When a server fails, a building floods or ransomware locks every file at 7 a.m. on a Monday, nobody wants to be inventing a plan. A written disaster recovery plan, or DR plan, tells everyone what to do, in what order and who decides. It does not need to be a hundred-page binder. For most small and mid-size firms, ten to fifteen well-organized pages are enough, as long as they are accurate and reachable when the network is down.
Courts do not pause for firm outages, and clients expect their lawyers to keep working. A good plan protects deadlines, confidentiality and the firm's reputation.
Section 1: Purpose and scope
State which systems and locations the plan covers and which events it addresses: hardware failure, cyberattack, fire, flood, extended power loss, loss of internet and loss of a key person. Define who can declare a disaster, usually the managing partner or a named delegate, and who is the backup if that person is unavailable.
Section 2: Contact list
Keep an up-to-date list with mobile numbers, not just office extensions.
- Firm leadership and decision makers.
- IT provider and emergency escalation numbers.
- Internet, phone and key software vendors, including account numbers or support PINs.
- Cyber insurance carrier and broker, with the claim reporting line.
- Outside counsel for breach response.
- Building management and landlord.
- Bank contacts for wire and trust account issues.
Section 3: Critical systems and priorities
Rank systems by how fast the firm needs them. A simple tiering works.
- Tier 1, hours: email, phones, practice management, document access and calendar and deadline tracking.
- Tier 2, a day or two: billing, accounting and trust reporting, scanning and e-filing tools.
- Tier 3, longer: archived matters, marketing systems and internal wikis.
For each system, record the recovery time objective and recovery point objective: how long it can be down and how much data could be lost. Make sure your backups can really meet them.
Section 4: Backup and recovery details
Document where backups live, how often they run, who can restore them and how to reach credentials if the main network is unavailable. Record the location of any offline copy. Include step-by-step recovery instructions for each Tier 1 system, written so a competent person who did not build the system could follow them.
Section 5: Work continuity
Describe how people keep working. Can staff work from home on firm laptops? Is there a secondary office or a shared workspace you could use? How are phones forwarded? Where are court deadlines tracked if the calendar is down? Keep a printed or offline list of critical upcoming deadlines, updated weekly, because it can save you in an outage.
Section 6: Communication
Plan how you will reach people if email is out. A group text, a messaging app account or a call tree works. Draft templates in advance for clients, courts and staff, and decide who approves messages. Rule 1.4 emphasizes keeping clients reasonably informed, and a prepared message makes that easier under pressure.
Section 7: Cyber incident annex
If the disaster is a cyberattack, the steps differ. Include isolating affected devices, contacting the carrier before engaging vendors if the policy requires it, preserving evidence, engaging breach counsel and assessing notification duties. ABA Formal Opinion 483 discusses a lawyer's obligations after a breach, and state laws vary. Never restore from backups until the intrusion is understood, or you may reintroduce the attacker.
Section 8: Roles and responsibilities
Name an incident lead, an IT lead, a communications lead and a records lead, each with a backup. Clear roles stop confusion in the first hour.
Section 9: Testing and maintenance
A plan that is never exercised fails. Run a tabletop exercise once a year: walk through a scenario and note gaps. Test restores quarterly. Update the plan after staff, vendor or system changes, and keep a revision history.
Where to store the plan
Keep copies somewhere independent of your network: printed in a secure location, in a personal cloud account of the incident lead with proper protection or on a secured device. A plan stored only on the server that failed is of limited help.
Getting help
Counsel Cyber builds and tests DR plans for law firms, including tabletop exercises with partners and staff. If your firm does not have one, we can draft it with you.