The same control set can be reasonable for one organization and indefensible for another. Proportionality is what separates them.
Start a conversation with the Incident Concierge, already scoped to risk proportionality. Pick a starting point, or describe the incident directly.
Proportionality is the clause in the reasonable-security standard that actually decides cases, and it is the one least amenable to a checklist. It asks whether the safeguards an organization maintained were commensurate with what it held and what it faced — the sensitivity and volume of its data, the regulatory regime over it, the threat environment for its sector, its resources, and the harm a compromise would cause. The analysis is genuinely two-directional, which practitioners on both sides tend to forget: a small organization holding trivial data is not required to run an enterprise program, and an organization holding millions of sensitive records does not discharge its duty by pointing at a modest budget. Getting this right is what stops the standard collapsing into either perfection or excuse.
Each factor pushes the expected standard up or down, and they are assessed together.
Health, financial and biometric data raise the standard sharply. So does sheer scale.
Where a sector rule applies it usually sets a floor beneath the proportionality analysis.
Whether the sector was known to be actively targeted, and whether the organization knew.
Real and relevant, and not a defense for omitting basic controls that cost little.
What a compromise would do to the people whose data it is. Raises the expected standard.
Earlier incidents, audit findings or intelligence. Knowledge of a risk raises what is expected in response.
How proportionality is assessed.
Where the line sits between an unfortunate breach and a negligent one.
An organization that suffered a similar incident, received an audit finding, or was warned about a threat and did not respond proportionately is in a materially weaker position than one that never knew. Prior warnings are the first thing a competent plaintiff looks for.
Partially, and it is weaker than defendants expect. Resources are a legitimate factor and no one is required to spend without limit — a small organization is genuinely not held to a bank's program. But budget does not excuse controls that are basic and inexpensive, and multi-factor authentication, tested backups, and a patching process now fall on the wrong side of that line for almost anyone. Budget is also considerably less persuasive where the organization chose to hold large volumes of sensitive data: the proportionality argument runs on what you held, not only on what you could afford.
With evidence rather than assertion, which is harder than it sounds and often decides which expert is believed. Credible peer evidence comes from published sector surveys, regulatory guidance aimed at organizations of that size, framework tiering, and the expert's own documented experience across comparable environments. What does not travel well is an expert generalising from enterprise practice to a mid-market defendant, and a competent cross-examination will find that gap quickly.
Yes, in both sensitivity and volume, and this is one of the more settled parts of the analysis. An organization that chose to collect and retain millions of sensitive records has assumed a correspondingly higher obligation to protect them. It also raises a question defendants frequently have no good answer to: why was that data still being held at all? Retention beyond any business need is a recurring and avoidable aggravating fact, because the cheapest control is not holding the data.
Regularly, and it is under-used. Where a plaintiff's expert argues for controls that would be disproportionate for an organization of that size and risk profile — enterprise-grade monitoring for a small operation, say — proportionality is the direct answer, and it is more persuasive than disputing the control's value. The defense is strongest where the organization can show it actually performed a risk assessment, reached a reasoned conclusion, and documented it at the time.
Describe what the organization held and faced. The Institute will help you frame the proportionality question.