Why is a retained DFIR firm hired through outside counsel, and what changes in how you write findings?
answer
- the report is the risky document
- who directed the work, not who typed the label
- advice and work product, never the facts
- wide distribution can waive it
- notes carry artefacts, not opinions on fault
basics
~20 sCounsel engages the firm so its work informs legal advice and may be shielded from later disclosure. Notes then carry observed artefacts, sources and timestamps, never speculation about fault. The underlying logs and evidence are never protected.
solid answer
~50 sA forensic report says, in detail, what an organisation missed and when. Contracted straight by the security team, it is an ordinary business document and far more likely to be produced in litigation or regulation. Engaging the firm through outside counsel means the work is directed by lawyers to inform legal advice, which is what any protection attaches to. Two limits matter in practice. First, the protection is not automatic: courts have ordered forensic reports handed over where the work looked like the company's ordinary-course scope rather than something counsel genuinely directed. Second, it covers advice and work product, not facts. Logs, disk images, alerts and the timeline of what happened are discoverable regardless. So write notes as observed artefact, source, timestamp and what it does and does not show, and keep opinions about negligence, blame or liability out of them.
go deeper
Know the shape: outside counsel engages the forensic firm so its analysis supports legal advice, and your notes should record observed artefacts with sources and timestamps rather than opinions about who was at fault.
Explain the mechanism and its limits: protection can cover counsel-directed advice and work product but never the underlying facts or evidence, it depends on the engagement being genuine rather than labelled, and broad distribution can waive it.
Show you can operate under it without slowing the response, keeping remediation flowing to engineers while the written analysis is controlled, and that you coach your team on note discipline before an incident rather than during one.
Be ready to defend the structure itself: when a counsel-directed engagement is worth its cost and friction, how you keep it from becoming theatre, and how you avoid the posture starving engineering of what it needs to fix things.
## The report is the most dangerous document in the incident When an intrusion is declared, the artefact that most often surfaces years later is not a log file. It is the written analysis: a narrative saying an adversary was inside from this date, reached these systems, and got in through a control that should have stopped them. That document is invaluable for fixing the organisation and awkward for defending it. The engagement structure is the mechanism organisations use to manage that tension. ### What engaging through counsel actually does Legal systems protect two related things: confidential communications between a client and its lawyers seeking or giving legal advice, and material prepared in anticipation of litigation or to support that advice. The names differ by jurisdiction, US attorney-client privilege and work-product doctrine, legal advice privilege and litigation privilege in England and Wales, and the strength varies widely, but the structural logic is the same. If outside counsel engages the forensic firm and directs its work so counsel can advise the organisation, the firm's analysis is more plausibly part of that advice-giving. If the security team signs the statement of work under a pre-existing operational retainer and the firm reports into the security organisation, the same analysis looks like routine business. ### It is a structure, not a magic word This is the part candidates get wrong. Two failures recur: 1. **Labelling as a substitute for substance.** Typing *privileged and confidential* on an email does not make it so. What the courts look at is who directed the work, why it was done, who received it and whether an equivalent report would have been produced anyway. Where the work matched a firm's existing incident-response retainer, its scope and its ordinary distribution, US courts have ordered production despite counsel being nominally involved. 2. **Believing facts become secret.** Protection can cover advice and the work product created to support it. It never covers the underlying facts or the evidence. The Windows event logs, the SaaS audit trail, the disk image, the alert that fired, the dates the adversary was present: all of that is what happened, and what happened is discoverable. You cannot make a log privileged by emailing it to a lawyer, and you should never tell an engineer you can. ### Waiver Protection can be lost by sharing. Circulating the report to an auditor, a customer, an insurer's non-legal staff or a wide internal distribution list can waive it in whole or in part. This is why counsel usually controls the report's distribution and why a technical summary intended for engineers to act on is often written as a separate, deliberately factual document. ### What it changes for you day to day - **Write facts, not verdicts.** *At 02:14 UTC the HR platform's audit trail records 4,102 employee records exported by account j.doe from IP x* is a fact. *We clearly should have had alerting on bulk export* is an opinion about fault; it belongs in a remediation discussion counsel is part of, not in the case notes. - **Do not editorialise about blame or legal conclusions.** Whether this constitutes a reportable breach is a legal determination. Writing *this is a breach* in an incident ticket pre-empts counsel and can be quoted back at the organisation. - **Keep to the channel you were told to use.** Cross-posting the analysis into a wide chat channel expands the circle and risks waiver. - **Mark and route as instructed.** If counsel asks for a marking or wants the report addressed to them, do it, and understand it is the direction of the work, not the marking, that carries the weight. - **Do not let it slow remediation.** Facts and fixes flow normally. Engineers still get told which patch to apply and which credential to rotate. If a privilege posture is stopping defenders from defending, the posture is being applied wrongly. ### Where the boundary sits Counsel owning the legal posture does not make counsel the investigator. The security team still decides what to collect, in what order, and what the artefacts support. What changes is the audience of the written product and the discipline of its language. A candidate who can say *facts and evidence are never protected, the analysis and advice may be, and the structure has to be real* has the whole thing.
- Does a privileged posture stop you from telling engineers what to fix?No, and if it does the posture is being misapplied. Facts and remediation instructions flow normally: rotate this credential, revoke these tokens, apply this patch. What is controlled is the written analysis and the legal conclusions in it. Many organisations deliberately produce a plain technical remediation document alongside the counsel-directed report so defenders are never blocked.
- Can protection be lost after the report is written?Yes, most commonly through distribution. Sharing the report with an auditor, a customer, an insurer's business staff or a broad internal list can waive it, sometimes for the whole document rather than the shared part. Counsel therefore controls circulation, and anything the wider organisation needs is usually restated in a separate factual summary.
- Are the disk images and logs you collected protected once counsel is engaged?No. Evidence and the facts it records are discoverable however the engagement is structured. Protection can attach to counsel-directed analysis and advice, not to the artefacts themselves or to what actually happened. Anyone who thinks routing collection through a law firm hides the underlying data has misunderstood the mechanism.
saying these in an interview costs you the question
- Thinks labelling an email privileged is what creates protection
- Claims logs and images become protected once counsel is engaged
- Writes speculation about negligence into case notes
- States in a ticket that this is a reportable breach
- Assumes the same protection exists identically in every jurisdiction
- Uses privilege as a reason to withhold fixes from engineers