Break-fix IT bills a San Antonio law firm when something fails and watches nothing in between. That’s the whole problem. The duties that ethics guidance now puts on lawyers, like monitoring for intrusions, supervising vendors, and knowing what was taken, all happen between incidents. On the Texas Attorney General’s breach list, law firms took a median 58 days to find their breaches. For what the service itself covers, start with our guide to managed IT for San Antonio law firms.
San Antonio law firms are leaving break-fix IT because the duties that matter most, monitoring for intrusions, supervising the IT vendor, and proving what happened, fall between incidents, and break-fix only shows up after something breaks.
Managed IT covers those gaps for a flat monthly fee. It costs more on paper. Whether it costs more in practice depends on firm size, and the numbers below cut both ways. For the full per-user bands by firm profile, see our breakdown of law firm IT cost in San Antonio.
Hourly repair against a monthly fee is an old argument. Mostly settled, too. Our break-fix vs managed IT comparison for San Antonio businesses already covers the general version, insurance forms and all. This one is narrower. It’s about law firms, and about obligations a dental office or a roofing company simply doesn’t carry.
Start with the local shape of the profession. Bexar County had 1,072 law offices in 2025 employing 7,180 people, according to the Bureau of Labor Statistics QCEW count for offices of lawyers. About 6.7 people per office. Big enough to hold years of privileged files. Too small, almost always, to employ anyone whose job is IT. That’s the size where break-fix hangs on longest, and it’s also the size where it quietly stops working.
The pattern in these handoffs isn’t subtle. Nobody leaves break-fix because the technician was rude. They leave because a rule, a client, or a breach asked a question the technician couldn’t answer. That’s the shift.
What Does Break-Fix Actually Mean for a Law Firm?
Break-fix is an IT arrangement where a law firm pays a technician by the hour or by the ticket, only when something fails. Nothing gets monitored, patched on a schedule, or restore-tested between calls. Managed IT replaces that with a flat monthly agreement that makes the provider responsible for keeping systems watched, patched, backed up, and recoverable.
For a long time that trade looked reasonable. A 4-lawyer practice a few blocks from the Bexar County Courthouse, one server in a closet, a technician who came when the copier jammed. Fine. The baseline the profession still runs on is thinner than most partners assume, though. In the ABA’s 2023 Cybersecurity TechReport, only 19% of firms with 2 to 9 lawyers said they had an incident response plan, 27% of those firms had ever had an outside security assessment, and 32% of all respondents still backed up to an external hard drive.
An external drive. In a firm holding other people’s secrets.
Why Does Break-Fix Fail Law Firms Faster Than Other Businesses?
A law firm’s obligations keep running when nothing is broken. ABA ethics guidance and the Texas rules expect lawyers to monitor their systems, supervise the people and vendors who touch client data, and act promptly on a breach. Break-fix isn’t present for any of those moments. Not one.
Most businesses can shrug off a slow IT vendor. Law firms can’t. A law firm answers to a disciplinary rulebook, a breach statute, and a filing clock, and every one of them assumes somebody was paying attention before the call came in. Here’s how the duties line up against what an hourly arrangement actually delivers.
| Duty | Where it comes from | What it asks for between incidents | What break-fix supplies |
|---|---|---|---|
| Watch for intrusions | ABA Formal Opinion 483 (2018) | Reasonable efforts to monitor systems, data sources, and outside vendors | Nothing until someone notices a problem |
| Understand the tools | Texas Rule 1.01, comment 8 (2019) | Keep up with the benefits and risks of the technology the firm uses | Advice only when a call is placed |
| Supervise nonlawyers | Texas Rule 5.03 | Reasonable efforts to keep the conduct of assistants in line with the lawyer’s obligations | Work you never see, done on a schedule you don’t set |
| Protect confidences in the cloud | Texas Rule 1.05 and Ethics Opinion 680 (2018) | Stay alert to breaches and take reasonable precautions with cloud systems | No review of settings after the first install |
| Tell clients and the state | ABA Formal Opinion 483 and Tex. Bus. and Com. Code 521.053 | Notify affected clients, notify Texans within 60 days, and notify the Attorney General within 30 days at 250 or more | No logs showing what was reached |
| File on time | Tex. R. Civ. P. 21(f)(5) and (6) | E-file before midnight on the deadline day | Emergency rates, if anyone answers |
The top row is the one I’d underline. In Formal Opinion 483, the ABA ethics committee concluded that lawyers must make reasonable efforts to monitor the technology and office resources connected to the internet, external data sources, and external vendors. Without that duty, the committee wrote, a lawyer’s recognition of a breach “could be relegated to happenstance.”
