home  /  standard of care
department of standard of care

The fight is rarely about what happened. It is about what should have been in place first.

Standard-of-care experts are routinely the most influential witnesses in breach litigation, on both sides — because everything else follows from whether the security was reasonable.

begin here

What happened, and when did you learn of it?

Start a conversation with the Incident Concierge, already scoped to standard of care. Select a subject area to prompt it, or describe the incident directly.

Incident Conciergestandard of care · orientation, not a security opinion
Tell me roughly what the organization is, what happened, and when it was discovered. I'll help you see what a standard-of-care analysis would examine. I won't opine on whether the security was reasonable — that is the expert's job, not mine.

Every breach looks negligent in hindsight, and that is precisely why the standard-of-care question is so contested. The analysis is not whether an organization was breached — competent organizations are breached — but whether the safeguards in place before the incident were reasonable for the risk that organization actually carried. In practice an expert works through access management, patching, network segmentation, privilege, monitoring, backups and incident response planning, and asks whether each was proportionate to what the organization held and what it faced. Plaintiffs use that analysis to establish negligence; defendants use it to show reasonable practice. The reason it decides so many matters is that causation and damages both sit downstream of it: if the security was reasonable, the rest of the case rarely survives.

specialization areas

Areas in this part of the practice.

What the standard is measured against, and how the measurement is actually done.

methodology

How this department investigates.

How the Institute approaches the standard — what the analysis asks, never what it concludes about your organization.

Risk-proportionate assessmentWhether safeguards matched the organization’s actual risk profile, not an abstract ideal.
Control-by-control reviewAccess, patching, segmentation, privilege, monitoring, backup, response planning.
Frameworks as evidenceHow NIST, ISO and CIS are used to establish practice — and what they do not settle.
The pre-incident recordWhat the organization knew and decided BEFORE the breach, which is what the standard is measured against.
Hindsight disciplineSeparating what was reasonable then from what is obvious now. The central analytical risk.
Sector expectationsWhat comparable organizations in the same sector actually did, which is the real benchmark.
common questions

The standard of care — the questions counsel ask.

What does "reasonable security" actually mean?

Security measures aligned to the organization's actual risks, achievable with available technology, and not imposing disproportionate burden. That formulation is doing real work in each clause. "Aligned to risks" means a regional retailer and a hospital system are not held to one list. "Achievable with available technology" bounds the claim to what existed at the time. "Not disproportionate" is what stops the standard becoming perfection. What it is not is a checklist — and the most common error on both sides is treating some published control set as though satisfying it ends the question or failing it decides it.

Does following NIST or ISO settle it?

No, and it is more useful than that sounds. A recognized framework is powerful evidence of what the profession considers accepted practice, and an organization that mapped its program to one and can show the mapping is in a materially better position than one that cannot. But frameworks are risk-management structures rather than compliance floors — most contain controls an organization may reasonably conclude do not apply to it. The defensible position is not "we followed NIST" but "we assessed our risk against NIST, made these decisions for these documented reasons, and here is the record."

How is hindsight handled?

Deliberately, and it is the hardest discipline in the analysis. After an incident the attack path is obvious, the missing control is obvious, and the decision not to buy that control looks indefensible. The standard is what a reasonable organization would have done with what was knowable beforehand — so the analysis has to be anchored in the pre-incident record: the risk assessments, the budget decisions, the vulnerability reports, the things flagged and the things deferred. That record is also what a plaintiff will use most effectively if it shows a known risk was raised and dismissed.

Who actually needs this analysis?

More parties than usually commission it. Plaintiffs' counsel need it to establish the duty was breached. Defense counsel need it early enough to know whether the security position is strong, because that shapes settlement posture far more than the breach facts do. Insurers need it for coverage decisions and subrogation. And boards increasingly need it independent of litigation, because the same analysis answers "were we reasonable" before anyone is asking it under oath.

Test the security position early.

Describe the incident and the environment. The Institute will help you see what the analysis needs.

incident conciergeorientation · not a security opinion
Tell me roughly what the organization is, what happened, and when it was discovered. I'll help you see what a standard-of-care analysis would examine. I won't opine on whether the security was reasonable — that is the expert's job, not mine.