Bridging the Communication Gap

The Legal Lifecycle of a Cyber Incident · Macquarie University · 11 May 2026

LEGAL
Company

Artificer Legal Pty Ltd
ABN 83 678 885 179

Office

3/55 Pyrmont Bridge Rd
Pyrmont NSW 2009

Contact

hello@artificer.legal
+61 2 7240 1969

Liability limited by a scheme approved under Professional Standards Legislation

The lawyers on the other side of the triage call

Two practitioners who run incident matters from the legal seat — and who routinely sit opposite the forensic teams you might one day join.

Tyler Wright

Tyler Wright

Principal · Artificer Legal

Tyler began his legal career in general practice before moving in-house at Agilyx Group, a multinational technology company implementing complex finance and HR systems. He then moved to Clyde & Co as breach counsel. During the pandemic he joined Slipstream Cyber as Incident Response Manager, before later founding Artificer Legal and its sister DFIR practice, Artificer Cyber.

Adam Elbanna

Adam Elbanna

Senior Associate · Gilchrist Connell

Adam worked for over 6 years as a paralegal before admission to the legal profession, following which he was a foundational member of the Cyber Incident Response Practice at Clyde & Co. He then moved to Gilchrist Connell and is now a Senior Associate in their cyber practice. Has run incident matters across SME, mid-market and ASX-listed insureds, working under instruction from most of Australia's most well known cyber underwriters.

Two objectives for the next 90 minutes.

01 — Bridge the communication gap

Forensic investigators tend to assume lawyers neither need nor should have a detailed grasp of the technology or environment. Lawyers tend to assume the same about investigators and the legal landscape — privilege, the Privacy Act, cyber insurance. The reality is that incident work is multi-disciplinary.

Both sides need a working command of the other's domain. Today is a step toward closing that gap. We will examine:

  • The different perspectives involved in a claim under a cyber insurance policy.
  • What everyone's looking for in each of the conversations you might be involved with.
  • Examples of mistakes you might make by not properly considering the other party's position or perspective.
  • Things to watch as your career progresses in the legal domain that applies to your work.

02 — See where your work lands

The forensic report you write is one document inside a much longer process: privilege, privacy advice, regulatory defence, third-party claims risk and litigation, subrogated recoveries. By the end of today you'll see how your investigation moves through the full lifecycle of a cyber insurance claim. We will look at:

  • How lawyers read a digital forensics report and what risks they're worried about in both your execution as an investigator as well as whats in the content of your report.
  • The unenvious job of trying to cloak a forensic investigation under legal professional privilege (how you can help)
  • What happens after your advice is delivered and how lawyers use it as a factual matrix to feed into their risk analysis under privacy and data protection laws, and to guard against lawsuits.
  • What might happen if you're called up to go to court and give evidence in proceedings as an expert witness.

Seven parts, in the order an incident actually unfolds

  1. 01

    Before the breach

    What your customer has done to prepare (or failed to do).

  2. 02

    Day zero

    The 5pm Friday afternoon triage call.

  3. 03

    Operating as an expert witness

    Your duties as an expert witness operating in the chaos of a cyber incident.

  4. 04

    The forensic report

    Walking through a sample forensic report to see how lawyers will read it.

  5. 05

    Tensions

    Lawyers vs forensic teams — the competing commercial and professional drivers.

  6. 06

    The privacy advice letter

    Where the report lands and how it feeds into real-world business advice.

  7. 07

    Close

    What we hope you take away — and Q&A.

Part 01

Before the breach.

Why cyber insurance is becoming increasingly important in DFIR engagements.

Cyber insurance is increasingly the lens through which DFIR operates

DFIR are purchased increasingly through cyber insurance policies — many jobs are built around delivering inclusions under a cyber policy.

Why it's become a primary risk-management tool

  • Incidents are treated as inevitable. Boards and regulators (APRA CPS 234, ASIC director duties) have moved from "prevent" to "prepare" — meet an objective standard of readiness, not a guarantee of no breach.
  • Public examples make it unignorable. Optus and Medibank turned data breaches into board-level conversations; the "Australia under attack" narrative did the rest.
  • Notification chaos. Everyone knows someone who's received a breach letter — the externalised cost is now visible.
  • Capital and licensing pressure. AFSL holders, APRA-regulated entities, and government suppliers increasingly can't operate without baseline controls — and increasingly can't get those controls underwritten without a policy in place.

What's typically in a cyber policy

Every cyber policy splits along one line:

  • First-party — losses the insured suffers itself: business interruption, IR and recovery costs, ransom payments, stolen funds, data restoration.
  • Third-party — liability the insured owes someone else from the same event: privacy and security claims, regulator investigations and fines (OAIC, ASIC), PCI assessments, D&O exposure.