Happenstance. An ethics committee described the break-fix model in one word.
To be fair to the opinion, it isn’t strict liability. A breach that slips past reasonable monitoring isn’t automatically an ethics violation, because skilled attackers hide well. The exposure comes when the firm made no reasonable effort to detect an intrusion and that gap is why the breach happened. That’s a meetable standard. Just not by waiting for the phone to ring. The Texas ethics opinions that sit beside it are mapped control by control in our guide to cybersecurity compliance for San Antonio law firms.
ABA opinions don’t bind Texas lawyers on their own. They’re persuasive, and Texas has its own versions of these duties. Three matter most here. The Supreme Court of Texas added the benefits and risks of relevant technology to the competence comment in Rule 1.01 on February 26, 2019. Texas Rule 5.03 requires a supervising lawyer to make reasonable efforts to keep the conduct of nonlawyer assistants compatible with the lawyer’s own obligations, and Opinion 483 applies the matching ABA rule to outside technology vendors. And the Professional Ethics Committee’s Opinion 680 approved cloud storage for client files in 2018 on the condition that lawyers stay alert to breaches and take reasonable precautions.
Supervision is where break-fix leaks worst. A break-fix invoice that says 2.5 hours, server issue resolved, tells a managing partner nothing about which accounts were touched, which settings changed, or whether the admin password still sits in the technician’s phone. Would you accept that report from a new associate? You can’t supervise work you never see. Nobody can.

How Long Do Law Firm Breaches in Texas Go Unnoticed?
About 2 months at the median. Among the law-firm filings on the Texas Attorney General’s public breach list that report both a start date and a discovery date, the median gap was 58 days, and 12 of 26 ran 90 days or longer.
We built that number ourselves. On September 24, 2026 we pulled every listing on the Attorney General’s Data Security Breach Reports page, 633 filings published between September 22, 2025 and September 21, 2026. Then we read every entity name and kept the law firms, dropping the CPA firms and medical practices that share the PLLC suffix. 33 filings from 31 firms remained. Small sample, clear split.
| What the Texas filings show | Law firms, Sept. 2025 to Sept. 2026 |
|---|---|
| Law-firm breach filings | 33, from 31 firms (5.2% of all 633 filings) |
| Texans affected | 269,248 |
| Filings by Texas-based firms | 12 |
| San Antonio law offices on the list | 3, affecting 5,597 Texans |
| Median days from breach start to discovery | 58 (26 filings reported both dates) |
| Found 90 or more days after the breach began | 12 of 26 |
| Found within 7 days | 9 of 26 |
| Exposed Social Security numbers | 33 of 33 |
| Exposed medical information | 24 of 33 |
The data splits in two. One group found out within days. The other found out a season later, sometimes more than a year later. The list doesn’t say how each intrusion worked, and discovery dates are self-reported, so some firms probably entered the day they confirmed which files were involved rather than the first alert. The split still holds.
Fast detection is possible. 9 firms managed it.
The medical row surprised me more than the timing did. It shouldn’t have. 24 of the 33 filings exposed medical information, which tracks with personal injury, workers’ compensation, and family law practices that hold medical records by the box. Every single filing exposed Social Security numbers. And this isn’t a small-firm story or a big-firm story, because national firms with thousands of attorneys sit on the same list as solo offices. It’s a detection story.
We aren’t naming the 3 San Antonio offices. They reported as the law requires, and that’s the part of the process that worked. What matters for everyone else is the clock. Texas gives a business 60 days after it determines a breach occurred to notify affected residents, and the Attorney General must hear within 30 days when 250 or more Texans are involved, a deadline SB 768 shortened in 2023. Both clocks start when the firm determines a breach happened. Monitoring decides when that is.
One more wrinkle catches attorneys off guard. Opinion 483 counts an event as a data breach when client information is compromised or when the lawyer’s ability to perform legal services is significantly impaired. So ransomware that locks every file without stealing one still counts. Read that twice. The firm then has to work out whether material client information was accessed, and it can’t do that without logs a break-fix arrangement never kept.
What Does an E-Filing Deadline Have to Do With Your IT Contract?
