When a cyber incident occurs, organisations understandably focus on containment: restoring systems, investigating what happened and meeting reporting deadlines. But another issue needs attention from the outset: legal privilege.
Legal privilege is not about hiding information. It creates a protected space in which an organisation can speak candidly with its solicitors, assess a fast-moving crisis, and obtain legal advice without those communications automatically becoming available to regulators, claimants or courts later.
That protection can be critical. A cyber attack often generates a rush of emails, messages, meeting notes and technical reports as teams try to understand the scale of the incident. Months-or even years-later, those records may be sought during a regulatory investigation or compensation claim. Unless they are protected by privilege, they may have to be disclosed.
Why timing matters
Privilege should not be treated as an afterthought once an incident has been contained. The documents created in the first hours and days of a breach can become important evidence later. Organisations should therefore involve their in-house legal team or external solicitors as early as possible.
Early legal involvement helps ensure that communications and investigations are structured appropriately, while also allowing the organisation to understand its obligations to regulators, affected individuals and other stakeholders.
When is information privileged?
While there are some differences between Scots law and English law, the general position is:
-
Legal advice privilege protects confidential communications between a solicitor and client made for the purpose of seeking or giving legal advice. In a cyber incident, this may include discussions about legal liability, notification duties, communications with affected people and the organisation’s response strategy.
-
Litigation privilege can protect documents created for the dominant purpose of dealing with actual or anticipated litigation or regulatory action. These need not be prepared by a solicitor. This requires more than a hypothetical possibility of a dispute or investigation: it must be genuinely in prospect.
In the immediate aftermath of many cyber incidents, legal advice privilege is the more likely head of privilege to apply. It can cover the exchanges needed for an organisation to obtain legal advice while it works through a developing situation. Litigation privilege might attach to documents created later, if regulatory action or litigation becomes a likely prospect.
Simply marking a document “legally privileged”, or copying a solicitor into an email, does not create privilege in the document in and of itself. The purpose and content of the communication remain central to whether or not it is protected by privilege.
Forensic reports need careful handling
External forensic investigations are often essential after a significant attack. They can help establish how an incident occurred, whether it is ongoing, what data may have been affected and whether any security gaps contributed to the breach.
However, a forensic report may contain sensitive findings, and its conclusions can evolve as the facts become clearer. Ideally, any such report should be instructed by solicitors for the purpose of providing legal advice. This means that privilege may attach to it, or the communications around it.
Avoid accidental waiver
Privilege can be lost-or waived-if protected material is circulated or discussed too widely.
Organisations should establish a small, clearly defined incident response group responsible for managing legal communications. Key strategic discussions, particularly those concerning liability, legal duties and response decisions, should involve legal advisers.
Documents that are genuinely privileged should be clearly labelled “Legally Privileged and Confidential” and shared only with those who need access. Teams should also be cautious about summarising or paraphrasing legal advice in wider emails, board papers or external communications, as this can risk waiving protection.
A practical priority for boards
Cyber resilience is often discussed in technical terms, but effective incident response also depends on governance and legal preparedness. Boards should ensure that their incident response plans identify who will contact legal advisers, how communications will be controlled and how external experts will be instructed.
The central point is simple: legal privilege gives organisations the space to address a cyber crisis openly and directly. In the pressure of an attack, people need to be able to identify problems, test options and seek advice without fearing that every preliminary comment may later be taken out of context. Bringing legal advisers in early helps preserve that space and can make a material, strategic difference if regulatory scrutiny or claims follow.
If you would like to discuss the issues raised above, do not hesitate to contact our specialists below.
This topic is discussed further in Let's Talk Cyber Episode 58, featuring Tommy McCarthy, CEO of OSP Cyber Academy, with Rebecca Roberts, Director at Burness Paull. Click here to listen to the podcast episode.
Written by
Related News, Insights & Events
Error.
No results.
Webinar recording: Employment law lab - July 2026
11/08/2026
Listen to our bi-monthly employment webinar. Your one-stop for all things employment law-related.
AI: perspectives on pitfalls and possibilities for pension schemes
10/08/2026
This blog explores how to implement appropriate AI governance into pension schemes.
Wildfires and the right of responsible access: Understanding Scotland's laws on fires and barbeques
31/07/2026
Following Scotland's recent wildfires, we examine the legal rules on fires and barbecues, including access rights, byelaws, restrictions and the responsibilities of outdoor users.
{name}
{properties.pageSummary}
{properties.eventName}
{properties.pageDate|date:dd/MM/yyyy}{properties.shortDescription}
{properties.headline}
{properties.pageDate|date:dd/MM/yyyy}
{properties.shortDescription}