Who Controls Your Firm's Technology?
Category: Technology Ownership & Business Continuity
Resource Type: Article
Last Updated: August 2026
Reading Time: 7-9 minutes
By Eric Helms, GSEC
Founder, Helmlight Consulting LLC
Category: Technology Ownership & Business Continuity
Resource Type: Article
Last Updated: August 2026
Reading Time: 7-9 minutes
By Eric Helms, GSEC
Founder, Helmlight Consulting LLC
A law firm can use a technology system every day without actually controlling it.
The firm's website may have been created under a web designer's account. Its domain name may be registered by someone else. A former employee may still be the administrator for an important service. A consultant may be the only person who knows how to access a critical system.
Everything may work perfectly well - until that person leaves, becomes unavailable, or the firm needs to make a change.
That is when a technology inconvenience can become a business problem.
For a solo attorney or small law firm, technology ownership does not mean doing everything yourself. It means making sure the firm retains enough control to manage, recover, and transfer the systems and information it depends on.
In this article you'll learn:
What technology control actually means
Which systems your firm should review
Why relying on one employee or vendor can create problems
What administrator and recovery access your firm should maintain
How to identify technology the firm may not fully control
Practical steps for improving technology ownership
Consider your firm's email.
You may send and receive email every day, but could someone at the firm:
Add or remove a user?
Reset an account if someone is locked out?
Change security settings?
Review who has administrator access?
Update billing information?
Recover the account if the primary administrator becomes unavailable?
If the answer is no, the firm may use the system without truly controlling it.
The same question applies to many other parts of your technology.
Technology control usually involves more than knowing a password. It means knowing who owns the account, who has administrative authority, how access can be recovered, and whether the firm can transfer the service if necessary.
A small law firm may depend on more systems than it realizes.
Some of the most important ones to review include:
Domain name registration
DNS and domain-management accounts
Microsoft 365 or Google Workspace
Website hosting and website administration
Case-management software
Document-storage systems
Backup services
Accounting and billing systems
Electronic-signature services
Client portals
Internet and telephone services
Security products
Password-management systems
Other cloud services containing firm or client information
You may not need to manage these systems personally.
But the firm should know who does.
Your domain name may be used for your website, email addresses, and other online services.
If it is registered under a web developer's, employee's, or outside consultant's account, the firm may have difficulty managing or transferring it later.
Ideally, the firm should know:
Which company is the domain registrar
Which account owns the domain
Which email address receives renewal and recovery notices
Who can log in to manage it
When it renews
Who controls its DNS settings
A vendor can still help administer the domain.
The important distinction is that the vendor should be helping manage an asset the firm controls - not owning the asset on the firm's behalf.
Administrator accounts can make significant changes to technology systems.
Depending on the service, an administrator may be able to:
Create or delete users
Reset passwords
Change security settings
Access or manage data
Change billing information
Connect other applications
Disable services
Every firm should know who holds those privileges.
That does not mean everyone should be an administrator. In fact, limiting administrative access is usually preferable.
But the firm should avoid situations where a single outside person - or an employee who could leave - is the only administrator for a critical service.
There should be a reliable way for the firm to regain control.
One common problem occurs when a business service is created using someone's individual account.
For example:
A website is created using an employee's personal Google account.
A cloud service is registered using a consultant's email address.
A software subscription is tied to the office manager's personal account.
Recovery codes are stored only on one person's computer.
Billing notices go to someone who no longer works at the firm.
These arrangements may seem harmless when they are created.
The weakness becomes apparent when that person is no longer available.
Whenever possible, important business systems should be tied to firm-controlled accounts and contact information rather than someone's personal identity.
Having the correct username and password is only part of account control.
Modern services may also depend on:
Multi-factor authentication
Passkeys
Authenticator applications
Recovery email addresses
Recovery phone numbers
Security keys
Backup or recovery codes
Ask what would happen if the person who normally signs in were unavailable.
Could someone authorized by the firm still recover the account?
This does not mean sharing individual passwords or authentication methods among employees.
It means configuring important business systems so that access does not depend entirely on one person's device, email address, or phone number.
Billing information is another useful thing to check.
Ask:
Who receives the invoice?
Whose credit card is being charged?
Who receives renewal notices?
Who can change the subscription?
What happens if that person's card is cancelled?
A service may technically belong to the firm while all of its administrative and billing information points to someone else.
That can make a simple renewal or account change unexpectedly difficult.
Using an IT consultant, managed service provider, web designer, or other technology vendor is not a problem.
