The 3-2-1 rule is one of the oldest ideas in data protection: keep three copies of your data, on two different types of storage, with one copy offsite. It is simple enough to remember and flexible enough to adapt. For law firms, though, the interesting question is what counts as "your data" and what threats the copies must survive.
Today, ransomware operators deliberately look for backups and try to destroy them before demanding payment. A backup that an attacker can delete is not really a backup. So the modern version of 3-2-1 adds a fourth idea: at least one copy must be protected against tampering.
Mapping the rule to a law firm
Copy one: production data
This is the live data your attorneys work on. It might include a file server or cloud file storage, a document management system, practice management data, accounting databases, Exchange or Microsoft 365 mailboxes, and desktop folders where people save things they should not.
Copy two: a local or nearby backup
A backup appliance or storage device on your network allows fast restores for ordinary mistakes: a deleted folder, a corrupted file, an overwritten draft. Its weakness is proximity. Fire, theft, or ransomware that spreads on the network can affect it as well.
Copy three: an offsite, protected backup
This copy lives somewhere else, ideally with immutability, which means that once written, it cannot be modified or deleted for a set retention period, even by an administrator account. That feature is what saves you when credentials are stolen.
Two media types
Historically this meant disk and tape. Today it can mean on-premises disk plus cloud object storage. The point is that a single failure mode, such as a firmware bug or a ransomware strain, should not take out both.
What law firms often forget
Cloud services are not automatic backups
Microsoft 365, Clio, NetDocuments and similar services keep your data available, but their agreements generally do not promise recovery of an item you or an attacker deleted, beyond limited retention windows. Read the terms of each service. Consider a third-party backup for mailboxes, SharePoint and OneDrive, and an export plan for practice management data.
Laptops and local folders
If attorneys save work on their local drives, that work is outside your server backup. Either block local storage of client files through policy, or include endpoints in the backup scope.
Databases and line-of-business software
Accounting, timekeeping, and trust accounting systems often run databases that need application-aware backups. A plain file copy of a running database can be unusable on restore.
Retention and legal holds
Client file retention rules and litigation holds may require preserving data for years. Your backup retention should be set deliberately, not by default. Confirm with your state bar and your firm's file retention policy how long client files must be kept, and coordinate with your IT provider so deletion policies do not conflict.
Questions to ask about your current backups
- What exactly is backed up, and what is not?
- Where do the copies live, and who can delete them?
- Is there an immutable or offline copy?
- How often do backups run, and what is the most data we could lose?
- Who reviews failure alerts, and how quickly?
- When was the last time we restored real data and checked it?
If the answer to the last question is "never" or "we are not sure," that is the most important finding. A backup that has not been restored is a hope rather than a plan.
Encryption and access
Encrypt backups in transit and at rest, and keep the encryption keys somewhere other than the backup system itself. Use separate administrator credentials for backup management, protected with MFA, so that a compromised domain admin account cannot erase your recovery options.
Documenting your plan
Write a short recovery runbook that lists each system, where its backup lives, who can restore it, and in what order systems should come back. Print a copy. If your network is down, you will not be able to open it from the file server.
Where we fit
Counsel Cyber designs and monitors backup and recovery for law firms, including immutable offsite copies, Microsoft 365 protection and regular restore tests. If you would like to find out whether your current setup meets even the basic 3-2-1 standard, we can review it with you and report the gaps in plain English.