What you say during a cyber breach can — and will — be used against you
Brief
The first 24 hours after a cyber incident are messy. Teams are moving fast, and a lot gets said on Slack or email that can come back later. People are scrambling to contain the issue, figure out what happened and keep things moving. In the process, they create a record that doesn’t always age well.
Months and sometimes years later, when the dust is settled, CISOs often find out that those early communications get pulled apart in litigation or investigations. What your team documented and how they said it can have a longer tail – and a more disastrous financial outcome – than the attack itself.
It’s easy to see how this happens. The instinct once you learn you’ve been breached is to move fast. Get on a call. Fire off a Slack message. Loop in the lawyers. Start figuring out what happened.
My experience is that cyber litigation doesn’t hinge only on what happened.
