Ransomware on Sunday Night: What the Recovery Clock Looks Like When You Have a Deposition Tuesday
Sunday night at 11pm, someone’s laptop — left on and connected to the office network — starts encrypting files. By the time your first associate arrives Monday morning, your document management system is down, your network shares are inaccessible, and there’s a ransom note on every workstation screen.
You have a deposition Tuesday at 9am. Exhibits are in the DMS. The transcript request went out Friday. Your hearing is Thursday — motion papers due to opposing counsel by noon Wednesday.
The firms that get through a weekend incident without missing a deadline aren’t the ones with the best luck. They’re the ones who understood, before it happened, what recovery actually takes.
The Recovery Clock, Honestly
When ransomware hits a firm with no preparation, the sequence looks like this:
- Hour 0–2: Someone realizes the problem isn’t a single machine. IT (internal or external) gets called. The scope of the infection gets assessed.
- Hour 2–6: Decision point — pay the ransom or restore from backup. If you’re restoring, where are the backups? Are they clean? When were they last tested?
- Hour 6 onward: Assuming clean backups exist and are accessible, restoration begins. Restore time is a function of data volume and circuit speed, not a fixed 12–24 hours. Pulling 2–4 TB from cloud backup over a 100 Mbps circuit is tens of hours to a few days. The same job on a 1 Gbps circuit is closer to 4–10 hours — still not “back by lunch,” and that’s before you verify the restore is clean.
- After restore: Systems come back online. Staff can access files. But which version of those files?
That last question is where RPO — Recovery Point Objective — becomes concrete.
What RPO Means When Your Deposition Is in 36 Hours
RPO is the maximum age of data you can recover. If your backup runs nightly at midnight, your RPO is roughly 24 hours — meaning in a worst-case scenario, you lose up to a day’s worth of work.
For a litigation firm, that 24-hour window might include:
- Exhibit revisions made Saturday afternoon
- The final version of a declaration your paralegal finished Sunday morning
- Deposition outline edits your associate made Sunday evening before the attack hit
If those files aren’t in your backup, they don’t exist anymore. You’re working from the version that existed Friday night.
A 4-hour RPO — available through continuous or near-continuous backup — cuts that loss window dramatically. The difference in cost between nightly backup and 4-hour incremental backup is typically on the order of $50–$150/month, depending on data volume (illustrative, not a quote). The difference in outcome on a Monday morning like this one is significant.
What RTO Means When Your Hearing Is Thursday
RTO — Recovery Time Objective — is how long it takes to get from “everything is down” to “staff can work again.”
A documented RTO of 4 hours sounds fast. What it actually means depends on what your IT provider is committing to:
- 4 hours to begin restoration, or 4 hours to complete it?
- Does the RTO cover a full server failure, or just certain types of outages?
- Is that RTO backed by a contract with defined credits, or is it a sales number?
For a firm with physical servers on-site and no offsite failover, a realistic RTO after a ransomware event is 24–72 hours. That’s not a scare number — it’s the time it takes to assess the damage, source clean hardware if needed, restore data, and verify that restored systems are actually clean before reconnecting them to the network. Reconnecting too fast and reinfecting from a compromised device is a real failure mode.
For a firm with cloud-based infrastructure or a properly configured backup and disaster recovery (BDR) appliance, RTO can be measured in hours. Some BDR appliances can spin up a virtualized copy of your server locally while the full restore runs in the background — meaning staff can access files within 2–4 hours even while the full recovery is still in progress.
With a deposition Tuesday and a hearing Thursday, the difference between a 4-hour RTO and a 48-hour RTO is the difference between a difficult Monday and a genuinely damaging week.
The E-Filing Question
One thing litigation firms often overlook in recovery planning: your ability to file doesn’t depend entirely on your own systems.
If your document management system is down but you have a clean laptop with internet access, you can still access:
- PACER (federal courts) — your account is cloud-based. As long as you have your credentials stored somewhere outside the compromised network (a password manager, a printed sheet in a locked drawer), you can access case dockets, download filed documents, and submit filings through CM/ECF from any browser.
- Odyssey eFileNV (Nevada state courts) — same principle. Your account lives on Tyler Technologies’ servers, not yours. A ransomware attack on your office network doesn’t touch it.
This matters for two reasons. First, it means your Thursday hearing deadline may be survivable even if your internal systems aren’t fully restored — as long as you can reconstruct or access the documents you need. Second, it means your recovery plan should explicitly account for which attorneys have their e-filing credentials accessible outside the office network, and whether those credentials are current.
A firm that loses access to its own DMS but can still pull filed versions of its motion papers from PACER and submit a corrected version through eFileNV is in a very different position than a firm that can’t access anything.
This isn’t a workaround — it’s a legitimate part of your continuity plan. Write it down. Make sure more than one person knows it.
The Backup Questions Worth Asking Now
Most firms think they have backups. Fewer firms know the answers to these questions:
Where are the backups stored? If your backup destination is a NAS device on the same network as your servers, ransomware will encrypt the backups too. Offsite or cloud backup with versioning is the standard. Air-gapped or immutable backup storage is better.
How long are backups retained? Ransomware dwell time is often weeks before anyone notices — long enough that a 7-day retention window can mean every backup you have already contains the malware. That is a common pattern, not a law. Thirty-day retention is a reasonable minimum for a litigation firm. Ninety days is better.
When was the last time you actually restored from backup? Not “ran a backup” — restored. If your IT provider can’t tell you the date and result of the last test restore, you don’t actually know whether your backups work.
How long did the last test restore take? This is your real RTO. Not the number in the sales sheet — the number from the last time someone actually ran the recovery process and timed it.
What a Reasonable Recovery Plan Looks Like
You’re not trying to build a Fortune 500 disaster recovery program. You’re trying to make sure a Sunday night ransomware attack doesn’t blow a Tuesday deposition or a Thursday hearing.
The components that matter for a litigation practice with a live docket:
- Offsite or cloud backup with immutable storage — so ransomware can’t encrypt your backups
- RPO of 4 hours or less — so you’re not losing a full day of work
- A BDR appliance or cloud failover — so you can get staff working in hours, not days
- 30-day backup retention minimum — so a slow-moving infection doesn’t compromise every backup you have
- Documented credentials for PACER and eFileNV stored outside the primary network — so e-filing access survives an outage
- A written incident response plan — a one-page document that tells the managing partner who to call first, in what order, and what not to do (like reconnecting systems before they’ve been verified clean)
None of this requires exotic technology. It requires decisions made before the Sunday night call, not during it.
The Math
A BDR appliance with cloud replication and 30-day retention typically runs roughly $300–$600/month depending on data volume (illustrative ranges, not a quote). That’s often the difference between a 4-hour RTO and a 48-hour one.
A missed deposition costs more than that in attorney time alone — before you get to continuance fees, a damaged client relationship, or the consequences of a missed filing deadline.
The question isn’t whether the investment is worth it. The question is whether you’ve done the math before you needed to.
If you’re a litigation firm in the Henderson or Las Vegas area and you’re not sure how your current backup setup would hold up against this scenario, our IT assessment is a good place to start. It takes about ten minutes and gives you a specific picture of where your recovery gaps are — before you need to find out the hard way.