ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Disaster Recovery Planning for Law Firms: RTO, RPO and Priorities

Learn what recovery time and recovery point objectives mean, how partners can set them, and how to order your firm's systems for restoration after a disaster.

3 min readBy Counsel Cyber Team

Backups answer one question: do we still have our data? Disaster recovery answers a harder one: how quickly can we work again, and with how much lost? For a law firm with court deadlines, closings and client emergencies, the second question usually matters more.

Two terms sit at the center of disaster recovery planning: recovery time objective and recovery point objective. They are simple ideas that many firms never formally define, which means nobody has agreed on what "recovered" means until the day it is tested.

RTO and RPO in plain English

  • Recovery time objective (RTO) is how long the firm can be without a system before the impact becomes unacceptable. "We need email back within four hours" is an RTO.
  • Recovery point objective (RPO) is how much data loss is tolerable, measured in time. "We can lose at most one hour of work" is an RPO.

A nightly backup gives an RPO of roughly a day: if a failure occurs at 4 p.m., you may lose everything since the previous night. If that is unacceptable for your document management system or time entries, you need more frequent protection.

Why partners must choose the numbers

IT can estimate what is technically possible, but the business decides what is acceptable. A litigation team in trial may need documents within an hour. A transactional group may tolerate a half-day outage but not the loss of a day's redlines. These are business judgments, and they carry costs, because tighter targets generally mean more expensive technology.

Step 1: List your systems

Include email, document management, practice management, billing and accounting, phones, file shares, remote access, printers and scanners, and any specialty software such as e-discovery or e-filing tools.

Step 2: Rank by importance

Sort systems into tiers.

  1. Tier 1: Critical. Work stops without them. Typically email, identity and login services, document management and internet connectivity.
  2. Tier 2: Important. Painful but survivable for a day or two, such as billing or accounting.
  3. Tier 3: Deferrable. Can wait a few days, such as archives or rarely used applications.

Step 3: Set targets for each tier

For each system, record the RTO and RPO the partners will accept. Be realistic. Then ask IT or your provider whether the current setup can meet them. The gap between "needed" and "actual" is the work to be done.

Step 4: Decide the order of restoration

Dependencies matter. Nothing works without network and identity services. Document management may depend on a database server. Write down the order, so that nobody improvises during a crisis.

Step 5: Plan for the people side

Technical recovery is only part of the picture. Decide:

  • Who declares a disaster and who is the backup if they are unavailable?
  • How will we communicate if email is down? Keep an out-of-band contact list with personal mobile numbers, stored offline or in a location that does not depend on firm systems.
  • How will attorneys meet deadlines meanwhile? Consider paper contingencies, court notification procedures and temporary workspaces.
  • Who speaks to clients and what do they say?

Step 6: Test it

A plan that has never been exercised is a theory. Start small: a tabletop exercise where the group talks through a scenario such as a ransomware infection on a Friday afternoon or a burst pipe in the server room. Then progress to technical tests where you actually restore a system in a separate environment and time it. Record the real RTO. The number is often longer than anyone expected.

Common pitfalls

  • Assuming cloud services eliminate the need for planning. Credentials, internet access and tenant-level problems can still stop work.
  • Confusing a backup with a recovery plan. Having data does not mean having a working environment.
  • Keeping the plan only on the server that failed.
  • Forgetting dependencies like licensing keys, DNS and firewall configurations.
  • Never updating the plan after changes in staff or systems.

Keep the plan short and current

A usable plan is a few pages: contacts, tiers with RTO and RPO, restoration order, decision-makers and vendor numbers. Print copies and store them off site. Review after every significant change and at least annually.

How Counsel Cyber can help

Counsel Cyber helps law firms define recovery targets, build and test disaster recovery plans and run tabletop exercises with partners. If you would like help getting a first plan on paper, we would be glad to work through it with you.