Free Resource · guide

How Should a Law Firm Back Up Matter Files, Email, and Microsoft 365?

A law firm's backup plan has to be designed by data type, because matter files, email, Microsoft 365, billing data, and closed-matter archives each fail and recover differently. The working standard is three copies on two kinds of storage with one off site, at least one copy that ransomware cannot alter, and restores you actually test, because a backup you haven't restored from is a hope, not a plan. And the retention behind it all is set by your records policy and your obligations, not by whatever window a platform happens to keep by default.

Ask a law firm what would hurt most to lose and the answer is immediate: the matter files. Ask what their backup actually covers and the answer gets slower. Most firms have a backup. Far fewer have a backup designed around the five kinds of data a practice actually runs on, and the difference only shows up on the worst possible day, mid-litigation, with a deadline on the calendar and a partner standing at someone’s desk.

The right way to think about firm backup is by data type, because each one fails differently, recovers differently, and carries different obligations. Here is each one in turn.

What do matter files and the document management system need?

Matter files are the working product of the firm: pleadings, contracts, discovery, correspondence, work product. Two design questions decide whether they are really protected.

Where do they actually live? In most firms the honest answer is several places at once: a document management system, a file server, a SharePoint or OneDrive library, and the informal edges, a scans folder, an attorney’s desktop, exhibits on a laptop that travels to court. The backup has to follow the real working locations, not the official one. A perfect DMS backup does not help with the deposition transcript that only ever existed in a “ToSort” folder.

Is the system backed up as a system? If your document platform runs on a database, the database and the document store have to be captured together, in a consistent state. A backup that copies live files underneath a running database can restore documents that have lost their matter associations, their version history, and their metadata. Technically the files came back. Practically, the firm’s library became a pile. This is application-aware backup, and it is the difference between restoring data and restoring the practice.

One more trait matters for legal documents specifically: retention depth beats backup frequency. The common loss is not a dramatic crash. It is a brief overwritten with the wrong version, or a folder quietly deleted, discovered months later when the matter heats up again. If versions and backups only reach back 30 days, the good copy is already gone by the time anyone notices.

How should a law firm back up email?

Email at a law firm is not just communication, it is often evidence, and it is frequently part of the client file itself. That raises the bar in two ways.

First, retention duties attach to it. Correspondence about a matter may need to be kept as long as the matter file, and when litigation is reasonably anticipated, firms generally operate under a duty to preserve relevant material. The specifics are legal questions for the firm, not for its IT provider, but the backup design has to be capable of honoring whatever the firm decides. A preservation obligation is very hard to honor on a platform that only reaches back a few weeks.

Second, mailbox recovery has to be granular. The realistic email emergency is rarely “the whole server is gone.” It is one attorney’s folder structure emptied by a bad sync, one thread deleted, one departed employee’s mailbox needed a year later. A backup that can only restore an entire mailbox to a point in time, wholesale, turns a ten-minute fix into an afternoon of merging. Look for the ability to search and restore individual items and folders.

Departures deserve their own line. Attorneys and staff leave, and their mailboxes and files hold matter history the firm still owns. The backup, not the platform’s default post-departure grace period, is what makes that history durable.

Isn’t Microsoft 365 already backed up by Microsoft?

No, and this is the most common gap we find in professional firms of every kind. Microsoft operates on a shared responsibility model: they are responsible for keeping the service available and protecting it from failures on their side. Recovering your data after your own people delete it, after an account is compromised, or after ransomware syncs encrypted files to the cloud is your side of the line.

What looks like backup inside Microsoft 365 is a set of deletion grace periods, and their windows are defaults, measured in days or weeks, not an archive: recoverable items retention in Exchange Online, recycle bins in SharePoint and OneDrive, a default holding period for a departed user’s OneDrive after the account is removed. Useful for “I deleted that this morning.” Useless for “we need the file as it stood last spring,” and no help at all when a compromised account’s files are encrypted and the encrypted versions replicate to the cloud looking like legitimate edits.

The fix is a third-party Microsoft 365 backup with its own storage and its own retention that the firm controls, covering Exchange, SharePoint, OneDrive, and Teams. For a firm, this is not an add-on to the backup plan. Given how much matter correspondence and how many working documents live in Microsoft 365, it is a third of the backup plan.

What about time, billing, and trust accounting data?

Billing data is easy to overlook because it is not the client file, but losing it means losing unbilled time, aging receivables, and the records behind trust accounting, which is not a category where “we reconstructed it as best we could” is an acceptable sentence.

Like the DMS, practice management and billing platforms usually sit on a database and need application-consistent backups, coordinated with the software rather than copied underneath it. If the platform is hosted by the vendor, the question changes shape but does not go away: what does the vendor protect, what can they restore, how fast, and what copy does the firm itself hold? We support the environment these systems run on and coordinate with the software vendor directly when the answer lives inside the application, so the firm is not stuck relaying messages between its IT provider and its billing vendor.

Timing matters here too. The most valuable thing in the billing system is often the newest: this month’s unbilled time. Daily backups mean a worst case of losing a day of entries; make sure the firm has consciously accepted whatever that window is.

Why do closed matters need their own plan?

A matter closing does not end the firm’s responsibility for its records. Retention obligations commonly run for years after closure, and how long depends on the matter type, the jurisdiction, and the firm’s own records policy. The policy is the firm’s decision, made with its own guidance. The IT job is blunt: the archive has to actually reach as far as the policy says, and remain restorable the whole way.

