Ransomware and the Small Law Firm: A Recovery Readiness Checklist
By Raj Sidhu, Founder & CEO of inTech Consulting, author of "Beyond the Prompt: A Business Owner's Guide to Understanding AI." Published September 22, 2026.
A small law firm's ransomware recovery readiness comes down to eight specific, testable items: immutable backups, a documented RTO and RPO, a rehearsed tabletop exercise, and a clear notification plan. Most firms have a backup. Far fewer have tested whether that backup actually gets them back to work.
Why Are Law Firms a Disproportionate Ransomware Target?
Three things make firms attractive targets. They hold concentrated, high-value confidential data (settlement details, M&A terms, litigation strategy) in one place. Most run lean internal IT, often a single person or a part-time arrangement. And court deadlines create real pressure to pay quickly rather than rebuild slowly, which attackers know and price into their ransom demands.
That combination, valuable data plus thin IT plus deadline exposure, is why firms show up disproportionately in ransomware incident data year over year.
Backup vs Recoverability: What's the Difference?
A backup is a copy of your data. Recoverability is whether that copy can actually restore your systems to a working state within a timeframe your firm can survive. Firms discover the gap between the two during an actual incident, which is the worst possible time to learn it.
A backup that exists but has never been test-restored is an assumption, not a plan.
The Recovery Readiness Checklist
Eight items, each with a direct answer to what "ready" actually means.
- Does your firm follow the 3-2-1 backup rule? Three copies of data, on two different types of media, with one copy off-site. If ransomware can reach and encrypt your backup the same way it reached your primary files, it isn't a real backup.
- Is at least one backup copy immutable or air-gapped? Modern ransomware actively hunts for and encrypts connected backup systems. An immutable copy can't be altered or deleted even by someone with admin credentials, and an air-gapped copy is physically or logically disconnected from the network.
- Does your firm have a documented RTO? Recovery Time Objective is how long your firm can be down before the damage becomes unacceptable. For most small firms, "unacceptable" arrives faster than owners expect once billing, filing deadlines, and client communication stop.
- Does your firm have a documented RPO? Recovery Point Objective is how much data loss is tolerable, measured in time. A nightly backup means a worst-case RPO of nearly 24 hours of lost work. Firms with high daily document volume often need something tighter.
- Has the RTO and RPO actually been tested? A documented target means nothing until someone has run a real restore and timed it. Untested numbers are guesses with a decimal point.
- Has your firm run a tabletop exercise? A structured walk-through of a simulated incident, covering who makes the call to shut down systems, who contacts the insurance carrier, and who drafts client notifications, before any of that has to happen for real.
- Do you know what your practice management or document management system's native backup does not cover? Most platforms back up their own database, not your file shares, email, or endpoint devices. Assuming platform backup means full backup is one of the most common gaps we find.
- Has your firm reviewed its cyber insurance questionnaire against what's actually in place? Carriers increasingly deny claims when a firm answered "yes" to MFA, endpoint detection, or immutable backups on the application and can't demonstrate it at claim time.
Not sure how your firm scores against this checklist? Get a straight readiness assessment against all eight items before an incident forces the answer.
What Does a Tabletop Exercise Look Like for a 15-Person Firm?
It doesn't require a consultant or a full day. A working tabletop for a firm that size runs two hours and covers a single scenario: ransomware hits on a Wednesday morning with a filing deadline Friday. The exercise walks through who has authority to disconnect systems, which vendor gets called first (insurance carrier, then forensics, then your backup and recovery provider), and who drafts the message to affected clients before legal counsel reviews it.
Firms that run this once a year consistently recover faster than firms improvising the sequence for the first time during a real incident.
What Are Your Notification Obligations After a Ransomware Attack?
Ransomware that encrypts or exfiltrates client data triggers the same reasonable efforts and breach response obligations under RPC 1.6 and ABA Formal Opinion 483 that apply to any other confidentiality incident. That means stopping the breach, determining scope to the extent reasonably possible, and notifying current clients whose confidential information was likely accessed, without waiting for a complete forensic investigation to finish first.
Depending on the data involved, state breach notification law may also require notice to individuals whose personal information was exposed, on a separate and sometimes shorter timeline than the bar's ethical requirements.
Illustrative example, not a specific client engagement: a 15-attorney firm in Tacoma with a documented RTO of 8 hours and a tested immutable backup restored core systems in just under 6 hours after a ransomware event, filed a required extension motion for the one deadline affected, and never paid the ransom. The determining factor wasn't luck. It was that the 8-hour target had actually been rehearsed twice before the real incident happened.
What Do Cyber Insurance Carriers Actually Check?
Carriers have tightened underwriting significantly, and the gap between what firms claim on the application and what they can prove at claim time is now a leading cause of denied ransomware claims. The items most commonly misrepresented, whether through misunderstanding or optimism:
- Multi-factor authentication enforced firm-wide, not just available
- Endpoint detection and response, not just traditional antivirus
- Immutable or air-gapped backup, not just off-site backup
- Documented incident response plan, not an informal understanding of "what we'd do"
A firm should walk through its current security posture against the actual insurance questionnaire before renewal, not after a claim gets denied.
Frequently Asked Questions
Why are law firms targeted by ransomware more than other small businesses?
Firms concentrate high-value confidential data, typically run lean internal IT, and face court deadline pressure that increases willingness to pay quickly, a combination that consistently shows up in ransomware targeting data.
What's the difference between a backup and recoverability?
A backup is a stored copy of data. Recoverability is whether that copy can actually restore systems to a working state within a timeframe the firm can survive, which can only be confirmed through an actual test restore.
What is the 3-2-1 backup rule?
Three copies of data, stored on two different types of media, with at least one copy off-site. Ransomware that can reach and encrypt a connected backup defeats a backup that doesn't follow this structure.
What are RTO and RPO?
Recovery Time Objective is how long a firm can tolerate being down before serious damage occurs. Recovery Point Objective is how much data loss, measured in time, is tolerable. Both need to be documented and tested, not just estimated.
Does a practice management system's backup cover the whole firm?
Usually not. Most practice management and document management platforms back up their own database, not file shares, email, or individual workstations, which leaves a gap firms often don't discover until an incident occurs.
What does a ransomware attack require under law firm confidentiality rules?
The same reasonable efforts and breach response obligations that apply under RPC 1.6 and ABA Formal Opinion 483, including stopping the breach, determining scope, and notifying clients whose confidential information was likely accessed or disclosed.
Test your firm's ransomware recovery readiness before an attacker does. We work with law firms across Washington, Oregon, Idaho, and Montana on backup architecture, tested recovery times, and incident response planning.