When a cyber incident occurs, organisations understandably focus on containment: restoring systems, investigating what happened and meeting reporting deadlines. But another issue needs attention from the outset: legal privilege.

Legal privilege is not about hiding information. It creates a protected space in which an organisation can speak candidly with its solicitors, assess a fast-moving crisis, and obtain legal advice without those communications automatically becoming available to regulators, claimants or courts later.

That protection can be critical. A cyber attack often generates a rush of emails, messages, meeting notes and technical reports as teams try to understand the scale of the incident. Months-or even years-later, those records may be sought during a regulatory investigation or compensation claim. Unless they are protected by privilege, they may have to be disclosed.

Why timing matters

Privilege should not be treated as an afterthought once an incident has been contained. The documents created in the first hours and days of a breach can become important evidence later. Organisations should therefore involve their in-house legal team or external solicitors as early as possible.

Early legal involvement helps ensure that communications and investigations are structured appropriately, while also allowing the organisation to understand its obligations to regulators, affected individuals and other stakeholders.

When is information privileged?

While there are some differences between Scots law and English law, the general position is:

  • Legal advice privilege protects confidential communications between a solicitor and client made for the purpose of seeking or giving legal advice. In a cyber incident, this may include discussions about legal liability, notification duties, communications with affected people and the organisation’s response strategy.

  • Litigation privilege can protect documents created for the dominant purpose of dealing with actual or anticipated litigation or regulatory action. These need not be prepared by a solicitor. This requires more than a hypothetical possibility of a dispute or investigation: it must be genuinely in prospect.

In the immediate aftermath of many cyber incidents, legal advice privilege is the more likely head of privilege to apply. It can cover the exchanges needed for an organisation to obtain legal advice while it works through a developing situation. Litigation privilege might attach to documents created later, if regulatory action or litigation becomes a likely prospect.

Simply marking a document “legally privileged”, or copying a solicitor into an email, does not create privilege in the document in and of itself. The purpose and content of the communication remain central to whether or not it is protected by privilege.

Forensic reports need careful handling

External forensic investigations are often essential after a significant attack. They can help establish how an incident occurred, whether it is ongoing, what data may have been affected and whether any security gaps contributed to the breach.

However, a forensic report may contain sensitive findings, and its conclusions can evolve as the facts become clearer. Ideally, any such report should be instructed by solicitors for the purpose of providing legal advice. This means that privilege may attach to it, or the communications around it. 

Avoid accidental waiver

Privilege can be lost-or waived-if protected material is circulated or discussed too widely. 

Organisations should establish a small, clearly defined incident response group responsible for managing legal communications. Key strategic discussions, particularly those concerning liability, legal duties and response decisions, should involve legal advisers.

Documents that are genuinely privileged should be clearly labelled “Legally Privileged and Confidential” and shared only with those who need access. Teams should also be cautious about summarising or paraphrasing legal advice in wider emails, board papers or external communications, as this can risk waiving protection.

A practical priority for boards

Cyber resilience is often discussed in technical terms, but effective incident response also depends on governance and legal preparedness. Boards should ensure that their incident response plans identify who will contact legal advisers, how communications will be controlled and how external experts will be instructed.

The central point is simple: legal privilege gives organisations the space to address a cyber crisis openly and directly. In the pressure of an attack, people need to be able to identify problems, test options and seek advice without fearing that every preliminary comment may later be taken out of context. Bringing legal advisers in early helps preserve that space and can make a material, strategic difference if regulatory scrutiny or claims follow.

If you would like to discuss the issues raised above, do not hesitate to contact our specialists below. 

This topic is discussed further in Let's Talk Cyber Episode 58, featuring Tommy McCarthy, CEO of OSP Cyber Academy, with Rebecca Roberts, Director at Burness Paull. Click here to listen to the podcast episode. 

Written by

Nick Warrillow

Nick Warrillow

Partner

Dispute Resolution

nick.warrillow@burnesspaull.com +44 (0)131 473 6115

Get in touch

Related News, Insights & Events

Error.

No results.

Class Action

UPDATE: Scotland’s class action ‘opt out’ proposal

01/09/2026

This insight discusses the Scottish Civil Justice Council (SCJC) responses, which reveal a clear divergence of opinion.

Read more
Verbal Contracts – A Stark Reminder That They Can Be Binding And Enforceable

Verbal contracts – a stark reminder that they can be binding and enforceable

13/08/2026

This blog explores a recent case confirming that verbal agreements can be legally binding under Scots law.

Read more
Employment Law Lab

Top tips for handling data privacy issues

11/08/2026

This blog covers the current privacy issues organisations are facing and offers practical, actionable guidance to remain compliant.

Read more

Want to hear more from us?

Subscribe here Subscribe here