home  /  insights  /  is-the-incident-response-report-privileged
Incident Response & Forensics

Is the forensic incident response report privileged?

Not by default, and not because a law firm signed the engagement letter. Four federal decisions ordered production, and the reports that stayed protected differed in ways that were set up before the investigation began.

September 15, 2026 · 13 min read

The short answer

Not automatically. Federal courts have repeatedly ordered forensic incident response reports produced in discovery — In re Capital One Consumer Data Security Breach Litigation (E.D. Va. 2020), Wengui v. Clark Hill PLC (D.D.C. 2021), In re Rutter’s Data Security Breach Litigation (M.D. Pa. 2021) and Leonard v. McMenamins Inc. (W.D. Wash. 2023) — and in each the report had been commissioned through outside counsel. What separated those reports from the ones that stayed protected was not the paperwork but whether the organization could show that the report would not have been prepared in substantially similar form absent the prospect of litigation, and whether the report in fact carried legal advice rather than facts. The question is unsettled and the applicable test varies by circuit, and in the decided cases the outcome turned on a record built before the investigation started rather than on anything done after the report existed.

What this article establishes

  • In In re Capital One Consumer Data Security Breach Litigation, MDL No. 1:19md2915 (E.D. Va.), Magistrate Judge John Anderson ordered the Mandiant report produced on May 26, 2020, and Judge Anthony J. Trenga affirmed on June 25, 2020, holding that Capital One had not shown the report would not have been prepared in substantially similar form but for the prospect of litigation.
  • In Wengui v. Clark Hill PLC, 338 F.R.D. 7 (D.D.C. Jan. 12, 2021), Judge James Boasberg rejected a claimed two-track investigation because, in his words, the “two-track story finds little support in the record,” and ordered the Duff & Phelps report produced.
  • In In re Rutter’s Data Security Breach Litigation, No. 1:20-CV-382 (M.D. Pa. July 22, 2021), Magistrate Judge Karoline Mehalchick found neither work product nor attorney-client privilege applied, relying on a statement of work whose stated purpose was to determine whether a compromise had occurred.
  • In Leonard v. McMenamins Inc., No. C22-0094-KKE (W.D. Wash. Dec. 6, 2023), Judge Kymberly Evanson ordered the Stroz Friedberg report produced and held that communications involving the forensic firm were not privileged merely because an attorney was copied.
  • The two decisions the losing parties kept citing are In re Target Corp. Customer Data Security Breach Litigation, MDL No. 14-2522 (PAM/JJK) (D. Minn. Oct. 23, 2015), where Magistrate Judge Jeffrey J. Keyes, after an in camera review, sustained privilege and work-product claims over Data Breach Task Force communications while ordering two sets of board-update emails produced; and In re Experian Data Breach Litigation, No. SACV 15-01592 AG (DFMx) (C.D. Cal. May 18, 2017), where Judge Andrew J. Guilford denied a motion to compel the Mandiant report, relying in part on the fact that the full report was never given to Experian’s internal incident response team.
  • In re FirstEnergy Corp., 154 F.4th 431 (6th Cir. Oct. 3, 2025) (No. 24-3654), granted mandamus and vacated a production order covering counsel-run internal investigations; it is not a data breach case.

Why is a forensic incident response report not automatically privileged?

Because the work product doctrine asks why the document was created, not who signed the engagement letter, and a forensic incident response report is usually something the organization needed anyway. Federal Rule of Civil Procedure 26(b)(3)(A) protects documents prepared in anticipation of litigation, and the federal courts apply a “because of” test to decide whether a particular document qualifies. Where a report would have been created in substantially similar form regardless of the litigation, it fails that test.

That framing is what makes breach investigations hard to protect. In Wengui v. Clark Hill PLC, 338 F.R.D. 7 (D.D.C. 2021), Judge James Boasberg wrote that for many organizations, “discovering how [a cyber] breach occurred [is] a necessary business function regardless of litigation or regulatory inquiries” — quoting In re Dominion Dental Services USA, Inc. Data Breach Litigation, 429 F. Supp. 3d 190 (E.D. Va. 2019), which was in turn quoting In re Premera Blue Cross Customer Data Security Breach Litigation, 296 F. Supp. 3d 1230 (D. Or. 2017). An organization has to find out what happened in order to fix it, to notify, and to answer its regulators. A court that starts from that premise is already most of the way to ordering production.

The attorney-client privilege runs into a separate problem. It protects communications made to obtain or provide legal advice; it does not protect facts. A report that reconstructs initial access, dwell time and scope is a factual document, and calling it privileged on its cover page does not change what is inside it.

What did the court actually hold in In re Capital One Consumer Data Security Breach Litigation?

That the Mandiant report was not protected work product, because Capital One failed to show it would not have been prepared in substantially similar form but for the prospect of litigation. Magistrate Judge John Anderson granted the motion to compel on May 26, 2020, and on June 25, 2020 Judge Anthony J. Trenga of the Eastern District of Virginia overruled Capital One’s Rule 72 objections and affirmed, in MDL No. 1:19md2915.

