Artificer Legal Pty Ltd
ABN 83 678 885 179
3/55 Pyrmont Bridge Rd
Pyrmont NSW 2009
hello@artificer.legal
+61 2 7240 1969
Liability limited by a scheme approved under Professional Standards Legislation
Two practitioners who run incident matters from the legal seat — and who routinely sit opposite the forensic teams you might one day join.
Principal · Artificer Legal
Tyler began his legal career in general practice before moving in-house at Agilyx Group, a multinational technology company implementing complex finance and HR systems. He then moved to Clyde & Co as breach counsel. During the pandemic he joined Slipstream Cyber as Incident Response Manager, before later founding Artificer Legal and its sister DFIR practice, Artificer Cyber.
Senior Associate · Gilchrist Connell
Adam worked for over 6 years as a paralegal before admission to the legal profession, following which he was a foundational member of the Cyber Incident Response Practice at Clyde & Co. He then moved to Gilchrist Connell and is now a Senior Associate in their cyber practice. Has run incident matters across SME, mid-market and ASX-listed insureds, working under instruction from most of Australia's most well known cyber underwriters.
Forensic investigators tend to assume lawyers neither need nor should have a detailed grasp of the technology or environment. Lawyers tend to assume the same about investigators and the legal landscape — privilege, the Privacy Act, cyber insurance. The reality is that incident work is multi-disciplinary.
Both sides need a working command of the other's domain. Today is a step toward closing that gap. We will examine:
The forensic report you write is one document inside a much longer process: privilege, privacy advice, regulatory defence, third-party claims risk and litigation, subrogated recoveries. By the end of today you'll see how your investigation moves through the full lifecycle of a cyber insurance claim. We will look at:
What your customer has done to prepare (or failed to do).
The 5pm Friday afternoon triage call.
Your duties as an expert witness operating in the chaos of a cyber incident.
Walking through a sample forensic report to see how lawyers will read it.
Lawyers vs forensic teams — the competing commercial and professional drivers.
Where the report lands and how it feeds into real-world business advice.
What we hope you take away — and Q&A.
Why cyber insurance is becoming increasingly important in DFIR engagements.
DFIR are purchased increasingly through cyber insurance policies — many jobs are built around delivering inclusions under a cyber policy.
Every cyber policy splits along one line:
The same incident can trigger expenses on both sides — and your forensic findings feed each of them differently.
The triage, scoping and the agendas of everyone involved in the response.
A summary of the communication pathways to setup an Insured's Incident Response Team.
By day three, every party is operating on their own clock and their own workstream – lets unpack the agendas of each party at this stage of the incident response.
| Party | Key question they're asking | What's driving them |
|---|---|---|
| Insured (CEO / CISO) | "How bad is it, and when are we back up?" | Business continuity, customer impact, board exposure |
| Broker | "Is my client being looked after under the policy I sold them?" | Client retention, future renewal, reputation in the market |
| Insurer / claims handler | "What's the reserve? Is the reserve accurate?" | Cost certainty, indemnity scope, reporting structure |
| Coverage counsel | "Where can the insurer reduce or decline cover?" | Reducing costs of overall claim, limiting claim blowout |
| Breach counsel | "Are we under privilege, how quickly can we move, how big is this incident really?" | Privilege, regulatory defensibility, downstream litigation exposure, but ultimately: are all parties happy - insurer AND insured |
| Crisis comms / PR | "How do we contain this? What's Plan B if it blows up?" | Narrative control, demonstration of skill, get more work in future |
| MSP / IT provider | "Can we gain more work, and is the incident attributable to us?" | Avoid blame, make money, justify ongoing involvement & future work |
| Forensic provider — you | "How much work is involved in the investigation? How effectively will the client be managed?" | Defensibility of the report, scope clarity, evidentiary integrity, not being overburdened with client management |
You duties as an expert witness operating in the chaos of a Cyber Incident.
