Cyber incident response and legal professional privilege

Published By:

Professional man in a suit smiling, possibly for Elementor Single Post.

Gavin McInnes

Founder of GRM LAW

Key Takeaways:

  • Privilege turns on dominant purpose: Legal professional privilege protects confidential communications and documents created for the dominant purpose of legal advice or litigation, and copying a lawyer in does not create it.
  • Engage the lawyer first: A forensic report has a real prospect of protection when the lawyer is engaged first, retains the forensic firm directly and receives the report.
  • Notification obligations still apply: Privilege protects the legal analysis of exposure and strategy, and the business must still assess and notify eligible data breaches under the Privacy Act 1988 (Cth).
Jump to...
September 24, 2026

When a business discovers a ransomware attack or a data breach, the instinct is to call the IT provider or a forensic security firm first and worry about lawyers later, if at all. That sequencing is understandable. It is also, very often, the decision that later prevents a business from protecting its own investigation from disclosure. An incident response generates a large volume of sensitive material: forensic reports, log analysis, chat transcripts with a threat actor, negotiation records, internal briefings and board updates. Some or all of this material may later be sought by a regulator, an affected customer, an insurer or a party to litigation. Whether it can be withheld from disclosure depends heavily on decisions made in the first hours of the incident, well before anyone is thinking about a court case. Engaging a lawyer early, and structuring the response around that engagement, is often the single choice that determines whether legal professional privilege is available at all.

What legal professional privilege actually protects

Legal professional privilege is not a general shield over everything produced during a cyber incident. It protects confidential communications and documents that are brought into existence for the dominant purpose of giving or receiving legal advice (legal advice privilege), or for use in litigation that is reasonably anticipated or already underway (litigation privilege). The test that matters is dominant purpose. If a document was created mainly to restore systems, satisfy an insurer, brief staff or keep the business running, it does not become privileged just because a lawyer later reads it or forwards it.

Plain factual material is treated differently again. System logs, backup files, network diagrams and the underlying technical evidence of what happened are not privileged simply because they sit in a lawyer’s file. Privilege can attach to legal advice about those facts, and in the right circumstances to a report commissioned for the dominant purpose of that advice or of anticipated litigation, but it does not convert the facts themselves into something that can be withheld.

Why forensic reports are so often found not to be privileged

The most common privilege dispute in a cyber incident concerns the forensic report: the document that sets out how the attacker got in, what was accessed, and what needs to be fixed. Businesses frequently assume that because a lawyer was copied in, or because the report is marked “privileged and confidential”, the report is automatically protected. It is not that simple.

Courts have taken a narrow view of privilege claims over forensic reports where the surrounding evidence shows the report was actually commissioned to understand and remediate the problem, restore operations, or satisfy the requirements of a cyber insurance policy, rather than for the dominant purpose of legal advice or anticipated litigation. Where the forensic firm was engaged directly by IT, by management, or by the insurer before a lawyer was involved, and the report was then widely circulated to operational staff, the technical provider, the insurer and the board, it becomes very difficult to argue after the fact that the dominant purpose was legal. A label on the front page does not change the true purpose for which a document was created, and a regulator or opposing party is entitled to look behind the label at the retainer arrangements, the instructions given to the forensic firm, and who actually received and used the report.

This matters because a forensic report is usually the single most damaging document in a later dispute or regulatory inquiry. It often contains the clearest available account of what went wrong, how long the vulnerability existed, and what the business knew and when. Losing privilege over that document can shape the outcome of everything that follows.

Structuring the engagement to protect privilege

Privilege is not guaranteed by good intentions. It depends on the structure of the engagement from the outset. A business that wants a genuine prospect of protecting its investigation should, as a starting point:

  • Engage a lawyer as the first call, before the forensic firm, insurer panel provider or any other external vendor is instructed.
  • Have the lawyer retain the forensic firm directly, under a scope of work that records the dominant purpose as providing legal advice or preparing for anticipated litigation or regulatory action.
  • Address the forensic report to the lawyer rather than to the board, the insurer or IT management, and have the lawyer control further distribution.
  • Separate the privileged legal workstream (advice, strategy, regulator liaison) from the operational remediation workstream (patching, system restoration, business continuity), so that documents genuinely created for remediation are not later mislabelled as privileged and documents genuinely created for legal advice are not diluted by a mixed purpose.
  • Keep distribution of privileged material tight, on a need to know basis, and avoid forwarding legal advice into group chats, all staff briefings or unfiltered insurer correspondence.

The purpose of this structure is to allow candid internal analysis, the kind of analysis a business needs in order to actually understand and fix the problem, without every draft, working assumption and internal criticism becoming discoverable evidence in a later dispute. It does not involve concealing wrongdoing from a regulator or another party with a legitimate right to know.

