Build the Plan Around Seven Recovery Requirements
A law firm’s disaster recovery plan should define seven requirements: critical legal workflows, recovery priorities, recovery time and data-loss targets, protected backups, alternate operating procedures, assigned response roles, and recurring recovery tests.
For a 25–50 employee law firm, the plan should answer practical questions before an outage occurs:
- How will attorneys access matter documents?
- How will the firm communicate with clients and courts?
- Which systems must be restored first?
- How much recent work can the firm afford to lose?
- Who has authority to declare an emergency?
- How will employees work while systems are unavailable?
- How will leadership know that restored information is complete and safe?
A backup system is only one component of disaster recovery. The complete plan must connect technology restoration with legal deadlines, employee communication, client obligations, vendor coordination, cybersecurity response, and continuity of operations.
Use this seven-part framework to create a recovery plan that protects both confidential information and billable work.
1. Identify the Legal Workflows That Cannot Stop
Begin with the firm’s business processes rather than its servers or software.
Ask partners, administrators, attorneys, paralegals, finance personnel, and other key employees which activities must continue during a technology disruption.
Critical law firm workflows may include:
- Accessing matter documents
- Sending and receiving email
- Communicating with clients
- Meeting court and filing deadlines
- Accessing calendars and docketing systems
- Conducting legal research
- Recording time
- Producing invoices
- Processing payroll
- Receiving client payments
- Using phone and videoconferencing systems
- Accessing practice-management software
Complete a business impact analysis
For each workflow, document:
- The employees who perform it
- The applications and information required
- The vendors involved
- The equipment and connectivity required
- The maximum acceptable interruption
- The financial or legal impact of delay
- Any manual workaround
This process is commonly called a business impact analysis. Its purpose is to identify which operations require the fastest recovery and which can remain unavailable longer without creating unacceptable harm.
Separate urgent work from important work
Every system may feel important, but not every system needs to be restored in the first hour.
For example:
- Email and matter documents may require immediate attention.
- Timekeeping may tolerate a temporary manual process.
- Archived marketing files may remain unavailable for several days.
- A conference-room display may not be a recovery priority.
Prioritization allows the response team to focus limited time and resources on the systems that protect clients, deadlines, revenue, and confidentiality.
2. Create a Tiered Recovery Priority List
Organize systems into recovery tiers so the technical team knows what to restore first.
| Recovery tier | Typical law firm systems | Example target |
|---|---|---|
| Tier 1: Immediate | Email, identity, internet, matter documents, practice management, phones | 0–4 hours |
| Tier 2: Same business day | Timekeeping, billing, scanning, legal research, remote access | 4–12 hours |
| Tier 3: Next business day | Accounting reports, administrative file shares, secondary applications | 12–24 hours |
| Tier 4: Deferred | Archives, training systems, nonessential internal resources | 24–72 hours |
These ranges are examples rather than universal standards. Each firm should set targets based on its practice areas, deadlines, staffing, client commitments, and recovery budget.
Identify system dependencies
A system cannot always be restored independently.
For example, the practice-management platform may depend on:
- Microsoft 365 identity
- Internet access
- A database
- A document repository
- A licensing server
- A vendor-hosted integration
- Multi-factor authentication
The recovery plan should show these dependencies so the team does not attempt to restore systems in the wrong order.
Assign one business owner to each critical system
The business owner confirms whether the recovered system is usable for legal work. Technical staff may be able to verify that an application starts, but an attorney or administrator must confirm that matter information, permissions, dates, documents, and workflows are correct.
3. Define Recovery Time and Data-Loss Targets
Every critical system should have two approved recovery targets.
- Recovery Time Objective: The maximum acceptable period the system can remain unavailable.
- Recovery Point Objective: The maximum amount of recently created or changed information the firm can afford to lose.
Recovery Time Objective example
If the firm sets a four-hour Recovery Time Objective for matter documents, its recovery design should support usable access within four hours after a qualifying disruption.
Recovery Point Objective example
If the firm sets a one-hour Recovery Point Objective, the backup or replication process should be designed so that no more than approximately one hour of recent changes is lost.
Match the target to the business impact
Faster recovery and smaller data-loss windows generally require more resilient systems, more frequent protection, additional infrastructure, and greater cost.
