{"id":9169,"date":"2026-08-18T09:00:00","date_gmt":"2026-08-18T09:00:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9169"},"modified":"2026-08-18T09:00:00","modified_gmt":"2026-08-18T09:00:00","slug":"what-you-say-during-a-cyber-breach-can-and-will-be-used-against-you","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9169","title":{"rendered":"What you say during a cyber breach can \u2014 and will \u2014 be used against you"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">The first 24 hours after a cyber incident are messy. Teams are moving fast, and a lot gets said on Slack or email that can come back later. People are scrambling to contain the issue, figure out what happened and keep things moving. In the process, they create a record that doesn\u2019t always age well.<\/p>\n<p class=\"wp-block-paragraph\">Months and sometimes years later, when the dust is settled, CISOs often find out that those early communications get pulled apart in litigation or investigations. What your team documented and how they said it can have a longer tail \u2013 and a more disastrous financial outcome \u2013 than the attack itself.<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s easy to see how this happens. The instinct once you learn you\u2019ve been breached is to move fast. Get on a call. Fire off a Slack message. Loop in the lawyers. Start figuring out what happened.<\/p>\n<p class=\"wp-block-paragraph\">My experience is that <a href=\"https:\/\/nam10.safelinks.protection.outlook.com\/?url=https%3A%2F%2Fwww.csoonline.com%2Farticle%2F572499%2Fcybersecurity-litigation-risks-on-the-rise-what-cisos-should-worry-about-the-most.html&amp;data=05%7C02%7Ctweismann%40marketbridge.com%7Cc65bf2bccffd4298f25308deedb21199%7C2f0f75c5488d4df5b20e251bac7750fe%7C0%7C0%7C639209546276916345%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;sdata=hO7IsV1kSMvJYw3m7bOog2XY0VLGo3ZZ7BUk5knjwU8%3D&amp;reserved=0\">cyber litigation<\/a> doesn\u2019t hinge only on what happened. It also hinges on what you documented and what you said when it was happening. The problem is that the communications generated in those first chaotic hours often become evidence in litigation, regulatory investigations and enforcement actions. Many organizations operate under a dangerous illusion: copying legal on an email or Slack message makes it protected. It doesn\u2019t.<\/p>\n<p class=\"wp-block-paragraph\">Attorney-client privilege and work-product protection are real, but they are not a panacea. I\u2019ve seen that courts evaluating privilege claims in cyber cases don\u2019t care whether legal was merely copied on the thread. They need to see if the predominant purpose of a communication was to obtain or provide legal advice. A technical summary of how an attacker moved through a network, a timeline of what was patched and when, or an incident report documenting what the security team found are often created for operational reasons. Courts regularly rule these materials discoverable even when general counsel reviewed them afterward.<\/p>\n<p class=\"wp-block-paragraph\">The Sedona Conference, whose <a href=\"https:\/\/nam10.safelinks.protection.outlook.com\/?url=https%3A%2F%2Fwww.thesedonaconference.org%2Fwgs%2Fwg11&amp;data=05%7C02%7Ctweismann%40marketbridge.com%7Cc65bf2bccffd4298f25308deedb21199%7C2f0f75c5488d4df5b20e251bac7750fe%7C0%7C0%7C639209546276935553%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;sdata=ZWG5J9BlGGkAi8FA3%2FA6MYYiGZDkHUlqKU0WtqwSAzo%3D&amp;reserved=0\">working groups produce widely cited legal guidance<\/a> on cybersecurity and electronic information, has noted that courts are increasingly scrutinizing exactly these questions: was the communication created for legal advice, or was it ordinary business documentation that happened to pass through legal hands?<\/p>\n<h2 class=\"wp-block-heading\">Where privilege actually breaks down<\/h2>\n<p class=\"wp-block-paragraph\">During breach mitigation, you might expect the most damaging moments to come from technical forensics or a security program that couldn\u2019t withstand scrutiny. But the reality is that companies get into trouble when people\u2019s internal content filters break down under pressure.<\/p>\n<p class=\"wp-block-paragraph\">When a cyber incident hits, <a href=\"https:\/\/www.csoonline.com\/article\/4079876\/70-of-cisos-say-internal-conflicts-more-damaging-than-cyberattacks.html\">chaos is the norm<\/a>. Security teams need to deal with containment deadlines, regulatory notification windows, executive escalations and a hundred other priorities, none of which can wait. It\u2019s a stressful environment, and people tend to make assumptions or be overly candid across channels, whether it\u2019s Slack, Teams or emails.<\/p>\n<p class=\"wp-block-paragraph\">Comments like these create the most damaging evidence when they are exposed in discovery and become exhibits in a trial:<\/p>\n<p>\u201cWe were supposed to fix this six months ago\u201d<\/p>\n<p>\u201cNobody takes this seriously\u201d<\/p>\n<p>\u201cWe knew this was a risk\u201d<\/p>\n<p class=\"wp-block-paragraph\">If your incident response is happening in a 40-person Slack channel with legal just sitting in it, you are creating a searchable record for the plaintiff. Many executives and security teams operate with the misguided notion that adding your lawyer to an incident-specific Slack channel or slapping \u201cACP\u201d (attorney-client privilege) on the channel title means any conversation in that channel is protected. It is not.