The chain runs from the specific failure to the intrusion, to what was reached, to what left, to what was done with it. Each link needs evidence.
Start a conversation with the Incident Concierge, already scoped to causation & exposure. Select a subject area to prompt it, or describe the incident directly.
Causation in a breach case is usually argued as a single step — the security was inadequate, therefore the plaintiff was harmed — and it is not one step. It is a chain: a specific control failure permitted a specific intrusion; that intrusion reached particular systems; particular data left those systems; that data reached someone who used it; and that use produced the harm claimed. Each link needs its own evidence, and they fail in different ways. The technical links can often be established from forensic evidence, provided it was preserved. The final links, from exfiltration to misuse to harm, frequently cannot be established at all for any individual, which is why so much of this litigation turns on whether exposure without demonstrable misuse is itself a compensable injury — an unsettled question of law that varies by jurisdiction, and one this Institute describes rather than answers.
The technical causal chain, the exposure-versus-misuse gap, and what the evidence supports across a group.
How the Institute approaches causation — the technical chain, never the dollar figure and never the legal conclusion.
At the two ends, for opposite reasons. At the front, the defense argues the missing control would not have prevented this particular intrusion — a real argument, since a sophisticated attacker who entered through a zero-day was not stopped by the unpatched system nobody used. At the back, the chain from exfiltration to misuse to harm to a specific individual usually cannot be evidenced at all: stolen data is aggregated, resold, and mixed with data from other breaches, so tying one person's fraud loss to one breach is rarely possible. The middle links are the well-evidenced ones.
Genuinely unsettled, jurisdiction-dependent, and squarely a question of law rather than a technical one — so treat any confident general answer with suspicion, including from a technical expert. What the Institute can say is what the evidence typically shows: that demonstrating individualised misuse traceable to a specific breach is difficult and often impossible, which is why the legal question carries so much weight. Whether increased risk, mitigation costs or loss of privacy suffice in your forum belongs with counsel.
By testing it against the actual attack path, which is the only way it can be assessed rather than asserted. If the intrusion began with credential stuffing against an account without multi-factor authentication, the argument that MFA would not have helped is weak. If it began with a novel exploit against a fully patched system, the argument that better patching would have prevented it is weak in the other direction. The analysis is specific: which control, against which step, at which point. Generic arguments about attacker sophistication carry little weight either way.
No, and the separation is deliberate rather than a limitation. This Institute covers whether the failure caused the exposure — a technical question answered from forensic evidence. What the resulting loss is worth is a different discipline with its own methodologies and its own admissibility record, and it belongs to the Economic Damages Institute, which covers class-wide models, causation-versus-damages and the measures of loss properly. Where you need both, they are two engagements and frequently two experts.
Describe the failure and the harm alleged. The Institute will help you see where the chain is thin.