Ransomware and the Monday-morning test for law firms

Monday morning, the files will not open, and there is a hearing on Wednesday

The real question is not only whether an attack can happen. It is whether your lawyers can work again on Monday, and how long that would honestly take.

Ask Tony for a free 30-minute insurer readiness review.

What you can count on

  • Under 2 hrsto restore a failed server from local backups
  • 30 days lockedbackups no one can delete early, not even us
  • 24/7a person answers (604) 813-7881

What happens

Illustrative, not a client story. This is a made-up sketch, built from public notices. It is not about a Benson Hunt client.

A small firm finishes a normal Friday. Over the weekend someone gets in, often through a click on a link or attachment, a stolen password, or a remote access door left open. By Monday morning the files will not open, email is down, and a note on the screen asks for payment.

There is a hearing on Wednesday. The managing lawyer’s first question is whether there is a backup. The second question matters more: how old is it, and how long would it take to bring back?

The answer often depends on choices made long before: where the backups live, whether the attacker could reach them with the same sign-in, and whether anyone has ever tried a restore.

The public notices behind this sketch
  • The Law Society of BC’s December 2020 notice to the profession describes a BC firm locked out of its computers, client lists, email and accounting files until a Bitcoin ransom was paid, likely after a click on a link or attachment. Read the notice
  • A 2021 Law Society of BC advisory lists hacking or unauthorized access, including ransomware, among the top four kinds of reported breach, alongside misdirected correspondence, lost or misplaced records or devices, and theft. Read the advisory
  • QBE’s 2026 threat report says law and professional services remain among the most targeted sectors, and that attackers work to compromise backups. QBE report
  • A 2025 report by Fenix24 and ILTA, based on a 2024 survey, found that about half of law firms report having immutable backups, and that only 18% apply MFA to production storage and 37% to backup storage. Fenix24 is a vendor, so read it as one view. Survey release
Live filesCopy 2Copy 3Can an intruder reach them?

Which copy is clean?

A copy the intruder cannot reach is worth a great deal.

Last night? Last week?

How old is it?

Last night’s copy and last week’s copy are very different Mondays.

Measured, not guessed

How long to bring it back?

Not in theory. In hours, for your real data.

Three questions for your Monday-morning test. If you cannot answer them today, that is a useful thing to learn before Monday.

Why it happens

In plain words, and with nobody to blame.

Someone gets in

Often through a click on a link or attachment, a stolen password, or a remote access door left open to the internet.

Then they move around

On a flat network with shared admin passwords, one computer can lead to many. The goal is often the servers and, importantly, the backups.

A backup nobody has tried

A copy that sits behind the same sign-in, or has never been restored, is a hope rather than a plan.

What fixes it

Nothing makes a firm immune. The aim is to make getting in harder, to keep a problem small if it starts, and to have a clean copy to come back to.

  • Hyper-V with at least 2 virtual servers. One handles sign-in (the domain controller) and one is a dedicated app server for your software. Each is a set of files that can be backed up and brought back onto other hardware, which is usually quicker than rebuilding a physical server. We do not promise zero downtime. Hyper-V for law firms
  • 3-2-1 backups with an offsite copy. Three copies, on two kinds of storage, with one offsite, held in Canada, in Vancouver, BC. We do spot checks on multiple copies of the backups and a yearly disaster recovery test. Restores run as fast as the backup storage allows. A backup is only real once a test restore has proven it works.
  • Immutable backups. Right after a backup is written, it is locked so it can’t be changed or deleted for 30 days. Not forever, just long enough to matter. While the lock is on, ransomware can’t encrypt or delete those copies, and a mistake can’t erase them. This is standard in our builds for law firms, and Veeam supports it with a hardened repository or object storage with object lock.
  • RAID, but not as a backup. RAID keeps a server running when a drive fails. It does nothing about ransomware. RAID 10 for virtual machine storage is standard in our builds, set up with standard ITIL change and configuration practice.
  • Layer 3 PoE switches and VLANs. We recommend them, and we can set them up. Separate lanes for staff, servers, guests and devices, so a problem in one lane has a harder time reaching the others.
  • Multi-factor sign-in, patching, and Huntress Managed EDR on every computer we manage. We recommend a weekly patching schedule. These close common ways in, and a person reviews the alerts. Monitoring is 24/7, with email and SMS alerts to our team. Huntress, a separate security team, works alongside us.
  • Awareness training, and no exposed remote desktop. Short quizzes and a monthly report card for staff, and remote desktop is never exposed to the internet. How our training works

A real story, told honestly

A Vancouver law firm was hit by ransomware. We reviewed their IT afterwards and recovered some files using existing, publicly available decryptors. Some files were still lost. What the review found

Live dataCopy 2Copy 3

3 copies

Your live data and two backups.

Storage AStorage B

2 kinds of storage

So one kind of failure can’t take both.

Vancouver, BC

1 copy offsite

Held in Canada, in Vancouver, BC.

A backup is only real once a test restore has proven it works.

Questions behind the Monday-morning test

These are the questions we help you answer. Ask us which ones matter most for your firm.

  • When was the last test restore, and what did it prove?
  • Could someone with a stolen admin password delete your backup copies? Not our immutable copies. For 30 days after each one is written, no one can change or delete it, not even an administrator or Benson Hunt.
  • Which system comes back first: email, the calendar, documents or trust accounting?
  • Who do you call first, and does your insurance policy say who that should be?

Where this meets the rules: in BC, Rule 10-4 asks for reasonable security for records and an immediate written report to the Law Society if custody or control is lost (see the advisory). Whether an incident has to be reported is a question for your firm’s own lawyer. This is IT guidance, not legal advice.

Why it matters, in plain words

The tech behind this page, and why it’s there. See all the plain guides.

Immutable backups

Why ransomware goes after the firm’s backups first

Without backups, the firm has to pay or rebuild. Our copies are locked for 30 days, and no one, not even us, can delete them early.

Read more about Immutable backups

Multi-factor sign in

Why a stolen password shouldn’t open a lawyer’s inbox

Passwords leak. A second check on a phone or a security key stops most stolen passwords from working.

Read more about Multi-factor sign in

DNS filtering

Why a bad link can fail before the page loads

Every web visit starts with a lookup. Known bad sites are blocked right there, in the office and on laptops.

Read more about DNS filtering

Ransomware questions we hear

Should we pay the ransom?

That is a decision for the firm, with your lawyer, your insurer and the police, not an IT call. What we can do is help you reach the point where paying is not your only way back. If you have cyber insurance, check its steps early, since policies often say who to call first.

Is RAID a backup?

No. RAID keeps a server running when a drive fails, but it will happily copy a deletion or an encrypted file across every drive. A backup is a separate copy, kept somewhere else.

Can Hyper-V stop ransomware?

No. Hyper-V makes recovery easier because servers are files that can be backed up and restored elsewhere. Getting in is made harder by the other layers: sign-in protection, patching, monitored endpoint protection, training and separate networks.

How fast could we be back?

It depends on how much data there is, where the copies sit and what was affected. We would rather work out an honest answer with you now than promise a number. That is what the Monday-morning test is for.

Want to run the Monday-morning test together?

Our regular hours are Monday to Friday, 7am to 5pm MT. For emergencies we are 24/7 on the same number, and it is always answered by a person. Call (604) 813-7881 and ask Tony for your free 30-minute insurer readiness review. No pressure, no jargon.