If your report is tendered as expert evidence, you are bound by a code of conduct. The code varies by jurisdiction, but the spine is the same.
What every version requires of you, in substance:
Legal professional privilege (also called client legal privilege under the uniform evidence legislation) protects confidential communications between a client and their lawyer from being compelled in litigation, regulatory investigations, or production to third parties.
Why the law protects it. The High Court treats privilege as a substantive right, not a mere rule of evidence (Daniels Corporation v ACCC (2002); Esso v Commissioner of Taxation (1999)). The justification is practical: the administration of justice depends on clients being able to tell their lawyers the unvarnished truth — including the embarrassing, the incriminating, and the uncertain — and lawyers being able to give frank advice in return. Without that protected channel, clients self-censor, advice gets worse, and disputes are resolved on incomplete facts. Privilege is the price the system pays for candour.
It comes in two limbs:
The test is dominant purpose, not "a purpose". If the dominant purpose of an incident report is to fix the network, restore operations, or brief the board, it is not privileged — even if a lawyer commissioned it, sat on the call, or received a copy.
Privilege is not limited to lawyer–client communications. It can extend to communications with — and reports prepared by — third-party experts, but only if the dominant purpose test is satisfied.
The through-line: privilege can protect a forensic report, but courts will look at the contemporaneous record — instructions, scoping, drafts, distribution — to decide what the dominant purpose actually was.
A privileged report is not subpoena-able, not discoverable in civil proceedings, and not (without waiver) producible to regulators. That changes the calculus on both sides — for the insured, for counsel, and for you as the forensic expert.
The most common strategy is to break what would have been a single investigation report into three deliverables, each with its own scope and audience:
Each engagement, each scope, each distribution list is deliberate. Done well it gives counsel a defensible privilege claim over the findings; done sloppily it produces three documents that all get produced anyway.
Robertson v Singtel Optus Pty Ltd [2023] FCA 1392 (Beach J), upheld in Singtel Optus Pty Ltd v Robertson [2024] FCAFC 58 (Murphy, Anderson, Neskovcin JJ, 27 May 2024).
McClure v Medibank Private Ltd [2025] FCA 167 (Beach J, 4 April 2025).
Australian Securities and Investments Commission v RI Advice Group Pty Ltd [2022] FCA 496 (Rofe J, 5 May 2022).
How the breach counsel reads the report, and what you might be asked to change.
The drafting process is not a solo exercise. From the moment containment is reached, the report is co-produced with counsel — and the conversations along the way are exactly what privilege fights end up turning on.
Present a draft report with findings. The first draft goes to counsel — not to the client's IT team, not to the board, not to the insurer's claims handler. It contains your full technical narrative and the conclusions you would stand behind in cross-examination today.
Lawyer review call with the investigator. Counsel reads the draft and gets you on the phone. The review focuses on alignment to scope (is what you've written what counsel asked you to opine on?), removal of out-of-scope material (observations that are interesting but not part of the engagement, or that counsel does not want you to opine on), and re-characterising findings that are in scope so they are accurate but less prejudicial — "the actor exploited a vulnerability in [software]" instead of "[Client] did not have the latest version of [software]."
None of this is dishonest. It is the legitimate work of taking a technical document and making it fit for legal use.
Further draft circulated, or final report issued. Depending on the size of the changes, you either go round the loop one more time or sign off the final. The final is the one that goes to the client and (if applicable) the regulator. Earlier drafts and your call notes still exist — and may be produced if privilege is later lost.
Before we pull the report apart on the next slides, here is the real thing — a representative DFIR report drafted under counsel's instructions.
Read it the way a lawyer reads it: where does the executive summary land, what gets quantified, what gets characterised, how is uncertainty flagged, and which sentences could survive cross-examination.
david.greenfie_l_d@outlook.com) used to send altered banking details to the third-party purchaser mid-settlement.Let's jump into the real problems that a lawyer would have with this report and what council will ask you as the report author to change. We will talk about the report using page and line number references displayed on screen.
