Almost every firm has backups. Far fewer have ever proven they can restore from them under pressure. The gap between those two statements is where firms lose days, and sometimes clients, after a ransomware attack, a failed server, or an accidental deletion.
A green checkmark in a backup dashboard tells you a job ran. It does not tell you the data is complete, uncorrupted, readable, or recoverable in a time your practice can tolerate. Testing is how you find out.
Two numbers to settle first
Before testing, agree on two targets with the partners.
- Recovery time objective (RTO): how long the firm can be without a system before the damage becomes serious. For a litigation group near a filing deadline, that may be hours.
- Recovery point objective (RPO): how much recent work the firm can afford to lose. If backups run nightly, you could lose up to a day of work.
Write both down for each critical system: email, document management, practice management, billing, and file shares. Your test then has a pass or fail standard.
Types of backup tests
File-level restore (monthly)
Pick a handful of files at random, including a large one, an old one, and one from a different department, and restore them to a separate location. Open them. Confirm they are readable and complete.
Application restore (quarterly)
Restore a full database or mailbox to a test environment and confirm the application works with it. For cloud tools like Microsoft 365, ask whether your backup covers mailboxes, SharePoint, and OneDrive, and test restoring an individual user's mail.
Full-system recovery (annually)
Simulate losing a server or a whole site. Rebuild from backup in an isolated environment and time it. This is the only test that reveals dependencies, such as a license server nobody remembered or a password stored only on the machine that died.
A simple test script
- Choose the system and the restore point, such as last Tuesday at 11 p.m.
- Start a timer.
- Restore to an isolated location, never over production.
- Verify contents: file counts, open sample documents, run a query.
- Stop the timer and compare against the RTO.
- Record who tested, when, what was restored, how long it took, and any problems.
- Fix the problems and schedule a retest.
What commonly goes wrong
- Backups that exclude a drive or database added after the original setup
- Retention that is too short to reach back past a slow-burning problem
- Backups stored on the same network, so ransomware encrypts them too
- Backup credentials that share the same admin account an attacker has stolen
- Restores that take far longer than anyone assumed because of bandwidth limits
- Cloud services assumed to be backed up by the vendor, when the vendor only guarantees availability
Protect the backups themselves
Attackers know to go after backups first. Use a design with at least one copy that is offline or immutable, meaning it cannot be changed or deleted for a set period, even by an administrator. Keep backup management behind multifactor authentication and separate from everyday admin accounts.
A common guideline is the 3-2-1 approach: three copies of data, on two kinds of media, with one stored off-site. Modern versions add that at least one copy should be immutable.
Document the results
Keep a simple log of each test. This record has several uses:
- Evidence for cyber insurance applications, which commonly ask about backup testing
- Answers to client security questionnaires
- Proof of reasonable diligence if a client or regulator asks later
- A trend line showing whether restore times are improving
Involve the people who depend on the data
Ask a paralegal or office manager to confirm the restored data is actually what they would need. IT can verify a file opens, but only the user knows whether the right matter folder, version, and email thread are there.
Budgeting for it
Testing costs staff time, not much software. A realistic annual schedule is twelve short file tests, four application tests, and one full recovery drill. Compared with the cost of a week offline, it is small.
A concluding thought
Counsel Cyber builds and tests backup and recovery plans for law firms in Texas, Arkansas, Louisiana, Oklahoma, and Kansas. If you cannot remember the last time you restored something, we can run a test with you and give you a written report you can share with partners and insurers.