ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Protecting Practice-Management Data: Backing Up Cloud Applications

Cloud practice-management and document platforms are not automatically backed up the way partners assume. Here is how to protect that data yourself.

3 min readBy Counsel Cyber Team

Moving to cloud software changed what firms worry about. Servers in the closet gave way to subscriptions to Clio, NetDocuments, iManage, Microsoft 365 and similar platforms. Many partners reasonably conclude that the vendor takes care of backup. That is partly true and partly a trap.

Vendors protect their own infrastructure against hardware failure and outages. What they generally do not promise is to protect you from your own mistakes, a malicious insider, a compromised account that deletes data, or a retention window that has expired. This is often called the shared responsibility model, and understanding where the line sits is essential.

What vendors typically cover

  • Availability of the service and redundancy in their data centers
  • Disaster recovery for their own platform
  • Some limited recovery of deleted items for a short period

What they typically do not cover

  • Restoring data after an attacker with valid credentials deletes or encrypts it and the retention window passes
  • Recovering from bulk changes or bad integrations that overwrite records
  • Long-term retention beyond the plan's default
  • A point-in-time restore of the entire environment as it existed last month

The details differ by vendor and plan, so read the terms and ask direct questions in writing.

Questions to ask each vendor

  1. How long are deleted items recoverable, and who can recover them?
  2. Can you restore a single matter or document to an earlier point in time?
  3. Is there a full export option, in what format, and how long does it take?
  4. Do backups exist that are independent of our account, and how are they protected?
  5. What happens to our data if we cancel or the vendor is acquired?
  6. How quickly would you notify us of a security incident?

Approaches to protecting the data

Third-party backup services

Several products back up Microsoft 365 mail, OneDrive, SharePoint and Teams into a separate repository. Some cover other cloud applications, and options for specific legal platforms vary, so verify support before purchase.

Scheduled exports

For applications without third-party backup, schedule regular exports of contacts, matters, notes, billing and documents, and store them in a protected location. Test that exports can be opened and that relationships between records survive.

Immutable storage

Store backup copies in a way that prevents deletion or alteration for a defined period, even by administrators.

Account protection

The best backup is often preventing the compromise itself. Enforce multi-factor authentication, restrict administrators, review connected apps and monitor logs.

Practice-specific considerations

  • Billing and trust records. These require long retention and accurate histories. Check your state's record-keeping rules with your bar.
  • Document versions. Confirm whether your document management system's version history protects you from overwrites, and whether it counts as backup. Usually it does not.
  • Email. Mailboxes contain client communications that may be subject to legal holds.
  • Integrations. A faulty sync between systems can corrupt records in both. Know how to roll back.

Testing

Run restore tests for each platform at least annually. Restore a sample matter into a sandbox if possible, or open an export and verify contents. Record results.

Documenting your plan

For each system, write down where the data lives, who administers it, how it is backed up, how long retention lasts, who can restore and how long that takes. This one-page inventory also helps with client questionnaires and insurance applications.

Ethical angle

ABA Model Rule 1.1 Comment 8 addresses understanding technology risks and benefits, and Rule 1.6(c) addresses protecting client information. Rule 1.15 on safekeeping property is often relevant for trust-account records, so confirm how your state applies it. Understanding the real limits of your vendors' backups is part of that picture.

A hypothetical scenario

Consider a hypothetical firm whose compromised administrator account deletes a large set of matters from its practice-management system. The vendor can restore only items deleted within a short window, and the firm notices after that window closed. A separate scheduled export would have preserved the data.

How we help

Counsel Cyber designs backup strategies for cloud-based law firms, including Microsoft 365 and practice-management data, and tests restores with you. If you would like to know what your vendors really protect, we can help you ask the right questions.