Skip to content
    August 20, 2026| Top Floor Team| 11 min read

    Is Your Breach Forensic Report Privileged? Probably Not

    Do not assume your breach forensic report is protected. In the Capital One consumer data breach litigation (E.D. Va., 26 May 2020, affirmed 25 June 2020), a federal court ordered Capital One to hand plaintiffs its Mandiant forensic report even though the work had been papered through outside counsel, because the same work would have been done in substantially the same form without litigation on the horizon. A court reached a similar result in Wengui v. Clark Hill (D.D.C., January 2021). Privilege turns on how the engagement is structured and how the report is used, not on who sends the invoice.

    This is not legal advice, and privilege is a question for your counsel on your facts. What follows is the practitioner's view of what those decisions looked at, what the surviving structure (In re Target, D. Minn., 23 October 2015) did differently, and the handful of things worth settling before an examiner touches a disk.

    Key takeaways

    • Two well-known decisions ordered production of forensic reports commissioned through counsel: Capital One (E.D. Va. 2020) and Wengui v. Clark Hill (D.D.C. 2021).
    • The recurring test is counterfactual: would this work have been done, in substantially this form, even if litigation were not anticipated? A pre-existing services agreement makes the answer yes.
    • Distribution is the second killer. A report circulated to operations, the board, auditors, and regulators looks like a business document no matter what the engagement letter says.
    • The structure that has held up is two genuinely separate tracks with different scopes and different deliverables, not one report with a privilege legend on the cover.
    • Privilege is not always the right objective. Some reports need to be shared to be useful, and PCI Forensic Investigator reports go to the payment brands regardless of what you would prefer.

    What the courts actually held

    Capital One (E.D. Va., 26 May 2020, affirmed 25 June 2020). Mandiant was already engaged under a pre-existing services agreement when the incident occurred. After discovery of the breach, outside counsel signed a letter agreement, but the scope of the work did not meaningfully change, Capital One had paid Mandiant out of a fund the company itself denominated "business critical" expenses, and the finished report went well beyond counsel: roughly fifty employees, a corporate governance email box, the board, four regulators and Capital One's accountant. Applying the test of whether the document "would not have been prepared in substantially similar form but for the prospect of litigation," the court held Capital One had not carried that burden, and ordered the report produced.

    Wengui v. Clark Hill (D.D.C., 12 January 2021). Clark Hill argued the two-track approach: an internal or ordinary-course investigation on one side, a separate counsel-directed investigation on the other. The court was not persuaded on those facts, in part because the counsel-directed report was the only real investigation and its findings were shared for remediation and with law enforcement. Calling something a second track does not make it one if the first track does not exist.

    In re Target (D. Minn., 23 October 2015), the contrast. Target ran a genuinely bifurcated response: one investigation aimed at the payment-card and business obligations, whose materials were produced, and a separate counsel-directed investigation aimed at informing legal advice, which the court protected. The distinguishing feature was not the paperwork. It was that two different investigations with two different purposes actually existed.

    Read the three together and the pattern is unmissable. The court reads what happened, not what the engagement letter says happened.

    The test that decides it: would you have done this anyway?

    Work-product protection under Federal Rule of Civil Procedure 26(b)(3) covers documents prepared in anticipation of litigation. The practical question courts keep returning to is counterfactual: strip the litigation risk out of the picture, and would this investigation still have happened in substantially this form?

    For most breach forensics the honest answer is yes. You would still need to know how the attacker got in, what they touched, and whether data left, because you cannot remediate or notify without those answers. That is a business need, and a business need is exactly what defeats the claim.

    Which means the facts that move the needle are the ones that make this engagement look different from what you would have done anyway:

    • A new, incident-specific engagement letter, signed by counsel, rather than a change order under an existing agreement.
    • A stated purpose in that letter: the work is directed by counsel to inform legal advice about the incident.
    • Payment from the legal budget, invoiced to counsel, rather than booked as an IT operating expense.
    • A scope that is genuinely about the legal questions, and a separate deliverable for the operational ones.
    • A named, short distribution list, enforced from day one.

    None of those is a magic word. Together they are the difference between "we relabelled our usual vendor work" and "we commissioned something we would not otherwise have commissioned."

    The two-track structure, and why it is not a trick

    The structure that has survived scrutiny looks like this. One track is the operational investigation: the work you would do regardless, producing the remediation findings your engineers and your auditors need. It is not privileged and it is not pretending to be. The second track is a counsel-directed investigation scoped to the legal questions, producing a report that goes to counsel.

    Three conditions make that real rather than cosmetic. The scopes must differ, so that the second track is not simply the first one with a different cover page. The deliverables must differ and must actually be written separately. And the distribution must differ, with the counsel-directed report going only to the people counsel names.

    The cost objection is fair: two tracks means paying for some duplicated collection. In practice the duplication is smaller than people expect, because evidence acquisition can often be shared while examination and reporting diverge, and your counsel can tell you whether that sharing is acceptable on your facts. What is not acceptable is a single investigation with a privilege legend stamped on it, which is the version that lost in Clark Hill.

    There is also an uncomfortable corollary for vendors, including us. If your forensics firm already works for you under a standing agreement, that existing relationship is the exact fact pattern that undermined Capital One's claim. A firm that offers to "just add forensics to the current statement of work" is doing quiet, permanent damage. We cover the sequencing in When Should You Call an Outside Incident Response Firm?.

    How a protected report loses protection afterward

    Even a well-structured engagement can be undone in the weeks after the report lands. The recurring failure modes are mundane.

    Broad internal circulation. Forwarding the report to the whole IT department, attaching it to a board deck, or dropping it in a shared drive with open permissions all argue that it was a business document. Counsel should name the recipients, and the list should be short and written down.

