What You Say During a Cyber Breach Can -- and Will -- Be Used Against You
What You Say During a Cyber Breach Can – and Will – Be Used Against You
Cyber breach communications can become costly evidence 💰, making disciplined documentation and privilege practices essential from day one. What your team documented and how they said it can have a longer tail - and a more disastrous financial outcome - than the attack itself. The problem is that the communications generated in those first chaotic hours often become evidence in litigation, regulatory investigations, and enforcement actions.
Attorney-client privilege and work-product protection are real, but they are not a panacea. Courts evaluating privilege claims in cyber cases don’t care whether legal was merely copied on the thread. They need to see if the predominant purpose of a communication was to obtain or provide legal advice. Materials created for operational reasons are regularly ruled discoverable even when general counsel reviewed them afterward. The Sedona Conference, whose working groups produce widely cited legal guidance on cybersecurity and electronic information, has noted that courts are increasingly scrutinizing exactly these questions: was the communication created for legal advice, or was it ordinary business documentation that happened to pass through legal hands? Comments like these create the most damaging evidence when they are exposed in discovery and become exhibits in a trial: “We were supposed to fix this six months ago,” “Nobody takes this seriously,” “We knew this was a risk.”
If your incident response is happening in a 40-person Slack channel with legal just sitting in it, you are creating a searchable record for the plaintiff. The courts have made it abundantly clear that a channel with dozens of participants is not considered privileged. If you’re combining legal strategy discussions with operational discussions, there’s a very high likelihood that you’re going to overshare and put some questionable things on the record.
Additionally, if your AI tool is training on your incident data, you may have already waived privilege. Courts have only begun addressing whether AI-generated communications carry privilege protections and case law remains thin. Early decisions indicate that using consumer-grade AI tools, in which the provider may train on user inputs, creates real exposure, since courts tend to look unfavorably on privilege claims when information has been shared with outside parties. Enterprise tools using AI need to be designed to ensure confidentiality to have the highest likelihood of preserving legal privilege.
Privilege is not something you can improvise under pressure. It must be designed into the process, establishing a clear structural separation between operational record and legal strategy discussions that should remain protected. If these are discussed in the same communication channel, then you’re not protecting privilege; you’re diluting it. Keeping those functions deliberately separated in dedicated places makes privilege claims far more credible when they’re held up to scrutiny later. In practice, that means defining specific channels and tools for legal strategy versus day-to-day incident operations, limiting participation in privileged discussions, and testing your process during tabletop exercises. In breach litigation, the biggest liability usually isn’t what happened. It’s what your team said about it and where they said it.