Incident analysis for litigators. cyber insurers. boards. general counsel. coverage counsel. class action defense. regulators. trustees.

Every breach looks negligent in hindsight. The question is whether the safeguards were reasonable before it — and everything else in the case sits downstream of the answer.

3areas
8subject areas
30days of logs, typically
How it works

The evidence is disappearing while the decision is being made.

Volatile memory is gone at reboot. Log retention is commonly thirty days and sometimes seven. Reimaging a compromised host is correct security practice and it ends the forensic record on that host. All three happen before most matters have counsel — which is why the first section of this site is about preservation rather than analysis.

Traditional
Reconstructing it months later
With the Institute
A record that still exists

Preserve First

Suspend log rotation, capture memory before reboot, image before you remediate. Minutes of work, and irreversible in the other direction. What disappears, and how fast.

Test the Security Position

Standard-of-care experts are routinely the most influential witnesses in breach litigation, on both sides, because causation and damages both follow from whether the security was reasonable. How the standard is assessed.

Walk the Chain

A failed control and a harmed person are separated by more links than either side argues, and they break at the ends. Causation and exposure.

begin here

What happened, and when did you learn of it?

Describe the incident to the Incident Concierge. It will help you see what is at risk of being lost, what a standard-of-care analysis would examine, and what expertise the matter needs. It does not assess a live incident, does not opine on whether any organization’s security was reasonable, and is not legal advice.

Incident Conciergeorientation, not a security opinion
Tell me roughly what happened and when it was discovered — and whether anything has been rebooted, reimaged or restored since. That last answer decides what evidence is still recoverable, so it is worth establishing first.
Advisory

When the question is bigger than one incident

Boards increasingly want the standard-of-care analysis before anyone is asking for it under oath, because the same review that would be run adversarially in litigation produces the documented risk decisions that make a position defensible. The Institute performs that review independently, for a fixed fee agreed in advance.

writing from the Institute

The uncomfortable parts, said plainly.

A breach does not prove the security was unreasonable. Following NIST does not settle it either. The most damaging document is usually a vulnerability report showing a known risk was raised and quietly deferred.

All insights
A server cabinet standing ajar in a dark data center aisle
Standard of Care
Does a data breach mean the security was unreasonable?
No — and resisting that inference is most of what a defense analysis does. But the manner of the intrusion matters enormously, and some fact patterns are much harder to defend than others.
September 4, 2026
An open technical standard on a desk, its pages densely annotated by hand
Standard of Care
Is following the NIST Cybersecurity Framework enough to show reasonable security?
It is strong evidence and it does not end the question. Frameworks are risk-management structures, not compliance floors, and every one of them expects the organization to decide which controls fit its circumstances.
September 4, 2026
A grid of index cards pinned to a dark wall, a single card caught in the light
Standard of Care
Why is a deferred vulnerability the most damaging document in a breach case?
Because it defeats the hindsight defense. The risk did not need to be spotted with the benefit of the breach — the organization had already found it, written it down, and decided to wait.
September 4, 2026
Rows of storage drive indicator lights receding into the dark, most of them out
Incident Response & Forensics
What evidence disappears first after a breach, and how fast?
Volatile memory is gone at the next reboot. Log retention is commonly thirty days and sometimes seven. Both clocks are usually running before anyone has called a lawyer.
September 4, 2026
An opened hard drive on a workbench beneath an inspection lamp
Incident Response & Forensics
Does reimaging a compromised machine destroy the forensic evidence?
It ends the record on that host — and it is also correct security practice. The tension is real, it is resolved by imaging first, and it is usually created by people doing their jobs properly.
September 4, 2026
An empty glass-walled meeting room at night, laptops still open on the table
Incident Response & Forensics
How is the adequacy of an incident response judged after the fact?
Against what was reasonably knowable at each decision point — not against the timeline as it reads once the full picture is known. The recurring findings are delay in escalation and containment that outran the investigation.
September 4, 2026
common questions

What people ask in the first hours.

These come before the analysis does. If you are dealing with a live incident, the first answer is the one that matters today.

We just discovered an incident. What should we do in the next hour?
Suspend log rotation, and do not reboot or reimage anything you have not imaged first. Those two steps take minutes, cost almost nothing, and are irreversible in the other direction — volatile memory is gone at reboot and rolled-over logs do not come back. Then issue a written litigation hold covering security telemetry, ticketing, chat and vendor records, not only email. Everything else, including who to engage and in what order, can be decided tomorrow. These cannot.
What does the Institute actually do?
It explains what the technical questions in a breach dispute are and what evidence they need: whether the safeguards were reasonable for the risk, whether the response was adequate, and whether the failure caused the exposure. It is a reference and a diagnostic. It does not assess live incidents, does not perform incident response, and does not opine on whether a particular organization was reasonable — that is the expert opinion this site helps you obtain rather than the one it supplies.
Does being breached mean our security was unreasonable?
No, and resisting that inference is much of what a defense analysis does. Competent, well-defended organizations are breached; sophisticated attackers succeed against reasonable safeguards. The legal standard asks whether the safeguards were reasonable beforehand, not whether they held. That said, the manner of the breach matters enormously — an intrusion through a year-old unpatched vulnerability with a published exploit is a very different fact pattern from a novel supply-chain compromise, and pretending otherwise helps nobody.
We follow NIST. Are we covered?
It is strong evidence and it does not end the question. Frameworks are risk-management structures rather than compliance floors, and every one of them expects the organization to decide which controls fit its circumstances. That decision is the substance of the standard. The defensible position is not "we followed NIST" but "we assessed our risk against NIST, made these decisions for these documented reasons, and here is the record" — which is a materially stronger place to be, and a rarer one.
How is the Institute paid?
The orientation and the reference material are free and require no account. Where an organization wants the standard-of-care review performed properly — independently, and ideally before anyone is demanding it — that is a private engagement billed as a fixed fee agreed in writing beforehand. Where a matter needs a retained testifying expert, the Institute helps identify the right one through its expert network.
Do you calculate what the breach cost?
No. This Institute covers the technical chain — whether the control failure produced the exposure. What the resulting loss is worth is a different discipline with its own methodologies and its own admissibility record, and it belongs to our Economic Damages Institute, which covers class-wide models and the measures of loss properly. Matters needing both are usually two engagements and often two experts, and it is better to know that early.

Preserve today. Analyze tomorrow.

Describe the incident. The Institute will help you triage what is at risk of being lost — with no incident-response service to sell you.

talk to the Institute
Incident Conciergeorientation, not a security opinion
Tell me roughly what happened and when it was discovered. If this is live or recent, the first thing worth knowing is whether anything has been rebooted, reimaged or restored — that decides what evidence is still recoverable.