The same incident can trigger expenses on both sides — and your forensic findings feed each of them differently.

The supply chain prepared to respond to cyber claims

Scenario A Independent panel — every role retained separately
01 Insured Policyholder 02 Broker Notifies & advocates 03 Insurer Coverage decision 04 Law firm Panel breach counsel Coverage counsel Forensic provider MSP / IT PR & comms Notification, ransom, other specialists
Scenario B Vertically integrated — insurer runs forensics, law firm runs PR
01 Insured Policyholder 02 Broker Notifies & advocates 03 Insurer Coverage decision 04 Law firm Panel breach counsel In-house forensics Coverage counsel In-house PR & comms In-house notification MSP / IT Notification, ransom, other specialists
Part 02

Day zero.

The triage, scoping and the agendas of everyone involved in the response.

Day Zero — how an Incident Response Team assembles

A summary of the communication pathways to setup an Insured's Incident Response Team.

Insured customer Spill centre broker / IR mgr Breach counsel panel lawyer Forensic provider you Insurer claims handler Coverage counsel insurer-side 01 · Activation — call into the spill line policy goes live; IR manager assigned 02 · Counsel engaged — panel lawyer calls insured proposes services under the policy 03 · Forensic seat filled — investigator named cc: claims handler — incident summary 04 · Scoping call — forensic walks through with insured & counsel scope already shaped by the three calls before yours 05 · Engagement letter — privilege framing set names instructing party, defines scope 06 · Quote returned — hours, blended rates, budget envelope tied to the scope in the engagement letter 07 · Recommendation lands with the insurer scope + estimate — the document the insurer approves spend against 08 · Coverage counsel engaged — forensic work begins cleared to start under a reserve — work can begin

8 parties, 8 agendas

By day three, every party is operating on their own clock and their own workstream – lets unpack the agendas of each party at this stage of the incident response.

Party Key question they're asking What's driving them
Insured (CEO / CISO) "How bad is it, and when are we back up?" Business continuity, customer impact, board exposure
Broker "Is my client being looked after under the policy I sold them?" Client retention, future renewal, reputation in the market
Insurer / claims handler "What's the reserve? Is the reserve accurate?" Cost certainty, indemnity scope, reporting structure
Coverage counsel "Where can the insurer reduce or decline cover?" Reducing costs of overall claim, limiting claim blowout
Breach counsel "Are we under privilege, how quickly can we move, how big is this incident really?" Privilege, regulatory defensibility, downstream litigation exposure, but ultimately: are all parties happy - insurer AND insured
Crisis comms / PR "How do we contain this? What's Plan B if it blows up?" Narrative control, demonstration of skill, get more work in future
MSP / IT provider "Can we gain more work, and is the incident attributable to us?" Avoid blame, make money, justify ongoing involvement & future work
Forensic provider — you "How much work is involved in the investigation? How effectively will the client be managed?" Defensibility of the report, scope clarity, evidentiary integrity, not being overburdened with client management
Part 03

Operating as an expert witness.

You duties as an expert witness operating in the chaos of a Cyber Incident.

Your paramount duty is to the court — not the party paying you

If your report is tendered as expert evidence, you are bound by a code of conduct. The code varies by jurisdiction, but the spine is the same.

  • Federal Court — Harmonised Expert Witness Code of Conduct, attached as Annexure A to Practice Note GPN-EXPT. Every expert must read it and acknowledge they are bound by it.
  • NSW — Uniform Civil Procedure Rules 2005, Schedule 7. Applies in the Supreme, District and Land & Environment Courts.
  • Victoria — Supreme Court (General Civil Procedure) Rules, Order 44 and Form 44A. Not the harmonised code; broadly aligned but worded differently.
  • Queensland — UCPR rule 428. Has its own code; did not adopt the harmonised version.
  • WA, SA — separate court-specific rules; also did not adopt the harmonised code.

What every version requires of you, in substance:

  • Paramount duty to the court — overriding any duty to the party retaining you. You are not an advocate.
  • Stay within your expertise — and say so when a question is outside it.
  • Show your working — qualifications, assumptions, material facts, methodology, and the literature or data relied on.
  • Flag uncertainty — where an opinion is provisional, or the data is incomplete, say so on the face of the report.
  • Update on change of opinion — if you change your view on a material matter after delivering the report, you must issue a supplementary report.
  • Confer in good faith — when directed to meet with the other side's expert, exercise independent judgement; you cannot be instructed to withhold agreement.

