Business continuity and backup: protecting the firm's business from data loss

Summary

For a law or notary firm, backup alone is not enough: while the former saves data, business continuity ensures that operations can continue even after a major failure or a ransomware attack. In this guide, we analyze the 3-2-1 backup rule (three copies, two different media, one offsite and immutable copy), RPO and RTO metrics, and the creation of a 5-step disaster recovery plan tested periodically. We also examine the obligations set by GDPR and NIS2, the comparison between on-premise, cloud, and hybrid architectures, and how active monitoring with artificial intelligence allows anomalies to be identified before they turn into an operational blockage.


Over the past five years, the nature of cyber risk for the legal sector has undergone a genetic mutation. Until not long ago, the interruption of activities in a professional firm was considered an exceptional event, almost always attributable to hardware failure: a mechanical hard drive damaged by wear and tear, an electrical failure, or the accidental deletion of a network folder by a distracted coworker.

Today the scenario is radically different. Law and notary firms safeguard a information assets among the most attractive on the market: non-public court documents, economic-financial expert reports, confidential communications covered by professional secrecy, banking data, and sensitive personal files. This concentration of critical data has turned law firms into priority targets for criminal groups specialized in attacks double and triple extortion ransomware : it is no longer just a matter of encrypting files to halt operations, but of threatening the public release of confidential client documents.

In this context, limiting oneself to a generic notion of "backup" is a mistake that can cost the very survival of the business. The real challenge for professional firms is not simply keeping a copy of the files, but ensuring the Business Continuity : the ability to restore workflows, database access, and telematic communications very quickly, minimizing economic, reputational, and deontological impact.

From simple copying to business continuity: understanding the paradigm shift

In the common vocabulary of many professionals, the terms “backup” and “business continuity” are still used interchangeably. However, these are two concepts located on distinct logical and strategic levels.

What is backup and what are its intrinsic limitations

The backup it is the technical operation of static data duplication from a primary source to a secondary medium (local, remote, or in the cloud). It is an indispensable measure, but in isolation, it does not guarantee work continuity. Having data saved on an external medium does not mean being able to resume operations immediately after an incident: if the central server breaks down or becomes corrupted, the files are safe, but the infrastructure that allows lawyers to consult them, draft legal documents, and synchronize procedural deadlines remains down.

Business Continuity

the business continuity is the overall architectural, organizational, procedural, and technological framework that enables a firm to continue delivering its services even during or immediately following a severe disaster, whether it is a network outage, a natural disaster, or a violent cyber attack. Business continuity includes backup, but integrates it with:

  • Disaster Recovery (DR) : the set of policies and technical tools for the timely recovery of IT systems, servers, and applications
  • Resource redundancy : the duplication of compute nodes, power supply, and connections to avoid single points of failure (Single Point of Failure)
  • Documented emergency plans : clear operational protocols that instruct each member of the firm on what to do, who to contact, and which alternative channels to use during the emergency

The real cost of downtime in a law firm

When a partner or administrator evaluates investments in cybersecurity, the calculation is often flawed by a misperception: the cost of the technology fee is compared with the presumed probability of suffering irreparable damage. The correct parameter to consider instead is the cost of downtime , meaning the economic and strategic value of each single hour of forced downtime for the firm.

Direct damages and loss of productivity

In an organization with ten to fifty professionals, a 48-hour system outage results in loss of hundreds of billable hours . Lawyers cannot access defensive briefs, digital case files are inaccessible, and the consultation of jurisprudential precedents is compromised. Added to this is the cost of administrative and secretarial staff, unable to perform their normal duties.

