ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Retention and Backups: How Long Should a Law Firm Keep Its Data?

Backup retention balances recovery needs, cost and file-retention duties. Here is how to set a sensible schedule and avoid the common retention mistakes.

3 min readBy Counsel Cyber Team

A backup is not an archive, and an archive is not a backup. Mixing them up is one of the quieter mistakes a law firm can make. Backups exist so you can recover from loss or damage. Archives exist so you can keep records for as long as you are required or choose to. The two overlap in storage but serve different purposes, and a retention schedule should treat them separately.

Backups and File Retention Are Different Problems

Your firm likely has file-retention obligations for client matters, trust records and business records. Those are driven by your state's rules, your engagement letters and your insurer's guidance. Nothing in a backup system replaces a proper records policy, and this post does not tell you how long you must keep client files. Confirm those periods with your state bar or ethics counsel.

What a backup retention schedule answers is different: how far back in time do we need to be able to rewind?

Why Retention Length Matters for Recovery

Short-term retention handles everyday mistakes

Someone deletes a folder, overwrites a draft or a document becomes corrupted. These problems are usually noticed within days. Frequent recent restore points, often daily, are what you need.

Medium-term retention handles slow-burn problems

Some issues go unnoticed for weeks. An employee may quietly delete files before leaving, or a corrupted file may be backed up repeatedly before anyone opens it. Having weekly and monthly restore points lets you reach back past the damage.

Long-term retention handles unusual events

Ransomware attackers often sit inside networks for days or weeks before triggering encryption. If your backups only go back a few days, every copy may contain the intruder. Having older, clean restore points can be the difference between a clean recovery and a prolonged rebuild.

A Common Tiered Approach

Many firms use a tiered structure like this, adjusted to their needs:

  • Daily restore points kept for a few weeks.
  • Weekly restore points kept for a few months.
  • Monthly restore points kept for a year or more.
  • Annual snapshots kept longer, when business or client needs justify the cost.

The right numbers depend on your recovery requirements, your storage costs and the sensitivity of your work. Ask your provider to show your current schedule in writing.

Costs and Tradeoffs

Longer retention means more storage, which means more cost. Immutable storage, which cannot be altered or deleted for a set period, is a valuable protection against ransomware but locks in data for that period. Balance these carefully, and focus longer retention on systems that matter most, such as document management, email and financial data.

Privacy and Deletion Considerations

Keeping everything forever is not automatically safer. Old backups contain old data, including information a client may have asked you to return or destroy, or that your retention policy says should be gone. When a matter file is destroyed under policy, copies in backups may persist until they age out. Make sure your policy addresses this, and that clients' expectations, as stated in engagement terms, match reality.

Steps to Set Your Schedule

  1. Identify critical systems and how much history each needs for recovery.
  2. Decide how far back you would want to restore after a slow-burn event.
  3. Review your cyber-insurance and client contract requirements, since some specify backup practices.
  4. Align backup expirations with your records policy, so deletion is consistent.
  5. Document the schedule and review it annually.
  6. Test that an older restore point can actually be recovered, not just that it exists.

Mistakes to Avoid

  • Treating backup retention as a substitute for a records-retention policy.
  • Keeping only a few days of history.
  • Retaining everything indefinitely with no review.
  • Forgetting cloud platforms, whose built-in recycle bins are short.
  • Not knowing what your current schedule actually is.

Where Counsel Cyber Fits

Counsel Cyber designs backup schedules for law firms, with recovery objectives that reflect real risks and reporting you can share with partners or clients. If you cannot say how far back you could restore today, we can help you find out.