Privilege Dies in the Distribution List
…and other lessons from modern incident response
Somewhere between the ransom note arriving in your inbox and opposing counsel eyeing your forensic report, your incident stopped being a technical problem. A ransomware crew posts your data, and a reporter calls before your security team has finished figuring out which accounts were compromised. At that point the story belongs to everyone but you. That’s incident response in 2026, and pretending it’s an IT cleanup job is how companies end up as case law.
The invoices are public, and they’re recent. In March 2023, LockBit demanded $10 million from Managed Care of North America (MCNA), and after management refused, the crew published 700GB of stolen data covering 8,923,662 individuals, the largest healthcare breach reported that year. The reconstruction assembled from the federal docket in Crowe v. Managed Care of North America, where the deal received preliminary approval in July 2026, puts the eventual bill somewhere between $16 million and $23 million once defense fees, forensic work, remediation, and settlement ceilings are stacked. The ransom was never the expensive part.
Delta Dental is still paying for the MOVEit zero-day three years on, having settled with New York’s Department of Financial Services over a vulnerability Progress Software moved quickly to patch. The settlement announcement puts the exposure at 6.9 million individuals across the broader Delta Dental network. And a Massachusetts Superior Court settlement over a handful of compromised employee mailboxes cost American Consumer Credit Counseling as much as $2.15 million. A full 169 days passed between the first unauthorized access and the first affected consumer learning about it.
For most companies, incidents are no longer a matter of if, or even when; repeat attacks are the norm. Add AI-enabled exploitation and model failures to the threat list, and the scope of what counts as an “incident” keeps widening. But from where the business leaders sit, an incident is an incident, and it gets one response team whether the root cause was ransomware or a biased model.
The Roster Outgrew IT Years Ago
The single most expensive mistake in incident response is showing up with only technical people. Legal, human resources, customer service, and communications all have jobs to do on day one, and they need to know their assignments before the fire starts. A workable roster covers these roles.
| Role | What they contribute during response |
|---|---|
| Executive sponsor | Makes shutdown, notification, and escalation calls in minutes; keeps the C-suite and board informed |
| Incident commander | Connects the technical and communication tracks; owns the big picture |
| IT and security | Drives containment, supports forensics, feeds notification analysis |
| Breach counsel | Directs the investigation, manages privilege, advises on notification obligations |
| HR and customer service | Handles the humans, internal and external |
| PR | Press strategy, statements, message consistency |
| Outside bench | Forensics, insurance, notification vendor, eDiscovery, ransom negotiators, credit monitoring |
Find your bench before you need it
Forensic, insurance, notice, eDiscovery, negotiation, and communications advisors should be identified before an incident, because you don’t want to be comparison shopping vendors at 2 a.m. on a holiday weekend. Insurance carriers often require their own approved panel anyway, so the introductions might as well happen in peacetime.
Decide who can pull the plug, in advance
In a fast-moving incident, decisions arrive on a schedule of minutes rather than quarterly governance cycles. Somebody with actual power needs to be reachable, informed, and empowered to shut down a system or authorize customer notification without convening a committee.
When it’s an AI incident
A bad model output is a security question and a legal question at the same time, and organizations building AI response plans treat that ambiguity as normal. The operating rule is simple. When nobody’s sure whether the incident is a cyber event, an AI event, or both, the security lead and the attorneys get called simultaneously.
Run the Response in Tracks
- Technical track. Containment, evidence preservation, account security, system recovery.
- Communication track. Internal updates, customer notices, regulator assessment, message consistency as facts change.
- Legal track. A separate, counsel-directed investigation beneath both.
One warning on vocabulary. “Two-track” gets used both for this technical/legal split and for the two investigations running inside the legal track, so say which one you mean before the meeting starts.
The incident lead connects the tracks, which is why that role matters more than any org chart suggests. Both outer tracks run under a constraint that never lifts. You have to be transparent before you have every answer, and informed enough not to guess.
Inside the legal track, the first investigation is the ordinary-course business work, which produces findings you’re willing to share for compliance and remediation. The second is the counsel-directed investigation, which exists for legal advice and, eventually, litigation. Keeping them separate is the difference between a discoverable file and a protected one, and courts have blessed the structure when companies actually maintain it.
AI incidents run through the same machinery, provided it was built correctly. For model-driven incidents, liability triage now runs ahead of technical triage, and a model that denies people loans, housing, or jobs creates problems in all three tracks at once.
Privilege Survives Planning and Dies in Execution
The doctrine in four sentences
In Upjohn v. United States, the Supreme Court held that communications between corporate counsel and employees can be privileged, rejecting a narrow view that limited privilege to top management. Privilege protects communications made to get or give legal advice, never the underlying facts. United States v. Kovel, a 1961 Second Circuit decision, extended protection to consultants when counsel needs them to render advice, which is the doctrinal hook that lets forensic firms work under privilege at all. Work product, a related protection for materials prepared in anticipation of litigation, follows friendlier waiver rules.
Attorney-client privilege can evaporate on disclosure to almost any third party; work product typically survives anything short of handing it to an adversary.
Seven factors courts weigh
When judges evaluate whether a forensic report is protected, they weigh seven factors drawn from recent decisions.
- When outside counsel was retained
- Who hired the consultant
- Whether the consultant had a pre-existing operational relationship with the company
- The actual content of the work product
- Whether a parallel, non-privileged investigation existed
- How widely the work product was distributed
- How the company ultimately used it
Five of the seven factors are about execution, not architecture. You can retain counsel promptly, draft a beautiful engagement letter, and still lose protection because the report went to fifteen executives.
