Ten years ago, a serious intrusion was largely a matter for the IT director and, eventually, an insurance claim. The legal consequences arrived slowly, if at all, and the evidence was rarely examined by anyone whose report would be tested in court. That model no longer survives contact with UK GDPR, the ICO's enforcement posture, the standard exclusions in modern cyber insurance policies, or the volume of data-subject litigation that now follows publicised breaches.
The organisations that come through an incident with reputation, insurance cover and legal position intact are, almost without exception, the ones that treated the first 24 hours as an evidence-preservation problem rather than a service-restoration problem. That reordering of priorities is the single most important shift in this discipline over the last five years.
The obligations that make forensics unavoidable
| Obligation | Trigger | What forensics is expected to supply |
|---|---|---|
| UK GDPR Art. 33 | Personal data breach affecting rights and freedoms | Nature of the breach, categories and approximate numbers of data subjects and records affected |
| UK GDPR Art. 34 | High risk to affected data subjects | A factual basis for the notification and the mitigation described to those data subjects |
| Cyber insurance policy | Any claim for indemnity | Independent investigation, root-cause analysis, evidence of remediation |
| Civil claim / group action | Post-breach litigation by data subjects | Contemporaneous evidence of scope, mitigation and organisational response |
| NIS Regulations / DORA (financial) | Significant incident affecting operators or financial entities | Incident timeline, impact assessment, formal report to competent authority |
What changes when forensics is done properly from hour one
- Notification to the ICO can be made accurately, on time, and without the qualifying language that invites follow-up enforcement.
- Insurance recovery is materially more likely; the carrier's panel forensic firm will accept preserved evidence rather than restart the investigation.
- Data-subject notifications can be tailored to what was actually affected, rather than issued to a broader population out of caution.
- Litigation risk falls, because the organisation can show what happened, when it acted, and what it did about it.
- Any subsequent prosecution — whether of an insider or of an external actor identified during response — has evidence a court can rely on.
What goes wrong when it is not
The typical failure pattern is fast remediation and no preservation. Endpoints are re-imaged, servers are rebuilt from clean backups, cloud tenants are re-tenanted, logs age out of their default retention windows, and by the time a lawyer is instructed there is nothing left to examine. The organisation is then in the position of having to negotiate with the ICO, its insurers and its claimants without a defensible account of what happened — and every one of those counterparties knows it.
The single most expensive decision in a cyber incident is almost always taken in the first three hours, by someone who did not know they were making it: the decision to rebuild before imaging.
Where the legal team should sit in the response
- 01Instruct external counsel immediately. This establishes legal professional privilege over the investigative work product, provided the forensic examiner is instructed by counsel and not by the client directly.
- 02Retain the forensic examiner through counsel. This is not a formality — it is the mechanism by which the investigation report is protected from disclosure to opposing parties in any later civil claim.
- 03Agree the notification timetable in writing. The 72-hour clock is a legal decision, not a technical one; the examiner's role is to supply the facts, not to draft the notification.
- 04Preserve first, remediate second. Live images of affected systems, cloud audit logs exported to the examiner, endpoint memory captures where feasible — all before rebuilds begin.
- 05Document every decision. A contemporaneous decision log is the single most useful document in any post-incident review, ICO investigation or civil claim.
Why an independent examiner matters
The internal IT team, however competent, is a witness to the incident, not an investigator of it. Their emails, their configuration decisions and their access logs are part of what will be examined. Instructing an independent examiner — through counsel, on a defined scope — separates the investigation from the incident and produces a report the organisation can rely on in front of any tribunal, regulator or insurer that later asks the question.
Frequently asked questions
When the examiner is instructed by external counsel for the dominant purpose of advising on legal risk or contemplated litigation. Instructions issued directly by the client to the examiner do not generally attract litigation privilege over the resulting report.
Yes. Article 33 requires notification within 72 hours of becoming aware, in phases if necessary. The forensic evidence is what allows you to complete or correct the notification in later phases rather than retract it.
Most cyber policies specify a panel of pre-approved responders. Using an off-panel firm without prior consent can void the indemnity. Confirm panel status before instructing.
Only where preservation has already been achieved (memory capture, disk image, log export) and business continuity genuinely cannot wait. Rebuilding without preservation destroys the evidence you will later need to defend.
It sets out the scope of the investigation, the evidence sources examined, the methodology applied, the factual findings (with references to specific artefacts), the limitations of what could be established, and a statement of truth from the named examiner who will attend to defend it.