A vCIO or technology advisor should help leadership compare:
- The cost of the recovery design
- The estimated cost of downtime
- The value of recently created work
- Client and contractual expectations
- Court and filing deadlines
- Cyber insurance requirements
- The availability of temporary workarounds
The final targets should be approved by firm leadership rather than chosen solely by the backup vendor or IT provider.
4. Protect Backups From the Same Event Affecting Production
A reliable recovery design should assume that the original environment may be unavailable, damaged, encrypted, deleted, or under investigation.
Backups should include:
- Multiple copies of critical information
- At least one isolated or immutable copy
- Separate administrative credentials
- Encryption during transfer and storage
- Monitoring for failed or incomplete jobs
- Defined retention periods
- Protection for local and cloud-based data
- Documented restoration procedures
- Recurring recovery tests
Do not use the same credentials everywhere
An attacker who compromises a general administrator account should not automatically gain control of production systems, security tools, and backups.
Backup administration should use separate, protected credentials with strong authentication and limited access.
Protect cloud information as well as servers
Moving email and documents to the cloud does not eliminate the need for recovery planning.
The firm should evaluate recovery for:
- Exchange Online mailboxes
- SharePoint sites
- OneDrive files
- Teams-connected documents
- Cloud practice-management platforms
- Cloud accounting systems
- Electronic signature platforms
- Other hosted legal applications
Review the vendor’s native recovery capabilities, retention periods, export options, contractual responsibilities, and whether separate backup protection is appropriate.
Monitor backup failures as urgent events
A failed backup should not remain unnoticed until the firm needs to restore information.
The provider should define:
- Who reviews backup alerts
- How quickly failures are investigated
- When leadership is notified
- How unresolved failures are escalated
- How coverage gaps are documented
911 IT’s business continuity services combine data backup, disaster recovery, continuity planning, and 24/7 support.
5. Document How the Firm Will Operate During an Outage
Disaster recovery restores technology. Business continuity explains how the firm will continue operating until restoration is complete.
For each critical workflow, document a temporary procedure.
Email outage
The plan may identify:
- An emergency communication platform
- A staff notification method
- Approved temporary contact procedures
- Who communicates with clients
- How messages will later be preserved in the official record
Internet outage
The plan may include:
- A secondary internet connection
- Approved mobile hotspots
- Temporary remote-work procedures
- A nearby alternate workspace
- Instructions for accessing cloud systems securely
Document system outage
The firm may use:
- Approved offline matter packets
- Read-only emergency copies
- Controlled exports of critical calendars and contacts
- A temporary secure collaboration area
- A process for reconciling changes after restoration
Timekeeping outage
Attorneys and staff may record time in an approved temporary worksheet or form. The plan should explain how entries will be validated and imported after the system returns.
Phone outage
The firm may redirect the main number, use approved mobile devices, activate a cloud-based alternate, or provide employees with a temporary calling procedure.
Office access problem
A fire, utility failure, building restriction, or severe weather event may make the office unavailable even when technology is functioning.
The plan should address:
- Remote-work capability
- Secure device access
- Mail and package handling
- Physical files
- Client meetings
- Emergency contact information
- Alternate workspace
Every workaround should protect confidentiality. Convenience during an emergency does not justify using personal email, unsecured file-sharing tools, or uncontrolled devices.
6. Assign Recovery Roles Before an Emergency
A disaster recovery plan should identify who makes decisions, who performs technical work, and who communicates with employees, clients, vendors, insurers, and other stakeholders.
Executive incident leader
This person has authority to declare an emergency, approve business priorities, allocate resources, and coordinate leadership decisions.
Technical recovery lead
This person directs containment, system restoration, backup recovery, infrastructure work, and technical vendor coordination.
Legal and compliance lead
This person coordinates legal analysis, preservation requirements, contractual obligations, notification decisions, outside counsel, and regulatory considerations.
Operations lead
This person manages employee instructions, alternate workflows, office logistics, staffing, and business continuity.
Communications lead
This person prepares and approves internal messages, client communications, website notices, and other external statements.
Vendor and insurance coordinator
This person contacts the cyber insurer, forensic resources, telecommunications providers, software vendors, recovery vendors, and other approved third parties.
System business owners
These employees validate that restored applications and information support actual legal work.