Characterising the conduct as data collection emphasises a motive the report doesn't actually need to attribute — and pushes the framing away from the more obvious driver here, which is financial fraud against a third-party purchaser.
"This represents a sustained data collection effort."
Counsel asks for: present the facts; do not characterise the threat actor's motive when it is not necessary to the findings.
Ref: p. 19 / line 36
"Should be assumed" pushes a worst-case hypothesis into the body of the report as if it were a conclusion. The available evidence doesn't support download — it just doesn't exclude it. The wording should reflect that.
"it should be assumed the Accounts mailbox was exposed and possibly downloaded using the MailPilot application."
Counsel asks for: "it is possible, but could not be determined from the available evidence, whether mailbox contents were downloaded."
Ref: p. 5 / line 20
This sentence opens doors that the evidence didn't open. It volunteers two unproven possibilities — malware that was present then removed, or a compromise method not detectable by endpoint analysis — both of which a plaintiff will happily run with.
"the absence of malware on endpoints does not exclude the possibility that malware was present and subsequently removed, or that the credential compromise occurred via a method not detectable through endpoint analysis."
Counsel asks for: remove, or restate only as the scope of the endpoint examination. Do not open the door to the insufficiency of the steps actually taken.
Ref: p. 21 / line 32
Whether application registrations were "routinely monitored" is a governance judgement about Greenfield's IT operations — not a factual finding about this incident. The report wasn't engaged to opine on it.
"Application registrations and their associated permissions were not routinely monitored."
Counsel asks for: remove. Out of scope; reads as a negligence finding the engagement letter never asked for.
Ref: p. 8 / line 38
Two problems in one sentence: the report wasn't asked to recommend remediation, and the phrasing implies the existing SPF/DMARC/DKIM configuration is currently inadequate — without having actually reviewed it.
"SPF, DMARC, and DKIM settings were not reviewed in detail during this engagement but should be assessed as part of any remediation program."
Counsel asks for: remove from the report. Preserve as separate verbal advice if the firm wants to flag it.
Ref: p. 9 / line 3
The Microsoft 365 Environment section spends several sentences explaining the retention limits of the Business Basic licence. That doubles as a finding that Greenfield bought an inadequate tier — even though licence selection wasn't in scope.
"Microsoft 365 Business Basic ... sign-in logs are retained for a maximum of 30 days; mailbox audit logs are retained for 90 days. ... sign-in log data covering the Apr–Aug 2024 intrusion period had been overwritten and was not recoverable."
Counsel asks for: peel back to commentary about which mailboxes were in scope. Note retention limits factually where they bear on a specific evidentiary gap, not as an environment-level critique.
Ref: p. 8 / line 39
One sentence in the containment table implies that MFA was not enabled on Greenfield accounts before the incident. That is exactly the kind of admission a plaintiff or regulator builds a negligence case around.
"Multi-factor authentication (MFA) enabled on selected Greenfield accounts."
Counsel asks for: omit if MFA configuration was not within the scope of the investigation. If retained, phrase very carefully — describe the action without implying the prior state.
Ref: p. 22 / line 14
Whose interests align, whose don't: let's explore the inherent tensions in the parties responding to the incident.
We've spent the last few sections examining the key questions and the drivers of each party — what the insured wants, what the insurer needs, what counsel is solving for, and what the forensic firm is trying to deliver. Each of those parties is internally coherent. The friction lives between them.
The following slides explore seven of those tensions in turn.
Privilege-protective process is materially different from how a forensic firm normally operates. Every protective step costs time, money and clarity.
Both sides know the privilege process is slower, more expensive, and harder to hold the line on under incident-response time pressure. The question, every matter, is whether it's worth it.
