Skip to content
August 18, 2026

What you say during a cyber breach can — and will — be used against you

What you say during a cyber breach can — and will — be used against you

The first 24 hours after a cyber incident are messy. Teams are moving fast, and a lot gets said on Slack or email that can come back later. People are scrambling to contain the issue, figure out what happened and keep things moving. In the process, they create a record that doesn’t always age well.

Months and sometimes years later, when the dust is settled, CISOs often find out that those early communications get pulled apart in litigation or investigations. What your team documented and how they said it can have a longer tail – and a more disastrous financial outcome – than the attack itself.

It’s easy to see how this happens. The instinct once you learn you’ve been breached is to move fast. Get on a call. Fire off a Slack message. Loop in the lawyers. Start figuring out what happened.

My experience is that cyber litigation doesn’t hinge only on what happened. It also hinges on what you documented and what you said when it was happening. The problem is that the communications generated in those first chaotic hours often become evidence in litigation, regulatory investigations and enforcement actions. Many organizations operate under a dangerous illusion: copying legal on an email or Slack message makes it protected. It doesn’t.

Attorney-client privilege and work-product protection are real, but they are not a panacea. I’ve seen that courts evaluating privilege claims in cyber cases don’t care whether legal was merely copied on the thread. They need to see if the predominant purpose of a communication was to obtain or provide legal advice. A technical summary of how an attacker moved through a network, a timeline of what was patched and when, or an incident report documenting what the security team found are often created for operational reasons. Courts regularly rule these materials discoverable even when general counsel reviewed them afterward.

The Sedona Conference, whose working groups produce widely cited legal guidance on cybersecurity and electronic information, has noted that courts are increasingly scrutinizing exactly these questions: was the communication created for legal advice, or was it ordinary business documentation that happened to pass through legal hands?

Where privilege actually breaks down

During breach mitigation, you might expect the most damaging moments to come from technical forensics or a security program that couldn’t withstand scrutiny. But the reality is that companies get into trouble when people’s internal content filters break down under pressure.

When a cyber incident hits, chaos is the norm. Security teams need to deal with containment deadlines, regulatory notification windows, executive escalations and a hundred other priorities, none of which can wait. It’s a stressful environment, and people tend to make assumptions or be overly candid across channels, whether it’s Slack, Teams or emails.

Comments like these create the most damaging evidence when they are exposed in discovery and become exhibits in a trial:

  • “We were supposed to fix this six months ago”
  • “Nobody takes this seriously”
  • “We knew this was a risk”

If your incident response is happening in a 40-person Slack channel with legal just sitting in it, you are creating a searchable record for the plaintiff. Many executives and security teams operate with the misguided notion that adding your lawyer to an incident-specific Slack channel or slapping “ACP” (attorney-client privilege) on the channel title means any conversation in that channel is protected. It is not.

The courts have made it abundantly clear that a channel with dozens of participants is not considered privileged. The more people on the channel, the weaker the claim. If you’re combining legal strategy discussions with operational discussions, there’s a very high likelihood that you’re going to overshare and put some questionable things on the record.

Courts also do not limit discovery to the current incident. Opposing counsel is free to request documentation from prior incidents. This includes how the organization handled those events, what was said and what processes existed. The standard must hold across every incident, including the ones that never became public. If it doesn’t, you’re vulnerable.

The AI problem nobody has figured out yet

If your AI tool is training on your incident data, you may have already waived privilege. Courts have only begun addressing whether AI-generated communications carry privilege protections and case law remains thin.

There are some early warning signs.

Early decisions indicate that using consumer-grade AI tools, in which the provider may train on user inputs, creates real exposure, since courts tend to look unfavorably on privilege claims when information has been shared with outside parties. Enterprise tools using AI need to be designed to ensure confidentiality to have the highest likelihood of preserving legal privilege.

AI note-takers are another gray area. Does an automated transcription tool change the level of privilege in a meeting where counsel is present? We don’t know yet, but there are some indications.

Is the AI a party to the incident?  Arguably not, but that depends on the confidentiality protections in place and how the tool is designed. If there are no confidentiality protections, bye-bye privilege. Next, who all has access to the content of the AI output?  If it is an unprivileged group, privilege might be gone too. We need to think about all of this without even mentioning the requirement that an attorney be involved in the communication. There are a lot of factors at play.

Designing for privilege before the breach

By the time you’re in the middle of an incident, it’s already too late to fix this. Privilege is not something you can improvise under pressure. It must be designed into the process. That means establishing a clear structural separation between:

  • Operational record — the factual documentation that will show what the organization did and when
  • Legal strategy discussions that should remain protected (what you say, disclose and defend)

If these are discussed in the same communication channel, then you’re not protecting privilege; you’re diluting it. Hiring “dual-tracked” forensic firms with one being directed by outside counsel doesn’t solve this problem either. Instead, keeping those functions deliberately separated in dedicated places, rather than scattered across personal devices, consumer apps or improvised channels, makes privilege claims far more credible when they’re held up to scrutiny later.

In practice, that means defining specific channels and tools for legal strategy versus day-to-day incident operations, limiting participation in privileged discussions to those who truly need to be there, documenting who controls access and retention for each, and testing your process during tabletop exercises rather than live-fire events. Most teams have a plan going in, but that’s not what the lawyers pay attention to. When the subpoena arrives, the focus shifts to what was said and documented. That’s the part that sticks, and the part you must be able to defend.

In breach litigation, the biggest liability usually isn’t what happened. It’s what your team said about it and where they said it.

Subscribe to get the latest tech updates!

We don’t spam! Read our privacy policy for more info.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.