ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

3-2-1 Backups for Law Firms: What the Rule Means Today

What the 3-2-1 backup rule means in practice for a law firm, including cloud platforms, immutability and the restore tests that most firms skip.

3 min readBy Counsel Cyber Team

Ask a managing partner whether the firm is backed up and the answer is usually yes. Ask when the last full restore was tested and the room gets quiet. A backup you have never restored is a hope, not a plan.

The 3-2-1 rule is the simplest framework for getting this right: keep three copies of your data, on two different types of storage, with one copy offsite. It has been a standard recommendation for years, and it still holds up, with a few modern adjustments that matter a lot for ransomware.

Breaking Down 3-2-1

Three copies

Your production data counts as the first copy. You then need two more. One backup is a single point of failure, because the backup itself can be corrupted, deleted or encrypted.

Two types of storage

Do not rely on one kind of medium or one vendor. A common pairing is a local backup appliance for fast restores plus a cloud copy for resilience. The point is that a single failure should not take out everything.

One offsite

A fire, flood, tornado or theft can destroy the office and every device in it. Offsite copies are what let a firm reopen quickly. For firms in Texas, Oklahoma, Arkansas, Louisiana and Kansas, severe weather alone is reason enough.

The Modern Update: Make One Copy Unchangeable

Ransomware operators know that backups are the thing standing between them and a payout, so they hunt for them. Modern guidance often extends the rule: at least one copy should be immutable (it cannot be altered or deleted for a set period) or air-gapped (not reachable from the network). Make sure backup administrator accounts use multi-factor authentication and are separate from everyday admin logins.

What Law Firms Often Forget to Back Up

  • Microsoft 365 data. Microsoft runs the platform, but under its shared responsibility model, protecting your data from deletion, corruption or a compromised account is largely your job. Mailboxes, OneDrive and SharePoint need their own backup.
  • Practice-management and document-management data. Confirm how Clio, NetDocuments, iManage or similar platforms handle retention and recovery, and whether you can export a full copy.
  • Laptops and local files. Lawyers save things in odd places. Decide whether endpoints are backed up or whether work must live in managed repositories.
  • Servers and line-of-business databases, including billing and accounting systems.
  • Configuration and credentials, such as firewall settings and identity-provider setup, which are painful to rebuild from memory.

Two Numbers to Define

Backups are only useful against targets you have set:

  • Recovery Point Objective (RPO): how much data loss is tolerable. If the answer is "no more than a few hours of work," nightly backups are not enough.
  • Recovery Time Objective (RTO): how long the firm can be down. A firm with a hearing on Monday has different needs than one with a flexible calendar.

Write both down, get partner sign-off, and design backups to meet them.

Test Restores on a Schedule

  1. Restore a few random files monthly and confirm they open.
  2. Restore a full mailbox or matter folder quarterly.
  3. Run a full-system restore at least annually, ideally into an isolated environment.
  4. Record the time it took and compare it with your RTO.
  5. Fix whatever failed and test again.

Confidentiality Matters Too

Backups contain the same privileged client information as production systems. Encrypt them in transit and at rest, control who can access them, and understand where your vendor stores data. Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized access to client information, and backups are part of that picture.

A Quick Monthly Habit

Put a recurring calendar item on the administrator's desk: open the backup report, confirm every job succeeded, and note any warnings. Five minutes a month catches silent failures long before they matter, and it creates a record you can show an insurer or client who asks how backups are monitored.

Next Step

Counsel Cyber designs and monitors backup and recovery for law firms, including restore testing. If you are not sure whether your current setup meets 3-2-1, we can review it with you and show you where the gaps are.