<\/p>\n<p class=\"wp-block-paragraph\">The courts have made it abundantly clear that a channel with dozens of participants is not considered privileged. The more people on the channel, the weaker the claim. If you\u2019re combining legal strategy discussions with operational discussions, there\u2019s a very high likelihood that you\u2019re going to overshare and put some questionable things on the record.<\/p>\n<p class=\"wp-block-paragraph\">Courts also do not limit discovery to the current incident. Opposing counsel is free to request documentation from prior incidents. This includes how the organization handled those events, what was said and what processes existed. The standard must hold across every incident, including the ones that never became public. If it doesn\u2019t, you\u2019re vulnerable.<\/p>\n<h2 class=\"wp-block-heading\">The AI problem nobody has figured out yet<\/h2>\n<p class=\"wp-block-paragraph\">If your AI tool is training on your incident data, you may have already waived privilege. Courts have only begun addressing whether AI-generated communications carry privilege protections and case law remains thin.<\/p>\n<p class=\"wp-block-paragraph\">There are some early warning signs.<\/p>\n<p class=\"wp-block-paragraph\">Early decisions indicate that using consumer-grade AI tools, in which the provider may train on user inputs, creates real exposure, since courts tend to look unfavorably on privilege claims when information has been shared with outside parties. <a href=\"https:\/\/www.csoonline.com\/article\/3966034\/ai-in-incident-response-from-smoke-alarms-to-predictive-intelligence.html\">Enterprise tools using AI<\/a> need to be designed to ensure confidentiality to have the highest likelihood of preserving legal privilege.<\/p>\n<p class=\"wp-block-paragraph\">AI note-takers are another gray area. Does an automated transcription tool change the level of privilege in a meeting where counsel is present? We don\u2019t know yet, but there are some indications.<\/p>\n<p class=\"wp-block-paragraph\">Is the AI a party to the incident?\u00a0 Arguably not, but that depends on the confidentiality protections in place and how the tool is designed. If there are no confidentiality protections, bye-bye privilege. Next, who all has access to the content of the AI output?\u00a0 If it is an unprivileged group, privilege might be gone too. We need to think about all of this without even mentioning the requirement that an attorney be involved in the communication. There are a lot of factors at play.<\/p>\n<h2 class=\"wp-block-heading\">Designing for privilege before the breach<\/h2>\n<p class=\"wp-block-paragraph\">By the time you\u2019re in the middle of an incident, it\u2019s already too late to fix this. Privilege is not something you can improvise under pressure. It must be designed into the process. That means establishing a clear structural separation between:<\/p>\n<p><strong>Operational record<\/strong> \u2014 the factual documentation that will show what the organization did and when<\/p>\n<p><strong>Legal strategy discussions<\/strong> that should remain protected (what you say, disclose and defend)<\/p>\n<p class=\"wp-block-paragraph\">If these are discussed in the same communication channel, then you\u2019re not protecting privilege; you\u2019re diluting it. Hiring \u201cdual-tracked\u201d forensic firms with one being directed by outside counsel doesn\u2019t solve this problem either. Instead, keeping those functions deliberately separated in dedicated places, rather than scattered across personal devices, consumer apps or improvised channels, makes privilege claims far more credible when they\u2019re held up to scrutiny later.<\/p>\n<p class=\"wp-block-paragraph\">In practice, that means defining specific channels and tools for legal strategy versus day-to-day incident operations, limiting participation in privileged discussions to those who truly need to be there, documenting who controls access and retention for each, and testing your process during tabletop exercises rather than live-fire events. Most teams have a plan going in, but that\u2019s not what the lawyers pay attention to. When the subpoena arrives, the focus shifts to what was said and documented. That\u2019s the part that sticks, and the part you must be able to defend.<\/p>\n<p class=\"wp-block-paragraph\">In breach litigation, the biggest liability usually isn\u2019t what happened. It\u2019s what your team said about it and where they said it.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>The first 24 hours after a cyber incident are messy. Teams are moving fast, and a lot gets said on Slack or email that can come back later. People are scrambling to contain the issue, figure out what happened and keep things moving. In the process, they create a record that doesn\u2019t always age well. [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9170,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9169","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9169"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9169"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9169\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9170"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9169"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9169"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9169"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}