Everything, after 5 p.m. Texas civil documents are timely if e-filed before midnight on the deadline day unless a set hour applies, and the rules guarantee an extension after a technical failure only when the missed deadline was one the rules themselves imposed.
Read Texas Rule of Civil Procedure 21(f)(6) closely. If a document is late because of a technical failure or a system outage, the filer may seek appropriate relief from the court. If the missed deadline was imposed by the rules, a reasonable extension must be given. Must, not may. A deadline from a scheduling order or a statute sits outside that guarantee. There, you’re asking.
Picture a Tuesday night before a response is due in a Bexar County district court. The brief is done. Around 9 that night the VPN into the document system stops connecting, or the multi-factor prompt goes to a phone that’s dead in a car on Loop 410, or a Microsoft 365 license lapsed that afternoon and nobody saw the warning. Small failures. Under break-fix, the fix is a voicemail and a callback tomorrow, at the $125 to $250 hourly range for San Antonio break-fix work, with after-hours calls at the top of that band. Under a managed agreement, it’s a ticket someone is already on. Huge difference, that late.
That’s why the after-hours clause is the first thing I’d read in any agreement a firm signs. Ours is built around 24/7 IT support in San Antonio, and our help desk’s average first response is 5.06 minutes. The same logic holds for appellate work at the Fourth Court of Appeals and for federal filings in the Western District of Texas, which run on their own rules and their own systems. Different courts. Same midnight.

Why Are San Antonio Firms Feeling This Now?
Because Bexar County law offices are getting bigger while their IT arrangements stay the same. Law-office employment rose 3.7% in 2025 while the number of offices barely moved, so the average office grew from 6.5 to 6.7 people. Small shift. Real consequences.
In raw numbers, BLS counted 256 more law-office jobs in Bexar County in 2025 and only 5 more offices. Firms are adding paralegals, associates, and intake staff inside the same four walls. Each hire is another laptop, another mailbox, another set of credentials to shut off the day that person leaves. Break-fix counts none of it.
San Antonio also runs smaller than the other big Texas markets. In the same BLS data, Harris County’s law offices averaged 8.6 people in 2025 and Dallas County’s averaged 9.3, against Bexar’s 6.7. Smaller offices, longer runway. More local firms sat comfortably in the zone where an hourly contractor felt adequate, which is why a wave of them now hits the ceiling at roughly the same time.
Downtime got more expensive, too. BLS puts the average law-office job in Bexar County at $113,260 in 2025, or $2,178 a week. That’s about $54 an hour per person, so a 7-person office pays roughly $381 an hour in wages while its systems are down, before a single billable hour gets written off. The billable side is bigger, and our look at managed IT for Texas professional services firms works through what an outage costs a billable-hour practice.
Then the paperwork shows up. The ABA survey found 41% of firms with 10 to 49 lawyers had been asked by a client for their security requirements, against 15% of firms with 2 to 9. Grow past 10 lawyers and the questionnaires start arriving. Break-fix can’t answer them, because it never wrote anything down.
Texas added a reason of its own in 2025. SB 2610 lets a business with fewer than 250 employees use a written cybersecurity program as a defense against exemplary damages after a breach, as long as the program existed before the breach and matched the firm’s size. It’s a narrow shield. Actual damages still apply. But our Texas SB 2610 safe harbor guide shows the program has to be real and documented ahead of time, and an hourly contractor doesn’t produce one.
When Does Break-Fix Still Make Sense for a Law Practice?
Bias disclosed, we sell managed IT. Break-fix is still a defensible choice for a narrow set of practices, and pretending otherwise wouldn’t help anyone reading this.
- A solo attorney working entirely in cloud software such as Clio and Microsoft 365, with no server or network storage box in the office.
- Nobody joining or leaving. No turnover means almost no account cleanup.
- No medical records on file, and no client funds moving by wire.
- Multi-factor authentication turned on everywhere, the security tools included in your Microsoft 365 plan enabled, and someone who actually reads the alerts. That last part is the one that slips.
Add a second person, a closet server, or a personal injury caseload, and the math shifts quickly. Honestly? It’s not the rate. It’s that the duties in the first table stop being theoretical once more than one person holds the keys.
What Should Change First When a Law Firm Switches?
The first weeks of a switch should close the gaps the rules care about, in roughly this order.