Maintain current contact information
The plan should include:
- Primary and alternate contacts
- Business and mobile phone numbers
- Personal or alternate communication channels approved for emergencies
- After-hours vendor numbers
- Insurance policy contacts
- Outside counsel contacts
- Building and utility contacts
A copy of the contact list should remain available outside the primary environment. A plan stored only on the unavailable server cannot guide the response.
7. Test the Plan With Real Restorations and Exercises
A disaster recovery plan is not complete until the firm has tested whether it works.
Testing should include three levels.
Level 1: File and mailbox restoration
Restore selected files, folders, emails, mailboxes, or cloud documents and verify that the content is complete and usable.
Level 2: Application or system restoration
Restore a server, database, application, or representative environment and confirm that users can complete required workflows.
Level 3: Business continuity exercise
Conduct a tabletop or live simulation involving firm leadership, operations, legal, communications, and technology personnel.
A useful exercise may begin with this scenario:
At 8:15 a.m. on a filing deadline, employees cannot open matter documents. Several computers display unusual file names, email access is intermittent, and the backup dashboard cannot be reached.
The participants should work through:
- The first 15 minutes
- The first hour
- The first business day
- Client and court communications
- System restoration priorities
- Insurance and legal coordination
- Employee work instructions
Document every test
The report should identify:
- The date and scope
- The systems and information tested
- The recovery source used
- The elapsed recovery time
- The amount of data loss, if any
- Whether the information was usable
- Whether the approved target was met
- The problems discovered
- The assigned corrective actions
- The next test date
A green backup dashboard is not equivalent to a documented restoration test. Recovery must be demonstrated through usable results.
Use a Four-Phase Recovery Process
During an actual incident, organize the response into four phases.
Phase 1: Assess and contain
- Confirm the incident.
- Identify affected users, systems, and locations.
- Prevent additional damage.
- Protect backups and unaffected systems.
- Preserve logs and evidence.
- Notify the incident leadership team.
Phase 2: Stabilize operations
- Activate temporary communication methods.
- Provide employees with approved instructions.
- Identify urgent client and court deadlines.
- Activate alternate workflows.
- Contact insurers, counsel, and critical vendors as required.
Phase 3: Restore prioritized systems
- Confirm the recovery environment is safe.
- Restore systems in dependency order.
- Validate data integrity and permissions.
- Test critical legal workflows.
- Return users in controlled groups.
Phase 4: Review and improve
- Document the timeline and decisions.
- Identify the cause and contributing factors.
- Update security controls.
- Reconcile temporary records and workarounds.
- Update the recovery plan.
- Assign corrective actions and deadlines.
What Should Be in the Written Recovery Plan?
The plan should contain enough detail to guide action without becoming so complex that no one can use it during an emergency.
Include:
- Purpose and scope
- Incident declaration criteria
- Critical business workflows
- System recovery tiers
- Recovery Time Objectives
- Recovery Point Objectives
- System dependencies
- Response roles and authority
- Emergency contact information
- Backup locations and recovery procedures
- Alternate operating procedures
- Employee communication templates
- Client communication procedures
- Vendor and insurance contacts
- Testing schedule
- Plan maintenance responsibilities
- Version history and approval record
Keep protected copies in multiple locations
Maintain copies that remain accessible when the primary network, Microsoft 365 environment, office, or password manager is unavailable.
Copies may be stored through approved secure methods such as:
- An isolated cloud repository
- A protected emergency portal
- An encrypted offline copy
- A controlled printed executive copy
The plan itself may contain sensitive technical and contact information, so access should be limited and reviewed.
A Practical Plan for a 35-Employee Law Firm
Consider a Salt Lake City law firm with 35 employees, one office, several remote attorneys, Microsoft 365, a cloud practice-management system, a local document server, VoIP phones, and an outsourced IT provider.
The firm identifies five Tier 1 capabilities:
- Identity and authentication
- Matter documents
- Practice management
- Internet and phone communication
Its approved targets include:
| Capability | Recovery time target | Data-loss target |
|---|---|---|
| 4 hours | 1 hour | |
| Matter documents | 4 hours | 1 hour |
| Practice management | 6 hours | 2 hours |
| Phones | 2 hours | Not applicable |
| Billing | 24 hours | 4 hours |
The plan includes:
- Managed backup of the local document server
- An isolated backup copy
- A separate Microsoft 365 recovery strategy
- A secondary internet connection
- Cloud-based phone redirection
- Approved remote-work procedures
- A quarterly file and mailbox restoration test
- A semiannual server recovery test
- An annual leadership tabletop exercise
- A 24/7 emergency support number
The firm also keeps an offline list of current deadlines, key contacts, system owners, and emergency procedures.