The facts the court relied on are worth stating precisely, because they recur. Capital One had entered a Master Services Agreement with Mandiant on November 30, 2015 and a Statement of Work dated January 7, 2019 covering incident response, digital forensics and remediation, with a final report as a deliverable. After the breach was confirmed, Capital One retained Debevoise & Plimpton on July 20, 2019, and on July 24, 2019 Capital One and Debevoise signed a Letter Agreement under which Mandiant would do the same work “as directed by counsel.” The court found that the Letter Agreement reflected “the same scope of work Mandiant had already agreed to provide under the MSA and SOWs,” and that what the Letter Agreement changed was direction and delivery: “all work completed by Mandiant was to be conducted at the direction of Debevoise (not Capital One) and … any deliverables were to be produced directly to Debevoise (not Capital One).”

Distribution mattered too, though not as a waiver holding. The report went to Capital One’s legal department, its Board of Directors, its financial regulators, its outside auditor and dozens of employees — approximately fifty employees, four regulators and the company’s accountant, on the magistrate judge’s findings. Judge Trenga held that the magistrate judge had referenced that distribution to underscore Capital One’s business need for the report, not to strip protection from an otherwise protected document, and that doing so was not legal error. On payment, the opinion records that Capital One had paid Mandiant for the work under the Master Services Agreement and Statements of Work from a fund it denominated “business critical” expenses, and that the work reflected in the report was paid first from a retainer already held under the 2019 Statement of Work and then from Capital One’s Cyber budget, with those payments later re-designated as legal expenses.

The Institute takes no position on whether Capital One’s security or its response met any standard. The decision is cited here for what it says about discovery, which is the only thing it decided.

What is the two-track problem, and why did it fail in Wengui v. Clark Hill PLC?

A two-track investigation means running an ordinary-course business investigation that is produced in discovery alongside a separate, counsel-directed investigation that is withheld — and in Wengui v. Clark Hill PLC, 338 F.R.D. 7 (D.D.C. Jan. 12, 2021), Judge James Boasberg found the second track existed on paper but not in the record. Clark Hill argued that its usual vendor, eSentire, had handled investigation and remediation while Duff & Phelps, retained by outside counsel Musick, Peeler & Garrett, worked a separate legal track. The court held that “its two-track story finds little support in the record.”

What defeated it was evidence of a single investigation. The firm produced no sworn statement that eSentire had conducted its own inquiry into how the breach happened, no comparable eSentire findings, and no documents showing eSentire doing investigative or remedial work after September 14, 2017 — the day Duff & Phelps was called in. Clark Hill’s own interrogatory answers stated that its understanding of the incident was based “solely” on outside counsel and the consultants counsel retained. The Duff & Phelps report had also been shared with select firm leadership and IT staff and with the Federal Bureau of Investigation.

The attorney-client ruling was separate and just as blunt. Applying the narrow Kovel doctrine, the court concluded that Clark Hill’s true objective was Duff & Phelps’s expertise in cybersecurity rather than legal advice, pointing to the report’s “pages of specific recommendations on how Clark Hill should tighten its cybersecurity.” Recommendations are one of the things clients most want from a forensic firm, and they are also one of the things that most clearly reads as non-legal.

What did In re Rutter’s Data Security Breach Litigation turn on?

The statement of work and a corporate designee’s deposition testimony. In In re Rutter’s Data Security Breach Litigation, No. 1:20-CV-382 (M.D. Pa. July 22, 2021), Magistrate Judge Karoline Mehalchick held that neither the work product doctrine nor the attorney-client privilege protected the Kroll report, and ordered it produced within fourteen days.

Rutter’s received two endpoint alerts on May 29, 2019, retained BakerHostetler the same day to advise on notification obligations, and BakerHostetler engaged Kroll Cyber Security the next day. The statement of work said the purpose of the investigation was “to determine whether unauthorized activity within the Rutter’s systems environment resulted in the compromise of sensitive data, and to determine the scope of such a compromise if it occurred.” The court read that as evidence that Rutter’s did not yet hold a belief that litigation would result — as the opinion put it, without knowing whether a breach had occurred, the company could not be said to have unilaterally believed litigation would follow. The corporate designee then testified that he was not contemplating lawsuits at the time and was unaware of anyone else at the company who was.

The standard the court applied was the Third Circuit’s: aiding “identifiable” or “impending” litigation must have been the “primary motivating purpose behind the creation of the document,” quoting United States v. Rockwell International, 897 F.2d 1255, 1266 (3d Cir. 1990), and the initial inquiry is whether the party that ordered the document held a “unilateral belief” that litigation would result. On the attorney-client side, the court noted that the statement of work had Kroll working alongside Rutter’s own IT personnel to identify and remediate vulnerabilities, with no mention of attorney involvement in that service, and concluded that the report and communications were factual or, where advice was involved, “did not include legal input.”

What distinguished the forensic reports that stayed protected?