Procedural forfeitures and disciplinary sanctions

Digital justice and the Electronic Trial do not grant unjustified margins of flexibility. The inability to file a document by midnight on the deadline date due to a system crash exposes the professional and the firm to very serious consequences:

  • Incurable procedural forfeitures to the detriment of the client
  • Professional liability and subsequent insurance claims with premium increases
  • Disciplinary proceedings before the Bar Association for violation of the duties of diligence, competence, and custody of documents

Reputational damage and loss of customer trust

In the mid-to-high-end legal services market, trust is the primary asset. Having to inform a corporate client or an investment fund that an M&A negotiation or an international arbitration is delayed because the firm's data has been compromised destroys the credibility built over decades of a career. To prevent these critical issues at the root, the most advanced organizations integrate data management with advanced document management software for law firms , ensuring traceability, versioning, and preventive isolation of working documents.

Core metrics: defining RPO and RTO for the legal sector

A business continuity plan cannot be based on generic formulas. It must rest on precise quantitative parameters, agreed upon between the firm's management and the technology provider: RPO and RTO .

Parameter Technical definition Application in the law firm
RPO (Recovery Point Objective) Maximum tolerable time span between the last backup and the failure: measures the volume of data at risk of being lost. If the RPO is set to 24 hours, a failure at 18:00 wipes out the work done throughout the day. For a modern firm, the ideal RPO is between 15 minutes and 1 hour.
RTO (Recovery Time Objective) Maximum time needed to fully restore systems operations after an outage. Measures for how many hours or days the study remains inactive. A 2-hour RTO allows notifications and hearings to resume; a 3-day RTO puts impending deadlines at risk.

Precisely defining RPO and RTO allows for selecting the appropriate technology: from continuous incremental backup to virtual machines replicated in a warm cloud, ready to start up in a few minutes in the event of an on-premise server failure.

The 3-2-1 Backup Rule Applied to Professional Practices

The cornerstone of any data backup infrastructure remains the strategy of 3-2-1 Backup , formulated to eliminate any statistical probability of simultaneous file loss.

3 copies of the data

You must always have at least three distinct copies of the studio's documentary assets:

  • The production copy: active files on servers or workstations
  • A first local backup copy
  • A second geographically disparate backup copy

2 different technological supports

Copies must not reside on the same type of storage medium. Storing the backup only on a second disk of the same server, or on disks with the same technology, exposes the system to the exact same hardware failure factor or malware attack. The ideal combination involves dedicated high-speed local storage ( Enterprise NAS with RAID drives ) supported by secure cloud repositories.

1 off-site and immutable (WORM) copy

At least one copy must reside outside the physical location of the studio: this protects against environmental risks (fire, flood, theft of the physical machines). To counter modern malware designed to search for and delete network backups, the remote copy must also be immutable , based on technology Write Once, Read Many (WORM) or on encrypted and segregated snapshots ( air-gapped ), which prevent any modification or deletion for a predetermined period, even by users with compromised administrative privileges.

The regulatory and compliance framework: GDPR and NIS2 Directive

Safeguarding business continuity is not only a choice of good management sense, but a stringent regulatory obligation that increasingly affects the professional world.

The obligations of the General Data Protection Regulation (GDPR)

Article 32 of EU Regulation 2016/679 (GDPR) expressly requires the data controller to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. Among these measures, the regulation explicitly cites:

  • The ability to ensure on a permanent basis the confidentiality, integrity, availability, and resilience of processing systems and services
  • The ability to promptly restore the availability and access to personal data in the event of a physical or technical incident
  • A procedure to regularly test, verify, and evaluate the effectiveness of the technical and organizational measures adopted

Not having a tested disaster recovery plan can constitute a violation of Art. 32, which can be evaluated by the Data Protection Authority independently of any data breach. In this regard, the practical guidelines available through the Guidelines of the Italian Data Protection Authority , a benchmark for interpreting mandatory security measures.

The impact of the NIS2 Directive (EU 2022/2555)

With the entry into force and transposition of the NIS2 directive , cybersecurity and operational resilience requirements have widened their scope. Law firms do not automatically fall among essential or important entities directly, but they can be involved indirectly when a client subject to NIS2 (a bank, an insurance company, a strategic infrastructure manager) classifies them as relevant supplier and transfers to them, via contract, security requirements and incident notification obligations.

