ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

The 3-2-1 Backup Rule Explained for Law Firms

The 3-2-1 backup rule is a simple standard for protecting client files from ransomware, hardware failure, and disaster. Here is how a law firm can apply it.

3 min readBy Counsel Cyber Team

Ask a managing partner whether the firm's data is backed up and the answer is almost always yes. Ask whether the firm could restore its entire document system by Monday morning after a ransomware attack, and the room gets quieter. The gap between "we have backups" and "we can recover" is where firms get hurt.

A long-standing guideline helps close that gap. It is called the 3-2-1 rule, and it is simple enough for any firm administrator to check.

What 3-2-1 Means

  • 3 copies of your data: the original working copy plus two backups
  • 2 different types of storage: for example, a local appliance and a cloud service, so one failure mode cannot take out both
  • 1 copy offsite: physically and logically separate from your office, so fire, theft, flood or a network-wide attack does not reach it

Many security teams now add extra requirements: one copy that is immutable or offline, and zero errors on verification. Some describe this as 3-2-1-1-0. The principle is the same. No single event should be able to destroy every copy.

Why Law Firms Need It More Than Most

Law firms hold material that cannot be recreated: signed originals scanned and then shredded, work product, court filings, correspondence, and billing records. Some of it is subject to retention requirements and some is subject to client confidentiality duties. Losing it, or losing access to it, can interrupt client service and create ethical exposure. The ABA's Model Rule 1.4 on communication and Model Rule 1.6(c) on safeguarding information both bear on how a firm responds when client data is unavailable or exposed.

Where Firms Typically Go Wrong

Backups on the same network

If a backup drive is mapped as a normal network share, ransomware can encrypt it along with everything else. Modern ransomware often seeks out backups specifically. At least one copy must be unreachable from a compromised workstation or server account.

Cloud storage mistaken for backup

Having files in OneDrive, SharePoint, Dropbox or a practice management platform is not the same as having a backup. Syncing replicates deletions and corruption. Software-as-a-service vendors protect their infrastructure; most do not promise to restore a file you or a ransomware process deleted six weeks ago. Ask what retention and recovery options exist, and consider a separate backup of Microsoft 365 and key legal platforms.

Nobody tests restores

A backup that has never been restored is an assumption. Test regularly, and include a realistic scenario, such as restoring a document management database or a mailbox, not just a folder of spreadsheets.

Missing coverage

Firms often back up the file server but forget laptops, the accounting system, the phone system configuration, or the data held by a former IT provider. Build an inventory of every system holding firm data and mark whether each is covered.

A Simple Way to Apply It

  1. Inventory your data. List each system, where it lives, and who owns it.
  2. Set recovery goals. For each system, decide how much data loss is tolerable (recovery point) and how long you can be without it (recovery time). A firm may accept losing an hour of email but not a day of billing entries.
  3. Match the backup method to the goals. Hourly protection for critical systems, daily for lower-priority ones.
  4. Add an immutable or offline copy that attackers cannot alter.
  5. Test and document. Restore something every quarter and write down the result.
  6. Protect the backup credentials with MFA and separate accounts from everyday admin logins.

Questions to Ask Your IT Provider

  • Where is each copy, and can ransomware reach any of them?
  • When was the last full restore test, and how long did it take?
  • Are Microsoft 365 and our practice management data backed up separately?
  • How long do we keep backups, and does that match our retention obligations?
  • Who is alerted when a backup fails?

Getting Help

Counsel Cyber designs backup and recovery plans around how law firms actually work, including document management systems and trust accounting data, and runs scheduled restore tests so you know the answer before you need it. If you are unsure whether your current setup meets 3-2-1, we can review it with you.