ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

The 3-2-1 Backup Rule Explained for Small Law Firms

The 3-2-1 backup rule is simple, but many firms miss one part. Here is how to apply it to servers, laptops, and cloud practice-management data.

3 min readBy Counsel Cyber Team

Ask a managing partner whether the firm has backups and the answer is almost always yes. Ask whether those backups would survive ransomware, a fire in the server closet, or an administrator account being taken over, and the answer gets quieter. The 3-2-1 rule is a time-tested way to close that gap, and it works whether you are a solo practice or a 100-attorney firm.

What the rule says

  • 3 copies of your data: the live production copy plus two backups.
  • 2 different types of storage: for example, a local appliance and cloud storage, so a single failure mode cannot take out everything.
  • 1 copy offsite: physically and logically separate from your office network.

Many security professionals now add an extension: keep at least one copy that is immutable or offline, meaning it cannot be changed or deleted even by someone holding administrator credentials. Modern ransomware often hunts for backups first, so this one addition matters a great deal.

Applying it to a law firm

Servers and file shares

If you still run an on-premises file server, a local backup appliance gives you fast restores for day-to-day needs, such as a deleted folder. A second copy replicated to a cloud repository protects against theft, fire or flood. Confirm the cloud copy is separated from your domain login so that a compromised admin account cannot delete it.

Laptops and desktops

Attorneys keep working files on laptops more often than firms realize. Decide whether endpoints are backed up or whether policy requires all work to live in a managed repository. Either approach is workable. Silence is not.

Cloud practice-management and document systems

Clio, NetDocuments, iManage, Microsoft 365 and similar platforms are hosted by vendors, but hosting is not the same as backup. Vendors protect their infrastructure; they generally do not promise to restore your data after accidental deletion, a malicious insider or a compromised account. Read the terms for retention windows, and consider a third-party backup for mailboxes, SharePoint and OneDrive content and key practice-management exports.

Common mistakes

  1. Backups on the same network with the same credentials. If ransomware can reach the backup share, it can encrypt it.
  2. Never testing a restore. A backup job that reports "success" can still produce unusable data.
  3. Backing up the system but not the configuration. Rebuilding servers without documented settings costs days.
  4. No retention plan. Keeping only a few days of history means you may overwrite good data with damaged data before anyone notices.
  5. Forgetting client matter obligations. Retention and destruction obligations vary, so confirm with your state bar and your firm's policies.

Questions to ask your IT provider

  • Where does each of our three copies live?
  • Is at least one copy immutable or air-gapped?
  • Who holds the credentials to the backup system, and is MFA enforced?
  • When did we last perform a full restore test, and who witnessed it?
  • How long would it take to restore the case management system, and how do you know?
  • Are Microsoft 365 mailboxes and SharePoint data covered?

Why this matters ethically

ABA Model Rule 1.1 and its Comment 8 speak to a lawyer keeping abreast of the benefits and risks of relevant technology, and Rule 1.6(c) calls for reasonable efforts to prevent unauthorized access to client information. Availability of client files is part of protecting clients, and a firm that cannot retrieve its data after an incident has a problem beyond inconvenience. The ABA has not prescribed a specific backup design, so treat 3-2-1 as a sound practice rather than a mandated one, and confirm expectations with your state bar.

Next step

Sketch your current backup picture on one page: what is protected, where copies live, who can delete them and when you last restored. If you cannot fill in every box, that is your to-do list. Counsel Cyber builds and tests backup designs for law firms and can walk through your current setup, identify gaps and run a restore test with your team watching.