Large corporate clients now contractually require their legal consultants to formally demonstrate compliance with the supply chain resilience provisions set forth by the NIS2 Directive (EU 2022/2555) on the EUR-Lex portal . Not being able to document a solid Disaster Recovery Plan means risking exclusion from the fiduciary registries of major corporate entities. To offer unquestionable guarantees to clients and institutional partners, Lanpartners has aligned its processes with the most rigorous global standards, certified by ISO/IEC 27001 certification , which certifies compliance with the highest standards of security and resilience in information management.

Disaster Recovery Plan (DRP): how to structure it in 5 concrete steps

An disaster recovery plan effective is not a theoretical document put away in a drawer, but a ready-to-use operational guide in case of crisis. Here are the five key steps to implement it correctly in a law firm.

1. Critical asset mapping and data classification

Not all files have the same value at the same time. It is crucial to identify vital resources that require immediate recovery (practice management software, client and hearing databases, certified and standard email accounts, pending files with short-term deadlines), separating them from historical archives and closed cases, which can have wider recovery windows.

2. Evaluation and isolation of communication channels

In the event of a ransomware attack or the blocking of the firm's domain, standard email accounts and VoIP switchboards could become unusable. The plan must establish alternative and secure communication channels to allow partners to coordinate the emergency without using potentially infected infrastructure.

3. Emergency recovery procedures (failover and failback)

The document must describe in detail the instructions to activate the failover (the temporary switch to the secondary infrastructure or backup cloud) and the subsequent failback (the controlled return to the sanitized and verified primary environment). For an operational guide on what to do concretely in the first hours after a cyber attack, it may be useful to refer to Incident Response for professional firms .

4. Clear definition of roles

Who is authorized to declare a state of IT emergency in the firm? Who contacts the IT team? Who coordinates communications to clients or any Data Breach notification to the Privacy Guarantor within the 72 hours required by the GDPR? Roles must be assigned by name and accompanied by emergency contact details that are always accessible offline.

5. Periodic Disaster Recovery Testing

A backup that has never been tested does not exist. A report of At-Bay from 2023 , based on real data of ransomware claims managed by the insurer between 2019 and 2023, found that about 1 in 3 companies (31%) fail to restore data from backups during a ransomware attack, often due to corrupted, incomplete, or unreadable files, or backups never tested before the emergency. The study must therefore plan semiannual or annual simulations of bare-metal restore and application recovery to ensure that actual recovery times match the established RTO.

On-premise, cloud, and hybrid solutions: which architecture to choose?

The choice of infrastructural configuration depends on the size of the firm, the volume of documents handled, and the level of mobility required by the professionals.

On-premises infrastructure

Storing data exclusively on physical servers within the firm offers a sense of immediate control and allows high speeds on the local network. However, it entails high hardware maintenance costs, localized physical risks, and complexity in ensuring true geographic redundancy without duplicating expenses for a second private data center.

Full cloud solutions

Complete migration to public or private cloud environments relieves the firm from physical hardware maintenance and facilitates smart working. However, it is essential to verify where the servers reside, as client data must remain within the European Economic Area, and what guarantees of encryption and data sovereignty are provided by the provider.

The hybrid approach: the optimal solution

For most modern law firms, the hybrid architecture represents the ideal balance point. It provides for:

  • Local servers or NAS for maximum daily operational speed and low-latency access to heavy files
  • Automatic, continuous, and encrypted backup to professional European cloud with ransomware protection
  • Virtual instances ready to be launched in the cloud if the firm's physical office becomes inaccessible

To manage this complexity without taking precious time away from forensic work, most firms rely on Managed IT services for law firms and notary offices , delegating 24/7 proactive monitoring, security patch management, and verified backup execution to specialists.

