ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

How Long Should a Law Firm Keep Its Backups? A Retention Guide

Backup retention is a business and professional decision as much as a technical one. Here is how firms can set sensible periods and avoid common conflicts.

3 min readBy Counsel Cyber Team

Ask a firm how often it backs up and you will usually get a confident answer: nightly, or continuously. Ask how long those backups are kept and the answer is often a shrug. Retention, the length of time you keep each backup, quietly determines what you can recover. It also interacts with client file retention rules, litigation holds and the speed of ransomware discovery.

Setting retention is not purely a technical choice. It sits between IT, the firm's records policy and its professional obligations. This post lays out the factors and offers a practical way to decide. It is general information and not legal advice, and your state bar and ethics counsel should be consulted on file retention rules.

Why retention matters

A backup that only keeps the last seven days of copies is useful for an accidental deletion on Tuesday. It is much less useful if ransomware arrived quietly three weeks ago and has been encrypting files gradually, or if a staff member discovers in month two that a folder was damaged months earlier.

Retention is the difference between "we can restore yesterday" and "we can restore the version from before the problem began."

Three different things people call retention

It helps to separate them.

  • Backup retention. How long copies of systems and files are kept in the backup tool.
  • Records retention. How long the firm must keep client files under bar rules, engagement letters and its own policy.
  • Legal holds. A duty to preserve information when litigation or an investigation is reasonably anticipated.

These can conflict. A backup system that automatically deletes after 90 days may be fine for disaster recovery, but if a legal hold applies, relevant data may have to be preserved beyond routine cycles.

A tiered approach

Many firms use tiers, which balance cost and usefulness.

  1. Short-term, frequent copies. Hourly or daily snapshots kept for a few weeks to cover accidents and fast recovery.
  2. Medium-term copies. Weekly or monthly copies kept for several months to cover slow-burning problems.
  3. Long-term copies. Monthly or yearly archives kept longer to satisfy business or records needs.

The right numbers depend on your data volume, budget and risk. There is no universal figure, and anyone who quotes one without knowing your situation is guessing.

Questions to settle with the partners

  • What is our file retention policy for closed matters, and where does it live?
  • Do any client agreements require specific retention or deletion timelines?
  • Do any outside counsel guidelines require deletion on request or at the end of the engagement?
  • How would we apply a legal hold across live systems and backups?
  • How quickly would we notice a slow-moving problem?

The deletion question matters. If a client asks you to destroy their data at the end of a matter, backups can make that complicated. Many firms address it in the engagement letter by explaining how backup copies age out.

Retention and ransomware

Attackers frequently try to delete or encrypt backups before announcing themselves. Two protections help.

  • Immutable or offline copies that cannot be altered or deleted for a set period, even by an administrator account.
  • Separate credentials and MFA for the backup system.

Longer retention only helps if the older copies survive. Immutability is what protects them.

Microsoft 365 and cloud applications

Native retention settings in cloud services are not identical to independent backup. Deleted items may disappear after a set number of days, and administrators can change policies. Review what each platform retains by default, what you have configured and whether a separate backup is warranted for mail and document libraries.

Document your decision

Write down the retention schedule as a short list: what is backed up, how often, how long each tier is kept, where it is stored and who is responsible. Note the date approved and the next review date. If a dispute ever arises about what the firm kept or deleted, a dated policy applied consistently is much easier to defend than ad hoc practice.

Test across time

Occasionally restore an older copy, not just last night's. Pick a file from several weeks back and confirm it opens. Older backups can fail in ways recent ones do not, such as an expired encryption key or a retired storage target.

How Counsel Cyber can help

Counsel Cyber designs backup schedules and retention tiers for law firms, aligned to your records policy, and tests restores on a regular schedule. If you would like us to review your current retention settings, we are happy to take a look.