ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Ransomware Recovery Walkthrough for a Hypothetical Law Firm

A hypothetical timeline shows how a 25-attorney firm could recover from ransomware, and which backup and planning choices decide the outcome.

3 min readBy Counsel Cyber Team

Abstract advice about ransomware is easy to nod along with and hard to remember. A walkthrough helps. The following story is entirely hypothetical, built to show how decisions made before an incident shape what happens during one. Any resemblance to a real firm is coincidental.

Consider a hypothetical 25-attorney litigation firm with a document management system, Microsoft 365 email, a small on-premises server and an outside IT provider.

Hour 0: the discovery

At 7:40 on a Monday morning, a paralegal finds that she cannot open files on a shared drive. A text file on the desktop demands payment. She calls the IT provider's emergency number, as the firm's written plan instructs, rather than restarting the computer.

Decision that mattered: The firm had a printed incident contact sheet and staff knew to call, not tinker. Rebooting or deleting files can destroy evidence and sometimes spreads damage.

Hour 1: contain

The provider's engineer disconnects the affected computer and the file server from the network and isolates other devices that show suspicious activity. Endpoint detection software, which the firm had deployed, shows that the intruder entered through a stolen password on a remote access gateway lacking multi-factor authentication, and had been exploring for several days.

Lesson: Containment first, investigation second. The detection tool shortened the guesswork.

Hour 2: notify and mobilize

The managing partner opens the incident response plan. The firm contacts its cyber insurance carrier through the hotline on the policy, which connects it to approved forensics and breach counsel. Partners agree on a single spokesperson. Email is still working, but because attackers may be reading it, the team moves sensitive coordination to phone and a separate secure channel.

Lesson: Policies often require early notice and approved vendors. The firm had those numbers handy.

Hours 3 to 8: assess

Forensic investigators work to determine what happened, which systems were touched and whether data was copied out. Two key questions: Is the backup intact, and was data stolen? The firm's backup design follows the 3-2-1 idea, with an immutable cloud copy separate from the domain credentials. The attacker tried to delete backups but could not reach the immutable copy.

Lesson: Immutable, separate backups are what turn a catastrophe into a restoration project.

Day 1 to 2: rebuild and restore

The provider rebuilds the server from clean images rather than cleaning the infected one. It restores data from the most recent clean backup point, checking that the backup predates the intruder's first foothold. Passwords for all accounts are reset, sessions are revoked, MFA is enforced on the remote gateway and the exposed account is investigated.

Because the firm had set recovery targets in advance and tested restores, the real timeline roughly matched expectations. Attorneys use laptops and cloud email for the first day while the file server is restored.

Lesson: Prior restore tests meant no one was guessing.

Day 2 to 5: legal and client obligations

The investigators conclude that the attacker accessed some client files before encryption. The firm consults breach counsel. ABA Formal Opinion 483 discusses lawyers' obligations when a breach occurs, including monitoring for breaches, stopping them, restoring systems, determining what occurred and notifying affected current clients where required, and state breach notification laws may also apply. The firm drafts clear, factual client communications, with partners calling the most affected clients personally. Model Rule 1.4 addresses communicating with clients.

Lesson: Notification is a process, and counsel should guide it.

Week 2 and beyond: improve

The firm holds a review meeting: What failed? A remote access account lacked MFA. What worked? Backups, detection and the plan. It adds MFA everywhere, reduces administrator accounts, tightens remote access and schedules a tabletop exercise twice a year.

What to take from the story

  1. Call for help rather than improvising.
  2. Contain before cleaning.
  3. Keep an immutable, separate backup.
  4. Know your insurance requirements before the incident.
  5. Define recovery targets and test them.
  6. Plan client communications and consult counsel on notices.
  7. Fix root causes afterward.

The paying question

The hypothetical firm never faced the decision to pay a ransom because it could restore. Even so, the possibility of stolen data means that restoration alone does not end the matter. Payment decisions involve legal, insurance and law-enforcement considerations. The FBI generally discourages paying, and CISA offers ransomware guidance worth reading in advance.

How we help

Counsel Cyber helps law firms build the plans and protections shown above, and supports response if the worst day arrives. If you would like to run a tabletop exercise based on this scenario, we are glad to facilitate one.