AI-driven active monitoring: identifying anomalies before system failure

A well-designed continuity plan does not eliminate the risk of failure, but drastically reduces the time between an anomaly and its detection. This is where the active monitoring with artificial intelligence IT management in professional firms is changing in a concrete way: instead of relying solely on periodic manual checks or reactive user reports, AI-model-based monitoring systems analyze the behavior of servers, backups, networks, and applications in real-time, learning the "normal" patterns of a specific firm and flagging anything that deviates from them.

  • Early detection of anomalies, such as a backup taking longer than usual, an unusual spike in outbound traffic, or repeated login attempts outside of business hours, before they escalate into a full-blown outage or a successful attack
  • Reduction of the mean time to detection, which directly translates to a lower RTO because technical intervention starts before the damage spreads
  • Alert prioritization, to prevent IT staff (internal or vendor) from being overwhelmed by low-value notifications and losing sight of truly critical signals

This type of monitoring naturally integrates with the timely detection obligations required by regulations and with broader strategies of cybersecurity for businesses and NIS2 compliance , of which predictive monitoring is only one component, albeit an increasingly central one in preventing operational outages.

Quick resilience check-up: how secure is your firm?

To quickly understand the level of exposure of their firm, professionals can use this short checklist:

  • Do we make backup copies of operational data at least daily?
  • Is there at least one copy saved outside the firm's premises and protected with immutability (WORM)?
  • Do we know with certainty the maximum time required to restore systems in the event of a total shutdown (RTO)?
  • Have we performed a full disaster recovery test in the last six months?
  • Are the backup copies logically isolated from the main network to prevent ransomware propagation?
  • Do we have a written emergency plan that instructs partners and collaborators on how to proceed in the event of a cyber incident?

If the answer to one or more of these questions is negative or uncertain, the firm is operating under a condition of risk that could compromise its daily operations.

Investing in business continuity does not just mean purchasing storage space: it means building a shield to protect your firm's most important asset, namely reputation, confidentiality, and the trust placed in you every day by your clients. To analyze your systems architecture and build a continuity plan tailored to your firm's needs, you can explore our pathways of cybersecurity audits and solutions for law firms or contact the Lanpartners team for specialized consulting.

Frequently Asked Questions (FAQ)

What is the difference between backup and business continuity?

Backup is the static copy of data on secondary media: it protects files, but by itself it does not guarantee that the firm can resume operations immediately after a failure. Business continuity is the organizational, procedural, and technological set (disaster recovery, redundancy, emergency plans) that allows work to actually resume, not just recover files.

What are RPO and RTO and why are they important for a law firm?

RPO (Recovery Point Objective) measures how much data is at risk of being lost between backups; RTO (Recovery Time Objective) measures how long it takes to resume operations after an outage. For a law firm, where procedural deadlines are non-negotiable, both parameters must be explicitly defined with the IT provider, not left implicit.

What is the 3-2-1 backup rule?

It is the gold standard for data security: at least 3 copies of the files, on 2 different technological media, with at least 1 copy kept off-site and made immutable (WORM technology), so that no single failure or attack can compromise all copies simultaneously.

What do GDPR and NIS2 require regarding backup and disaster recovery?

Article 32 of the GDPR requires guaranteeing the ability to promptly restore access to personal data following an incident and regularly testing the effectiveness of the measures adopted. The NIS2 Directive extends these obligations along the supply chain: a law firm working for corporate clients subject to NIS2 may have to demonstrate, contractually, that it has a solid and documented disaster recovery plan.

How does AI-driven monitoring applied to backup and security work?

AI-based monitoring systems analyze in real-time the behavior of servers, backups, and networks, learning what the normal patterns are for that specific firm and flagging deviations, such as a slower-than-usual backup or after-hours access attempts, before they turn into operational downtime or a full-blown incident.

How often should a disaster recovery plan be tested?

Recovery simulations should be carried out at least once or twice a year, with bare-metal restore and application recovery tests. An untested backup is, in fact, a backup whose true reliability is unknown: a large part of recovery failures emerges precisely at the time of need, when it is too late to correct the problem.