A managing partner told us last year that his firm’s technology decision had been on the agenda for nineteen months. Not rejected — deferred. Every quarter it moved to the next meeting, because something more pressing always arrived first.
He wasn’t being negligent. He was doing what every busy practice does: prioritising the visible over the important. The trial next month outranks the server that’s been fine so far. The client matter outranks the backup nobody has tested.
What made the conversation interesting was that he’d finally sat down and worked out what those nineteen months had actually cost. Not in risk, which is abstract, but in hours already spent and revenue already gone.
The number surprised him considerably.
Delay has a price, and it’s measurable
Most firms think about IT decisions in terms of what they’d spend. Far fewer calculate what they’re spending already by not deciding.
That second number is harder to see because it doesn’t arrive as an invoice. It accumulates in fifteen-minute increments across a hundred small frustrations, and it never appears as a line item anywhere in the accounts.
Consider a firm of eight — five attorneys, three staff. Suppose each loses an average of twenty-five minutes daily to technology friction: hunting for the current version of a document, waiting on a large file to open, a remote connection that dropped, an email search that returned nothing useful, a workstation that needed restarting.
Twenty-five minutes doesn’t feel like a problem. Nobody logs it. But across eight people it’s more than three hours a day, and across a working year it approaches 800 hours.
Even valuing only the attorney portion at conservative rates, the annual figure lands in six figures for many firms this size. Against that, the entire cost of properly managed technology is a fraction — and the delay costs the full amount every single year it continues.
Where the hours actually disappear
Ask attorneys where time goes and they rarely mention IT. Ask them what frustrates them and the answers are more revealing.
Finding documents is almost always the largest single loss, and the most invisible. In firms without a properly configured document management system — or with one nobody was ever trained on — locating the current version of something becomes a recurring small tax on every matter. It’s rarely dramatic. It’s constant.
Version confusion costs more than the time it consumes. Two people working from separate copies, reconciled manually under deadline pressure, occasionally produces a set where Tuesday’s revision vanished because Wednesday’s copy came from Monday. Most of the time this gets caught in review. The exceptions are what keep managing partners awake.
Remote access that doesn’t hold turns productive hours into frustrating ones. Attorneys work from court, from home, from client offices, and access that’s slow or unreliable makes those hours worth substantially less than they should be.
Waiting for support is the loss firms most often underestimate. The technical problem might take ten minutes to resolve. If support means leaving a message and waiting for a callback, the cost isn’t the ten minutes — it’s the four hours it stayed unresolved.
The risks that compound while you wait
Time is the visible cost. The risks accumulating alongside it are less obvious but move in one direction.
Patch compliance drifts downward every month nobody manages it. Software vulnerabilities that vendors fixed remain exploitable on unpatched machines, and the pool of known-exploitable weaknesses grows continuously.
Access accumulates. Staff change roles, seasonal help comes and goes, and permissions that were temporary become permanent because removing them was never anyone’s task. Years later, people can reach files they have no reason to see, and former employees sometimes still have working credentials.
Backups degrade quietly. A backup job that has been failing since March reports the same green log it always did if nobody is checking. The gap between what you think you can recover and what you actually can widens invisibly.
And the insurance position shifts underneath you. Cyber coverage now typically requires evidence of specific controls — MFA, monitored backups, endpoint protection. A policy renewed on an application completed from assumption rather than verification is a problem waiting for a claim.
What a single incident costs a firm this size
Firms sometimes weigh prevention against the ransom figure they’ve read about. That’s the wrong comparison, because the ransom is rarely the largest number.
Start with the operational loss. A week without access to matter files, calendars, and email doesn’t produce a week of lost billing — it produces a week of salaries paid for work that couldn’t happen, followed by overtime clearing a backlog, followed by whatever the delay did to court deadlines that didn’t move.
Then the professional dimension. Rules of conduct require competence in safeguarding client information, and the review following an incident asks what the firm had done, not merely what happened. A firm demonstrating enforced MFA, tested backups, and monitored systems occupies a materially different position from one demonstrating good intentions.
Notification obligations follow, and California’s are among the more demanding in the country. Depending on the matters involved, disclosure may extend beyond affected individuals. The notification becomes a public record — an awkward document to have circulating in a market where firms refer work to each other.
