ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Three Copies, One Locked: Backup Basics for Law Firm Partners

The classic 3-2-1 backup rule gets an update for ransomware. Here is how a small law firm can apply 3-2-1-1 without buying enterprise gear or hiring staff.

4 min readBy Counsel Cyber Team

Most law firms believe they have backups. Fewer can say where the copies live, who can delete them, or how long a full restore would take. The 3-2-1 rule has been the standard shorthand for good backup design for years, and ransomware has pushed it to an extended version, often written 3-2-1-1. This post explains what each number means and how a small firm can apply it in practical terms.

The stakes are simple. A law firm's data is client confidences, court deadlines and billing records. If all of it is encrypted by an attacker, or lost to a failed server, the firm has duties to its clients regardless of what caused the outage. A backup that cannot be restored is not a backup.

What the numbers mean

The rule reads as a short checklist:

  • 3 copies of your data: the live production copy plus two backups.
  • 2 different types of storage: for example, a local appliance and a cloud service, so one failure mode does not take out everything.
  • 1 copy offsite: physically and logically separate from the office, so fire, flood, theft or a compromised network cannot reach it.
  • 1 copy that is immutable or offline: this is the addition. An immutable copy cannot be changed or deleted for a set retention period, even by an administrator account.

Why the extra "1" matters

Modern ransomware operators do not just encrypt files. They look for backup systems first, and they try to delete or encrypt those too. CISA's ransomware guidance has long recommended keeping offline, encrypted backups and testing them regularly. An immutable copy, or one that is truly disconnected, means that even a fully compromised domain administrator account cannot erase your last line of defense.

Applying it in a small firm

Consider a hypothetical 10-attorney firm with a file server in a closet, Microsoft 365 for email, and a cloud practice-management platform. Here is how the rule maps onto that environment.

Local files and servers

Back up the server image to a local appliance for fast restores, then replicate that backup to a cloud repository with immutability enabled. The local copy gets you running again in hours after a hardware failure. The cloud copy is what you rely on if the building or the network is compromised.

Microsoft 365

A common misunderstanding is that Microsoft backs up your mailboxes and SharePoint libraries the way you would expect a backup to work. Microsoft provides availability and some recovery windows, but it operates under a shared-responsibility model, and retention features are not the same as an independent backup. Many firms add a third-party backup of email, OneDrive, SharePoint and Teams data so a deleted mailbox or a malicious mass deletion can be reversed.

Cloud practice-management and document systems

Platforms such as Clio, NetDocuments and iManage have their own resilience and export options. Ask your vendor what their recovery commitments are, how long deleted data is retained, and whether you can obtain a periodic export that you control. Do not assume the vendor's redundancy replaces your own copy.

Common mistakes to avoid

  1. Backups on the same network with the same credentials. If the backup console uses the same administrator login as the rest of the domain, one stolen password reaches everything.
  2. No multi-factor authentication on the backup portal. Treat it like a bank account.
  3. Never testing a restore. Schedule a test of restoring a real matter folder and a mailbox at least quarterly, and a full-system recovery drill annually.
  4. Ignoring laptops. Attorneys often keep working files locally. Either enforce saving to the managed repository or include endpoints in backup scope.
  5. Unrealistic recovery expectations. Downloading several terabytes from the cloud takes time. Know your recovery time objective before you need it.

Questions to settle with your partners

  • How many hours of lost work can the firm tolerate? That is your recovery point objective.
  • How many hours or days can the firm be without systems? That is your recovery time objective.
  • Who is authorized to delete or change backup retention, and is that person approval-gated?
  • Where is the documentation for restoring, and can it be reached if the network is down?

Write the answers down. They drive your budget and your tool choices, and they are also the kind of facts cyber-insurance applications and client security questionnaires now ask about.

Getting started

You do not need to rebuild everything at once. Start by listing every place client data lives, mark which have two independent copies, and find the gaps. Then add an immutable offsite copy to the most critical systems first.

Counsel Cyber helps law firms design and test backup and recovery plans that fit their size and budget. If you would like a second set of eyes on your current setup, we are glad to run a short backup review and walk through a restore test with you.