News & Events

Your Backup Is Not a Backup Until You’ve Restored It: What Law Firms, Medical Practices, and Accounting Firms Get Wrong About Business Continuity

  • Your backup job says “successful.”
  • Your files are syncing to the cloud.
  • Someone told you the server is covered.
  • No one has restored a critical system in months, or years.
  • Ransomware is waiting for one compromised account.

That is not business continuity.

It is an assumption.

For law firms, medical practices, accounting firms, and organizations affected by the FTC Safeguards Rule, the difference matters. A backup is only one component of disaster recovery. Disaster recovery is only one component of business continuity. And none of it is reliable until you have tested the process under realistic conditions.

“We Have Backups” Is Not a Recovery Plan

“We have backups.”

It is one of the most common answers we hear during an IT assessment. It is also one of the least useful, until you ask better questions.

  • What systems are backed up?
  • How frequently?
  • Where are the copies stored?
  • Can ransomware reach them?
  • How long would restoration take?
  • Who knows the recovery process?
  • When was the last successful restore?
  • Was the restored data complete and usable?

A backup job completing successfully only proves that a backup process ran. It does not prove the data is intact, the applications can be rebuilt, or your team can return to work within an acceptable timeframe.

Think of it like medical care. A diagnostic test is valuable, but it is not the same as a treatment plan. A backup is evidence that information was copied. A tested recovery plan is what gets your business functioning again.

Professionals reviewing cybersecurity and recovery planning with a medical practice leadership team

Why Backups Fail During Ransomware

Ransomware changes the backup problem.

Attackers do not always stop at encrypting workstations and file servers. They may also target backup consoles, administrator accounts, cloud storage, and connected repositories. If your backup environment is accessible through the same compromised credentials, your “last line of defense” may be encrypted or deleted before you know an attack is underway.

Other failure modes include:

  1. Encrypted backups

    The backup exists, but it contains the same encrypted files as production.

  2. Corrupted backups

    A backup may report success while individual files, databases, or application dependencies are damaged.

  3. Incomplete coverage

    Critical systems may be excluded, including Microsoft 365 data, line-of-business applications, local databases, or configuration files.

  4. Unknown restoration time

    You may be able to recover eventually, but not before missing a court deadline, disrupting patient care, or losing a tax-season window.

  5. No clean recovery environment

    Restoring infected systems directly into production can reintroduce the attacker.

  6. No documented ownership

    “Margaret knows where the backups are” is not an incident response plan.

Reliable ransomware protection requires multiple layers: monitored backups, restricted administrative access, MFA, offline or immutable copies, clean restoration procedures, and recurring testing.

What FTC Safeguards, HIPAA, and GLBA Expect

Regulations do not generally require you to purchase one specific backup product. They do require organizations to understand their risks and maintain safeguards appropriate to their size, operations, and data.

FTC Safeguards Rule and GLBA

The FTC Safeguards Rule applies to covered financial institutions under the Gramm-Leach-Bliley Act, including many tax preparation firms, accounting firms, financial advisors, and other organizations engaged in financial activities.

The FTC’s official Safeguards Rule guidance requires a written information security program that addresses risk assessment, safeguards, monitoring and testing, service-provider oversight, and incident response.

The Rule does not prescribe a universal backup schedule or recovery time. However, a reasonable security program must account for the risk of customer information being destroyed, lost, damaged, or made unavailable. Your incident response and recovery procedures should therefore be documented, operational, and tested.

Accounting firms should be prepared to show:

  • A written information security program
  • A current risk assessment
  • Backup architecture and retention details
  • Encryption and MFA controls
  • Restore-test records
  • Incident response procedures
  • Evidence that weaknesses are being corrected

Law firms are not automatically covered by the FTC Safeguards Rule merely because they handle financial matters. Applicability depends on the activities your firm performs. Even when the Rule does not apply, client confidentiality, contractual obligations, cyber insurance requirements, and professional responsibilities still make tested recovery essential.

HIPAA and Medical Practices

Medical practices typically operate under HIPAA rather than GLBA. HIPAA’s contingency-planning requirements address:

  • A data backup plan
  • A disaster recovery plan
  • Emergency-mode operations
  • Testing and revision of those plans

The U.S. Department of Health and Human Services HIPAA contingency-planning guidance reinforces the need to protect electronic protected health information and maintain access when systems fail.

For a medical practice, downtime can affect scheduling, electronic health records, prescriptions, billing, patient communication, and clinical decision-making. “We will call the software vendor” is not a complete continuity strategy.

The Cost of Downtime Is Bigger Than Lost Productivity

Downtime math is straightforward:

Total downtime cost = lost billables + idle payroll + recovery labor + rework + client and regulatory impact

Consider a 25-person professional services firm with 15 billable employees averaging $200 per hour in billable capacity.

One hour of system downtime can eliminate approximately $3,000 in direct billable opportunity before accounting for administrative staff, recovery work, missed deadlines, or client frustration.

A practical planning range for firms with 10 to 150 employees may look like this:

  • 10 employees: approximately $3,000–$8,000 per hour
  • 20–50 employees: approximately $8,000–$25,000 per hour
  • 50–150 employees: $25,000 per hour and potentially much higher, depending on billing rates and operational dependencies

These are planning estimates, not guarantees. Your actual exposure depends on your industry, staffing, deadlines, revenue model, and how many systems become unavailable.