Good technology providers often need administrative access to do their work.
The important question is whether the firm could continue operating if that relationship ended.
For critical systems, the firm should know:
What the provider manages
Which accounts the provider can access
Whether the firm also has appropriate administrative authority
Where important account and service information is documented
How access could be transferred to another provider
A good vendor relationship should make the firm's technology easier to manage - not make the firm permanently dependent on that vendor.
Control is not only about accounts.
It is also about information.
Consider what would happen if the firm decided to stop using a particular service.
Could you retrieve your information?
Could you export client or matter data?
Could you obtain copies of documents?
Do you know where the firm's primary files are stored?
Do you know how they are backed up?
A system can be convenient today while still creating problems later if the firm does not understand how its information can be retrieved.
Choose one important system your firm depends on.
Then ask:
If the person who normally manages this system were unavailable tomorrow, could the firm still take control of it?
Try it with:
Could you administer Microsoft 365 or Google Workspace?
Domain
Could you renew it or change its DNS settings?
Website
Could you give a new web designer access?
Case-management system
Could you add or remove users and retrieve the firm's data?
File storage
Could another authorized person access the firm's documents?
Backup
Could someone actually restore the data?
If the answer depends on finding a particular employee, consultant, phone, or personal email account, you may have found a technology-ownership problem.
You do not need an elaborate database to begin.
For each important technology service, document:
Name of the service
What the firm uses it for
Primary account or firm contact
Who has administrative access
Billing contact
Recovery method
Renewal date, if applicable
Vendor or support contact
Where additional access information is securely maintained
Do not put passwords into an unsecured spreadsheet or document.
The goal is to document enough information that an authorized person can determine what the system is, who controls it, and how the firm can manage or recover it.
Technology ownership should also be part of employee and vendor transitions.
When someone leaves the firm, review:
Their user accounts
Administrator privileges
Shared services
Recovery information
Devices
Software subscriptions
Firm data they managed
Vendor relationships for which they were the primary contact
Simply disabling someone's email account may not address every system they controlled.
The same principle applies when changing technology vendors.
Before the relationship ends, make sure the firm has the access and information it will need afterward.
Your firm should be able to identify:
✓ The major technology systems it depends on
✓ Who owns or administers each system
✓ Which accounts have administrative privileges
✓ How critical accounts can be recovered
✓ Where billing and renewal notices are sent
✓ Which vendors have access to firm systems
✓ Where important firm data is stored
✓ How that data can be retrieved or restored
✓ What needs to change when an employee or vendor leaves
This does not require the attorney to become the firm's IT administrator.
It requires the firm to understand what it owns and make sure it can maintain control of it.
Technology ownership is easy to ignore while everything is working.
The problems usually appear when something changes.
An employee leaves.
A vendor relationship ends.
A phone is lost.
A credit card expires.
An administrator becomes unavailable.
The firm needs access to a system nobody else knows how to manage.
That is the wrong time to discover that the firm's technology depends on an account, device, or person it does not control.
Your firm does not need to personally manage every technology system it uses.
But it should always be able to answer three questions:
What do we depend on?
Who controls it?
Could we take control if we needed to?
If those answers are clear, your firm is in a much stronger position.
Who Should Own Your Law Firm's Domain Name? — Learn why the firm's domain should remain under firm control.
What to Check Before an Employee Leaves — Review accounts, access, data, and technology responsibilities before someone departs.
Technology Ownership Checklist — Use a practical checklist to identify who controls your firm's important technology systems.
Where Should a Small Law Firm Store Its Documents? — Learn why your firm should have a clearly defined location for its official documents.
Small law firms do not need to personally manage every technology system they use.
They do need to know what those systems are, who controls them, and how the firm could regain access if something changed.
A little documentation and planning now can prevent a much larger problem later if an employee leaves, a vendor relationship ends, or an important account becomes inaccessible.
The goal is not to eliminate outside help.
It is to make sure the firm remains in control of the technology and information it depends on.
Technology should support your law practice—not distract from it.
We believe the best technology decisions begin with understanding. By sharing practical knowledge and real-world guidance, we hope to help solo attorneys and small law firms build a stronger technology foundation with confidence.
If you're ready to apply these ideas to your firm, explore our services or tell us what’s going on. We’re happy to discuss your firm’s technology goals and help determine the right next step.
Follow us for IT guidance and security updates for small law firms
© 2026 Helmlight Consulting LLC. All rights reserved.