What privilege is — and why it matters to you

Legal professional privilege (also called client legal privilege under the uniform evidence legislation) protects confidential communications between a client and their lawyer from being compelled in litigation, regulatory investigations, or production to third parties.

Why the law protects it. The High Court treats privilege as a substantive right, not a mere rule of evidence (Daniels Corporation v ACCC (2002); Esso v Commissioner of Taxation (1999)). The justification is practical: the administration of justice depends on clients being able to tell their lawyers the unvarnished truth — including the embarrassing, the incriminating, and the uncertain — and lawyers being able to give frank advice in return. Without that protected channel, clients self-censor, advice gets worse, and disputes are resolved on incomplete facts. Privilege is the price the system pays for candour.

It comes in two limbs:

  • Advice privilege — communications made for the dominant purpose of the lawyer giving or the client receiving legal advice.
  • Litigation privilege — communications and documents brought into existence for the dominant purpose of actual or anticipated litigation.

The test is dominant purpose, not "a purpose". If the dominant purpose of an incident report is to fix the network, restore operations, or brief the board, it is not privileged — even if a lawyer commissioned it, sat on the call, or received a copy.

The cases that put forensic reports inside the tent

Privilege is not limited to lawyer–client communications. It can extend to communications with — and reports prepared by — third-party experts, but only if the dominant purpose test is satisfied.

  • Pratt Holdings v Commissioner of Taxation (2004) 136 FCR 357 — a loss-assessment firm (a pure third party, not the lawyer's agent) prepared a report so the company could instruct its lawyers. The Full Federal Court held the report was privileged. Authority that third-party expert reports can attract LPP, provided the dominant purpose at the time of creation was to enable legal advice.
  • Esso Australia Resources v Commissioner of Taxation (1999) 201 CLR 49 — High Court replaced the old "sole purpose" test with dominant purpose at common law, aligning it with the Evidence Act. The test now applied to every expert-report privilege fight.
  • FCT v Spotless Services (1996) 186 CLR 404 — defined "dominant" as "the ruling, prevailing or most influential purpose". Useful when a report has plausible legal and operational drivers.
  • AWB Ltd v Cole (No 5) (2006) 155 FCR 30 — investigation reports commissioned during the Cole inquiry. Young J's reasoning is the standard reference for how courts unpick the real purpose of a multi-purpose investigation, including who instructed it, who saw drafts, and how the scope was framed.
  • Propend Finance (1997) 188 CLR 501 — confirmed that confidential communications with third parties (including experts) attract litigation privilege where made for the dominant purpose of existing or anticipated litigation.
  • Glencore v Commissioner of Taxation (2019) 265 CLR 646 — High Court reaffirmed privilege as a substantive immunity, not merely a rule of evidence. Reinforces that a properly-claimed privilege is robust — but only if the underlying conditions are met.

The through-line: privilege can protect a forensic report, but courts will look at the contemporaneous record — instructions, scoping, drafts, distribution — to decide what the dominant purpose actually was.

Why practitioners fight to keep the forensic report privileged

A privileged report is not subpoena-able, not discoverable in civil proceedings, and not (without waiver) producible to regulators. That changes the calculus on both sides — for the insured, for counsel, and for you as the forensic expert.

The case for

  • Candour in the report. If the author knows the report cannot be weaponised by a future plaintiff, they will name root causes plainly — "patch was 14 months overdue", "MFA was off for the admin tier" — instead of hedging.
  • Frank advice from counsel. Lawyers can give a real risk assessment off the back of a real factual record, rather than triangulating around a sanitised public-facing version.
  • Strategic optionality. Privilege gives the insured time to decide what to disclose, to whom, and on what terms — regulator, class action, board, market — without the report being already in the wild.
  • Reduces the chilling effect. Without privilege, organisations commission shallower investigations or none at all, because every finding becomes a future exhibit. Worse incident response overall.
  • Protects the investigative process. Drafts, working hypotheses, and ruled-out theories don't end up cherry-picked in cross-examination.

The case against

  • Accountability. Victims, regulators, and the public have a legitimate interest in knowing what went wrong. Privilege can shield genuine corporate failure from scrutiny.
  • Information asymmetry in litigation. The defendant company knows exactly what happened; class-action plaintiffs are forced to litigate blind, or fight expensive privilege battles before they get to the merits.
  • Regulatory under-enforcement. ASIC, OAIC, and APRA can struggle to build cases when the best evidence sits behind a privilege claim. The threat of enforcement softens.
  • Encourages "law-washing". Routing routine operational reviews through a law firm purely to claim privilege distorts how investigations are commissioned and scoped.
  • Public-good information is suppressed. The cyber community learns less from each major breach because the technical detail of how it happened is locked away.

