Infographic on law firm data backup and ransomware preparedness with five-part framework and recovery tips.

How Should a Law Firm Back Up Its Data and Prepare for Ransomware?

September 11, 2026

How Should a Law Firm Back Up Its Data and Prepare for Ransomware?

For a law firm with 20 to 75 employees, a backup strategy should do more than copy files somewhere every night.

A practical recovery plan should answer at least 5 questions: what is protected, how often it's backed up, where recovery copies exist, whether restores are tested, and how the firm would continue operating after a serious outage or ransomware incident.

The most important question isn't:

"Do we have backups?"

It's:

"If our systems or data became unavailable today, could we actually recover them—and how long would that take?"

For law firms throughout the Greater Sacramento region and Northern Nevada, we recommend evaluating backup and recovery using a five-part framework:

Protect. Separate. Monitor. Test. Recover.

Here's what each one means.

The 5-Part Backup and Recovery Framework for Law Firms

A mature backup strategy should address five areas.

1. PROTECT

Identify the systems and information the firm cannot afford to lose.

2. SEPARATE

Avoid depending on one system, device, or location for recovery.

3. MONITOR

Know whether backups are actually completing.

4. TEST

Verify that important information can be restored.

5. RECOVER

Have a plan for getting attorneys and staff working again.

A backup product alone doesn't accomplish all five.

Someone needs to manage the process.

1. PROTECT: Know What Your Law Firm Actually Needs to Recover

Start with the business rather than the backup software.

Ask:

What technology would prevent our attorneys and staff from working if it disappeared tomorrow?

Depending on the firm, that may include:

  • Legal documents
  • Client files
  • Microsoft 365
  • Email
  • SharePoint
  • OneDrive
  • Servers
  • File shares
  • NetDocuments
  • Worldox
  • Practice-management applications
  • Accounting information
  • Employee data
  • Other business applications

Not every system will necessarily be backed up by your MSP.

Some cloud applications have their own data-protection and recovery models.

Some legal applications may be hosted and managed by the software provider.

The important thing is knowing who is responsible for what.

Microsoft 365 Doesn't Eliminate the Backup Conversation

Moving information to Microsoft 365 changes how data is stored and protected.

It doesn't eliminate the need for recovery planning.

Your firm may rely heavily on:

  • Exchange Online
  • OneDrive
  • SharePoint
  • Teams

Leadership should understand what information resides in each system and what recovery options exist.

The question shouldn't simply be:

"Is Microsoft protecting it?"

Ask instead:

"If an employee deletes something important, an account is compromised, or information becomes unavailable, what exactly is our recovery process?"

Your MSP should be able to explain that clearly.

2. SEPARATE: Don't Put All Your Recovery Options in One Basket

A backup is less useful if the same incident that damages production data can also destroy the recovery copy.

That's why separation matters.

The specific architecture depends on the firm's environment, but the principle is straightforward:

Your recovery strategy should not depend on the exact same failure point as your production environment.

For example, if a server fails, the backup shouldn't exist only on that server.

If credentials are compromised, your recovery architecture should consider whether those same credentials can affect backup systems.

If the office experiences a larger physical event, leadership should understand how that affects recovery.

The objective is resilience.

3. MONITOR: Somebody Needs to Know When a Backup Fails

Backups can fail.

Storage fills up.

Credentials change.

Software stops communicating.

A device goes offline.

A job completes with errors.

If nobody is monitoring the system, a backup problem can exist for days or weeks before anyone notices.

The worst time to discover that is during an actual recovery.

What Should Be Monitored?

Depending on the environment, your provider should understand:

  • Whether backup jobs completed
  • Whether errors occurred
  • Whether protected systems are checking in
  • Whether storage capacity is sufficient
  • Whether expected data is being protected
  • Whether failures require investigation

The objective isn't generating a report full of green checkmarks.

It's identifying problems before you need the backup.

4. TEST: A Successful Backup Isn't the Same as a Successful Restore

This distinction is critical.

Imagine your backup software reports:

SUCCESSFUL

every night.

Then a server fails.

You attempt recovery.

And discover the data isn't usable in the way you expected.

The backup technically existed.

The recovery strategy failed.

That's why restore verification matters.

Ask Your MSP This Question

"When did we last verify that our critical information could actually be restored?"

They should be able to answer.

The appropriate testing process depends on the environment and systems involved.

But "we've never tried" isn't a strong recovery strategy.

5. RECOVER: Know What Happens After the Incident

Suppose your law firm arrives Monday morning and a critical system is unavailable.

What happens next?

Who calls whom?

Which system gets restored first?

