Large firms have binders full of continuity plans. Small firms often have nothing written, and a plan that exists only in one person's head fails exactly when that person is unavailable. A disaster recovery plan does not have to be elaborate. Five or six pages, kept current and actually read, will do more good than a hundred-page document nobody opens.
This template outline works for a firm of a few lawyers up to a few dozen. Adapt it to your systems and your risk.
What counts as a disaster
Think beyond ransomware. Plan for fire or flood at the office, a failed server, a lost internet connection, an extended power outage, loss of a key vendor, a compromised email account, or the sudden unavailability of a key person. Texas, Oklahoma, Arkansas, Louisiana and Kansas firms may face severe storms, tornadoes, ice or hurricanes, so include regional weather in your thinking.
Section 1: Purpose and activation
State what the plan is for and who may declare a disaster. Name a primary decision-maker, usually a managing partner, and a backup. Define what triggers activation, such as the loss of email for more than an hour or the discovery of encrypted files.
Section 2: Critical systems and priorities
List your systems in the order they must return:
- Internet, phones and email
- Calendar and deadline tracking
- Document and file access
- Practice-management and time entry
- Billing, accounting and trust accounting
- Everything else
For each system, note the owner, the vendor, where it is hosted and your recovery targets. How long can the firm be without it, and how much recent data can it afford to lose?
Section 3: Contacts
Keep a contact list that works without the network:
- Partners and staff, with personal mobile numbers
- IT provider and emergency lines
- Internet and phone carriers
- Software vendors' support numbers
- Cyber-insurance broker and carrier claim line
- Bank contacts
- Landlord or building manager
- Outside breach counsel, if you have one
Print a copy, store a copy in a secure cloud location outside the firm's systems and give copies to key people.
Section 4: Backup and recovery information
Record what is backed up, how often, where copies reside, who can access the backup console and where credentials are stored. Note the location of any recovery keys. Attach the most recent restore test results. Keep these details in a secure place that does not depend on the systems you are trying to recover.
Section 5: Working during an outage
Decide in advance how people will work if the office is unavailable.
- Remote work. Can staff work from home on managed devices? Are cloud tools reachable and protected by MFA?
- Alternate space. Is there a coworking arrangement or partner's office available?
- Phones. Can office numbers be forwarded to mobile phones?
- Paper. Keep a small kit with blank engagement letters, trust-account check stock procedures and a printed list of upcoming deadlines.
Section 6: Court deadlines and client duties
This is the piece firms forget most often. Maintain an exported or printed list of critical deadlines each week. Identify who will contact courts about extensions, and how to notify clients about delays. Model Rule 1.4 covers keeping clients reasonably informed, and the ABA has recognized in its discussion of disaster planning that lawyers should consider how to protect client files and continue to serve clients.
Section 7: Communications
Prepare simple message templates for staff, clients and vendors. Choose a channel that does not rely on firm email, such as a group text or a free messaging service designated in advance. Appoint a single spokesperson.
Section 8: Recovery steps
For each priority system, write a brief step list: who does what, in what order, and where the instructions are. Include vendor escalation steps and the decision points for switching to alternate arrangements.
Section 9: Testing and maintenance
- Review the plan twice a year and after major changes.
- Run a short tabletop exercise annually, walking partners through a scenario such as "the server room flooded overnight."
- Test restores quarterly.
- Update contacts whenever staff change.
Common mistakes
- Storing the plan only on the server that fails
- Never testing it
- Assuming the cloud vendor handles everything
- Skipping insurance details
- Forgetting that people, not just systems, need a plan
Getting started
Draft a one-page version this week, covering priorities, contacts and decision-makers. Then expand it. Counsel Cyber helps firms build recovery plans and run tabletop exercises, and we can review a draft with you or help produce one from scratch.