ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Backup Mistakes Law Firms Make and How to Fix Each One

Seven common backup mistakes that leave law firms exposed to ransomware and outages, from untested restores to backups an attacker can delete, with fixes.

3 min readBy Counsel Cyber Team

Almost every law firm says it has backups. Far fewer can say how long a full restore would take, whether the backups would survive a ransomware attack, or when someone last tested them. The gap between having backups and being able to recover is where firms get hurt.

Here are seven common mistakes we see in firm environments generally, with a fix for each.

1. Never testing a restore

A backup that has never been restored is a hope, not a control. Jobs can report success while capturing incomplete data, or while the data is corrupt.

Fix: Schedule restore tests at least quarterly. Restore a sample of files, a mailbox, and periodically an entire server or application into an isolated environment. Record how long it took and who did it.

2. Backups an attacker can reach

Modern ransomware operators often look for backup systems first. If your backup repository is a network share, or its credentials are the same as your domain administrator account, an intruder can encrypt or delete it along with everything else.

Fix: Keep at least one copy that is immutable or offline, meaning it cannot be changed or deleted for a set retention period even by an administrator. Use separate credentials with multifactor authentication for the backup platform.

3. Assuming Microsoft 365 is backed up

Microsoft operates the service and provides resilience, but retention and recovery of your mail, OneDrive and SharePoint content are governed by settings and a shared responsibility model. Accidental deletion, malicious deletion by a compromised account, and sync errors can all lead to permanent loss after retention windows pass.

Fix: Review your Microsoft 365 retention settings and consider a third-party backup for mail, files and Teams data, particularly if your documents live in SharePoint.

4. Forgetting the practice-management data

Firms back up the file server and forget the cloud applications. Your case management, billing and document systems hold your most important records. Cloud providers protect their infrastructure, but export, recovery and retention options differ by vendor.

Fix: Inventory every system that holds client or financial data. For each, document where the data lives, how it is backed up, and how you would get it back. Ask each vendor about recovery options in writing.

5. No recovery objectives

Without defined targets, nobody knows whether a two-day outage is acceptable. Two terms help: recovery time objective, the maximum tolerable downtime, and recovery point objective, the maximum tolerable data loss.

Fix: Ask partners a simple question for each system: if this were down, how long could we operate, and how much recent work could we afford to redo? Design backup frequency and recovery tooling around those answers. A court deadline does not move because a server is down.

6. One copy, one location

A single backup on a device in the same office dies with the office in a fire, flood, or theft. The familiar 3-2-1 guideline is a useful baseline: three copies of data, on two kinds of media, with one copy offsite. Add an immutable copy and it is stronger still.

Fix: Confirm where each copy physically and logically lives. Make sure one is geographically separate, which matters in regions where storms can disrupt entire towns.

7. No written recovery plan

When systems fail, people improvise. Who calls the vendor? Who tells clients? Where do passwords live if your password manager is offline? Technology competence under Model Rule 1.1, Comment 8, and communication duties under Rule 1.4 both come into play when client data is unavailable, so check with your state bar on how that applies to you.

Fix: Write a short disaster recovery plan: contact lists, system priority order, vendor numbers, decision authority, and a client communication template. Print a copy and store it somewhere not dependent on your network. Rehearse it once a year with a tabletop exercise.

A simple starting checklist

  1. List every system holding client or financial data
  2. Define recovery targets with partners
  3. Confirm an immutable or offline copy exists
  4. Separate backup credentials and enforce MFA
  5. Run and document a restore test
  6. Write and print the recovery plan

Getting help

Counsel Cyber designs and tests backup and recovery for law firms, including Microsoft 365 and practice-management data. If you are unsure whether your backups would hold up in an incident, we can review your setup and run a restore test with you.