    Voluntary production to third parties. Handing the report to auditors, an acquirer's diligence team, a customer demanding assurance, or a regulator can waive protection, sometimes far more broadly than intended. Every one of those requests has an alternative: a summary letter written for that audience, prepared with counsel.

    Using it as the remediation plan. If engineering is working from the privileged report because no operational deliverable exists, the report is the business document. That is why the second track needs its own output.

    Quoting it in marketing or customer communications. Describing findings in a trust-center post or a customer notification can put the underlying document in play. Counsel should draft or approve anything external.

    The rule of thumb we give clients: assume that every person who receives the report is a person a plaintiff will ask about, and that every use of the report is an argument about its purpose.

    When privilege is the wrong thing to optimize

    Now the against-interest part, because the privilege conversation gets over-sold, sometimes by firms like ours.

    A report nobody can read is a report nobody can act on. If the practical effect of the privilege structure is that your engineers never see the findings, you have protected a document and left the vulnerability in place. That is a bad trade, and it happens more often than anyone admits. The fix is the operational track, not weakening the legal one.

    Some investigations are mandated to be shared. A PCI Forensic Investigator engagement exists to report back to the affected payment brands, which is what its own program guide says it is for. Privilege is not the frame there, and pretending otherwise wastes money.

    Regulators frequently reward candour. In some postures, counsel will advise sharing a clear factual account because the alternative reads as obstruction. That is a judgment call for your lawyer, and a consultancy asserting otherwise is out of its lane.

    Small incidents do not need the machinery. A single quarantined laptop with no regulated data and no plausible claim does not need breach counsel, a two-track investigation, and a distribution list. Build the structure for the incidents that warrant it and keep a proportionate process for the rest.

    And the honest caveat about us: we are a security consultancy, not a law firm. Everything above is a description of how engagements are commonly structured and what published decisions have said. Your counsel decides what applies to you.

    Where Top Floor fits

    We do the part of this that a law firm does not: the digital forensics work itself, structured so counsel can defend how it was commissioned. In practice that means accepting an incident-specific engagement letter from counsel rather than a change order on an existing agreement, writing the counsel-directed report and any operational deliverable as genuinely separate documents, and keeping to the distribution list we are given rather than helpfully copying your IT lead.

    Where an incident is live, that runs alongside incident response so containment does not quietly destroy the evidence the report depends on. And the preparation work, picking breach counsel, agreeing the engagement structure, and rehearsing the sequence before anything happens, is vCISO territory rather than examination hours, which makes it the cheapest part of the whole exercise.

    How to decide this week

    1. Ask your general counsel or outside counsel one question: if we had an incident on Friday, who signs the forensics engagement letter? If the answer is your IT director, you have found the gap.

    2. Get a template incident-specific engagement letter drafted now, with the stated purpose and the distribution mechanism already in it.

    3. Check whether any current security vendor could plausibly be asked to investigate an incident under an existing agreement. Fix the papering before, not after.

    4. Decide in advance who receives a forensic report, by role, and write it down. Three to six names is a normal list.

    5. Agree what the operational deliverable looks like, so engineering never has a reason to work from the privileged document.

    The summary in one line: privilege is earned by facts, so build the facts before the incident, and treat any vendor promising protection as a bolt-on with appropriate suspicion.

    Frequently asked questions

    Does hiring a forensics firm through a law firm make the report privileged?

    Not by itself. In the Capital One consumer data breach litigation the report was ordered produced despite an outside-counsel letter agreement, because a pre-existing services agreement covered substantially the same work, the cost had been treated as a business expense, and the finished report was distributed well beyond counsel. Courts test whether the work would have been done in substantially the same form without litigation in prospect, and for most breach investigations there is an obvious independent business reason to do it. Routing the engagement through counsel is a necessary step, not a sufficient one.

    What is the two-track approach to a breach investigation?

    It means running two genuinely separate investigations: an operational one whose findings go to your engineers and auditors and which is not treated as privileged, and a counsel-directed one, scoped to the legal questions, whose report goes to counsel under a controlled distribution. The approach was accepted in the Target data breach litigation, where two distinct investigations actually existed, and rejected in Wengui v. Clark Hill, where the supposed second track was the only real investigation. The three conditions that make it real are different scopes, separately written deliverables, and different distribution lists.

    Who should be allowed to read the forensic report?

    Whoever counsel names, and the list should be short, written down before the report exists, and enforced. Broad internal circulation, attaching the report to a board deck, sending it to auditors or to an acquirer's diligence team, or handing it to a customer are all arguments that the document served a business purpose, and voluntary production to a third party can waive protection more broadly than intended. When another audience genuinely needs information, the usual answer is a separate summary written for that audience with counsel's involvement, not forwarding the report.

    Is a PCI forensic investigation report privileged?

    Treat it as not privileged. Under the PFI Program Guide v3.2, both the Preliminary Incident Response Report and the Final PFI Report must be delivered to each affected Participating Payment Brand, to the entity under investigation, and to that entity's affected acquirer where it is a merchant. The PCI Security Standards Council administers the program rather than receiving the report: the guide has the investigator pull a case reference number through the PFI Portal that identifies the case "without identifying the Entity Under Investigation to PCI SSC," and the only artifact uploaded to the Council is a de-identified appendix that "must not contain any confidential or identifying details." Either way the report is created to be shared with parties outside your company, which is close to the opposite of the work-product posture. Companies facing both a card-brand mandated investigation and litigation risk generally run the PFI engagement on its own terms and keep any counsel-directed investigation separate. Ask your breach counsel to sequence the two before the PFI is appointed, because the appointment timeline is set by the brand rather than by you.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.