A genuinely separate ordinary-course investigation, or a report that the business side never received. The two decisions defendants cite most often are In re Target Corp. Customer Data Security Breach Litigation, MDL No. 14-2522 (PAM/JJK) (D. Minn. Oct. 23, 2015), and In re Experian Data Breach Litigation, No. SACV 15-01592 AG (DFMx) (C.D. Cal. May 18, 2017), and both were distinguished rather than overruled in the decisions that ordered production. Both are routinely described more broadly than they hold, so the orders themselves are worth reading.

In Target, Magistrate Judge Jeffrey J. Keyes was ruling on challenges to privilege log entries, not on a single forensic report. The order records that Target Corporation had retained Verizon Business Network Services to investigate; that one Verizon team conducted a separate investigation on behalf of the payment card brands; that outside counsel engaged “a separate team from Verizon to provide counsel with the necessary input”; and that the Verizon teams “did not communicate with each other about the substance of the attorney-directed investigation.” The court ordered Target to submit documents for in camera inspection, completed that review, then granted the motion in part — requiring production of chief-executive emails updating the board, which it found neither privileged nor work product — and denied it as to the Data Breach Task Force communications, finding the task force’s work was focused “not on remediation of the breach, as Plaintiffs contend, but on informing Target’s in-house and outside counsel about the breach.” It expressly limited its ruling to the entries submitted for in camera review. Judge Anthony J. Trenga read the case the same way in the Capital One opinion, describing Target as upholding protection “only after conducting an in camera review.”

In Experian, Judge Andrew J. Guilford denied the motion to compel the Mandiant report on work-product grounds and did not reach the attorney-client privilege. Jones Day, Experian’s outside litigation counsel, hired Mandiant, and the court found that “Mandiant was hired by Jones Day to assist Jones Day in providing legal advice in anticipation of litigation,” supported by declarations “as well as the fact that Mandiant’s full report wasn’t given to Experian’s Incident Response Team. If the report was more relevant to Experian’s internal investigation or remediation efforts, as opposed to being relevant to defense of this litigation, then the full report would have been given to that team.” On the argument that Mandiant had worked for Experian before, the court wrote that it “isn’t convincing in part because Mandiant’s previous work for Experian was separate from the work it did for Experian regarding this particular data breach.” The same narrow distribution defeated the waiver argument. The court was explicit about what it was not deciding: it was “not concluding that Mandiant’s 2013 report is privileged,” and not concluding that work done on the breach before Jones Day was hired was privileged.

Read together, the surviving pattern is narrow and expensive. Two investigations, two vendors or at least two clearly separated teams and scopes of work, factual findings that reach the business through the non-privileged track, and a counsel-directed report that the remediation team never sees. That last condition is the one organizations find hardest to accept, because the people fixing the environment are usually the people who most want the report.

Have later decisions changed the picture, and where do courts disagree?

The breach-specific decisions have continued in the same direction, while an appellate decision outside the breach context pushed back on one strand of the reasoning. In Leonard v. McMenamins Inc., No. C22-0094-KKE (W.D. Wash. Dec. 6, 2023), Judge Kymberly Evanson ordered production of the Stroz Friedberg report prepared after a December 2021 ransomware attack, finding it provided only factual information, that the forensic firm had contributed to business discussions and assisted with restoration, and that the supplemental scope of work showed restoration services rather than legal advice. The court also held that factual information in an email is not protected merely because an attorney was copied, and required the privilege log revised accordingly. It went further in the alternative, holding that even if the report were work product, Rule 26(b)(3)(A) would compel production because it was the only available information about how the breach occurred.

The countercurrent is In re FirstEnergy Corp., 154 F.4th 431 (6th Cir. 2025) (No. 24-3654, decided October 3, 2025), which is not a data breach case — it concerned internal investigations FirstEnergy Corporation undertook after federal bribery charges implicated the company — but which speaks directly to the business-use reasoning that runs through the breach decisions. The Sixth Circuit granted mandamus and vacated the production order, holding that “[w]hat matters under the attorney-client privilege is whether a company seeks legal advice … not what it later does with that advice.” District courts applying the “because of” test to a forensic report and the Sixth Circuit applying Upjohn to a counsel-run internal investigation are not squarely in conflict, but a litigant on either side of a breach dispute should expect the other to cite across that line.

None of this is advice about any particular engagement, and the Institute does not give legal advice or predict how a court will rule. Whether a report is protected in a given matter depends on the circuit, the record, and choices that were mostly made in the first week. The Institute’s work sits on the other side of that line: what the forensic record can establish, how response adequacy is judged, and what disappears first after a breach, which is the one thing that cannot wait for the privilege question to be settled. Preservation is not privilege-sensitive; see evidence preservation for what expires and when.

For informational purposes only. Not legal advice, not a security assessment, and not an opinion on whether any organization’s security was reasonable.

Related

The practice area

incident conciergeorientation · not a security opinion
Happy to. Tell me roughly what happened and when it was discovered — and whether anything has been rebooted, reimaged or restored since. That last answer decides what evidence is still recoverable, so it is worth establishing before anything else.