This does not guarantee uninterrupted operations. It gives the firm a measured, tested process for reducing downtime and making defensible decisions under pressure.
Example: Accidental Deletion Before a Filing Deadline
An attorney discovers that a matter folder containing final exhibits was deleted the evening before a filing deadline.
A weak response depends on searching recycle bins and hoping a backup exists.
A prepared response follows a documented process:
- The attorney contacts the 24/7 support line.
- The service desk records the affected matter, folder, user, and time.
- The technical team determines whether deletion, synchronization, or malicious activity occurred.
- The team identifies the most appropriate recovery source.
- The folder is restored to a controlled location.
- The responsible attorney verifies every required document.
- The team documents the recovery time and any missing changes.
- The event is reviewed for preventive improvements.
The difference is not merely having a backup. It is having an established path from incident report to verified legal use.
Example: Ransomware Disrupts the Office
Employees arrive Monday morning and discover that documents on several systems have been renamed and cannot be opened.
The response team should:
- Activate the incident plan.
- Isolate affected devices and accounts.
- Protect backup systems from further access.
- Determine whether the activity is continuing.
- Identify urgent court and client deadlines.
- Activate approved communication and workarounds.
- Coordinate with the insurer, counsel, and forensic resources.
- Confirm that the recovery environment is safe.
- Restore Tier 1 systems in dependency order.
- Validate information before returning users.
The firm should not restore systems blindly before containment. Otherwise, recovered systems may be compromised again or important evidence may be lost.
Example: The Office Is Unavailable for Three Days
A building incident prevents employees from entering the office, but cloud services remain available.
The continuity plan should address:
- How employees receive instructions
- Which employees have approved laptops
- How phone calls are redirected
- How physical mail is handled
- Where client meetings occur
- How paper files are accessed
- How employees report access problems
- How leadership monitors deadlines and staffing
A disaster does not need to damage servers to disrupt legal work. The plan must account for loss of facilities, people, communications, vendors, and utilities as well as technology failure.
What Law Firm Leaders Should Ask Every Quarter
- When was the last successful restoration test?
- What exactly was restored?
- How long did recovery take?
- Did the test meet the approved target?
- Which systems are not currently protected?
- Have any backup jobs failed repeatedly?
- Are cloud applications included in the recovery plan?
- Are backup administrator credentials separated from daily accounts?
- Has the contact list changed?
- Which recovery risks remain unresolved?
Read the six questions smart law firms should ask their IT provider every quarter for a broader review of cybersecurity, support, recovery, and accountability.
What Law Firm Clients Value During a Disruption
Customer feedback collected by 911 IT repeatedly emphasizes the importance of fast access to knowledgeable technicians, clear communication, and ownership through resolution.
Clients value a provider that:
- Answers through a live support channel
- Responds quickly during urgent situations
- Understands the client’s systems and vendors
- Explains the recovery process clearly
- Coordinates interconnected services
- Remains involved until operations are stable
- Identifies preventive improvements afterward
One legal-services client described depending on 911 IT for email, electronic court filing, legal research, and document access. The client emphasized the value of reaching a live technician and receiving patient assistance until the issue was resolved.
Another legal-industry client valued having one provider understand its IT, phone, and hosting environment. That familiarity reduced downtime and made it easier to coordinate recovery across multiple systems.
These experiences reinforce a core continuity principle: the recovery technology and the support process must be designed together.
25-Point Law Firm Disaster Recovery Checklist
- The firm has completed a business impact analysis.
- Critical legal workflows are documented.
- Systems are organized into recovery tiers.
- Every critical system has an approved Recovery Time Objective.
- Every critical data set has an approved Recovery Point Objective.
- System dependencies are documented.
- Every critical system has a business owner.
- Local servers are protected by monitored backups.
- Cloud data has an approved recovery strategy.
- At least one backup copy is isolated or immutable.
- Backup administration uses separate credentials.
- Backup failures are actively investigated.
- Alternate communication procedures are documented.
- Remote-work procedures are tested.
- Internet and phone alternatives are defined.
- Incident leadership roles are assigned.
- Current emergency contacts are available offline.
- Cyber insurance and outside counsel contacts are documented.