How will employees communicate?

Can attorneys access critical documents?

What vendors need to be contacted?

Does the firm have an alternate way to perform essential work?

Those questions move the conversation from backup to business continuity.

Backups protect information.

Business continuity focuses on keeping the organization operating.

You need both.

Backup vs. Disaster Recovery vs. Business Continuity

These terms are related, but they're not identical.

Backup

Creates recoverable copies of information.

Disaster Recovery

Defines how technology systems and information will be restored after a major failure.

Business Continuity

Addresses how the business continues functioning during and after the disruption.

A law firm can technically have backups without having an effective disaster-recovery or business-continuity plan.

That's why asking only:

"Do we have backups?"

doesn't tell leadership enough.

How Does Ransomware Change the Recovery Conversation?

Ransomware can turn an ordinary backup discussion into a much larger cybersecurity issue.

A ransomware incident may affect:

  • Workstations
  • Servers
  • Files
  • Credentials
  • Applications
  • Employee productivity

Recovery may require more than restoring files.

Before normal operations resume, the organization may need to understand:

  • What happened
  • Which systems were affected
  • Whether attacker access remains
  • Which credentials need attention
  • Whether systems can be trusted
  • What should be restored
  • In what order systems should return

That's why ransomware preparation should involve both cybersecurity and recovery planning.

Backups Are the Last Line, Not the First Line

A good ransomware strategy shouldn't begin with:

"We'll just restore from backup."

The better objective is preventing the incident from reaching that point.

At Integral Networks, our managed security approach uses multiple layers, including technologies and services such as:

  • Microsoft 365 Business Premium
  • Avanan email security
  • Deep Instinct endpoint protection
  • Blokworx managed security services
  • Managed patching
  • Microsoft 365 security configuration
  • Ongoing monitoring

Backup and recovery are part of the resilience strategy.

They're not a substitute for cybersecurity.

How Email Security Helps Reduce Ransomware Risk

Email is one potential entry point for malicious activity.

An employee may receive:

  • A malicious attachment
  • A phishing link
  • A fake Microsoft login
  • An impersonation attempt

That's why Integral Networks uses Avanan as part of our email security approach.

The objective is to identify suspicious content before an employee interacts with it whenever possible.

But no email platform catches everything.

That's why email protection works alongside authentication, endpoint protection, monitoring, patching, and employee awareness.

How Endpoint Protection Fits Into Recovery

Employee computers also need protection.

Integral Networks uses Deep Instinct endpoint protection as part of our managed security stack.

The objective is prevention.

But if an incident does occur, endpoint visibility also becomes important in understanding which systems may have been affected.

Again, this is why layered security matters.

You don't want your entire ransomware strategy depending on a single control.

A Hypothetical Law Firm Recovery Scenario

Consider a 40-person law firm.

Employees arrive Monday morning and discover that a critical system containing information needed for daily work is unavailable.

Suppose 20 employees are significantly affected for four hours.

That's already:

20 employees × 4 hours = 80 employee-hours

of disrupted productivity.

And that doesn't include:

  • Attorney deadlines
  • Client impact
  • IT recovery costs
  • Management time
  • Vendor coordination
  • Potential after-hours work

Now compare two environments.

Firm A

Leadership knows backups exist but doesn't know:

  • Who monitors them
  • When restores were tested
  • What systems have priority
  • Which vendors need involvement
  • How employees would work during recovery

The incident immediately becomes a discovery exercise.

Firm B

The environment is documented.

Backup status is monitored.

Recovery responsibilities are known.

Critical systems have been identified.

Vendors are documented.

The MSP has a defined escalation process.

The incident is still disruptive.

But the team isn't inventing the recovery plan while the business is down.

That's the difference planning makes.

How Quickly Should a Law Firm Be Able to Recover?

There isn't one universal answer.

A firm's acceptable recovery time depends on the system and business impact.

An archived file may tolerate a longer recovery period.

A system attorneys depend on throughout the day may not.

That's why leadership and the IT provider should discuss two concepts:

Recovery Time Objective

How long can the business reasonably tolerate the system being unavailable?

Recovery Point Objective

How much recent information could the business tolerate losing?

The appropriate answers depend on the firm's applications, workflows, technology, and business requirements.

The important thing is that someone has asked the questions.

Prioritize Systems Before Something Breaks

Not every technology system has the same business importance.

A useful exercise is to place systems into three categories.

Tier 1 — Critical

The firm cannot operate normally without them.

Tier 2 — Important

The outage significantly affects productivity, but temporary workarounds may exist.

