Most law firms dish up technology by implementing and supporting systems in-house. They have little choice but to deal with upgrades and replacements because vendors continually displace "obsolete" older versions of applications and hardware. These upgrades are usually costly and disruptive. Certainly, some changes are warranted but much of the turmoil absorbs IT staff resources and creates little value for a firm. The advent of cloud computing and managed services is providing firms a viable alternative.
CLOUD AND MANAGED SERVICES DEFINED
In general, there are two types of cloud services. The first, often called Software as a Service, involves an application—or set of like applications—run by a third-party vendor and accessed through the Internet via a web browser. The second approach involves data that is stored or shared via a third party’s infrastructure and accessed via the Internet. Examples of this type of service (security issues aside) would be Dropbox or Apple's iCloud.
Let's focus on SaaS. With these services, firm personnel access an application(s) via the Web to perform their day-to-day work. Their work product and data is stored on the vendor’s systems. Several vendors have set up integrated application sets (suites) that include practice management, document management, time entry, and billing for law firms.
As attractive as cloud services seem, however, firm lawyers may be uncomfortable about having the firm's data completely managed and stored by an outside vendor. The use of managed services is one way to address this issue.
With managed services, the firm maintains ownership of server and data center equipment, but contracts to have the day-to-day operations and upgrades managed by a vendor. It is possible to set up these services so they mimic a cloud service—thus the term “private cloud.” There are many shades within the spectrum of managed services, with vendors owning more or less of the infrastructure and applications.
The advantages of cloud-based services are many. They include:
• Access from anywhere there are Internet connections. • Reduced need to manage IT infrastructure (servers and data storage) within your firm. • Application and hardware upgrades handled by the vendor. • Predictable (fixed) pricing—usually based on the number of users. • Reduced capital spending. • Business continuity built-in. • Good vendors provide 24/7 support.
Managed services have similar advantages. However, the level of benefits from reduced capital spending and avoidance of software and hardware upgrade hassles will depend on how much of the IT infrastructure and associated applications continues to be maintained in-house by the firm.
The other major advantage of both approaches is the potential impact on IT staff utilization. With in-house systems, as much as 75 percent of staff time is dedicated to maintenance. By moving to cloud or manage services this maintenance component can be dramatically reduced. Of course, IT staff will need to take on a bigger role managing the vendors. The change nevertheless should free up significant IT staff time for value-added services that help the firm make better use of technology, particularly in pursuit of superior client service.
CAVEATS
These services are not a magic bullet. No contract with a cloud or managed services vendor should be entered into without the proper due diligence. Most importantly, firms need to make sure the vendor is financially sound and has a good track record, that a sufficient level of technology infrastructure and back-up is in place, and that firm data will be properly secured. It is important to “kick the tires” by testing the service thoroughly before making a commitment. Understanding how to get firm data back when the service is no longer needed is also critical.
A firm’s telecommunications network is what connects it to these services. To get best performance, a firm will need a robust network infrastructure that provides a high-speed telecommunications network connecting all your office-based systems with the cloud vendor and the Internet.
Using cloud-based applications may mean that firms will have to give up some ability to customize software and hardware for particular firm and lawyer needs. For example, the ability to customize interfaces or financial reports may be limited, or lawyers may have to live with restrictions on how quickly old documents can be retrieved. At some firms, cultural preferences will have to be considered and carefully managed.
MAKING THE TRANSITION
Transitioning from in-house-based systems to a cloud or managed services platform will require thorough planning to get the most benefit and minimize disruption. This change will not only affect how people in the firm access systems and information, but may require people to learn new systems and new ways of working. Also, significant role changes may be required for the in-house IT staff. Anticipating these changes and their impact will be an important to achieving the benefits of the systems transition and a successful project.The following steps are recommended:
1. Identify the applications and systems that will be transitioned. Determine if the target will be managed services or a move to cloud applications. 2. Clearly document your firm’s requirements for performance, availability, security, and functionality for the systems and applications that will be moved. 3. Identify and choose the service vendor or vendor(s) based on the requirements. This is typically done via a "request for proposal" process. 4. Develop a detailed transition plan for each application. Determine the human impact and develop appropriate change management, communications and training plans. 5. Run a pilot test with either a small group of people and/or a particular application. Adjust your plans based on the results of the test. Include a test of the vendor’s back-up and recovery processes. 6. Rollout to the firm.
Depending on the number of applications and the size of the firm, a transition could take from six to 18 months. Success with this type of project will depend on strong support from firm management and strong project management from the IT staff (or consultant if the skills do not exist in-house). The cost will also be highly dependent on firm size, geography and the applications and hardware involved.
Cloud and managed services hold great promise for law firms and other businesses. The potential for improving a firm’s access to technology while scaling back on the need for in-house technology infrastructure makes these service compelling. Done correctly, firms will benefit tremendously by spending more time focused on their core business of delivering outstanding service and results to clients rather than distracting technology issues far removed from that core.
Philip Wisoff is a principal at MTC Services, based in the New York Metro Area.
Contracting for cloud computing services is not new—since 1964 businesses have relied on remote computing. Of course, 50 years ago the services were on mainframes and over telephone lines; today the cloud services are on servers across the Internet.
