Ask a law firm if it has backups and the answer is almost always yes. Ask when it last restored a file from them, and the room often goes quiet. A backup that has never been tested is a hope, not a plan. The classic 3-2-1 rule gives firms a framework for building backups that survive both hardware failure and cyberattack.
The rule says to keep three copies of your data, on two different types of media or storage, with one copy offsite. Ransomware has pushed the guidance further, and many practitioners now speak of 3-2-1-1-0, adding one copy that is offline or immutable and zero errors after testing. CISA's ransomware guidance also emphasizes maintaining offline, encrypted backups and testing them regularly.
Breaking down the rule
Three copies
Your live data counts as one. Add two backups. If one backup is corrupted, accidentally deleted or encrypted, another remains.
Two types of storage
Storing both backups on the same device or the same type of system risks a single point of failure. A local appliance and a cloud repository are a common pairing for small firms, because local restores are fast and cloud copies survive a fire or theft.
One copy offsite
A fire, flood or burglary affecting your office should not take your backup with it. Offsite means physically separate, whether in a cloud service or another location.
Why ransomware changes the picture
Modern ransomware operators know that backups are the difference between recovery and payment. They look for backup consoles, delete snapshots and encrypt network shares, including mapped drives that backup software can reach.
Make one copy hard to alter
- Immutable storage prevents changes or deletion for a set retention period, even by an administrator account.
- Offline or air-gapped copies are not reachable from the network at all.
- Separate credentials for the backup system, not tied to your main directory, with MFA on the console.
If a stolen administrator password can delete every backup, you do not really have three copies.
What to back up
Think beyond the file server.
- Documents and matter files, wherever they live.
- Email, calendars and contacts, including Microsoft 365. Software-as-a-service vendors generally protect their infrastructure, but do not necessarily keep a restorable copy of a mailbox you deleted by mistake.
- Practice management and billing data, including trust accounting records.
- Cloud document management data.
- Server configurations and system images, so you can rebuild quickly.
- Laptops, if attorneys keep working files locally.
Ask your vendors what they back up and for how long, then fill the gaps.
Set recovery objectives
Two numbers guide the design. Recovery point objective is how much data you can afford to lose, measured in time. Recovery time objective is how long you can be down. A litigation firm facing a filing deadline may need hours, not days. Write the numbers down and make sure the design meets them, because a nightly backup cannot support a one-hour recovery point.
Test restores on a schedule
- Monthly: restore a few random files and open them.
- Quarterly: restore a full folder or mailbox and verify.
- Annually: rehearse a larger recovery, such as bringing back a server or key application in a test environment.
Record the date, what was restored, how long it took and who verified. Insurers and clients sometimes ask for that evidence.
Protect the backups themselves
- Encrypt backups in transit and at rest, and keep the keys safe, separate from the backups.
- Monitor backup jobs and alert on failures, since silent failures can persist for months.
- Review retention so you can go back far enough to predate an infection that was dormant.
- Restrict who can modify or delete backup jobs.
Common mistakes
- Backups that live on a drive attached to the same server.
- Cloud sync mistaken for backup, which replicates deletions and encryption too.
- No documentation of how to restore.
- Backup reports that nobody reads.
Closing thought
Rule 1.6(c) speaks to reasonable efforts to protect client information, and Rule 1.1 to competent representation. A tested backup supports both. Counsel Cyber designs and monitors backup and recovery for law firms, including restore testing. If you cannot remember your last restore, we can run one with you.