
- Operational record — the factual documentation that will show what the organization did and when
- Legal strategy discussions that should remain protected (what you say, disclose and defend)
If these are discussed in the same communication channel, then you’re not protecting privilege; you’re diluting it. Hiring “dual-tracked” forensic firms with one being directed by outside counsel doesn’t solve this problem either. Instead, keeping those functions deliberately separated in dedicated places, rather than scattered across personal devices, consumer apps or improvised channels, makes privilege claims far more credible when they’re held up to scrutiny later.
In practice, that means defining specific channels and tools for legal strategy versus day-to-day incident operations, limiting participation in privileged discussions to those who truly need to be there, documenting who controls access and retention for each, and testing your process during tabletop exercises rather than live-fire events. Most teams have a plan going in, but that’s not what the lawyers pay attention to. When the subpoena arrives, the focus shifts to what was said and documented. That’s the part that sticks, and the part you must be able to defend.
In breach litigation, the biggest liability usually isn’t what happened. It’s what your team said about it and where they said it.