That usually means a distinct archive tier rather than stretching the daily backup to hold everything forever. Daily backups are built for fast recovery of recent work; archives are built for durable, inexpensive, verifiable retention of closed work. Merging the two either makes the daily backup bloated and slow or quietly caps the archive at whatever the backup platform retains. And an archive is subject to the same rule as everything else here: if you have never pulled a closed matter back out of it and opened the documents, you do not know it works.

What standards should the whole design meet?

Four, and they apply across every data type above.

Three copies, two media, one off site. The 3-2-1 rule is the floor, not the ceiling: three copies of the data, on two different kinds of storage, with at least one copy away from the office. A backup drive in the same building as the server shares the server’s fires, floods, and burglaries.

One copy immutable. Modern ransomware crews find and destroy backups before they detonate, because a firm that can restore does not pay. An immutable copy cannot be altered or deleted for a set period, even with administrator credentials, which is exactly the scenario a compromised admin account creates. If every copy of your backups can be deleted by a credential that lives on your network, you have targets, not protection.

Restores tested on a schedule. A backup you haven’t restored from is a hope, not a plan. Test quarterly at minimum, and test outcomes, not job logs: open a restored matter folder and confirm the structure survived, restore a mailbox item, bring billing up from backup and run a report, pull one closed matter from the archive. Most backup failures are discovered during the emergency they were supposed to prevent, and that is a scheduling choice.

Recovery time matched to the calendar. A backup answers “is the data safe.” A recovery plan answers “how fast is the firm working again,” and for a firm the honest benchmark is the worst week, not the average one. Mid-trial, with a filing due, the difference between restoring the document system in two hours and rebuilding it over three days is not an IT metric, it is missed deadlines, idle attorneys, and a client watching it happen. Decide in advance which systems come back first and verify the platform can deliver that sequence at real speed. Those priorities cannot be set calmly during the incident.

Who should own all of this?

Someone has to, by name. Backup is the one system in the firm that fails silently, because no one interacts with it until the day it must work, and by then the verification you skipped is the recovery you don’t have.

Braintek has been doing exactly this ownership job for Texas businesses since 2002, with local teams in Houston and Dallas-Fort Worth. Our backup and disaster recovery service starts by inventorying what is actually protected today versus what everyone assumes is, then closes the gaps: application-aware coverage for document and billing systems, an independent Microsoft 365 backup, immutable copies, archive retention matched to your records policy, and restore tests on a schedule with results you can hand to a cyber insurer or a client security questionnaire. Fully managed support fits firms of roughly 10 to 50 people; larger firms typically pair us with internal IT in a co-managed arrangement.

If you want the picture for your own practice, start with our IT services for law firms or book a discovery call. The best time to find out what your backup can restore is any week you don’t need it to.

Do you know what your firm could actually restore today?

Tell us where matter files live, whether your document and billing systems run on premises or hosted, and how many people are in the firm. We'll map what's protected now, what everyone assumes is protected, and what a restore would look like the week of a trial.

By submitting, you agree to be contacted by Braintek about your inquiry.

FAQs

Doesn't Microsoft already back up our email and OneDrive?

Microsoft keeps the service running and protects against failures on their side. Recovering your data after a deletion, a compromised account, or ransomware is your responsibility under their shared responsibility model. The built-in retention windows are deletion grace periods measured in days by default, not an archive, and they do nothing when encrypted files sync to the cloud looking like ordinary edits. A firm needs an independent Microsoft 365 backup with retention it controls.

How long do we have to keep backups of client matters?

That depends on your jurisdiction, your practice areas, and the matter types involved, and it belongs in the firm's written records retention policy rather than in an IT default. The IT requirement is simpler to state: whatever the policy says, the backup and archive design has to actually reach that far. A common failure is a policy measured in years sitting on top of a backup platform holding 90 days.

Our document management system is the firm's memory. What does it need beyond a file backup?

If it runs on a database, it needs an application-aware backup that coordinates with the database instead of copying live files underneath it, or the metadata that makes documents findable can come back inconsistent. It also needs both halves captured together, the documents and the index, because a restore that returns files without their matter associations turns your library into a pile.

What actually protects backups from ransomware?

Immutability. At least one copy should be unchangeable and undeletable for a set period, even by an administrator account, because attackers go after backups first and an admin credential is exactly what they aim to steal. Separation of credentials matters too: if the same login that runs your network can purge your backups, you have one target, not a recovery plan.

How fast do we need to be able to restore?

Fast enough for the worst week on your calendar, not the average one. A firm in active litigation with a filing due does not have a spare three days while a full environment rebuilds. Decide up front which systems must be back in hours and which can wait, and confirm your backup platform can actually deliver that order, because those decisions cannot be made well during the incident.

How often should restores be tested?

On a schedule, at least quarterly, and the test is the restore, not the backup job's green checkmark. Open a restored matter folder and confirm the documents and their organization came back. Restore a mailbox search. Bring the billing system up from backup and run a report. Cyber insurance applications increasingly ask when you last did this, and 'never' is an expensive answer.

We have an office manager who handles IT. Is this something to outsource?

Backup is the one system where a quiet failure costs the most, because nobody looks at it until the day it has to work. If nobody at the firm is verifying jobs, testing restores, and matching retention to your records policy, the honest answer is that nobody owns it. That is the gap a managed provider closes, whether fully managed for a smaller firm or alongside internal IT at a larger one.

Ready for IT that just works?

Book a no-pressure discovery call. We'll review your setup and show you exactly where you stand.