Splitting the report to shield it

The most common strategy is to break what would have been a single investigation report into three deliverables, each with its own scope and audience:

  • Containment report — operational facts, written for the business so it can act. Not run through counsel and not claimed as privileged.
  • Forensic findings report — the technical narrative of what happened, prepared on counsel's instructions for the dominant purpose of legal advice. This is the document the privilege claim is built around.
  • Recommendations report — forward-looking remediation and uplift advice, scoped and instructed separately so it doesn't drag the findings into a "business as usual" characterisation.

Each engagement, each scope, each distribution list is deliberate. Done well it gives counsel a defensible privilege claim over the findings; done sloppily it produces three documents that all get produced anyway.

Optus / Deloitte — the multi-purpose report

Robertson v Singtel Optus Pty Ltd [2023] FCA 1392 (Beach J), upheld in Singtel Optus Pty Ltd v Robertson [2024] FCAFC 58 (Murphy, Anderson, Neskovcin JJ, 27 May 2024).

What happened

  • Class action arising from the September 2022 breach (~9.5m affected). Applicants sought production of Deloitte's forensic and management review.
  • Optus claimed both advice and litigation privilege over the report.
  • Court found at least three concurrent purposes — legal advice, identifying root cause for management, and reviewing cyber-risk policies. None was dominant.
  • CEO's public 3 October 2022 announcement framed the review as an external assurance exercise — before counsel was instructed. Board resolutions repeated the management/assurance framing.
  • Only the General Counsel swore evidence. No CEO, no Board, no Ashurst affidavit. Jones v Dunkel applied. The GC was found not to have been acting solely as legal adviser when he engaged Deloitte.

The lesson

  • Privilege is decided on contemporaneous objective evidence — engagement letters, Board papers, public statements. Retrospective characterisation will not save a multi-purpose engagement.
  • The dominant-purpose test is strict: a substantial or co-equal legal purpose is not enough.
  • External counsel (not the company) should engage the forensic firm.
  • The engagement letter and Board resolution should articulate the dominant legal purpose unambiguously.
  • Control public messaging — don't let the CEO publicly frame the work as a management review.
  • Be prepared to lead evidence from the actual decision-makers (CEO, Board), not just the GC.

Medibank — segregated workstreams, mixed result

McClure v Medibank Private Ltd [2025] FCA 167 (Beach J, 4 April 2025).

What happened

  • October 2022 breach (~3.9m customers; ~520GB exfiltrated, including mental-health and termination data) by a REvil-linked actor. Initial access via stolen third-party contractor credentials.
  • Medibank engaged multiple firms under MinterEllison's instruction — Deloitte (root-cause analysis, post-incident review, CPS 234 report for APRA), CrowdStrike (IR/forensics), and CyberCX / Threat Intelligence (ransom-payment and OAIC-notification advice).
  • The privilege fight ran in the consumer class action, alongside parallel OAIC civil-penalty proceedings, an APRA enforceable-undertaking process, and a shareholder class action.

The result — and the lesson

  • Not privileged / produced: the three Deloitte reports. Dominant purposes were customer/market reassurance, satisfying APRA, and avoiding an APRA-commissioned review. Public ASX statements about implementing PIR recommendations would have waived privilege regardless.
  • Upheld as privileged: CrowdStrike, CyberCX, Threat Intelligence material tied to legal advice on ransom payment, OAIC notification and Privacy Act compliance.
  • Lesson: structural separation of workstreams can preserve privilege over some forensic material — but a publicly-announced "external review" with regulator-facing scope is almost always cooked.
  • Forensic firms working under counsel's instructions, on a narrowly-scoped legal-advice question, fared better than firms hired to produce the headline post-incident report.

RI Advice / ASIC — when the forensic report is the regulator's evidence

Australian Securities and Investments Commission v RI Advice Group Pty Ltd [2022] FCA 496 (Rofe J, 5 May 2022).

What happened

  • AFS-licensee financial advice network. Nine cyber incidents across its authorised representative practices between June 2014 and May 2020 — BEC, phishing, ransomware, and a months-long file-server compromise affecting thousands of clients.
  • ASIC pleaded breaches of s 912A(1)(a) and (h) Corporations Act 2001 (Cth) — efficient/honest/fair, and adequate risk-management systems.
  • Theory: cyber-risk management is a risk-management system within s 912A.
  • Rofe J declared contraventions from 15 May 2018 to 5 August 2021.
  • Remedy: declarations, s 1101B compliance orders (engage Security in Depth under ASIC supervision) and $750,000 costs.

