Why is a breach not proof that the security was unreasonable?
Because security is a risk-management discipline, not a guarantee, and every serious legal and regulatory framing of the duty says so. The duty is generally framed as reasonable or appropriate safeguards, measured against the sensitivity of the data, the size and complexity of the organization, the threats it could foresee, and the cost of available mitigations. None of those formulations promises that an adequately protected organization will not be breached.
The practical version is simpler. A sufficiently motivated, sufficiently resourced attacker gets in. Nation-state actors and well-capitalised ransomware crews succeed against organizations with mature programs, full-time security staff and current tooling. If a breach alone established unreasonableness, the standard would be strict liability in everything but name, which is not what the statutes, the regulators or the case law describe.
What is hindsight bias and why does it matter so much in breach litigation?
Hindsight bias is the well-documented tendency to see an outcome as more predictable after it has happened than it ever was beforehand, and breach litigation is close to a perfect laboratory for it. Everyone assessing the security — the plaintiff’s expert, the regulator, the jury, and often the defendant’s own board — is doing so while holding the answer. The path the attacker actually took is lit up, and the several hundred other paths that were equally plausible in advance have gone dark.
The practical effect is that a defensible set of decisions can be made to look negligent simply by narrating them in the order the attack unfolded. A vulnerability that sat at position 400 on a risk register of 4,000 items looks like an obvious priority once it is the one that was used. It was not obvious at the time, and the analytical work of a standard-of-care assessment is largely the work of reconstructing what was actually knowable then.
This is why contemporaneous documents matter more than testimony in these matters. A risk register, a prioritization memo or a change-advisory record written before anyone knew the answer is evidence of the decision as it was actually made. Recollection reconstructed afterward is not, and everyone in the room knows it.
What fact patterns are genuinely hard to defend?
The hardest pattern is a known vulnerability, with an available fix, left in place past any defensible window, in a system the organization knew held sensitive data. That is hard because it defeats the hindsight objection: the risk did not have to be identified with the benefit of the breach, because the organization had already identified it and written it down.
Several others recur. Credentials with no multi-factor authentication on an internet-facing remote access path, years after MFA became a baseline expectation. Security tooling that was purchased and deployed but never actually monitored, so the alerts fired into an unread queue. Backups that were never tested and did not restore. An asset the organization did not know it had, holding data it did not know it held.
What these share is that they are not failures of sophistication but failures of follow-through, and they are legible to a lay factfinder without any expert translation. A jury does not need to understand lateral movement to understand that somebody was told about a problem, said they would fix it, and did not.
If a breach does not prove unreasonableness, what does the plaintiff have to show?
Broadly, that a specific safeguard fell below what was reasonable in the circumstances, and that the shortfall has a real connection to what happened. The framing varies by theory — negligence, contract, statute, or a regulator’s unfairness authority — but the structure is consistent: identify the duty, identify the specific deficiency, and connect that deficiency to the intrusion and the resulting exposure.
That second element is where a lot of breach claims are weaker than they first appear. It is common to see an expert report that catalogs twenty control deficiencies without establishing that any of them is the one the attacker used. A list of things an organization could have done better is not the same as an explanation of how the intrusion happened, and the difference is the whole case. The Institute treats those as separate questions and covers the second in how a control failure is connected to a specific breach.
How is reasonable security assessed if there is no single standard?
By triangulating several sources that all point at the same method rather than at a fixed checklist. Sector regulation supplies specific requirements where it applies. General consumer-protection and state data-security statutes supply a reasonableness duty scaled to the organization and the data. Contracts frequently impose their own, sometimes stricter, obligations. Published frameworks supply the vocabulary and the structure. Industry practice supplies the benchmark of what comparable organizations were actually doing at the time.
What emerges from all of them is a process standard rather than a control list: identify your assets and risks, decide which risks to mitigate, accept or transfer, implement accordingly, and revisit the decisions as things change. An organization that can show that process, with dated records, is in a far stronger position than one with a longer list of controls and no evidence of how they were chosen.
What should a defendant preserve and gather first?
The evidence that expires, before anything else — and that work is measured in hours, not weeks. Suspend log rotation, image before remediating, and capture volatile memory before any reboot. The Institute treats this as the first question on the site rather than a later one, and sets out the timescales in what disappears first after a breach.
After that, the documents that establish how decisions were actually made: risk assessments and registers, penetration test and vulnerability scan reports with their remediation tracking, change-management records, security budget and headcount requests, board and steering-committee materials, and vendor due-diligence files. These are the contemporaneous record of reasonableness, and they are also, reliably, the first thing the other side asks for.