Not whether the security was weak, but whether this weakness let this attacker in.
Start a conversation with the Incident Concierge, already scoped to breach causation. Pick a starting point, or describe the incident directly.
Establishing that an organization's security fell short is a standard-of-care finding. Establishing that the shortfall caused this intrusion is a separate exercise, and it is where a surprising number of otherwise strong cases become soft. The analysis is counterfactual: had the missing control been present, would this attack path have been closed? Answering it requires the attack path to be known in enough detail to test — initial access vector, the specific vulnerability or credential used, the movement that followed — which brings the whole thing back to whether the forensic evidence was preserved. Where the path is well evidenced, causation is often straightforward in both directions. Where it is not, both sides are reduced to arguing from the general adequacy of the program, which is a much weaker form of the argument.
The question is always specific: which control, against which step.
Which vector was used. Without this, counterfactual analysis is speculation.
Named specifically, not "inadequate security". Generality defeats the analysis.
The core question, tested against the evidenced path rather than in the abstract.
A control that would not have prevented entry may still have contained the damage.
Whether the attacker would simply have used another route. The strongest defense argument.
Whether better monitoring would have shortened dwell time, which affects scope rather than occurrence.
How causation is tested.
Whether a standard-of-care finding actually converts into liability.
It is a real argument when the attacker demonstrably had other routes available, and a weak one when the evidenced path ran straight through the missing control. The distinction is in the forensic record, which is another reason preservation decides so much.
Then causation becomes considerably harder for the plaintiff and the case shifts onto weaker ground for everyone. Without a known attack path there is no counterfactual to test, and the argument degenerates into competing generalisations about whether the program was adequate overall. Some plaintiffs argue that the failure to determine the entry point is itself evidence of inadequate monitoring and response — which is a real argument on adequacy, though a different one from causation. It is another reason the preservation question decides more than it appears to.
No, and treating prevention as the only relevant question loses a lot of ground unnecessarily. Segmentation may not stop an intruder entering but may confine them to one subnet holding nothing sensitive. Monitoring may not prevent entry but may cut dwell time from months to hours, which changes what was reached. Tested backups do not prevent ransomware but change whether the organization pays. Each supports a causation argument about the extent of harm rather than its occurrence, and extent is frequently where the money is.
It usually is several, and the sequence matters more than the count. Real incidents chain — a phishing email, then a credential without MFA, then flat network architecture, then absent monitoring — and each link is a separate control and sometimes a separate responsible party, including vendors. The productive analysis maps the chain and asks which links were load-bearing: which failures were necessary to the outcome, and which merely made it easier. That mapping also drives apportionment between defendants.
At the point where data left the environment. Everything after that — whether the data was used, by whom, to what effect, and what the resulting loss is worth — moves out of forensics and into other disciplines. What was done with the data is often unknowable; what the loss is worth is a damages question with its own methodologies and its own admissibility record, and it belongs with the Economic Damages Institute. Being explicit about that handoff is more useful than an expert stretching past their evidence.
Describe the attack path and the control at issue. The Institute will help you frame the question.