The lesson for forensic experts

  • Adequacy of cyber controls is "highly technical" and requires "the evidence of a relevantly skilled person". The forensic expert is the only person who can answer the central legal question.
  • The IR forensic report becomes the regulator's primary evidentiary record — incident timelines, scope of compromise, and control gaps were the agreed factual matrix on which liability was admitted.
  • Findings about delayed detection, unpatched systems, and AR-network gaps map directly onto s 912A elements.
  • Scoping language, root-cause attribution, and timeline precision in the report drive the contravention period — and therefore the size of the case.
Part 04

The forensic report.

How the breach counsel reads the report, and what you might be asked to change.

The process to refine the report

The drafting process is not a solo exercise. From the moment containment is reached, the report is co-produced with counsel — and the conversations along the way are exactly what privilege fights end up turning on.

  1. Present a draft report with findings. The first draft goes to counsel — not to the client's IT team, not to the board, not to the insurer's claims handler. It contains your full technical narrative and the conclusions you would stand behind in cross-examination today.

  2. Lawyer review call with the investigator. Counsel reads the draft and gets you on the phone. The review focuses on alignment to scope (is what you've written what counsel asked you to opine on?), removal of out-of-scope material (observations that are interesting but not part of the engagement, or that counsel does not want you to opine on), and re-characterising findings that are in scope so they are accurate but less prejudicial — "the actor exploited a vulnerability in [software]" instead of "[Client] did not have the latest version of [software]."

    None of this is dishonest. It is the legitimate work of taking a technical document and making it fit for legal use.

  3. Further draft circulated, or final report issued. Depending on the size of the changes, you either go round the loop one more time or sign off the final. The final is the one that goes to the client and (if applicable) the regulator. Earlier drafts and your call notes still exist — and may be produced if privilege is later lost.

Fanned-out pages of a sample forensic report

A sample forensic report

Before we pull the report apart on the next slides, here is the real thing — a representative DFIR report drafted under counsel's instructions.

Read it the way a lawyer reads it: where does the executive summary land, what gets quantified, what gets characterised, how is uncertainty flagged, and which sentences could survive cross-examination.

QR code
Sample document Scan for a sample forensic report

Greenfield & Associates — hypothetical BEC that ended in third-party fraud

The matter

  • Small AU professional services firm on M365 Business Basic.
  • Three mailboxes compromised: Reception, Admin, Accounts.
  • Phishing emails to Reception and Admin in April 2024 — fake Microsoft voicemail lure, credentials harvested via a lookalike sign-in page.
  • Accounts separately compromised in August via OWA from overseas IPs.
  • Persistence via covert inbox rules redirecting financial keywords externally, and a third-party Graph-API app (MailPilot) granted broad delegated permissions.

The outcome

  • Threat actor monitored a live property settlement via the Accounts mailbox.
  • Lookalike domain (david.greenfie_l_d@outlook.com) used to send altered banking details to the third-party purchaser mid-settlement.
  • Settlement balance paid into the fraudulent account.
  • Detected ~5 months after the first compromise; sign-in logs already overwritten under the 30-day Business Basic retention.
  • ~330 financial emails confirmed redirected externally before the rules were found and removed.

Now: How a lawyer reviews

Let's jump into the real problems that a lawyer would have with this report and what council will ask you as the report author to change. We will talk about the report using page and line number references displayed on screen.

Editorialising the threat actor's motive

Characterising the conduct as data collection emphasises a motive the report doesn't actually need to attribute — and pushes the framing away from the more obvious driver here, which is financial fraud against a third-party purchaser.

"This represents a sustained data collection effort."

Counsel asks for: present the facts; do not characterise the threat actor's motive when it is not necessary to the findings.

Ref: p. 19 / line 36

Excerpt of the forensic report with the relevant passage highlighted

Assumption masquerading as finding

"Should be assumed" pushes a worst-case hypothesis into the body of the report as if it were a conclusion. The available evidence doesn't support download — it just doesn't exclude it. The wording should reflect that.

"it should be assumed the Accounts mailbox was exposed and possibly downloaded using the MailPilot application."

Counsel asks for: "it is possible, but could not be determined from the available evidence, whether mailbox contents were downloaded."

Ref: p. 5 / line 20

Report excerpt with the assumption-as-finding passage highlighted

Inviting alternative compromise vectors

This sentence opens doors that the evidence didn't open. It volunteers two unproven possibilities — malware that was present then removed, or a compromise method not detectable by endpoint analysis — both of which a plaintiff will happily run with.

