A disaster recovery plan sounds like something only large organizations need. In practice, a ten-attorney firm is often more exposed, because it has fewer systems, less redundancy and no one whose full-time job is IT. When the server fails, the office floods, or ransomware hits, the plan is the difference between working from backup systems by afternoon and telling clients that their matters are delayed for a week.
You do not need a 100-page document. A clear, short plan that people can actually find and follow is what counts. Here are five steps.
Step 1: List what the firm cannot operate without
Start with a plain inventory of systems and rank them by how quickly the firm would suffer without them. A typical ranking for a law firm looks like this:
- Email and calendar, because deadlines and client communication depend on them
- Document management or file shares, where the work product lives
- Practice management, billing and time entry
- Trust accounting and bank access
- Phone system
- Court e-filing access and legal research tools
- Printers, scanners and everything else
For each, note where it runs (on-site server, cloud service or laptop), who supports it, and where its backup lives.
Step 2: Set recovery goals
For each critical system, agree on two numbers with the partners:
- Recovery time objective (RTO): how long can the system be down before the harm becomes unacceptable?
- Recovery point objective (RPO): how much recent data can the firm afford to lose?
These are business decisions, not technical ones. A firm that says "email must return within four hours and we can lose at most an hour of data" has a design target that IT can price and build toward. If the partners want faster recovery than the current setup provides, that is a budgeting conversation, and it is better to have it now.
Step 3: Match your protections to the goals
Compare what you have to what you said you need:
- Are backups frequent enough to meet the RPO?
- Could you restore within the RTO, given the size of your data and your internet speed?
- Is there an off-site and immutable copy that ransomware cannot touch?
- Is there a place to run systems if the office is unusable, such as cloud-hosted servers or attorneys working from home with firm laptops?
- Do you have spare hardware, or a vendor who can deliver it quickly?
Where there is a gap, list it, with a cost estimate and a priority.
Step 4: Write down who does what
Assign roles and backups for each:
- Decision maker: usually the managing partner, who declares a disaster and approves spending
- Technical lead: your IT provider or internal IT, who runs recovery
- Communications lead: who contacts clients, staff, the insurer and the court when necessary
- Administrative lead: who tracks vendors, supplies and staff status
Include phone numbers for everyone and for key vendors, your insurance carrier, your bank and your internet provider. Store the plan in several places that will survive an outage: printed copies, personal phones, and a cloud location not dependent on your own network.
Add a short list of immediate actions for the first hour, including how to reach clients if email is down, and who calls the courts if a deadline is at risk.
Step 5: Test it and keep it current
An untested plan is a guess. Schedule:
- Quarterly: a restore test of selected files and a mailbox
- Annually: a tabletop exercise where the partners, administrator and IT talk through a scenario, such as ransomware or a building fire, and a technical test of restoring a critical system
- After major changes: new offices, new software, staff turnover in key roles
Record what worked, what failed and what you changed. Update contact lists whenever someone joins or leaves.
Special considerations for law firms
- Client files and original documents: Some matters involve physical originals, such as wills or contracts. Include protection for paper in the plan.
- Confidentiality during recovery: Temporary workarounds, such as personal email or unapproved file sharing, can create their own breaches. Define approved alternatives in advance.
- Deadlines: Know how to request extensions and notify courts. Keep a calendar export available off-network.
- Insurance: Keep your policy numbers and carrier contact details with the plan, and read the notice requirements.
Keep it proportional
A plan for a small firm can fit on a few pages: the ranked systems list, the recovery goals, the roles with phone numbers, the first-hour checklist, and the test schedule. That is far more than many firms have.
How Counsel Cyber helps
We help firms build disaster recovery plans, design systems that meet their recovery goals and run the annual test with them. If you would like to start with a short gap review, we can arrange it.