Whether data was exfiltrated is the hinge that swings notification, regulator engagement, class-action exposure, and the size of the matter. It is also frequently ambiguous on the evidence — and that ambiguity is where the temptation lives.
The honest characterisation is "could not be confirmed or excluded." That is also the least commercially interesting answer.
This is the one where the witness code of conduct earns its keep. The framing of the exfiltration question is the single most commercially-influenced sentence in the report — and the easiest place to lose your independence one cautious adjective at a time.
Every incident has its own cast and its own pressure points — and the ones that bite hardest might be the ones nobody named at the kick-off call.
Think about:
How we take your factual findings and synthesize practical compliance advice.
The factual matrix of the incident. What was accessed, when, by whom, through what vector, with what indicators of exfiltration. Findings expressed in evidence — log entries, file paths, hashes, timestamps — with calibrated confidence and the limits of what the data can support.
It says what happened. It does not say what to do about it.
Takes the report's facts and works them against the Privacy Act. It steps through:
The whole NDB scheme collapses to two questions. Everything in the forensic report is being read against them.
The advice letter is the bridge: the report supplies the facts, and these two statutory questions are how counsel turns those facts into a notification call.
The NDB scheme puts the serious harm assessment on the affected entity — a retailer, a school, a clinic — and gives it no help. Nothing in the Privacy Act assumes the entity knows anything about identity crime, synthetic identity fraud, SIM-swap chains, credential stuffing economies, or how a leaked passport number is monetised six months later.
A forensic finding about what data was in scope of the access is not just an evidentiary point — it defines the population the entity has to write to.
A worked example of how cohorts get sorted once the report's data findings hit the harm assessment.
| Cohort / data exposed | Harm pathway | Call |
|---|---|---|
| Name + Tax File Number + DOB | TFN is a restricted-use identifier under the Privacy (TFN) Rule — direct enabler of ATO-facing identity fraud and refund fraud | Notify |
| Name + Driver Licence + DOB + Address | 100-point ID kit — synthetic identity creation, credit applications in the individual's name | Notify |
| Name + Passport number + DOB | International ID document — passport-led synthetic identity and travel-document fraud | Notify |
| Name + email address | Contact detail; routinely public via LinkedIn / company directories — no realistic serious-harm pathway beyond ambient phishing | No notify |
| Name + date of birth | Single attribute, not an identifier on its own; no realistic harm pathway absent a combining document | No notify |
| Name + residential address | Broadly available via public registers and rolls; no serious-harm pathway in isolation | No notify |
The line between buckets is a legal judgment built on the report's dataset findings. Move a person from one row to another and you change whether they get a letter.
Months — sometimes years — after IR closes, the same forensic record gets re-read by audiences you didn't write for. Two of those audiences matter most.
And in any of these, your report can be tendered and you can be called — expert-evidence rules apply retrospectively to work you did under operational pressure.
What we hope you take away from our discussion.
Your work sits inside a system of competing tensions — counsel, insurer, broker, MSP, regulator. The job is collaborative. Work with the colleagues around the bridge call to meet the challenges; nobody gets through an incident alone.
Fees, repeat business, vendor relationships and client expectations will, at some point, push back on what you write. You will encounter pressure to compromise your professional integrity. Recognise it for what it is and hold the line.
Pursue that end dutifully and faithfully — without ego, without advocacy, without ulterior purpose. The lawyers, insurers, regulators and courts that read your work are depending on you to do that well, even when the truth is awkward for the people paying the bill.
Insurance and legal professionals will lean on you to learn the technical ground. Don't be afraid to teach them — and use the same conversations to learn their drivers and the parts of their craft that help you collaborate more effectively.
Ask anything — we'll give you our views from the breach counsel's perspective.
Artificer Legal Pty Ltd
ABN 83 678 885 179
3/55 Pyrmont Bridge Rd
Pyrmont NSW 2009
hello@artificer.legal
+61 2 7240 1969
Liability limited by a scheme approved under Professional Standards Legislation