"the absence of malware on endpoints does not exclude the possibility that malware was present and subsequently removed, or that the credential compromise occurred via a method not detectable through endpoint analysis."

Counsel asks for: remove, or restate only as the scope of the endpoint examination. Do not open the door to the insufficiency of the steps actually taken.

Ref: p. 21 / line 32

Report excerpt with the alternative-vectors passage highlighted

Governance opinion that wasn't requested

Whether application registrations were "routinely monitored" is a governance judgement about Greenfield's IT operations — not a factual finding about this incident. The report wasn't engaged to opine on it.

"Application registrations and their associated permissions were not routinely monitored."

Counsel asks for: remove. Out of scope; reads as a negligence finding the engagement letter never asked for.

Ref: p. 8 / line 38

Report excerpt with the AAD monitoring passage highlighted

Unsolicited remediation recommendation

Two problems in one sentence: the report wasn't asked to recommend remediation, and the phrasing implies the existing SPF/DMARC/DKIM configuration is currently inadequate — without having actually reviewed it.

"SPF, DMARC, and DKIM settings were not reviewed in detail during this engagement but should be assessed as part of any remediation program."

Counsel asks for: remove from the report. Preserve as separate verbal advice if the firm wants to flag it.

Ref: p. 9 / line 3

Report excerpt with the SPF/DMARC/DKIM passage highlighted

The licence-tier passage

The Microsoft 365 Environment section spends several sentences explaining the retention limits of the Business Basic licence. That doubles as a finding that Greenfield bought an inadequate tier — even though licence selection wasn't in scope.

"Microsoft 365 Business Basic ... sign-in logs are retained for a maximum of 30 days; mailbox audit logs are retained for 90 days. ... sign-in log data covering the Apr–Aug 2024 intrusion period had been overwritten and was not recoverable."

Counsel asks for: peel back to commentary about which mailboxes were in scope. Note retention limits factually where they bear on a specific evidentiary gap, not as an environment-level critique.

Ref: p. 8 / line 39

Report excerpt with the M365 environment passage highlighted

A textbook preventive-control failure admission

One sentence in the containment table implies that MFA was not enabled on Greenfield accounts before the incident. That is exactly the kind of admission a plaintiff or regulator builds a negligence case around.

"Multi-factor authentication (MFA) enabled on selected Greenfield accounts."

Counsel asks for: omit if MFA configuration was not within the scope of the investigation. If retained, phrase very carefully — describe the action without implying the prior state.

Ref: p. 22 / line 14

Report excerpt with the MFA-enabled containment entry highlighted
Part 05

Tensions.

Whose interests align, whose don't: let's explore the inherent tensions in the parties responding to the incident.

Inherent tensions in the relationships

We've spent the last few sections examining the key questions and the drivers of each party — what the insured wants, what the insurer needs, what counsel is solving for, and what the forensic firm is trying to deliver. Each of those parties is internally coherent. The friction lives between them.

The following slides explore seven of those tensions in turn.

  • Engagement letter vs forensic agreement — whose paper governs the work.
  • Privilege playbook vs normal tempo — protective process requires careful control, runs against the normal practice of forensic provider/client procedures.
  • Witness code of conduct vs the hand that feeds — your professional obligations and compliance with the code vs the commercial reality of repeat work from breach counsel.
  • Calling exfiltration vs not — the framing that triggers (or ends) months of follow-on work.
  • Broker vs coverage counsel — broker advocates for the insured to maximise recovery; coverage counsel works for the insurer to scope and contest it.
  • MSP vs forensic provider — the incumbent IT/MSP and the incoming forensic firm each have a stake in where the blame for the incident lands.
  • Insurer vs MSP — the MSP wants the claim to fund upgrades that should already have been in place; the insurer's policy excludes betterment.
Let's now explore two of these in detail.

Run the privilege playbook — or just get the work done?

Privilege-protective process is materially different from how a forensic firm normally operates. Every protective step costs time, money and clarity.

What counsel wants

  • Engaged through the lawyer, not direct with the insured.
  • All communications routed via counsel; no IT-team Slack channels, no status decks for the board.
  • No premature written conclusions, no sub-contractors without notice.
  • Drafts go to counsel only. Iterative review before anything reaches the insured.
  • Engagement letter, board paper, and public statements all point at the same legal purpose.

What the firm normally does

  • Direct comms with the client's IT team to get hands on the environment fast.
  • Stand-up Slack channels, daily status decks for the insured's leadership.
  • Triage findings shared as they emerge, before anything is locked down.
  • Sub-processors (cloud SIEMs, AI triage, threat intel) used by default.
  • Final report shaped end-to-end by the technical team, not the lawyer.

