home  /  causation & exposure
department of causation & exposure

A failed control and a harmed person are separated by more links than either side argues.

The chain runs from the specific failure to the intrusion, to what was reached, to what left, to what was done with it. Each link needs evidence.

begin here

What happened, and when did you learn of it?

Start a conversation with the Incident Concierge, already scoped to causation & exposure. Select a subject area to prompt it, or describe the incident directly.

Incident Conciergecausation & exposure · orientation, not a security opinion
Tell me what control is alleged to have failed and what harm is claimed. I'll help you walk the chain between them — they are usually further apart than either side argues. I won't quantify the loss; that is the Economic Damages Institute's work.

Causation in a breach case is usually argued as a single step — the security was inadequate, therefore the plaintiff was harmed — and it is not one step. It is a chain: a specific control failure permitted a specific intrusion; that intrusion reached particular systems; particular data left those systems; that data reached someone who used it; and that use produced the harm claimed. Each link needs its own evidence, and they fail in different ways. The technical links can often be established from forensic evidence, provided it was preserved. The final links, from exfiltration to misuse to harm, frequently cannot be established at all for any individual, which is why so much of this litigation turns on whether exposure without demonstrable misuse is itself a compensable injury — an unsettled question of law that varies by jurisdiction, and one this Institute describes rather than answers.

specialization areas

Areas in this part of the practice.

The technical causal chain, the exposure-versus-misuse gap, and what the evidence supports across a group.

methodology

How this department investigates.

How the Institute approaches causation — the technical chain, never the dollar figure and never the legal conclusion.

Link-by-link analysisEach step in the chain assessed separately, because they fail for different reasons.
Counterfactual controlWhether the missing control would actually have prevented this intrusion, which is often contested.
Exposure versus misuseThe gap that decides most consumer breach litigation, and where the evidence usually runs out.
Individual versus group proofWhat can be shown across a population versus for any particular person.
Alternative sourcesWhether the same data was available from other breaches. A standard and effective defense.
Handoff to damagesWhere technical causation ends and quantification begins. A different discipline.
common questions

Causation — the questions counsel ask.

Where does the causal chain usually break?

At the two ends, for opposite reasons. At the front, the defense argues the missing control would not have prevented this particular intrusion — a real argument, since a sophisticated attacker who entered through a zero-day was not stopped by the unpatched system nobody used. At the back, the chain from exfiltration to misuse to harm to a specific individual usually cannot be evidenced at all: stolen data is aggregated, resold, and mixed with data from other breaches, so tying one person's fraud loss to one breach is rarely possible. The middle links are the well-evidenced ones.

Is exposure by itself an injury?

Genuinely unsettled, jurisdiction-dependent, and squarely a question of law rather than a technical one — so treat any confident general answer with suspicion, including from a technical expert. What the Institute can say is what the evidence typically shows: that demonstrating individualised misuse traceable to a specific breach is difficult and often impossible, which is why the legal question carries so much weight. Whether increased risk, mitigation costs or loss of privacy suffice in your forum belongs with counsel.

How is the "it would have happened anyway" defense handled?

By testing it against the actual attack path, which is the only way it can be assessed rather than asserted. If the intrusion began with credential stuffing against an account without multi-factor authentication, the argument that MFA would not have helped is weak. If it began with a novel exploit against a fully patched system, the argument that better patching would have prevented it is weak in the other direction. The analysis is specific: which control, against which step, at which point. Generic arguments about attacker sophistication carry little weight either way.

Do you calculate the damages?

No, and the separation is deliberate rather than a limitation. This Institute covers whether the failure caused the exposure — a technical question answered from forensic evidence. What the resulting loss is worth is a different discipline with its own methodologies and its own admissibility record, and it belongs to the Economic Damages Institute, which covers class-wide models, causation-versus-damages and the measures of loss properly. Where you need both, they are two engagements and frequently two experts.

Test the chain link by link.

Describe the failure and the harm alleged. The Institute will help you see where the chain is thin.

incident conciergeorientation · not a security opinion
Tell me what control is alleged to have failed and what harm is claimed. I'll help you walk the chain between them — they are usually further apart than either side argues. I won't quantify the loss; that is the Economic Damages Institute's work.