually apply to your firm, not a one-size-fits-all checklist.
Microsoft 365 Configured for Legal Work -- Document access controls, secure external sharing, Teams governance, and identity management set up for how attorneys and staff actually work, not how a generic business does.
A Structured Transition When Switching Providers -- Changing IT vendors is a risk point for any firm. We follow a defined onboarding process to take over from your outgoing provider without disrupting operations or losing access to critical systems.
Client confidentiality means nothing if your systems aren’t secure.
Partner with PK Tech.
![]()
Jordan Hetrick
Founder & CEO
Why Legal Services Firms Choose PK Tech
Secure Document Access
Protect legal files and client communications.
Email & Phishing Protection
Reduce risk from targeted legal industry attacks.
Secure Remote Work
Support attorneys securely from anywhere.
Microsoft 365 Security
Advanced controls for collaboration and communication.
Reliable Support
Fast response times when attorneys need help immediately.
Business Continuity
Minimize disruption and protect critical legal operations.
| Rightworks (formally Right Networks) | Thomson Reuters | PK Tech | |
|---|---|---|---|
| IT Fundamentals | |||
| Day-to-day IT support during business hours | |||
| Procurement and installation of business-class workstations, servers, network equipment, and cloud solutions | ❓ |
||
| 24x7x365 IT support availability | ❓ |
||
| Audited annually by a third party for security controls (SOC 2 Type II) | ❓ |
||
| Properly insured for comprehensive coverage of breaches, extortion, and mistakes | ❓ |
||
| 15+ years of Microsoft partnership and expertise | ❓ |
||
| CPA Industry Specific | |||
| Experts in helping CPA firms comply required regulations, such as the FTC Safeguards Rule, IRS Publication 4557 | ❓ |
||
| Familiarity and additional support offered during tax season deadlines | ❓ |
||
| Successful track record of hosting and managing tax applications in Microsoft Cloud | ❓ |
||
| Works well with internal IT managers as their backup, escalation point, and security advisor | ❓ |
||
| 15+ years of experience supporting CPA firms | ❓ |
||
Ready to speak with an expert?
| On your own | Generic MSP | PK Tech | |
|---|---|---|---|
| FTC Safeguards Rule | |||
| Qualified Individual to implement and supervise your company’s information security program The Qualified Individual can be an employee of your company or can work for an affiliate or service provider. The person doesn’t need a particular degree or title. What matters is real-world know‑how suited to your circumstances. The Qualified Individual selected by a small business may have a background different from someone running a large corporation’s complex system. If your company brings in a service provider to implement and supervise your program, the buck still stops with you. It’s your company’s responsibility to designate a senior employee to supervise that person. If the Qualified Individual works for an affiliate or service provider, that affiliate or service provider also must maintain an information security program that protects your business. |
Unknown |
||
| Conduct a risk assessment You can’t formulate an effective information security program until you know what information you have and where it’s stored. After completing that inventory, conduct an assessment to determine foreseeable risks and threats – internal and external – to the security, confidentiality, and integrity of customer information. Among other things, your risk assessment must be written and must include criteria for evaluating those risks and threats. Think through how customer information could be disclosed without authorization, misused, altered, or destroyed. The risks to information constantly morph and mutate, so the Safeguards Rule requires you to conduct periodic reassessments in light of changes to your operations or the emergence of new threats. |
|||
| Required safeguards | |||
| Implement and periodically review access controls Determine who has access to customer information and reconsider on a regular basis whether they still have a legitimate business need for it. |
🤝 |
||
| Know what you have and where you have it. A fundamental step to effective security is understanding your company’s information ecosystem. Conduct a periodic inventory of data, noting where it’s collected, stored, or transmitted. Keep an accurate list of all systems, devices, platforms, and personnel. Design your safeguards to respond with resilience. |
|||
| Encrypt customer information on your system and when it’s in transit. If it’s not feasible to use encryption, secure it by using effective alternative controls approved by the Qualified Individual who supervises your information security program. |
|||
| Assess your apps. If your company develops its own apps to store, access, or transmit customer information – or if you use third-party apps for those purposes – implement procedures for evaluating their security. |
|||
| Implement multi-factor authentication for anyone accessing customer information on your system For multi-factor authentication, the Rule requires at least two of these authentication factors: a knowledge factor (for example, a password); a possession factor (for example, a token), and an inherence factor (for example, biometric characteristics). The only exception would be if your Qualified Individual has approved in writing the use of another equivalent form of secure access controls. |
|||
| Dispose of customer information securely. Securely dispose of customer information no later than two years after your most recent use of it to serve the customer. The only exceptions: if you have a legitimate business need or legal requirement to hold on to it or if targeted disposal isn’t feasible because of the way the information is maintained. |
|||
| Anticipate and evaluate changes to your information system or network. Changes to an information system or network can undermine existing security measures. For example, if your company adds a new server, has that created a new security risk? Because your systems and networks change to accommodate new business processes, your safeguards can’t be static. The Safeguards Rule requires financial institutions to build change management into their information security program. |
|||
| Maintain a log of authorized users’ activity and keep an eye out for unauthorized access. Implement procedures and controls to monitor when authorized users are accessing customer information on your system and to detect unauthorized access. |
|||
| Regularly monitor and test the effectiveness of your safeguards. Test your procedures for detecting actual and attempted attacks. For information systems, testing can be accomplished through continuous monitoring of your system. If you don't implement that, you must conduct annual penetration testing, as well as vulnerability assessments, including system-wide scans every six months designed to test for publicly-known security vulnerabilities. In addition, test whenever there are material changes to your operations or business arrangements and whenever there are circumstances you know or have reason to know may have a material impact on your information security program. |