Both sides know the privilege process is slower, more expensive, and harder to hold the line on under incident-response time pressure. The question, every matter, is whether it's worth it.

Framing the data exfiltration question

Whether data was exfiltrated is the hinge that swings notification, regulator engagement, class-action exposure, and the size of the matter. It is also frequently ambiguous on the evidence — and that ambiguity is where the temptation lives.

What the evidence usually shows

  • Logs that establish access but not exfiltration.
  • Retention gaps that prevent confirmation either way.
  • Threat-actor tradecraft consistent with bulk download — but not directly observed.
  • A mailbox or share that could have been downloaded; available evidence cannot resolve the question.

Where the commercial pressure pulls

  • A finding toward exfiltration triggers e-discovery, data-subject identification, breach-mapping and notification work — often months of follow-on engagement for the same firm.
  • A finding away from exfiltration ends the matter and the billing.
  • The firm that calls "exfiltration likely" earns more from the matter than the firm that calls it "could not be determined."

The honest characterisation is "could not be confirmed or excluded." That is also the least commercially interesting answer.

This is the one where the witness code of conduct earns its keep. The framing of the exfiltration question is the single most commercially-influenced sentence in the report — and the easiest place to lose your independence one cautious adjective at a time.

What other tensions can you see?

Every incident has its own cast and its own pressure points — and the ones that bite hardest might be the ones nobody named at the kick-off call.

Think about:

  • Where else do incentives diverge between the parties involved in the incident response?
  • Think about commercial drivers, conversations that might be happening in the bacjground.
  • Who in the room has a commercial relationship that predates the incident, and what does that do to their advice/drivers?
Part 06

The privacy advice letter.

How we take your factual findings and synthesize practical compliance advice.

Report tells them what happened.
Advice tells them what it means.

The forensic report

The factual matrix of the incident. What was accessed, when, by whom, through what vector, with what indicators of exfiltration. Findings expressed in evidence — log entries, file paths, hashes, timestamps — with calibrated confidence and the limits of what the data can support.

It says what happened. It does not say what to do about it.

The privacy advice letter

Takes the report's facts and works them against the Privacy Act. It steps through:

  • the eligible data breach assessment under the NDB scheme;
  • the harm assessment — what was in the dataset, who is affected, and the likelihood of serious harm flowing from the exposure; and
  • the recommendation on notification — to the Commissioner, to affected individuals, and the form and timing of each.

Did access occur, and is there a risk of serious harm?

The whole NDB scheme collapses to two questions. Everything in the forensic report is being read against them.

1. Did unauthorised access or disclosure occur?

  • Privacy Act s 26WE — eligibility turns first on whether personal information held by the entity has been accessed by, or disclosed to, an unauthorised person, or is lost in circumstances where unauthorised access is likely.
  • The report needs to say, in evidence: what data, in what systems, was reachable by whom, when, and with what indicators that access actually occurred.
  • "Reachable in theory" is not the same as "accessed in fact." Lawyers will read findings of access very differently to findings of exposure.
  • Logs, file-touch timestamps, exfiltration indicators, attacker tooling — these are the facts the eligible-breach analysis is built on.

2. Is there a real risk of serious harm?

  • Privacy Act s 26WG — even where access occurred, notification is only required where a reasonable person would conclude the access is likely to result in serious harm to any of the affected individuals.
  • "Serious harm" includes physical, psychological, emotional, financial, and reputational harm.
  • The report drives this through the dataset (identifiers, financials, health, credentials) and the cohort (how many people, how vulnerable, what context).
  • Remedial action taken before harm materialises (s 26WF) can take the matter outside the scheme — another reason the report's containment timeline matters.

The advice letter is the bridge: the report supplies the facts, and these two statutory questions are how counsel turns those facts into a notification call.

The entity has to assess harms it has no expertise to assess

The NDB scheme puts the serious harm assessment on the affected entity — a retailer, a school, a clinic — and gives it no help. Nothing in the Privacy Act assumes the entity knows anything about identity crime, synthetic identity fraud, SIM-swap chains, credential stuffing economies, or how a leaked passport number is monetised six months later.

Why it falls to counsel

  • The entity is statutorily on the hook but rarely has the expertise. The risk is real and current; the knowledge sits with specialists.
  • It falls to legal practitioners to stay across the threat landscape: how identity documents, financials, health data, credentials, and behavioural data each map to specific downstream harms.
  • That's not a one-off uplift. Fraud typologies move — what was theoretical for a leaked Medicare number two years ago is now an active fraud pattern.
  • Counsel reads the forensic report and asks: for this dataset, what could realistically happen to a person, by whom, and how soon?