Privilege, regulators and mandatory notification

Privilege does not excuse a business from its notification obligations. Where personal information is involved, the notifiable data breaches scheme under the Privacy Act 1988 (Cth) generally requires eligible businesses to assess whether a breach is likely to result in serious harm and, if so, to notify affected individuals and the regulator. Those factual notification obligations apply regardless of any privilege claim over the legal advice about how to respond. A business can, and generally should, be transparent about what happened, what data was affected and what steps it is taking, while still protecting the confidential legal analysis of its exposure and strategy from disclosure. Engaging a data breach response lawyer early puts the notification analysis and the privilege structure in place from the first day.

Regulators are also entitled to ask questions about the facts of an incident, and cooperating openly on the facts, while keeping legal advice about strategy and exposure confidential, is a normal and defensible position. What a business should avoid is using privilege as a reason to withhold factual cooperation, because that approach tends to increase regulatory scrutiny.

Reporting to the board without waiving privilege

Boards and senior management need a clear and complete picture of a cyber incident to discharge their governance obligations. That creates a genuine tension: the more widely privileged advice is shared, the greater the risk that privilege is waived, whether deliberately or by conduct. Waiver can occur where privileged advice is forwarded outside the group that needs it, summarised in a way that discloses its substance in board minutes circulated more broadly than necessary, or shared with a third party such as an insurer or auditor without appropriate protections in place.

In practice, this usually means the board should be told that legal advice has been obtained and briefed on its practical consequences and recommended actions, without every board pack reproducing the advice verbatim or forwarding privileged correspondence by email to a wide distribution list. Minutes can record that the board considered legal advice and resolved to act on it, without setting out the reasoning in full. Where information genuinely needs to go to an insurer or another party with a shared interest in the outcome, that should be done deliberately, with advice on whether a common interest arrangement is appropriate, rather than as a matter of administrative convenience.

Directors who want to understand how these obligations interact with their broader duties should read our articles on director duties and cyber security in Australia and on the 2026 Privacy Act reforms and what they mean for boards, both of which cover the governance side of this problem in more depth.

Building the response before you need it

The businesses that manage a cyber incident well are almost always the ones that decided how they would respond before the incident happened. An incident response plan that names a lawyer as the first call, alongside IT and the cyber insurer, removes the need to make a structural decision about privilege while the business is also trying to contain an active attack. Pre-negotiated panel arrangements with a forensic firm, agreed in advance with a lawyer’s involvement built into the engagement terms, avoid the scramble to retrospectively fix a structure that was set up under pressure. It is also worth reviewing cyber insurance policy wording in advance to understand who the policy expects to be engaged first and in what order, since some policies effectively dictate a sequence that can work against a later privilege claim if it is not managed carefully. Putting this structure in place before an incident occurs is straightforward and low cost. Trying to fix it once an incident is already underway is far more difficult, and the cost of getting it wrong can go well beyond the cost of the breach itself.

Frequently asked questions

Does simply copying a lawyer into emails during a breach make everything privileged?

No. Privilege depends on the dominant purpose for which a document or communication was created. That purpose is not changed by who happens to be copied in. Adding a lawyer to an email chain after the fact does not convert operational or business material into privileged legal advice.

Can we claim privilege over a forensic report if we only engaged a lawyer after the report was already underway?

It is much harder, and often not possible. Courts examine the true purpose behind the engagement, including who instructed the forensic firm and who received the report. Retrofitting a privilege claim onto a report that was commissioned and circulated for operational reasons is unlikely to succeed.

Does claiming privilege stop us from notifying regulators or affected individuals?

No. Notification obligations under schemes such as the notifiable data breaches scheme relate to the facts of the incident and are separate from any privilege claim over legal advice about strategy and exposure. A business can meet its notification obligations while still protecting confidential legal advice from disclosure.

Can we share the privileged forensic report with our cyber insurer?

This needs care. Insurers often need the underlying facts to assess a claim, but sharing a fully privileged report without thought can waive privilege. Advice should be taken on how to give the insurer what it reasonably needs, through a common interest arrangement or a carefully scoped factual summary, without exposing the full privileged analysis unnecessarily.

If your business is responding to a cyber incident, or wants to put a response structure in place before one occurs, contact GRM LAW to speak with our cyber advisory team.

Disclaimer: This is general information only and is not legal advice. For advice on your circumstances, contact GRM LAW.

JUMP TO...
Table of Contents

Published By:

Professional man in a suit smiling, possibly for Elementor Single Post.

Gavin McInnes

Founder of GRM LAW

Contact us today.

Our senior lawyers will contact you to discuss your situation & outline next steps.

Legal & Compliance Insights

What Our Clients Say

Request Free Consultation

Not sure which matter or service is right for you? Leave your details & our lawyers will contact you to discuss your situation & outline next steps.

Enquire Now

Tell us briefly what you need help with & we’ll reply within 1 business day.

    ICT managed & secured by Black Shard  ·  SMB1001:2026 Gold certified