Client attrition arrives last and quietly. Nobody announces they’re leaving because of a breach. They simply send the next matter elsewhere, and the effect shows up in revenue months later, disconnected from its cause.
Three postponements that cost the most
Not every deferred decision carries equal weight. These three account for the majority of what firms lose.
Postponing Multi-Factor Authentication
The cheapest control available, and the one that prevents the largest share of incidents. Stolen credentials remain the most common way attackers get into a firm, and requiring a second factor stops the overwhelming majority of those attempts.
Firms delay it because it seems disruptive, or because partners object. Both objections have largely dissolved — modern implementations add seconds to a login. Meanwhile every month without it is a month where a single reused password is the only thing standing between an attacker and every client file.
The exemptions matter more than the delay. A firm with MFA on everyone except two partners has protected the accounts attackers weren’t targeting.
Postponing a backup test
Not implementing backups — testing them. Almost every firm has something running.
The test is what converts an assumption into a fact, and it’s routinely deferred because it takes effort and produces no visible benefit. Then a firm discovers during an actual incident that the job had been completing successfully for years while the data inside was unusable, or that the backup drive sitting in the server room was encrypted alongside everything else because ransomware specifically hunts connected storage.
Our backup and disaster recovery service handles verification automatically and tests recovery quarterly with a written result — which also happens to be exactly what an insurer or institutional client asks to see.
Postponing the move from reactive to proactive support
This is the structural one, and the hardest to see clearly because break-fix support genuinely works for what it covers.
Something fails, you call, someone fixes it, you pay. Simple and comprehensible. What the model cannot do — by design, not by neglect — is watch a network during the weeks an attacker typically spends inside one before triggering anything. There’s nobody confirming last night’s backup would restore, tracking patch compliance, or noticing a control that drifted out of effectiveness in the spring.
You cannot call someone about a problem you don’t know exists. That’s the entire gap, and it’s why our managed IT services and cybersecurity services operate as continuous monitoring rather than scheduled repair.
The question clients started asking
There’s a further cost to delay that didn’t exist five years ago.
Corporate and institutional clients now send security questionnaires to outside counsel, and some require evidence before engagement. A firm that can’t complete one satisfactorily doesn’t get told it lost on security — it simply isn’t shortlisted, and never learns why.
This changes the calculation meaningfully. Technology investment used to be purely defensive. It’s now partly commercial, because being able to state plainly that MFA is enforced firm-wide, that backups were tested on a documented date, and that systems are monitored continuously is increasingly a condition of competing for certain work.
Firms that addressed this early are winning engagements against firms that deferred. Neither side is aware of it happening.
Working out your own number
The exercise takes about twenty minutes and produces something more persuasive than any argument.
Ask three or four people to note, over a single week, roughly how much time they lose to technology — waiting, searching, restarting, calling for help. Don’t formalise it. A rough daily figure is enough.
Multiply the weekly average across your headcount, then across a working year. Apply whatever rate is appropriate. Then compare that annual figure against what properly managed technology would cost.
For most firms of this size, the comparison ends the discussion. The recurring loss substantially exceeds the fixed cost, and it repeats every year the decision waits.
That’s before assigning any value to the incident that doesn’t happen, which is the part nobody can calculate but everybody understands.
Advice from someone who’s seen the aftermath
If your firm has been carrying a deferred technology decision, the honest professional advice is this: don’t try to solve everything at once, but stop deferring the three items above.
Enforce MFA on every account this month. Get a genuine restore test performed and find out what the result is. Then have a straightforward conversation about whether reactive support still fits a practice holding what yours holds.
Those three steps close the majority of the exposure, and none of them requires a large project or significant disruption. The remaining improvements can follow at whatever pace suits the firm.
What doesn’t work is waiting for a quiet quarter. Practices like yours don’t have quiet quarters — that’s precisely why the decision has waited nineteen months.
Speak with an expert at RJ PRO Tech Group. We’ll review what your El Dorado Hills firm currently has, tell you which gaps genuinely matter and which don’t, and give you a written answer to the three questions above. Call 209-920-4077, or request an assessment and we’ll arrange a time that works around your calendar.