- Count every account. Microsoft 365, the practice management system, the document system, eFileTexas, and the bank portal for the trust account. Former associates and paralegals come out that week.
- Multi-factor authentication on everything that holds client data or moves money.
- Endpoint detection with monitored response around the clock, replacing antivirus nobody reads.
- A real restore test. If the backup is an external drive, it stops being the plan.
- Who calls clients, who calls the carrier, and who files with the Attorney General inside 30 days? A written incident response plan answers that before anyone needs it.
- A written vendor list, since Rule 5.03 supervision starts with knowing who has access.
None of that’s exotic. It’s just continuous. When we moved a multi-location personal injury firm off its previous provider, the day-one problems were offline network storage, slow remote access to case files, and onboarding and offboarding that couldn’t keep pace with staff turnover. The cutover happened without interrupting active cases, and the personal injury law firm case study covers how.
If you already have a contractor you trust, you don’t have to fire them to get here. That’s a different arrangement, and it’s covered in the questions below.

How Does Uprite Handle Law Firm IT in San Antonio?
Uprite Services is a Texas managed IT and cybersecurity provider with a San Antonio office at 11831 Radium Street. We run monitoring, patching, backup testing, and incident response for small and mid-sized organizations, law practices included, for a flat monthly fee, so the duties in this post have someone assigned to them. If you’d rather compare providers first, we ranked the IT providers that serve San Antonio law firms and published every score.
The numbers we publish are the ones we’re held to. A 5.06-minute average first response. 2,227 users supported. 98.4% client satisfaction, and a 120-day satisfaction guarantee. For firms, that means around-the-clock monitoring through our managed security services in San Antonio, support for the legal software you already run, and records you can hand a client, a carrier, or the Attorney General. Written down. Our Texas legal and professional services hub covers the broader practice, and the full offering sits under managed IT services in San Antonio. If you want the legal-specific version, start with legal IT support in San Antonio.
Not sure which of these duties your current setup actually covers? We’ll assess your firm’s monitoring, backups, accounts, and filing-night coverage against the rules above, then hand you the fixes in order of risk.
Get an AssessmentWhat San Antonio Attorneys Ask Before Dropping Break-Fix
Does the State Bar of Texas require a law firm to hire a managed IT provider?
No rule names a type of provider. Texas Rule 1.01 expects lawyers to understand the risks of the technology they use, Rule 5.03 expects supervision of the nonlawyers they rely on, and ABA Formal Opinion 483, persuasive in Texas though not binding, expects reasonable monitoring. A firm can meet those duties in-house, with a managed provider, or with a mix of both.
Is a 3-lawyer San Antonio firm too small for managed IT?
Probably not, once you count the staff. The average Bexar County law office had 6.7 people in 2025, and headcount drives the workload far more than the number of attorneys does. A solo practice running fully in the cloud can get by on break-fix. A 3-lawyer firm with 4 staff, a server, and a trust account usually can’t, because the account changes, patching, and backup testing never stop. Staff count decides it.
What happens if our systems fail right before an e-filing deadline?
Document the failure and ask the court for relief. Under Texas Rule of Civil Procedure 21(f)(6), a filer who misses a deadline because of a technical failure or system outage may seek relief, and gets a guaranteed reasonable extension only when the rules imposed the deadline. Court-ordered and statutory deadlines carry no such promise, which is why after-hours support matters on filing nights.
Does ransomware count as a breach if no client data was stolen?
It can. ABA Formal Opinion 483 treats an event as a data breach when client information is compromised or when the lawyer’s ability to perform legal services is significantly impaired. No client notice is needed if files were never out of reach for a material time and nothing was accessed. Anything beyond that needs a real investigation, and the Texas breach statute adds its own test for sensitive personal information.
Can we keep the IT contractor we already know?
Yes, in a co-managed setup. Your contractor keeps the work they know best, like phones or the practice management system, while a managed provider takes monitoring, patching, and after-hours response. Our page on co-managed IT in San Antonio explains how the split usually works.
How does managed IT cost compare with our break-fix bills?
$125 to $200 per user per month is the typical San Antonio range for a full managed agreement, against roughly $125 to $250 an hour for break-fix work. Where you break even depends on how many hours you actually buy in a normal year and what one bad week would cost. Software licensing sits on top of either model. Our San Antonio managed IT cost breakdown walks through the per-user math.









