Attorney-Client Privilege and Cybersecurity: What Your Security Team Doesn’t Know Is Costing You
Author: Marie Strawser, UMSA Managing Director
August 4, 2026
By the time most organizations introduce their CISO to their General Counsel (GC), something has already gone wrong.
A breach has been confirmed. The regulatory clock is ticking. The board wants answers. And now, at the worst possible moment, two of the most consequential people in the organization’s response are meeting for the first time, trying to figure out how to work together under conditions that make thoughtful collaboration nearly impossible.
This is a structural failure. And it is entirely avoidable.
I have been in rooms where security engineers sat alongside in-house counsel and finance executives for the first time, put there by a tabletop exercise or a crisis that forced the introduction. The reaction is almost always the same. These two audiences rarely occupy the same space, and they notice immediately how much they have not been telling each other.
That recognition is the starting point. This post is about what comes next. Here is why the CISO-GC relationship is one of the most strategically underinvested relationships in enterprise security and what to do about it.
Note: I am not an attorney, and nothing here is legal advice. This is operational guidance for how organizations can better prepare for the legal dimensions of cybersecurity incidents. Consult qualified legal counsel for advice specific to your situation.
The Privilege Problem Most CISOs Don’t Know They Have
When a cybersecurity incident occurs, your organization will investigate. That investigation will generate findings on what happened, when, how, which data was affected, and which controls failed. Those findings are valuable. They may also be discoverable in litigation if not properly structured.
Attorney-client privilege protects confidential communications between a client and their attorney made for the purpose of obtaining legal advice. Work product doctrine protects materials prepared in anticipation of litigation. When a breach investigation is conducted under proper legal direction, meaning counsel has been engaged to direct the investigation, not just notified after the fact, the findings may be protected from disclosure in subsequent litigation, regulatory inquiries, or class action proceedings.
When the investigation is conducted as a purely technical exercise, with counsel brought in later to review what the security team already documented, that protection is much harder to establish and often does not hold.
Most CISOs understand breach response. Very few have thought carefully about how the sequencing, documentation practices, and communication structure of their investigation impact the organization’s legal exposure. That is not a criticism. It is a gap because security and legal teams rarely talk until they must.
General Counsel’s Blind Spot
The gap runs in both directions.
Most General Counsels understand privilege doctrine and litigation strategy. Far fewer understand what a cybersecurity investigation produces, what the technical findings mean, or which artifacts from the investigation are most likely to surface in discovery.
A forensic investigation generates logs, timelines, chain-of-custody records, analyst notes, draft reports, and email threads often across multiple vendors, internal teams, and external responders. The GC who has not engaged with this process before an incident may not know which of those materials are most legally sensitive, which communications need to be handled differently, or what a forensic vendor’s standard documentation practices look like.
The result, in too many organizations, is that counsel and the security team are working from different mental models of the same event. Counsel is thinking about what can be disclosed and what needs to be protected. The CISO is thinking about containment, eradication, and recovery. Neither is wrong. They are just not coordinating.
What the Relationship Needs to Look Like Before the Breach
The CISO-GC relationship is not a crisis resource. It is an operational relationship that needs to exist before anyone needs it.
Here is what that looks like in practice.
Establish the relationship now, not later. Your CISO and your GC should have met, discussed how they will work together during an incident, and agreed on basic protocols before the first alert fires. That conversation does not need to be long. It does need to happen.
Agree on when counsel gets looped in. Not every security event requires legal involvement. A failed login attempt does not need GC notification. A confirmed breach of systems containing regulated data almost certainly does. Define the threshold in advance. The on-call security team should not be making that judgment call at 2 a.m. under pressure.
Understand what privilege protects and what it does not. Privilege is not a blanket that covers everything that happens after you call your lawyer. It has specific requirements, and courts scrutinize whether it was properly established. Your GC and CISO should understand together what the organization’s approach to privilege in investigations looks like, and that approach should be documented before it is needed.
Brief your incident response vendors on legal protocols. If you use an external incident response firm, they need to understand your organization’s legal structure and how counsel is engaged during investigations. Forensic vendors accustomed to producing technically thorough documentation may do so in ways that create legal exposure if legal direction has not been established. This is a vendor conversation to have before you need the vendor.
Include legal decision points in your tabletop exercises. Most cybersecurity tabletop exercises test technical response, communication protocols, and recovery sequencing. Fewer test the legal decisions: when to notify regulators, how to handle media inquiries without creating legal exposure, and whether to preserve or contain artifacts in ways that affect discovery obligations. These are decisions your leadership team will face in a real incident. Rehearse them.
The Finance Angle
Finance leaders at large organizations sit at the intersection of several incident-related legal exposures that go beyond security: SEC disclosure obligations for public companies, material event determinations, insurance claim documentation, and board reporting that may itself become a litigation artifact.
The CFO or Controller, who has never discussed the legal dimensions of a cyber incident with their GC, is carrying a risk they may not fully see. A breach that triggers a material disclosure obligation is not just a security event. It is a financial reporting event with legal deadlines and liability implications.
The right conversation is not just between the CISO and the GC. It is between the CISO, the GC, and Finance leadership before anyone needs to put it under pressure.
The Old View and the New View
Old View |
New View |
|
Legal gets involved after the technical investigation is complete |
Legal direction shapes how the investigation is conducted from the start |
|
Attorney-client privilege is a legal concern, not a security concern |
Privilege decisions affect what your security team documents and how |
|
The CISO-GC relationship activates during a breach |
The CISO-GC relationship is operational infrastructure, not a crisis resource |
|
Tabletop exercises test technical response |
Tabletop exercises test legal decision points alongside technical response |
The Conversation That Changes Everything
The organizations that manage cybersecurity incidents well are not always the ones with the most sophisticated detection tools or the largest security teams. They are the ones where the right people have already had the right conversations before the alert is fired.
The CISO-GC relationship is one of those conversations. Not because a regulator asked for it. Not because it appears on a compliance checklist. Because when a breach happens, and it will, the difference between a contained, well-managed response and a cascading legal and reputational crisis often comes down to decisions made in the first 24 hours. What to document. What to preserve. When to notify regulators. Who directs the investigation? Whether privilege attaches at all.
None of those decisions can be made well by people who have never thought through them together in advance.
You do not need an incident to justify this conversation. You need a 30-minute calendar invite and a willingness to close the gap before it matters.
Schedule it. Map the threshold for when counsel gets looped in. Read your incident response plan and mark the places where legal decision points should appear, but do not. Run a tabletop that tests the CISO-GC interface under pressure and watch what surfaces.
The breach that tests this relationship is coming. The only variable is whether the relationship exists before it arrives.