- Employee instructions are prepared in advance.
- Client communication procedures are defined.
- A file or mailbox has been restored recently.
- A critical system has undergone a recovery test.
- Leadership has completed a tabletop exercise.
- Test findings have assigned owners and deadlines.
- The plan is reviewed at least annually and after major changes.
Any answer of “no,” “probably,” or “our provider says the backups are fine” should become a documented action item.
Common Disaster Recovery Mistakes
Equating backup success with recoverability
A completed backup job does not prove that data is complete, applications will start, or attorneys can resume work within the required timeframe.
Testing only individual files
File restoration is important, but the firm should also test complete applications, system dependencies, permissions, and legal workflows.
Ignoring cloud applications
Cloud vendors provide resilient infrastructure, but the firm still needs to understand deletion recovery, retention, exports, account compromise, service interruptions, and vendor responsibilities.
Keeping the recovery plan only on the main network
The plan must remain accessible when the primary systems are unavailable.
Setting unrealistic recovery targets
A one-hour recovery target has little value when the firm has not funded or designed a system capable of meeting it.
Failing to assign decision authority
Technical teams can lose critical time when no one has authority to declare an emergency, approve downtime, contact insurers, or prioritize systems.
Restoring before containment
Restoring into a compromised environment can lead to repeated encryption, reinfection, or evidence loss.
Forgetting employee workarounds
Technology restoration may take hours or days. The firm needs approved procedures for continuing urgent legal work during that period.
Failing to update the plan
Employee changes, new applications, vendor changes, office moves, and cloud migrations can make an old recovery plan inaccurate.
Frequently Asked Questions
What is the difference between backup, disaster recovery, and business continuity?
Backup creates recoverable copies of information. Disaster recovery restores technology and data after disruption. Business continuity explains how the organization will continue critical work while normal systems, facilities, or people are unavailable.
How often should a law firm test backups?
Critical recovery processes should be tested on a recurring schedule, often quarterly. More frequent testing may be appropriate for systems with strict recovery targets or frequent changes.
How long should law firm recovery take?
There is no universal target. Each system should have a recovery time based on legal deadlines, client needs, financial impact, available workarounds, and the cost of recovery infrastructure.
Should Microsoft 365 be backed up?
The firm should evaluate Microsoft’s native retention and recovery capabilities against its own requirements for retention, restoration speed, independence, version recovery, and administrative control. A separate backup service may be appropriate when native capabilities do not meet those needs.
What is an immutable backup?
An immutable backup is protected against alteration or deletion for a defined period. It can reduce the risk that ransomware or a compromised administrator will destroy every recovery copy.
Who should approve recovery priorities?
Firm leadership should approve priorities with input from attorneys, administration, finance, legal counsel, and technology advisors. The IT provider should not make business-impact decisions alone.
Does cyber insurance replace a recovery plan?
No. Insurance may provide access to approved legal, forensic, notification, and recovery resources, but the firm still needs protected backups, continuity procedures, assigned roles, current contacts, and tested restoration capabilities.
Should a recovery plan include paper files?
Yes, when physical files are necessary for critical work. The plan should address office access, secure storage, duplication, retrieval, and alternate procedures.
How often should the written plan be updated?
Review it at least annually and after significant changes such as new applications, office moves, mergers, staffing changes, provider changes, major incidents, or failed tests.
Can a small firm create an effective recovery plan?
Yes. A smaller firm may have fewer systems, but it still needs defined priorities, recovery targets, protected backups, assigned roles, workarounds, and tests. The plan can be concise as long as it is specific and usable.
Recovery Must Be Proven Before the Emergency
A strong law firm disaster recovery plan connects seven elements:
- Critical legal workflows
- Tiered recovery priorities
- Approved time and data-loss targets
- Protected backups
- Alternate operating procedures
- Assigned response roles
- Documented recovery tests
The standard should not be whether backup software reports success. The standard should be whether the firm can restore usable information, resume critical legal work, communicate clearly, and meet approved recovery targets.
911 IT provides Utah law firms with protected data backup, disaster recovery planning, Microsoft cloud expertise, managed cybersecurity, live 24/7 support, local on-site service, and proactive technology guidance.
Explore our business continuity services, read why many law firms overestimate their recovery readiness, or schedule a 10-minute discovery call to review your firm’s recovery risks and testing process.
