ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Backup Testing for Law Firms: How to Prove Your Restores Work

How to test law firm backups on a schedule: file-level and full-system restore drills, what to record, and common failures that testing exposes.

3 min readBy Counsel Cyber Team

Ask most firm administrators whether their backups are working, and the answer is a confident yes based on a green checkmark in a dashboard. A green checkmark tells you the job ran. It does not tell you the data can be restored, that the restored files open, or that you can recover quickly enough to keep the firm functioning.

Backup testing closes that gap. It is dull work, which is exactly why it is so often skipped, and why firms learn about problems on the worst possible day.

Why backups fail quietly

Backups can fail in ways that never produce an alert:

  • A new server, database or shared folder was never added to the backup scope.
  • Backup credentials expired or were changed.
  • Data was copied but the database was in a state that cannot be recovered.
  • The retention window overwrote the good copy before anyone noticed corruption.
  • The restore process depends on a system that is itself down during a disaster, such as a domain controller or a password stored only on the file server.
  • The backup was encrypted by ransomware along with the production data.

Only a restore test will reveal these.

Three levels of testing

Level 1: Routine file restores (monthly)

Pick a handful of files and folders at random, including something from a practice management or document management export, and restore them to a temporary location. Open them. Confirm they are complete and readable. Record the date, who performed the test, and how long it took.

This catches everyday issues and is easy to schedule. A monthly check by your IT provider, with a short written report to the administrator, is a reasonable standard.

Level 2: Application and mailbox restores (quarterly)

Restore a mailbox item from Microsoft 365 backup, a database from the accounting or timekeeping system, and a folder from the document management platform. These tests verify that more complex data can be recovered in a usable state.

Include a restore from the offsite or immutable copy, not only the local one. That proves the copy you would rely on after a ransomware attack is real.

Level 3: Full recovery drill (annually)

Simulate a serious failure. Choose a critical system, such as the primary file server or the practice management database, and restore it into an isolated environment. Time the effort. Check that applications start and users could actually work.

A full drill also tests your documentation. Can someone other than your usual IT contact perform the steps? Are passwords and keys available when the network is down?

What to record

Keep a simple log for each test:

  1. Date and tester.
  2. What was restored and from which backup copy.
  3. How long it took.
  4. Whether the data was complete and usable.
  5. Problems found and who is fixing them.
  6. Date of the next test.

This record is useful beyond IT. Cyber insurance applications and client security questionnaires often ask whether backups are tested and how often. A log lets you answer truthfully and specifically.

Define success before you test

Decide in advance what "good" means. Two terms help:

  • Recovery point objective (RPO): how much recent data the firm can afford to lose. If you back up nightly, a failure at the end of the day could lose a full day of work.
  • Recovery time objective (RTO): how long the firm can be without a given system before the impact becomes unacceptable.

During a drill, compare actual results to these goals. If your attorneys expect to be working the same day after an incident and the drill shows a three-day recovery, you have found an important gap while there is still time to address it.

Common findings and fixes

  • Missing systems: add them to scope and re-test.
  • Slow restores from the cloud: consider a local copy for fast recovery plus an offsite copy for disasters.
  • Credentials in one place: store emergency credentials and recovery keys offline, with a copy in a secure location such as a safe.
  • Untested vendors: ask cloud providers for their own recovery options and test your own export.
  • No owner: assign a named person to review results and sign off.

Make it routine

Put test dates on the calendar for the year. Treat failures as useful news rather than blame. Share a summary with the managing partner each quarter.

Counsel Cyber builds regular restore testing into our backup service for law firms and provides written results you can show clients and insurers. If you are not certain when your firm last restored anything, that is a good place to begin, and we can help you set up the first test.