ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Retiring the File Server: Moving Your Firm's Documents to the Cloud

Thinking about replacing the old file server? This guide covers planning, permissions, migration and the mistakes that trip up law firms moving to the cloud.

3 min readBy Counsel Cyber Team

Many firms still have a server in a closet holding decades of files. It is aging, expensive to maintain, and one hardware failure or one ransomware infection away from a very bad week. Moving documents to a cloud platform such as SharePoint, a document management system like NetDocuments or iManage, or a practice-management tool is often the right call, but the move is a project, not a copy job.

Decide what you are moving to

The destination shapes everything else.

  • Microsoft 365 with SharePoint and OneDrive suits firms that want familiar folders, strong Office integration, and one vendor for email and files.
  • A legal document management system adds matter-centric organization, version control, and fine-grained security, often at higher cost and with a heavier rollout.
  • A practice-management platform stores documents alongside matters, contacts, and billing and may be enough for smaller firms.

Choose based on how your attorneys work, not on which is trendiest. Whichever you pick, confirm it supports multifactor authentication, audit logging, and a way to export your data.

Plan before you move anything

Clean up first

Years of duplicate folders, "final_v7_REAL" files, and departed employees' personal folders will follow you into the cloud unless you deal with them. Work with attorneys and records staff to decide:

  • What must be kept under your retention policy and engagement letters
  • What can be archived to cold storage
  • What can be deleted, with partner sign-off

Check applicable file retention rules with your state bar guidance, since requirements vary.

Map the permissions

Document who can see what today. Most file servers have accumulated permissions that nobody fully understands. Take the migration as a chance to build a cleaner model: access by practice group or matter team, with sensitive matters restricted.

Inventory dependencies

List everything that reads from or writes to the server: scanners that save to a folder, accounting software, templates, macros, scripts, and applications that use mapped drive letters. These hidden dependencies cause most go-live surprises.

Run the migration in stages

  1. Pilot group. Move one team first, and gather feedback on speed, search, and sync behavior.
  2. Bulk copy. Use a migration tool that preserves timestamps and permissions rather than dragging files by hand.
  3. Delta sync. Right before cutover, copy files that changed since the bulk copy.
  4. Cutover weekend. Make the old server read-only, finalize the sync, and verify counts.
  5. Support week. Have extra help available on Monday morning.

Watch for technical limits

Cloud platforms often have limits on path length, file names, special characters, and file size. Long nested folder names that worked on the server may fail on upload. Run an assessment before migration to flag them.

Train the people

The biggest complaint after a migration is "I can't find anything." Spend time on:

  • How the new folder structure works
  • How to share a document with a client securely rather than by attachment
  • How offline sync behaves and what a conflict looks like
  • Where to save things so they are backed up

Keep it secure after the move

  • Turn on MFA and conditional access before the first user logs in.
  • Limit external sharing and require expiring links for client sharing.
  • Use sensitivity labels or similar controls on especially confidential matters.
  • Back up cloud data. A cloud vendor generally guarantees availability of the service, not recovery from your own mistakes or an attacker deleting files, so check what your plan includes.
  • Enable audit logs and alerts for mass downloads or deletions.

Mistakes to avoid

  • Migrating everything unreviewed, including twenty years of clutter
  • Forgetting to decommission the old server securely, with data wiped
  • Skipping the pilot
  • Leaving the old server running "just in case" and unpatched
  • Assuming sync equals backup

Retiring the old hardware

Keep the old server in read-only mode for a defined period, such as 60 to 90 days, then take a final backup, wipe the drives following a recognized standard, and document the disposal. Hard drives that held client files should not simply be thrown away.

How we can help

Counsel Cyber plans and carries out migrations for law firms, including permission mapping, pilot rollouts, and post-migration security settings. If your file server's days are numbered, we can start with an assessment of what you have and a realistic timeline.