ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Backup Basics for Law Firms: Three Copies, Two Media, One Offsite

The 3-2-1 backup rule is a simple framework for protecting client files. Here is how a law firm can apply it, and the gaps that quietly defeat backup plans.

3 min readBy Counsel Cyber Team

Most law firms believe they have backups. Fewer can say where the copies live, who can delete them, or how long a full restore would take on a Monday morning with a trial deadline looming. The 3-2-1 rule is the oldest and simplest framework for answering those questions, and it still holds up well against modern ransomware.

The rule says to keep three copies of your data, on two different types of storage, with one copy stored offsite. For a law firm, "your data" means far more than the document management system. It includes email, billing data, practice-management records, scanned files, and the shared drives where staff keep the things nobody remembered to file properly.

What 3-2-1 Means in a Law Firm

Three copies

The first copy is your live production data. The second and third are backups. Having only one backup is a single point of failure, because a corrupt backup discovered during a crisis leaves you with nothing.

Two types of storage

If both backups sit on the same kind of device, one failure mode can take out both. A common pairing is a local appliance for fast restores plus a cloud repository for resilience. The goal is that a hardware failure, a bad firmware update, or a single vendor outage cannot destroy every copy at once.

One copy offsite

A fire, flood, tornado or break-in at your office should not take your backups with it. This matters especially for firms in the Texas, Oklahoma, Arkansas, Louisiana and Kansas region, where severe weather is a routine business risk. Offsite also means separate from your network credentials, which leads to the most important modern addition.

The Modern Upgrade: Immutable and Isolated Copies

Ransomware operators know that backups are your way out, so they hunt for them. If an attacker gains administrator access, they may try to delete or encrypt backup repositories before launching the main attack. CISA's ransomware guidance has long recommended keeping offline, encrypted backups and testing restoration regularly.

Many practitioners now describe this as 3-2-1-1-0: one additional copy that is offline or immutable (it cannot be changed or deleted for a set retention period), and zero errors after restore testing. Ask your provider two direct questions:

  • Can an administrator account in our environment delete our backups?
  • Is at least one copy protected by immutability or kept offline?

Common Gaps We See in Law Firm Backups

  • Microsoft 365 is assumed to be backed up. Microsoft provides availability of the service, but retention and recovery of your mailbox, OneDrive and SharePoint content are a shared responsibility. Confirm what your plan actually restores and for how long.
  • Cloud practice-management data is overlooked. If your matter and billing data live in a cloud platform, find out what the vendor backs up and whether you can export your own copy.
  • Laptops and local folders are excluded. Attorneys often save drafts to a desktop. If it is not in a protected location, it is not in a backup.
  • Nobody has ever tested a restore. A backup job reporting success only proves that data was written, not that it can be recovered.
  • Backup credentials are shared with the domain. If the same admin login controls both, one phished password compromises everything.

A Simple Checklist to Review This Quarter

  1. List every system holding client or firm data, including cloud applications.
  2. Mark which have a backup, where it is stored, and who controls access.
  3. Confirm at least one copy is offsite and at least one is immutable or offline.
  4. Define how long you could be down. This is your recovery time objective.
  5. Define how much recent work you could afford to lose. This is your recovery point objective.
  6. Schedule a restore test of a real matter folder and a real mailbox, and document the result.
  7. Make sure backup administration uses multi-factor authentication and separate credentials.

Why This Matters for Professional Duties

The ABA's Model Rule 1.1, Comment 8, discusses keeping abreast of the benefits and risks of relevant technology, and Rule 1.6(c) addresses reasonable efforts to prevent unauthorized access to client information. Losing client files to an avoidable failure raises obvious client-service concerns. Confirm the specifics with your state bar, but the practical point is simple: a documented, tested backup plan is the easiest way to show you took reasonable care.

Where Counsel Cyber Fits

Counsel Cyber builds and monitors backup and disaster recovery for law firms, including restore testing you can show to a client or insurer. If you would like a plain-English review of where your firm's data lives and whether it can actually be recovered, we are glad to walk through it with you.