IT First Response

Guides

Microsoft is not your backup: what a law firm actually needs

By Mario Del MazoAugust 2, 20266 minute read

Ask ten small firms whether their email is backed up and nine will say yes, because it is in the cloud. Most of them are wrong. What Microsoft sells is uptime: the service will be running, your data will not be lost to a failed Microsoft hard drive. What it does not sell is protection from the ways firms actually lose data, a mailbox emptied by an attacker, a matter folder deleted and discovered eight months later, ransomware that encrypts the desktop and syncs the damage neatly into the cloud. This guide covers what a real backup for a law firm looks like, the legal-specific requirements generic setups miss, and the one question that tells you whether yours is real.

Does Microsoft 365 back up your email?

Not in the sense the question means. Microsoft runs the service on redundant infrastructure and honors your retention settings, and that is the whole promise. Deleted items eventually purge. Ransomed files sync. An account takeover comes with the attacker's deletions included. Microsoft's own agreements describe this as shared responsibility: they run the platform, and protecting your data in it is your job. The fix is a third-party backup that copies email, OneDrive, SharePoint, and Teams out of the tenant every day, into storage the tenant's credentials cannot touch. For most small firms this is the single biggest gap in their setup, and they find out at the worst possible moment.

What a real backup looks like: 3-2-1-1-0

The standard worth holding any setup against is five numbers. Three copies of your data. On two different kinds of storage. One of them offsite. One of them immutable, meaning written so that nobody, not even an administrator, can alter or delete it during its retention window. And zero errors on a test restore you have actually performed. The last two numbers are the modern ones, and they are the ones that defeat ransomware, because attackers now wipe or encrypt backups first and squeeze the firm second. A backup that the day-to-day admin password can delete is not a safety net; it is one more thing on the list of what the attacker gets.

More of the firm needs backing up than you think

Email is only the obvious piece. A backup plan for a law firm has to account for the document store, wherever it lives; the practice management system, which for cloud platforms means periodically exporting your own data into storage you control so the firm is never entirely dependent on one vendor; the trust accounting and bookkeeping records; any file server still humming in a closet; and the laptops, where the honest fix is keeping working files in managed storage that already inherits the backup instead of on desktops that quietly hold the only copy of something important.

The legal-specific requirements generic setups miss

Every backup a firm makes is a copy of privileged client information, and that changes the requirements. The copies must be encrypted in transit and at rest. The storage should sit in US data centers, under a written agreement with the vendor about how your data is handled. Retention has to match the firm's record schedule, which is measured in years, while many backup products ship with a 30-day default that silently contradicts it. And the setup must respect legal hold: data the firm has a duty to preserve cannot be sitting in a system that auto-purges on a timer. None of this is exotic, but almost none of it is how a generic small-business backup gets configured by default.

The one question that proves it

Whoever runs your backups, ask them this: when did you last restore something, and can I see the note? A backup you have never restored from is a hope, not a plan, and the difference only surfaces on the day it matters most. A provider doing this properly restores something on a schedule, a mailbox item, a document, periodically a whole system, writes down the date and the result, and can show you the record without scrambling. That record is also exactly what a cyber-insurance carrier means when its questionnaire asks whether backups are tested, which is why the same habit that protects the firm also holds up the coverage. It is one of the questions my free Security Check asks every firm, and a not-sure there is not a failure; it is usually the most useful answer on the page.

FAQ

We keep everything in OneDrive. Is that not enough?

OneDrive is sync, and sync is not backup. It protects you if a laptop dies, but a deletion or a ransomware encryption syncs upward into the cloud copy just as faithfully as real work does. A backup is a separate, versioned copy that an attack on the live data cannot reach.

What is an immutable backup?

A copy written to storage that cannot be altered or deleted for a set period, by anyone, including an attacker who has stolen the administrator passwords. Ransomware crews go after backups first, so the copy that cannot be touched is the one that decides whether an incident is an afternoon or a catastrophe.

How long should a law firm keep backups?

As long as your record-retention obligations run, which for most firms is measured in years and set by your practice areas and your Bar's rules, not by a backup product's default. Many tools ship with 30-day retention out of the box, which quietly conflicts with a schedule the firm is already committed to. The backup has to honor your schedule; what that schedule is remains a question for the firm and its Bar.

Our practice management is cloud-based. Does its own backup cover us?

The vendor backs up its platform for its own survival, not yours. If your account is compromised, closed in a billing dispute, or the vendor has a bad day, their internal backup does not help you. A firm that periodically exports its practice management data into storage it controls is never completely dependent on any one vendor's continued goodwill.

Not sure whether your backup would pass the restore question? That is exactly the kind of thing worth finding out on a quiet Tuesday rather than during an incident. The law firm page shows how an engagement starts, and asking costs nothing and commits you to nothing. What ongoing support costs is published in what IT support costs a small law firm in Florida.

About the author

Mario Del Mazo is the owner of IT First Response, a managed IT and security practice in Fort Myers serving Lee County, Florida. His background is corporate IT for a healthcare organization operating under HIPAA and HITRUST standards. He publishes his prices, and every client environment is documented so nothing has to be explained twice. More about Mario.