For a law firm, four hours of downtime may mean missed filings or inaccessible discovery. For an accounting firm, it may occur during a deadline-heavy filing period. For a medical office, it may require cancelling appointments and reverting to manual workflows.

The cost of prevention is measurable. The cost of improvisation compounds quickly.

RTO and RPO: Two Numbers Every Business Leader Should Know

A real business continuity plan defines recovery objectives in business terms.

Recovery Time Objective, or RTO

RTO answers:

How quickly must this system be operational again?

Your email may need to return within a few hours. A historical archive may tolerate a longer recovery window. A clinical or practice-management system may be critical enough to require priority restoration.

Recovery Point Objective, or RPO

RPO answers:

How much recent data can the business afford to lose?

If your RPO is four hours, your backup strategy must allow you to recover data to within four hours of the incident. A nightly backup cannot meet that objective.

RTO and RPO should be defined for systems such as:

  • Email and identity
  • Document management
  • Practice-management platforms
  • Accounting and tax applications
  • Electronic health records
  • File servers
  • Client portals
  • Phone and communication systems

Without these objectives, your provider cannot design the right backup frequency, retention, cloud services, or restoration process.

What a Real, Tested Business Continuity Plan Includes

Your plan does not need to be hundreds of pages. It does need to be specific enough for someone other than the owner to execute.

At a minimum, it should include:

  1. A prioritized systems inventory

    Identify critical applications, dependencies, vendors, devices, data repositories, and administrative accounts.

  2. Offline or immutable backup copies

    Maintain protected copies that cannot be altered or deleted by ordinary production credentials. Follow a risk-appropriate version of the 3-2-1 strategy: multiple copies, different storage types, and at least one isolated or off-site copy.

  3. Encryption and access controls

    Backups should be encrypted in transit and at rest. Administrative access should require MFA, least privilege, logging, and regular review.

  4. Documented recovery runbooks

    Write down who does what, in what order, using which credentials, vendors, contacts, and escalation paths.

  5. Clean restoration procedures

    Restore into a known-safe environment. Validate systems before reconnecting them to production.

  6. Timed restore testing

    A practical baseline is automated backup verification, quarterly representative restore tests for critical data, and at least one broader recovery exercise each year. Accounting firms should consider testing before major filing seasons.

  7. Incident response tabletop exercises

    Walk leadership and staff through a ransomware scenario. Confirm who contacts the IT provider, cyber insurer, legal counsel, law enforcement, clients, and regulators.

  8. After-action documentation

    Record what worked, what failed, how long recovery took, and what will change before the next test.

IT specialists monitoring cloud systems and security dashboards in a modern operations environment

Cloud vs. On-Premises: Neither Is Automatically Safe

Cloud services can improve resilience by reducing dependence on a single office, server room, or physical device. They can also support geographic redundancy and remote access during a facility outage.

But cloud does not mean automatically backed up.

Microsoft 365, cloud file storage, and practice-management platforms may provide retention and recovery features, but those features vary. A deleted file, compromised account, misconfigured retention policy, or malicious insider may create gaps. You remain responsible for understanding what the vendor protects, and what it does not.

On-premises systems can provide control and predictable local performance. They also introduce risks involving hardware failure, fire, theft, power loss, aging infrastructure, and physical access.

The right answer is often a hybrid design based on your RTO, RPO, compliance requirements, budget, and operational realities.

The “I Got a Guy” Failure Mode

“I got a guy.”

“He handles the server.”

“Call Margaret. She has the backup password.”

That approach may be adequate for a printer problem. It is not a mature business continuity program.

Potential benefits of informal or internal support

  • Familiarity with your environment
  • Direct access to decision-makers
  • Lower apparent short-term cost
  • Existing knowledge of applications

Potential drawbacks

  • One person becomes a single point of failure
  • Documentation may be incomplete or outdated
  • Restore testing competes with daily support
  • Cybersecurity expertise may be limited
  • Employee turnover can remove critical knowledge
  • After-hours response may be unavailable
  • Compliance evidence may not exist

A qualified outsourced IT provider brings broader staffing, standardized procedures, monitoring, economies of scale, and experience supporting regulated organizations. The provider does not eliminate your responsibility, but it can give your firm the structure and accountability required to manage risk properly.

A good starting point is an IT assessment that reviews your backup architecture, identity controls, endpoint security, cloud services, vendor access, and recovery objectives.

Final Word

Your backup is not a backup until you have restored it.

For law firms, medical practices, accounting firms, and organizations affected by FTC Safeguards or HIPAA obligations, business continuity cannot depend on a green status icon or someone’s memory.

You need:

  • Defined RTOs and RPOs
  • Protected offline or immutable copies
  • Documented recovery runbooks
  • Regular restore testing
  • Ransomware-resistant access controls
  • Clear incident response ownership
  • Evidence that the process works

A PC of Mind helps regulated professional services firms build secure, resilient technology environments through managed IT services and cybersecurity services.

Do not wait for ransomware, a failed server, or a regulatory review to discover whether your business can recover.

Test the restore now, while recovery is still a drill.

This article is for general informational purposes and is not legal, regulatory, insurance, or compliance advice. Consult qualified counsel and cybersecurity professionals regarding your organization’s specific obligations.

Sources and Further Reading