ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Three Copies, Two Media, One Offsite: Backups for Law Firm Data

The 3-2-1 backup rule is a simple framework: three copies, two media, one offsite. Learn how it applies to a law firm's servers, cloud files and laptops.

3 min readBy Counsel Cyber Team

Ask a law firm whether it has backups and the answer is almost always yes. Ask where the copies live, how old they are and whether anyone has tried to restore from them, and the answers get less certain. The 3-2-1 rule is a widely used way to organize the conversation.

It is not a product. It is a pattern: keep three copies of your data, on two different types of storage, with one copy offsite. A common modern addition is that at least one copy should be offline or immutable, so an attacker or a mistake cannot alter it. Here is what each part means for a firm.

Three copies

The three copies include the original, the live data your staff use every day, plus two backups. The point is redundancy. If a single backup is corrupted or an attacker deletes it, a second copy survives.

A common mistake is counting a sync service as a backup. A file synchronization tool replicates changes, including deletions and encrypted files from ransomware. A backup preserves earlier versions that you can go back to.

Two types of storage

Using two different kinds of storage reduces the chance that one failure takes out everything. For instance, one copy on a local appliance and one in cloud storage. A firm that keeps its only backup on a drive plugged into the same server has one point of failure and one target for ransomware.

One copy offsite

A fire, flood, tornado or burglary at the office can destroy servers and the backup device next to them. Firms in Texas, Oklahoma, Arkansas, Louisiana and Kansas are no strangers to severe weather. An offsite copy, usually in a cloud data center, protects against local disasters and makes remote recovery possible if the office is inaccessible.

The modern addition: offline or immutable

Ransomware operators know firms rely on backups, and they often try to find and destroy them before demanding payment. A copy that cannot be changed for a set period, called an immutable backup, or one that is physically disconnected, is much harder to attack. Ask your provider whether your backups have this property and how it is enforced.

Also separate the credentials. If the same administrator account manages production systems and backups, an attacker who captures it can erase both. Backup administration should use distinct accounts with MFA.

What should be in scope

Firms often forget systems that matter.

  • File servers and document management repositories.
  • Practice management and billing data, if not fully vendor-hosted.
  • Email and calendars in Microsoft 365, which are not automatically backed up in the way many people assume.
  • Accounting and trust accounting systems.
  • Laptops and mobile devices holding local files.
  • Configuration of firewalls, servers and key applications, so you can rebuild.

Cloud platforms generally operate on a shared responsibility model. The provider keeps the service running, but you are typically responsible for protecting your data from deletion, corruption and misuse. Confirm what your vendors back up and for how long.

Questions to ask your IT provider

  1. What are we backing up, and what is excluded?
  2. How often does each backup run?
  3. Where are the copies stored, and which are immutable or offline?
  4. How long are backups retained?
  5. Are backups encrypted, and who holds the keys?
  6. When did we last perform a test restore, and what were the results?
  7. How long would it take to restore our most important systems?

If the answers are vague, that is information.

Retention and ethics considerations

Retention should reflect both your client file obligations and your own policies. State rules on file retention vary, so confirm yours with your state bar. Make sure backup retention does not conflict with your records policy, and that deleted client data does not survive indefinitely in places no one is managing.

Test it

A backup that has never been restored is an assumption. Schedule regular restore tests, including a full recovery exercise at least once a year, and record the results. We will cover restore testing in more detail in a separate post.

Where to go from here

Counsel Cyber designs backup and disaster recovery for law firms with immutable copies, separate credentials and documented restore tests. If you would like to compare your current setup against 3-2-1, we can run a short assessment and give you a plain-English summary.