Your IT Company Keeps You Running. That Is Not the Same as Keeping You Compliant.
It is a reasonable question, and firms ask it early: we already pay an IT company — isn’t this their job?
Sometimes part of it is. Often the most important part is not, and nobody has told you which.
The distinction is not about competence. Good IT providers are good at what they are hired to do. The distinction is about what each role is measured on, and what each one leaves behind.
Two different jobs
An IT provider is measured on whether things work. Is the network up, is email flowing, did the ticket get closed, did the backup job run last night. That work is real and your firm needs it.
Compliance is measured on something else entirely: whether you can produce written proof, on demand, to someone who does not know you and is not inclined to take your word for it.
A regulator, an underwriter, a bar or board investigator, or opposing counsel does not ask whether your systems are working. They ask you to show them:
- the written information security program that applies to your firm
- who is responsible for it, by name
- the risk assessment behind it, and when it was last done
- evidence that the controls you claim were actually in place on the date in question
- what you did when something went wrong, and when
Those are documents. They are not settings, and they are not a healthy dashboard.
Where the gap usually sits
Here is the part that surprises people. The gap is usually not the tools.
Many IT providers have already deployed the things a regulator expects to see working — multi-factor authentication, endpoint protection, patching, backups, email filtering. The controls frequently exist.
What is missing is the layer above them:
Nothing is written for your firm. The controls are configured in a console. There is no document that says this is our program, this is who owns it, this is why we chose these controls, this is when we review them.
Nothing maps to the rule that binds you. Your provider secured a network. Nobody wrote down which requirement of the FTC Safeguards Rule, IRS Publication 4557, SEC Regulation S-P, or the Texas rules reaching your practice each control is there to satisfy. Without that mapping, you have security you cannot point to.
Nothing proves what was true last March. Evidence is time-stamped. A screenshot taken today shows today. If a claim or an exam looks back eighteen months, current settings are not an answer.
Nobody is named. Nearly every rule that reaches your firm expects a person accountable for the program. That is a role your firm holds, and it cannot be outsourced by having a vendor.
Read your agreement, it is usually explicit
The cleanest way to settle the question is to look at what you actually bought.
Most managed services agreements describe systems: monitoring, maintenance, support hours, response targets, the equipment and software covered. Read the scope of work and see whether any of the following appear by name:
- a written information security program or WISP
- a documented risk assessment, on a stated cadence
- an incident response plan, tested
- evidence retained for a defined period, in a form you can hand over
- a named individual responsible for your compliance program
- responsibility for regulatory or examination response
If those are absent, they are not being delivered, and nothing has gone wrong. You were sold IT services and you are receiving IT services.
Some providers do offer this work, and offer it well. If yours does, it will be in writing and you should be able to ask for last year’s risk assessment and receive it. That is the test. Ask.
Why the answer matters more than it used to
For years the gap was invisible, because nobody asked. That has changed on three fronts at once.
Carriers ask now. Cyber applications no longer ask whether you have security. They ask which controls, on which surfaces, and whether the plan has been tested — and the answers become part of the contract.
Clients ask now. Corporate clients and lenders send vendor security questionnaires before engaging a firm or approving it to receive funds.
Regulators ask now. The obligations reaching Texas legal and financial firms are written in terms of documented programs, not good intentions.
In all three cases the question is directed at your firm. Your IT provider is not the one who signs, and the obligation does not transfer to them by contract.
See the eleven obligations that reach Texas legal and financial firms →
What we do, and what we do not
We are not your IT department, and we will not take that over.
We are a compliance and cybersecurity practice. Compliance is the only thing we do.
We start with a Compliance Readiness Review. We gather what your firm actually has, then review it against what each rule reaching your practice requires you to be able to produce. You get a written report: where you stand, where the gaps are, and what closing each one takes.
From there we create the plan. If you have IT — internal or outside — we guide them through the changes and they do the hands-on work. Your IT keeps doing their job. If you have no IT, we do the hands-on work ourselves, inside a scoped and defined remediation phase that ends.
Then we build the documentation, and keep it current, so the next questionnaire or exam notice is a matter of retrieving what already exists.
Common questions
Is compliance included in a managed IT services agreement?
Usually not. Most agreements cover systems — monitoring, maintenance, support and response times. Written programs, documented risk assessments, retained evidence and a named accountable person are generally outside that scope. Read the scope of work; if those items are not named, they are not being delivered.
My IT company set up MFA and backups. Isn’t that compliance?
Those are controls, and they matter. Compliance also requires that the control be written down, tied to the requirement it satisfies, owned by a named person, and evidenced for the period in question. Firms commonly have the controls and none of the record.
Can I outsource responsibility for my firm’s security program?
You can outsource the work. The obligation stays with the firm. Rules reaching Texas legal and financial firms expect an accountable person inside the practice, and a regulator’s questions are directed at you, not your vendor.
Do you replace our IT provider?
No. Where a firm has IT, internal or outside, we guide them through the changes and they perform the hands-on work. We review, plan, and build the documentation.
How do I tell whether my IT provider is already doing this?
Ask for last year’s risk assessment and your written information security program. If they exist, you will have them shortly. If the answer is that the systems are secure, that is an answer about controls, not documentation.