How it works in practice — bucketing

  • Counsel takes a view, on the facts you've established, of the types of information exposed for each cohort of individuals.
  • Affected individuals get sorted into buckets — typically by data class and severity (e.g. name + email, name + DOB + address, identity documents, financial credentials, health information).
  • Each bucket is then either in scope for the notification campaign or out of scope, based on the harm analysis applied to that bucket.
  • The forensic report determines which individuals fall into which bucket — so the precision of your dataset findings directly drives the size and shape of the notification campaign.

A forensic finding about what data was in scope of the access is not just an evidentiary point — it defines the population the entity has to write to.

Worked example, serious harm analysis

A worked example of how cohorts get sorted once the report's data findings hit the harm assessment.

Cohort / data exposed Harm pathway Call
Name + Tax File Number + DOB TFN is a restricted-use identifier under the Privacy (TFN) Rule — direct enabler of ATO-facing identity fraud and refund fraud Notify
Name + Driver Licence + DOB + Address 100-point ID kit — synthetic identity creation, credit applications in the individual's name Notify
Name + Passport number + DOB International ID document — passport-led synthetic identity and travel-document fraud Notify
Name + email address Contact detail; routinely public via LinkedIn / company directories — no realistic serious-harm pathway beyond ambient phishing No notify
Name + date of birth Single attribute, not an identifier on its own; no realistic harm pathway absent a combining document No notify
Name + residential address Broadly available via public registers and rolls; no serious-harm pathway in isolation No notify

The line between buckets is a legal judgment built on the report's dataset findings. Move a person from one row to another and you change whether they get a letter.

Your report is a live document for years

Months — sometimes years — after IR closes, the same forensic record gets re-read by audiences you didn't write for. Two of those audiences matter most.

What's still running

  • OAIC — s 26WK statement, possible CII inquiry, determination of serious breach.
  • Sector regulators — APRA (CPS 234) and ASIC (director duties) re-asking the same questions through different lenses.
  • Class actions — plaintiff firms build the case theory off your bucketing and timeline.
  • D&O claims — what the board knew and when, anchored by your incident timeline.
  • Contractual claims — B2B customers triggering notification clauses and audit rights.

Subrogation — the insurer's second claim

  • Once the insurer pays, common-law indemnity plus the policy's subrogation clause let it step into the insured's shoes.
  • Fastest-growing area of cyber litigation in Australia.
  • Targets: MSPs, systems integrators, security vendors (EDR / SOC / vCISO), supply-chain software, management consultants whose pre-incident advice expanded the loss.
  • Your causation analysis — what failed, in what order, which control would have stopped it — is one document subrogation counsel works from, though they often commission a separate report specifically for the litigation.

And in any of these, your report can be tendered and you can be called — expert-evidence rules apply retrospectively to work you did under operational pressure.

Part 07

Close.

What we hope you take away from our discussion.

Four things to take away.

1. You're part of a larger machine

Your work sits inside a system of competing tensions — counsel, insurer, broker, MSP, regulator. The job is collaborative. Work with the colleagues around the bridge call to meet the challenges; nobody gets through an incident alone.

3. Commercial pressure is real

Fees, repeat business, vendor relationships and client expectations will, at some point, push back on what you write. You will encounter pressure to compromise your professional integrity. Recognise it for what it is and hold the line.

2. You are a servant of the truth

Pursue that end dutifully and faithfully — without ego, without advocacy, without ulterior purpose. The lawyers, insurers, regulators and courts that read your work are depending on you to do that well, even when the truth is awkward for the people paying the bill.

4. Always be educating

Insurance and legal professionals will lean on you to learn the technical ground. Don't be afraid to teach them — and use the same conversations to learn their drivers and the parts of their craft that help you collaborate more effectively.

Q&A

Questions.

Ask anything — we'll give you our views from the breach counsel's perspective.

QR code linking to the slide deck
The slides Scan here to access
these slides.
Get in touch
Tyler Wright

Tyler Wright

Principal
Adam Elbanna

Adam Elbanna

Senior Associate - Gilchrist Connell
LEGAL
Company

Artificer Legal Pty Ltd
ABN 83 678 885 179

Office

3/55 Pyrmont Bridge Rd
Pyrmont NSW 2009

Contact

hello@artificer.legal
+61 2 7240 1969

Liability limited by a scheme approved under Professional Standards Legislation