|||
| Train your staff. A financial institution’s information security program is only as effective as its least vigilant staff member. That said, employees trained to spot risks can multiply the program’s impact. Provide your people with security awareness training and schedule regular refreshers. Insist on specialized training for employees, affiliates, or service providers with hands-on responsibility for carrying out your information security program and verify that they’re keeping their ear to the ground for the latest word on emerging threats and countermeasures. |
|||
| Monitor your service providers. Select service providers with the skills and experience to maintain appropriate safeguards. Your contracts must spell out your security expectations, build in ways to monitor your service provider’s work, and provide for periodic reassessments of their suitability for the job. |
|||
| Keep your information security program current. The only constant in information security is change – changes to your operations, changes based on what you learn during risk assessments, changes due to emerging threats, changes in personnel, and changes necessitated by other circumstances you know or have reason to know may have a material impact on your information security program. The best programs are flexible enough to accommodate periodic modifications. |
|||
| Create a written incident response plan. Every business needs a “What if?” response and recovery plan in place in case it experiences what the Rule calls a security event – an episode resulting in unauthorized access to or misuse of information stored on your system or maintained in physical form. Section 314.4(h) of the Safeguards Rule specifies what your response plan must cover: The goals of your plan; The internal processes your company will activate in response to a security event; Clear roles, responsibilities, and levels of decision-making authority; Communications and information sharing both inside and outside your company; A process to fix any identified weaknesses in your systems and controls; Procedures for documenting and reporting security events and your company’s response; and A post mortem of what happened and a revision of your incident response plan and information security program based on what you learned. |
|||
| Require your Qualified Individual to report to your Board of Directors. Your Qualified Individual must report in writing regularly – and at least annually – to your Board of Directors or governing body. If your company doesn’t have a Board or its equivalent, the report must go to a senior officer responsible for your information security program. What should the report address? First, it must include an overall assessment of your company’s compliance with its information security program. In addition, it must cover specific topics related to the program – for example, risk assessment, risk management and control decisions, service provider arrangements, test results, security events and how management responded, and recommendations for changes in the information security program. |
|||
-1.png?width=1000&height=705&name=Untitled%20design%20(1)-1.png)
We know Legal Services Firms
-
What did the ABA actually require when it updated its ethics rules for technology?
In 2012, the ABA amended two Model Rules that matter here. Comment 8 to Rule 1.1 made clear lawyers have a duty to be competent not only in the law, but in the technology used to practice it, and 40 states, plus DC and Puerto Rico, have since adopted that language into their own rules of professional conduct. The same year, Rule 1.6(c) added a separate, harder requirement: a lawyer "shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client." Then in 2018, ABA Formal Opinion 483 confirmed that when a breach involving client data happens, lawyers have a duty to notify affected clients and take reasonable steps to respond, and named the specific rules that duty runs through (competence, confidentiality, communication, and supervision of staff and vendors). None of this is aspirational language. It's what your bar complaint would cite if your firm got breached and handled it badly.
-
How do we know so much about law firm compliance?
We built PK Tech inside a CPA firm in 2009, and that's where the instinct comes from: protecting information a client handed over in confidence, under a professional obligation, with real consequences if you get it wrong.
Law firms operate under the same core demand, just under Model Rule 1.6 instead of a tax code. Confidentiality, competence, and accountability for what you do with sensitive client data, that's the discipline we were built on, and it's exactly what law firms are one of our core professional service verticals. We prove it the same way for every regulated client we work with: an independent SOC 2 Type II audit, every year, voluntarily, because a firm bound by privilege deserves more than just our word.You can read more about how PK Tech got its start here.
-
What IT regulations and rules apply to a law firm?
There's no single "HIPAA for lawyers," which is part of the problem; it's easy to assume you're covered by nothing. You're not. Model Rule 1.1 requires technology competence. Model Rule 1.6(c) requires reasonable efforts to prevent unauthorized access to client information. Model Rule 1.4 requires you to communicate with clients, including after a breach. Rules 5.1 and 5.3 make partners responsible for the technology and staff (and vendors) they supervise. Layer state bar ethics opinions on top of that, plus your state's general data breach notification statute, and you've got a real compliance stack even without an industry-specific federal law forcing it.
-
What official guidance actually exists for law firm cybersecurity?
ABA Formal Opinion 477R, from 2017, sets the standard for securing client communications sent digitally, and Formal Opinion 483, from 2018, builds on it with specific guidance for what to do when a breach actually happens. The ABA also publishes a Cybersecurity Handbook that several of these opinions reference directly for what "reasonable" security actually looks like in practice. On top of the ABA's guidance, individual state bars have issued their own opinions, California and New York both have influential ones on cloud storage and encrypted communication, so it's worth checking whether your state bar has weighed in beyond the model rules.
-
Can I just use a data security policy template and call it good?
No. We've watched this fail the same way across every regulated client we work with: a generic policy reads fine on paper and falls apart the moment it matters, because it was written to fill out a format, not to match your firm's case management system, your vendors, or where your client files really live. Rule 1.6(c)'s "reasonable efforts" standard is fact-specific by design, weighing the sensitivity of the information against the cost and difficulty of the safeguards required to protect it. A template can't do that math for your firm. It's a place to start, not the work itself.