Tier 3 — Non-Critical

The system can remain unavailable longer without materially affecting the firm's immediate ability to operate.

Once those priorities are understood, recovery planning becomes much more useful.

Your MSP knows what matters first.

Your Legal Application Vendors Matter Too

Law firms may depend on systems such as:

  • NetDocuments
  • Worldox
  • Practice-management platforms
  • Accounting applications
  • Other specialized legal software

Some may be cloud-hosted.

Some may run internally.

Some may involve both your MSP and the software vendor.

Your recovery plan should identify:

  • Who supports the application
  • Where the data resides
  • What recovery capabilities exist
  • Who needs to be contacted during an outage
  • What your MSP is responsible for
  • What the vendor is responsible for

That information should be documented before an incident.

The 10-Question Law Firm Backup and Recovery Check

Ask your current IT provider these questions:

  1. What exactly are we backing up?
  2. How often are backups performed?
  3. Who monitors backup failures?
  4. Where are our recovery copies located?
  5. When did we last verify a restore?
  6. What are our most critical systems?
  7. How quickly could we reasonably recover those systems?
  8. What Microsoft 365 recovery protections do we have?
  9. Which legal application vendors are part of our recovery plan?
  10. What happens if ransomware affects multiple systems?

Give yourself one point for every answer that's:

"I don't know"

or:

"I'm not sure."

0-2 Points

Leadership appears to have good visibility into the recovery strategy.

3-5 Points

Several areas deserve clarification.

6-10 Points

Your backup and recovery strategy deserves a more comprehensive review.

This isn't a technical backup audit.

It's a test of whether leadership actually understands how the firm would recover.

The 5 Warning Signs Your Backup Strategy Needs Attention

Look more closely if:

1. Nobody Can Explain What Is Backed Up

"We back up everything" isn't specific enough.

2. Nobody Knows When a Restore Was Last Verified

Backup success without recovery verification leaves an important question unanswered.

3. Backup Failures Aren't Actively Monitored

You shouldn't discover backup problems during an emergency.

4. Your Recovery Plan Exists Only in One Person's Head

Processes and responsibilities should be documented.

5. Your Firm Has Never Discussed Recovery Priorities

Your MSP needs to know which systems matter most to the business.

What Should Your MSP Be Doing?

For a 20-75 employee law firm, backup and recovery shouldn't operate independently from the rest of managed IT.

Your MSP should understand the relationship between:

Security

Prevent incidents where possible.

Monitoring

Identify problems quickly.

Documentation

Know how the environment works.

Backup

Maintain recoverable information.

Recovery

Restore technology after a failure.

Planning

Determine priorities before an incident.

That's the framework.

Backup and Recovery for Greater Sacramento Law Firms

Integral Networks supports law firms throughout the Greater Sacramento region, including Sacramento, Roseville, Rocklin, Folsom, Elk Grove, Woodland, Stockton, Modesto, and surrounding communities.

Our primary focus is organizations with 20 or more employees that need proactive IT management, cybersecurity, responsive support, and strategic planning.

Sacramento, CA: (916) 626-4000

Backup and Recovery for Northern Nevada Law Firms

Our second primary service area is Northern Nevada, including Reno, Sparks, Carson City, and surrounding communities.

We combine remote monitoring and management with local onsite capabilities when physical assistance is necessary.

Reno, NV: (775) 446-4100

Final Thoughts

A backup isn't successful because software displays a green checkmark.

It's successful when your business can recover the information it needs.

For law firms, use the five-part framework:

Protect.

Separate.

Monitor.

Test.

Recover.

Know what matters.

Protect it appropriately.

Monitor the protection.

Verify recovery.

And have a plan for getting employees working again.

Because when something serious happens, the question leadership cares about isn't:

"Did last night's backup job complete?"

It's:

"How quickly can we get the firm operating again?"

Ready for a Second Opinion?

If you're not confident you can answer the 10 backup and recovery questions above, Integral Networks can review your current environment and help identify gaps in backup, cybersecurity, documentation, monitoring, and recovery planning.

We provide managed IT, cybersecurity, Microsoft 365 management, backup oversight, vendor management, and strategic technology planning for law firms throughout the Greater Sacramento region and Northern Nevada.
:::

Related Articles

How Should a Law Firm Secure Microsoft 365 and Email?

What Should a Law Firm Expect From Its Managed IT Provider?

The 7 Biggest IT Problems We Find When Taking Over a New Law Firm

What Does Good Cybersecurity Look Like for a 20-75 Employee Business?

How Long Should It Take Your IT Provider to Respond to a Support Request?

Link copied to clipboard!