ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Live Data, Local Copy, Cloud Copy: Building 3-2-1 Backups at a Firm

What the 3-2-1 backup rule means, why ransomware has made it more important, and how a law firm can apply it with cloud tools and a realistic restore test.

3 min readBy Counsel Cyber Team

Ask a managing partner whether the firm has backups and the answer is almost always yes. Ask whether anyone has restored a client matter from those backups in the last year and the room gets quiet. The difference between having backups and being able to recover is where firms get hurt.

The 3-2-1 rule is a simple way to frame the question. It has been a standard of data protection for years, and it holds up well against modern threats like ransomware.

What 3-2-1 Means

  • 3 copies of your data: the working copy plus two backups.
  • 2 different types of storage: for example, a local device and a cloud service.
  • 1 copy offsite, away from your office and ideally away from your main network.

Many security teams now add an extension: one copy should be immutable or offline, meaning it cannot be changed or deleted, even by someone with administrator credentials. Ransomware operators increasingly hunt for backup systems and try to destroy them first.

Why Law Firms Need It

A firm's data is its inventory: client files, work product, trust records, billing history. Losing it affects deadlines, client trust and potentially your ethical duties. ABA Model Rule 1.1 and its comment on technology, along with duties about safeguarding client property, make dependable recovery a practical necessity.

Think of the threats a backup must survive:

  • Ransomware encrypting servers and connected drives
  • A failed hard drive or a damaged server room
  • An employee deleting a folder by accident
  • A fire, flood or severe storm, which are real concerns across the Southwest and Gulf region
  • A cloud account compromised and wiped by an attacker

Applying 3-2-1 in Practice

Copy 1: Your live data

Whether in Microsoft 365, a practice-management platform or an on-premises server, this is what you work on every day.

Copy 2: A local or secondary backup

Fast restores for everyday mishaps. Make sure it is not permanently mapped to staff computers as a drive letter, because ransomware can encrypt anything it can reach.

Copy 3: An offsite, protected cloud backup

This is your safety net for the worst day. Look for encryption, retention long enough to catch problems you notice late, and immutability features.

A Common Gap: Cloud Services Are Not Automatically Backed Up

Many firms assume that Microsoft 365 or their practice-management vendor keeps everything forever. Retention of deleted items is usually limited, and the vendor's responsibility is typically to keep the service running, not to restore your accidental deletions from last year. Read the terms and ask specifically about recovery of deleted mail, files and matters. Consider a third-party backup for Microsoft 365.

Questions Your Backup Should Answer

  1. What exactly is backed up? Servers, laptops, mailboxes, databases, practice-management exports?
  2. How often? Daily is common, but think about how much work your firm could afford to redo.
  3. How long are copies kept?
  4. Who is alerted when a backup fails?
  5. How long would a full restore take?

Test, Test, Test

A backup that has never been restored is an assumption. Schedule tests:

  • Monthly: restore a few random files and confirm they open.
  • Quarterly: restore a full matter folder or a mailbox.
  • Annually: simulate a bigger failure, such as rebuilding a server in a test environment.

Write down the results and the time each restore took. That record is also valuable to insurers and clients who ask about your practices.

Protect the Backup Itself

  • Use separate credentials for backup administration, with MFA.
  • Limit who can delete or change retention settings.
  • Monitor for unusual deletion activity.
  • Encrypt backups, since they contain the same sensitive data as the originals.

Start Where You Are

If you have only one backup and it sits in the same office as your server, add an offsite protected copy first. Then add testing. Perfection is less important than closing the largest gap.

Counsel Cyber designs and monitors backup and recovery for law firms, including restore testing. If you are unsure whether your current setup would hold up on a bad day, we can review it with you.