A Backup and Recovery Plan You Can Explain in Five Minutes

The 3-2-1 backup rule translated for a law firm, with a short checklist and the one test almost every office skips: actually restoring a file.

A dimly lit server room with rows of blinking storage drives and network cables
Jump to section
  1. The Three Copies Every Firm Needs
  2. Onsite, Offsite, and Offline Explained
  3. What to Back Up Beyond the Documents
  4. Test a Restore Before You Need One
  5. Write Down Who Does What When Things Fail
  6. The Whole Plan, on One Card

A partner once told me the firm was "fully backed up." Then a bookkeeper opened a bad attachment, ransomware ran overnight, and the backup turned out to be a single external drive that had been unplugged since a move eighteen months earlier. Nobody had checked. That is the story behind most backup disasters: not the absence of a plan, but the quiet failure of one everybody assumed was working.

You do not need an enterprise IT department to be safe. You need a plan simple enough to say out loud, and honest enough that you have actually tested it. Here it is, in checklist form.

The Three Copies Every Firm Needs

The classic rule is called 3-2-1, and it has survived decades because it is easy to remember and hard to argue with. Three copies of your data. Two different kinds of storage. One copy kept somewhere else entirely.

  • Three copies. Your live working data counts as one. You need two more that are genuine copies, not the same file synced to two screens.
  • Two media. Do not keep every copy on the same type of device in the same room. A local drive plus a cloud service, for example, so one hardware fault or one flood cannot take everything.
  • One offsite. At least one copy has to live away from the office, physically or in a separate cloud region, so a fire, theft, or burst pipe does not erase your practice.

Sync is not backup. A folder that mirrors your desktop to the cloud will faithfully mirror a deletion or an encryption attack too. Real backups keep older versions you can roll back to.

Tip. Write your three copies on one line: where copy one lives, where copy two lives, where copy three lives. If you cannot fill in all three from memory, you do not have a 3-2-1 setup yet.

Onsite, Offsite, and Offline Explained

People mix these three words up, and the difference matters when something goes wrong.

TypeWhat it meansProtects against
OnsiteA copy in your office, like a local server or driveFast recovery from an accidental delete or a single dead file
OffsiteA copy in another location or cloud regionFire, flood, theft, a building you cannot enter
OfflineA copy nothing can reach over the networkRansomware, which spreads to every drive it can touch

Offline is the one small firms skip, and it is the one that saves you from ransomware. If every copy is reachable from an infected machine, malware can encrypt all of them at once. An offline copy, whether a drive you unplug and lock away or an immutable cloud snapshot that cannot be altered for a set number of days, gives you a clean starting point. That immutability question belongs on your vendor vetting checklist.

What to Back Up Beyond the Documents

Ask most people what they are protecting and they will say "the files." Documents matter, but your practice runs on more than a folder of PDFs.

  1. Matter and client records. The data in your practice management system: parties, deadlines, notes, the connective tissue that tells you which document belongs to whom.
  2. Accounting and trust ledgers. Losing trust records is not just inconvenient, it is a law society problem. These need the same care as your client files, and often more.
  3. Email. Years of client correspondence and instructions. Do not assume your provider keeps it forever; check the retention setting.
  4. Calendars and limitation deadlines. A rebuilt file with no limitation date is a malpractice claim waiting to happen.
  5. Configuration. Templates, custom fields, user accounts, the setup that took months to tune. Rebuilding it from scratch is its own outage.

If your firm keeps matters, billing, and trust in one system, confirm how that system is backed up and how you would get a copy out. A1 CMS keeps these records together, so one restore brings back the whole picture rather than a scattered set of exports. Whatever you use, the question is the same: what exactly comes back, and how fast.

Watch out. If you cannot read your data without the vendor's software, you do not fully control it. Ask for your data in a portable format and store a copy you can open independently.

Test a Restore Before You Need One

This is the step almost everyone skips, and it is the whole point. Until you have actually restored a file, you do not know whether your backup works. The only way to find out is to bring something back and open it.

Schedule a real test at least twice a year. Pick a file, or better yet a full matter, and actually recover it to a separate location. Open it. Confirm it is complete and current. Note how long it took, because "we can restore" and "we can restore by Tuesday" are very different answers when a client is on the phone.

The first time you restore a file should never be the day you desperately need it. Every IT person who has watched a firm learn this the hard way

Two numbers make this concrete. Your recovery point is how much work you are willing to lose, which decides how often you back up. Your recovery time is how long you can be down before it hurts. Put a real figure on each. A litigation practice mid-trial and a solicitor's office between closings will answer differently, and both are fine as long as they are deliberate. It is the same muscle you build for a broader remote work security plan: decide the standard first, then measure against it.

Write Down Who Does What When Things Fail

The last piece is the least technical and the most neglected. When the drive dies at 4:45 on a Friday, panic fills the gap left by a missing plan. So write the plan while everyone is calm.

  • Who notices. Someone owns checking that backups actually ran. A silent failure is the most dangerous kind, because you find out only when you reach for the copy that was never made.
  • Who to call. Your IT contact, your software vendors, your law society's practice advisor if client data or trust records are involved. Numbers on paper, not buried in the system that just went down.
  • Who tells clients. If a deadline is at risk, someone has to communicate, and honestly. Decide in advance who speaks and what they say.
  • Where the plan lives. Printed and offline. A recovery plan trapped inside the system you are recovering is no plan at all.

Keep it to one page. If it runs longer, nobody reads it under pressure, which is the only time it matters. Store the printed copy where the people on call can find it, and refresh it whenever a tool or a phone number changes. For the human habits that prevent half these incidents, pair this with firm-wide MFA and a shared sense of how phishing gets in.

The Whole Plan, on One Card

Here is everything above, short enough to pin above a desk:

Three copies. Two kinds of storage. One offsite, one offline. Back up documents, records, trust ledgers, email, and setup. Test a restore twice a year and time it. Keep a one-page, printed plan naming who checks, who calls, and who tells clients.

None of this needs a big budget or a specialist on staff. It needs a decision and a recurring reminder. Book the first restore test for a quiet afternoon this month, walk one file all the way back, and write down what you learn. The firms that recover gracefully are not the ones with the most expensive tools. They are the ones who practised before the bad day arrived. For more of this practical footing, the rest of our legal tech and security writing and the knowledge base pick up where this leaves off.

Priya Natarajan

Legal technology editor

Priya covers where legal work and software meet, with a healthy skepticism for hype and a soft spot for tools that quietly save hours.

Run your firm on one calm platform

Matters, billing, trust accounting, client portal, and automation, together in A1 CMS. Try it free, no card required.