skip to content

What is a legal hold, and when does the duty to preserve intrusion evidence begin?

level: juniorimportance: must knowfreq 60%

answer

  1. reasonably anticipated, not filed
  2. counsel issues, counsel releases
  3. suspend routine destruction first
  4. preserving is not collecting
  5. scope by system and date range

basics

~20 s

A legal hold is a written directive to suspend routine deletion of material relevant to a dispute. The duty attaches when litigation is reasonably anticipated, usually well before any complaint, subpoena or regulator letter arrives.

solid answer

~50 s

A legal hold, or litigation hold, is a written instruction from counsel that named material must not be deleted, overwritten or allowed to expire while a dispute is live or anticipated. The trigger is not the filing of a lawsuit: the duty to preserve attaches the moment litigation is reasonably anticipated. If an intruder reached our estate over a partner's site-to-site VPN and that partner's insurer has begun asking who was negligent, we are already past that line. Counsel issues the hold and only counsel releases it, in writing; the SOC never lifts a hold because the incident ticket closed. In practice it means three things: inventory the relevant material (mailboxes, VPN and firewall logs in the archive, tickets, endpoint telemetry, backups), suspend every automated process that would destroy it, and record what you suspended and when. Preserving is not the same as collecting, but preservation in place only counts where nothing is quietly deleting.

go deeper

for a junior

Be ready to say that a legal hold suspends routine deletion and that the duty starts when litigation is reasonably anticipated, not when papers are served. Know that counsel issues and releases it, never the SOC.

for a middle

Explain the mechanics: which automated jobs would destroy intrusion evidence, how preservation in place differs from collection, and why vendor-held endpoint telemetry usually has to be exported rather than left in place.

for a senior

Show you can turn a hold into an inventory of deletion mechanisms with a named owner per job, and that you escalate the anticipation question to counsel rather than waiting to be told.

for a principal

Own the standing arrangement: an agreed trigger that gets counsel involved early, a documented scope template naming systems and date ranges, and clarity on who pays for and who ends the preservation.

## What a legal hold actually is A legal hold (also called a litigation hold or preservation notice) is a written instruction, normally issued by in-house or outside counsel, that identified material must not be deleted, overwritten, altered or allowed to expire while a dispute is live or reasonably anticipated. It is a duty placed on the organisation, not a product feature. The organisation then implements it with technical controls, and those controls almost all live with the SOC and its platform teams, because they own the machinery that would otherwise destroy the material: the log archive, mail retention, the case system, backup expiry, host reimaging. ## The trigger is anticipation, not filing The common wrong answer is that preservation starts when a lawyer's letter or a subpoena arrives. It starts earlier: when litigation is *reasonably anticipated*. Things that clearly cross that line include a partner telling you their intrusion traversed a shared VPN into your network while their insurer investigates who was negligent; notifying a customer of a breach; dismissing an employee over data theft; receiving a preservation letter from another party; or counsel opening a matter. Things that do not cross it include a routine commodity-malware alert closed the same shift. A useful operating rule for a SOC: the moment someone outside the incident channel starts asking *whose fault it was*, or an outside party's lawyer or insurer appears in the thread, raise it with counsel and ask whether a hold should issue. The SOC does not decide that litigation is anticipated; the SOC makes sure the question is asked before the next retention cycle runs. ## Who issues it, and who lifts it Counsel issues the hold. Counsel releases it, in writing. Neither the SOC lead nor the platform administrator paying for the extra storage may decide the hold is over, and "the incident is closed" is not a release. Holds routinely outlive the investigation that spawned them by years, because civil litigation moves far more slowly than incident response. ## What preservation means in practice Preservation is not collection. You do not have to image every host on day one. Preservation in place is acceptable where the material is genuinely stable, and it is *not* stable anywhere an automated process can delete it. So the practical work is an inventory, and for each source three questions: what deletes this, on what schedule, and who owns the switch that stops it? For an intrusion that arrived over a partner VPN four months ago, that inventory typically covers: - VPN concentrator and firewall logs in the object-storage archive, where a lifecycle expiry rule deletes objects on a fixed age - the SIEM's searchable index, where an index-lifecycle delete phase drops old indices - mailboxes of the people who discussed the partner connection, where a retention policy purges items and users can delete their own - the ticket or case system, which may auto-purge closed records - endpoint telemetry held by the vendor, frequently the shortest window you have and not under your control, so export rather than rely on it - backups, which expire on their own schedule - the affected hosts themselves, which a rebuild queue will happily reimage ## Scope it by system, not only by person Custodian-based holds name employees and preserve their mailboxes and files. Machine-generated telemetry has no custodian, so a hold written purely as a list of people leaves every lifecycle rule running untouched. Written well, a hold's scope reads as: this system, this date range, this job or mechanism that would destroy it, this named owner who confirms it is suspended. ## Third-party data You cannot place a hold on data you do not control. The partner's own firewall logs, and often a SaaS provider's platform logs, are theirs. Counsel sends a preservation notice or asks for it in writing; you record the request and its date, because the gap between what you preserved and what you merely asked for is a question you will be asked later. ## Recording it Write down when the duty attached and why, what the hold covers, who acknowledged it, which jobs were suspended and when, and anything you could not preserve with the reason. That contemporaneous record is what makes the preservation defensible; without it you are asking a court to take your word for it years later.

  • Who is allowed to decide a hold is over?
    Counsel who issued it, in writing. Closing the incident ticket, finishing eradication or the retention period expiring are all irrelevant. The SOC and the platform team record the release notice and only then restore the normal deletion jobs, noting the date they did so.
  • Does preserving mean imaging every affected host straight away?
    No. Preservation in place is acceptable where nothing will destroy the material. It fails wherever an automated process can delete or overwrite it, or where a host is queued for rebuild, so those are the sources you copy out to a preservation location first.
  • The disputed traffic is in the partner's firewall logs. Can you hold that?
    No. You can only preserve what you control. Counsel sends the partner a written preservation notice, and you record what was requested and when. That record matters later: a gap you asked about in writing reads very differently from one nobody noticed.

A hold is a pause button on the shredder, not a request for a photocopy: you stop the destruction first, then decide what to copy out.

saying these in an interview costs you the question

  • Waits for a subpoena or filed complaint before preserving anything
  • Says the SOC can lift the hold once the incident is closed
  • Treats a hold as covering mailboxes and nothing else
  • Confuses preservation with imaging every host in the estate
  • Assumes the existing retention policy already satisfies the hold

context