The case law
There’s good news buried in the case law. In In re FirstEnergy Corp., the Sixth Circuit forcefully reaffirmed the Upjohn framework in 2025, holding that what matters on privilege is whether the company sought legal advice in the first place, not what it later did with that advice. The court also rejected expansive waiver theories, finding no subject-matter waiver from disclosures in a deferred prosecution agreement.
The rest of the ledger is uglier, and remarkably consistent.
| Case | Year | What killed the protection |
|---|---|---|
| In re Dominion Dental Services USA | 2019 | Operational purpose, customer notifications, shared with non-legal departments |
| In re Capital One | 2020 | Longstanding vendor relationship, scope never changed, report to four regulators and business units |
| In re Rutter’s | 2021 | Engagement letter read like an IT monitoring contract, and the client read the report before the law firm did |
| Wengui v. Clark Hill | 2021 | Blended investigation, FBI coordination, forensics firm worked with third parties without counsel present |
| Leonard v. McMenamins | 2023 | Retained through counsel, but the report ran to business remediation and was widely shared internally |
| In re Samsung Customer Data Security Breach | 2024 | Distribution alone; fifteen executives received it |
Companies lose privilege on distribution and use, not on doctrine.
Execution rules that follow from the case law
- Counsel hires the consultant, under a separate privileged engagement rather than a statement of work bolted onto an existing operational contract.
- Findings go to counsel, and counsel decides distribution on a need-to-know basis, documented somewhere.
- Sensitive conclusions about causes and recommendations travel orally or in tightly controlled settings (attorneys who do this for a living say the phone call is underrated).
- Resist slapping “privileged and confidential” on everything and cc’ing counsel on routine operations. Over-designation doesn’t create privilege, can waive what you had, and occasionally invites sanctions. Judges have noticed the pattern, and they don’t love it.
Communicating While Blind
The core dilemma of incident communications is simple. You owe people transparency before the facts are settled, but you can’t guess, and both premature silence and premature certainty carry regulatory and reputational costs.
One incident, three audiences
- Internal. What’s confirmed, what’s affected, what to do right now, and who speaks externally. Include the prohibitions, because well-meaning employees improvise explanations and forward suspicious emails around otherwise disciplined responses.
- Customers and partners. What happened, what data or services are involved, what you’re doing, what they should do, and where updates land. Plain language, no forensic detail, no speculation about root cause.
- Regulators. A factual record of what happened, who is affected, and what you’re doing about it. Under the General Data Protection Regulation (GDPR), the UK and EU set a 72-hour clock for notifying the supervisory authority once a notifiable personal data breach is identified, with phased updates permitted. In the US, you’re juggling state breach statutes, sector regulators, public companies’ Securities and Exchange Commission (SEC) reporting obligations, and contractual notice duties that vendors sometimes forget exist.
Timing, narratives, and pre-staged follow-ups
Notify early and you’re the company that was transparent. Investigate first and you’re the company that avoided overnotification with a rushed, wrong notice. Both positions hold, provided you can reconstruct the timeline from discovery to notification on demand.
The MOVEit zero-day forced hundreds of downstream businesses into exactly this position in 2023, and the lag is the part people underestimate. Exploitation began May 27, the patch shipped May 31, and Delta Dental’s $2.25 million settlement with New York’s Department of Financial Services arrived almost three years later, in April 2026. Communication decisions made in the first week get litigated in year three, and the companies that fared best pre-staged a general notice plus a detailed follow-up for people with specific questions rather than freestyle drafting under deadline. One habit belongs in written policy. Read every outbound message as if a plaintiff’s lawyer will put it in front of a jury, because one might.
Draft the Record for the Reader You Fear
Your incident response document is evidence the moment litigation starts, so write it that way.
- State facts neutrally, including timestamps, IP addresses, and what logs were reviewed, without editorial seasoning like “obviously suspicious.”
- Show your reasoning so conclusions hold up.
- Avoid legal terms of art. Skip personally identifiable information (PII), protected health information (PHI), and their cousins in favor of listing the specific data fields involved, because those labels import statutory meanings you may not intend to concede.
- Keep blame and “lessons learned” out of the record entirely.
The classic example is the closing sentence problem.
- Problematic. “Our security team ensured that our systems were free from any unauthorized access.”
- Better. “No evidence of unauthorized activity was observed following remediation efforts by our security team.”
The first version is an admission waiting for cross-examination about how you were so sure, while the second is a statement of evidence that a competent examiner can defend.
Preparation Is the Whole Game
Everything above happens under pressure, so preparation is the part that earns its keep. The best plans read like a brochure, not a book. Teams and checklists, backup contacts, activation criteria, and key questions, rather than a hundred-page manual nobody opens during an outage.
- Tabletop exercises on the calendar at least annually, ideally paired with a review of attacks that nearly succeeded. Asking what would have happened if the last defensive layer had failed produces sharper lessons than hypotheticals.
- Hard-copy contact sheets and an out-of-band communication path for the scenario where your own platforms are compromised.
- A plan review twice a year, plus updates whenever people change roles, which they tend to constantly.
The End of the Story
Back to the ransom note, the data leak, the reporter’s call. The companies that survive those mornings with their privilege intact, their customers still talking to them, and their regulators merely annoyed are the ones where security and legal rehearsed this together before it happened. One team, multiple tracks, from the first hour.
Nobody responds alone. The ones who try usually end up linked in a CourtListener docket.