home  /  insights
writing from the institute

The uncomfortable parts, said plainly.

A breach does not prove the security was unreasonable. Following a framework does not settle it either. What follows is the Institute’s writing on the questions that actually decide these matters — standard of care, response adequacy, and technical causation.

An empty office chair reflected indistinctly in a dark monitor
Causation & Exposure

What does attribution actually prove in a breach case?

Naming the attacker is compelling and frequently beside the point. Who did it and whether the defendant’s safeguards were reasonable are close to independent questions.
September 4, 2026 · 4 min read
A wall of archive filing drawers with a single drawer pulled open
Causation & Exposure

Is data being exposed the same as data being misused?

No, and the distinction carries a great deal of weight. Establishing that records were accessible, that they were accessed, that they were taken, and that they were used are four separate findings with four different evidentiary bases.
September 4, 2026 · 5 min read
A dense network patch panel with one cable lit along its whole length
Causation & Exposure

How do you prove a specific control failure caused a specific breach?

By reconstructing the intrusion chain link by link and asking, at the link in dispute, whether the missing control would actually have stopped it. A list of deficiencies is not a causal argument.
September 4, 2026 · 5 min read
An empty glass-walled meeting room at night, laptops still open on the table
Incident Response & Forensics

How is the adequacy of an incident response judged after the fact?

Against what was reasonably knowable at each decision point — not against the timeline as it reads once the full picture is known. The recurring findings are delay in escalation and containment that outran the investigation.
September 4, 2026 · 4 min read
An opened hard drive on a workbench beneath an inspection lamp
Incident Response & Forensics

Does reimaging a compromised machine destroy the forensic evidence?

It ends the record on that host — and it is also correct security practice. The tension is real, it is resolved by imaging first, and it is usually created by people doing their jobs properly.
September 4, 2026 · 5 min read
Rows of storage drive indicator lights receding into the dark, most of them out
Incident Response & Forensics

What evidence disappears first after a breach, and how fast?

Volatile memory is gone at the next reboot. Log retention is commonly thirty days and sometimes seven. Both clocks are usually running before anyone has called a lawyer.
September 4, 2026 · 5 min read
A grid of index cards pinned to a dark wall, a single card caught in the light
Standard of Care

Why is a deferred vulnerability the most damaging document in a breach case?

Because it defeats the hindsight defense. The risk did not need to be spotted with the benefit of the breach — the organization had already found it, written it down, and decided to wait.
September 4, 2026 · 4 min read
An open technical standard on a desk, its pages densely annotated by hand
Standard of Care

Is following the NIST Cybersecurity Framework enough to show reasonable security?

It is strong evidence and it does not end the question. Frameworks are risk-management structures, not compliance floors, and every one of them expects the organization to decide which controls fit its circumstances.
September 4, 2026 · 4 min read
A server cabinet standing ajar in a dark data center aisle
Standard of Care

Does a data breach mean the security was unreasonable?

No — and resisting that inference is most of what a defense analysis does. But the manner of the intrusion matters enormously, and some fact patterns are much harder to defend than others.
September 4, 2026 · 6 min read
incident conciergeorientation · not a security opinion
Happy to. Tell me roughly what happened and when it was discovered — and whether anything has been rebooted, reimaged or restored since. That last answer decides what evidence is still recoverable, so it is worth establishing before anything else.