All kinds of businesses depend on cloud services, but departments often sign the cloud agreements without bothering to consult the organization's IT department, much less management. As a result, management may not realize the importance of the cloud contracts until the contract ends and the customer cannot get its data, or get the data in the format it expects.
To learn more about what to expect, I asked John Ansbach, general counsel of GDT (General Datatech)
Peter Vogel: Cloud services offer service level agreements, but this is somewhat confusing because the cloud contract is an agreement between the customer and provider. Can you explain what SLA means?
John Ansbach: Service level agreements are specific provisions set out in a master cloud contract between a cloud service provider and a customer that detail what will be provided, and the levels or metrics the CSP is required to attain when providing those services.
For instance, a commonly requested (but expensive) requirement is for a cloud availability level of 99.9 percent from 7 a.m to 7 p.m. during regular business days over any 30 day period. Some service level examples include turn-around time (which relates to how quickly your CSP responds to an issue), and recovery time objective (most commonly used with disaster recovery and data storage).
RTO relates to how quickly your CSP can get your environment back up and running. SLAs within a cloud contract will typically set out exactly what is required of the CSP, as well as what happens in the event the metrics are not met.
PV: Can customers pay a premium to get more frequent data backup or any higher levels of service?
JA: They certainly can, but the question is, “Should they?” Not every customer needs the most frequent data backup or the absolute highest level of any cloud specific performance metric.
When customers want cloud data backup, what they are really looking for is to minimize risk and provide for disaster recovery. To make that happen, vendors typically will work with clients to analyze their specific needs related to data security, cost competitiveness, and performance availability.
It is important for customers to know that options for fast and frequent backup certainly exist. Some CSPs offer low-cost storage—but with restricted access that can result in unexpected overall operational costs or even higher restore times. The most important thing to remember when considering whether to pay a premium for any higher level of cloud service is to work with someone who understands your specific needs and business, and can properly structure a contract and SLA that meets those needs within a cost-effective environment.
PV: If a customer migrates to another cloud provider, can the customer use the same software applications?
JA: At the risk of giving the typical attorney answer, the most accurate answer here is, “It depends.” Migration from one cloud to another, or from on-premise to a cloud, can be technically complex. If you are an attorney representing a client, it is essential to catalog or inventory what applications your client needs to ensure transfer over when they are selecting the new cloud provider. You will also need to get commitments up front from that the new provider and the migration service (if different) to be sure they can and will deliver the promised migration, including those apps (software applications). This is an important conversation that must take place early on in the process. Typically, it will be set out with specificity in a "Statement of Work" to provide your client with a measure of comfort. This also will help lawyers simplify the process for their clients.
PV: What kind of data security is available? Particularly for privacy requirements, such as the Health Insurance Portability and Accountability Act of 1996, and the Health Information Technology for Economic and Clinical Health Act, for medical customers?
JA: Generally speaking, there are four tiers of data center design that allow for varying levels and degree of security. Tier 1 provides clients with site infrastructure that guarantees 99.671 percent availability and, among other things, includes components of non-redundant capacity.
On the other end of the spectrum, Tier 4 security provides everything that Tiers 1 to 3 provides to a client, as well as fault-tolerant site infrastructure with electrical power storage and distribution facilities that guarantee 99.995 percent availability and cooling equipment that is independently dual powered.
Because of HIPAA and HITECH, medical cloud customers generally are looking for the best, most cost-effective data security they can obtain, while also ensuring compliance. Currently there is no HIPAA and HITECH compliance "certification" available, but there is plenty of guidance available to enable and document compliance by following the principles of the mandates.
Lawyers should suggest that their clients look for vendors that meet their data security needs and are compliant with HIPPA and HITECH requirements. They should offer established administrative procedures, physical safeguards and technical safeguards that follow the HIPAA Final Security rule. This will help your clients meet the requirements to keep everyone's protected health information safe.
Cloud contract provisions should require the CSP to meet or exceed applicable regulatory requirements such as HIPAA and HITECH, and should further specifically require the CSP to indemnify the customer for failures to meet SLAs.
PV: Is attorney client privilege at risk on the cloud?
JA: It can be, but so far courts have not adopted a standard waiving the privilege for cloud-based communications, for example, cloud-based email services such as Gmail and Yahoo! Mail. Rather, where courts have examined the issue they seem to apply the same analysis as they would elsewhere asking whether or not the client could reasonably expect the communication to remain private.
There typically is no expectation of privacy and hence any privilege would be waived if the communications take place in the cloud using social media such as Facebook, or LinkedIn. However, the privilege may well remain intact if a Gmail private email account based in the cloud was password protected and maintained in a manner otherwise consistent with applicable policies (such as an employer’s email policy).
PV: Any advice about what team or personnel should collaborate on cloud contracts?
JA: Attorneys and technical folks must work closely together so that everyone is on the same page about what the client wants and expects from the CSP, especially in terms of service and support. Explore whether the providers' legal team works closely with technical specialists—including the product architects who specialize in software as a Service—and other hardware and system people to ensure that contracts are not only legally sound, but also technically correct and accurate. Clients should be sure that their lawyers understand and are comfortable with cloud technology, technology experts, and representatives of finance and management.
Peter Vogel is a partner at Gardere Wynne Sewell, based in Dallas. Email: pvogel@gardere.com.John Ansbach is general counsel of General Datatech, based in Dallas, Texas. Email: jansbach@gdt.com.