For years, the standard advice on backups was the 3-2-1 rule: keep three copies of your data, on two different types of media, with one copy off-site. It remains a sound foundation. But ransomware operators now deliberately hunt for backups, and a firm whose backup is reachable from the same network as its servers can lose both at once. That is why many security practitioners now describe 3-2-1-1-0.
This post explains each number in plain English and what it means for a firm with client files, trust records and court deadlines.
Breaking down 3-2-1-1-0
- 3 copies of your data: the live data plus two backups
- 2 different types of storage, for example a local appliance and cloud storage
- 1 copy off-site, away from the physical office, so fire, flood or theft does not take everything
- 1 copy that is offline, air-gapped or immutable, meaning it cannot be changed or deleted, even by an administrator account, for a set period
- 0 errors, meaning backups are verified and restore tests actually succeed
The two newer digits address the most common real-world failures: backups that ransomware encrypts alongside the main data, and backups that nobody ever tested.
Why immutability matters
Attackers who gain administrator credentials will often try to delete backup repositories before launching encryption. An immutable copy, enforced by the storage service itself, means those deletion commands fail. Ask your provider whether your off-site backup supports immutability and for how long the retention lock applies.
What a law firm needs to protect
Backups should cover more than the file server. Make a list and check each one:
- Document management system and its databases
- Practice-management data, whether hosted or on-premise
- Microsoft 365 mailboxes, OneDrive and SharePoint, because Microsoft's service availability is not the same as a backup of your data that you control
- Accounting and trust-accounting records
- Laptops that hold local files, if policy allows local storage
- Configuration of network devices, firewalls and servers
Recovery goals, not just copies
Backups are only useful if you can restore in the time your practice can tolerate. Two terms help:
- Recovery point objective (RPO): how much recent work you can afford to lose. If backups run nightly, you may lose up to a day.
- Recovery time objective (RTO): how long you can be without systems before the damage is serious.
Ask the partners a simple question: if the server were gone on Monday morning, what would we need back by noon? The answer shapes your backup design.
Testing: the zero in the formula
A backup that has never been restored is a hope, not a control. Build testing into the calendar:
- Monthly: spot-restore a few files and an email mailbox item
- Quarterly: restore a full server or critical application to an isolated environment
- Annually: walk through a full disaster scenario with partners, staff and your IT provider
- After any major change: new servers, new software, new cloud migrations
Write down the result each time, including the time it took. That record is also valuable evidence for cyber insurance applications.
Mistakes to avoid
- Using a network drive that is permanently mapped to the backup target
- Sharing the same administrator credentials for production and backup systems
- Assuming a green "success" status means the data is restorable
- Forgetting to back up cloud applications
- Never calculating how long a full restore would take over your internet connection
Confidentiality of the backups themselves
Backups contain every client's confidential information. They should be encrypted in transit and at rest, access should be limited, and you should know where the data physically resides.
A next step
Counsel Cyber designs and monitors backup systems for law firms, including restore testing. If you are unsure how your current setup measures against 3-2-1-1-0, we are happy to review it and show you the gaps.