A law firm is the one client in the room that already knows how discovery works. It runs preservation, collection and production for other people for a living. So the natural assumption is that a firm, of all businesses, is ready for the digital version of its own trade. That assumption is where the trouble starts.
Readiness is not tested on a quiet afternoon. It is tested inside a bad week, on a live court deadline, during a breach. The real question is whether a New South Wales practice could do four things at once: place a defensible legal hold within hours, collect from cloud and mobile sources without destroying evidence, notify a regulator inside a statutory window, and defend the privilege of its own forensic report. Few firms below the top tier can currently show all four.
And the fourth is the one almost nobody plans for. When a firm is breached and commissions an investigation to understand the damage, it assumes the resulting report is protected. The Australian courts have just shown, in the most-watched data case in the country, that this assumption is wrong. The document a firm writes to understand its own failure can become the plaintiff's sharpest exhibit against it.
So the spine of the matter is this. Preparedness for eDiscovery and digital investigations is not a tool a firm buys. It is a set of disciplines it rehearses before the clock starts, and the firm that owns every platform can still hold none of them.
Five ways it bites, ranked
The detail is below, but here is the bottom line first, worst first.
1. Losing privilege over your own breach report. The most distinctive risk, and the least reversible. When a firm commissions a post-incident forensic review, it assumes legal professional privilege will shield it. In the Medibank consumer class action the company was refused leave to appeal and ordered to hand three Deloitte reports to the applicants, because those reports served mixed legal, operational, regulatory and public-relations purposes. Structure the engagement wrongly on day one and the investigation into your own failure becomes discoverable against you.
2. Ransomware and client-file theft, mid-matter. The signature event for a law firm is the encryption and leak of client files. Professional services now sit among the most-targeted sectors globally, the average legal-sector data breach costs around US$5.08 million, and a compromised trust account turns a single spoofed settlement email into a six-figure loss. One South Australian conveyancing firm had a client defrauded of $338,000 through a fraudulent invoice after its email was compromised.
3. Failing to preserve, then facing an adverse inference. If a NSW firm's client is ordered to give discovery and key custodian mailboxes were never placed on hold while auto-deletion ran, the client faces adverse-inference arguments and cost sanctions, and the firm faces a negligence exposure. A defensible legal hold, issued the moment a dispute becomes likely, is the single most cost-effective control in the whole field, and preservation failures are rarely recoverable once deletion has run.
4. Losing client data through a vendor you never audited. Legal work is parcelled out to eDiscovery platforms, cloud hosts, transcription services and offshore review teams, and each is a route in. In February 2026 a court-transcription provider exposed sensitive Australian federal and state court files after subcontracting work offshore in breach of government contracts. A firm can secure its own perimeter perfectly and still surrender a client's entire document universe through the supplier running its review.
5. Filing an AI-hallucinated authority in a NSW court. The fastest-moving risk. Since Practice Note SC Gen 23 took effect in February 2025, AI-assisted chronologies, indexes and summaries are permitted only where confidentiality is preserved and every citation is independently verified. Firms that skip the check are already being sanctioned: in December 2025 a federal family-law court referred a solicitor and two counsel to their regulators and ordered $10,000 in costs thrown away over AI-generated authorities.
The trade you run for others, and the one you cannot survive
A law firm carries a double exposure that almost no other business does. It holds vast quantities of privileged, discoverable client material that attackers want and courts can compel, and at the same time it must run discovery and forensic investigations for clients to a standard the courts now police closely. The same electronic material a firm is ethically bound to protect is the material it will one day have to preserve, produce and stand behind in court.
Attackers follow value density, and few sectors hold more per gigabyte than legal services. A single practice may hold merger terms, litigation strategy, trust-account details, identity documents and privileged advice for hundreds of clients. That concentration is now measurable rather than anecdotal: professional services ranked among the top three most-targeted industries globally through 2025 and held a top-five position into 2026, and the economics of attacking them have sharpened fast, with the average ransom demanded of a legal-sector organisation climbing about 60 per cent in a single year.
Note. The average ransom demanded of a legal-sector organisation rose about 60 per cent in a year, while attack volume against the sector rose 54 per cent. Law firms are now worth the effort.
Buy the full report
Forensic Tech Risk
Am I Prepared for eDiscovery and Digital Investigations?
53 pages
- Country
- Australia
- State or Territory
- New South Wales
- Industry
- Legal Services
The record year, and why the timing is the point
The clearest recent signal is volume. Data-breach notifications to the national regulator reached 1,205 in 2025, the highest annual total since the scheme began in 2018 and an 8 per cent rise on the year before. The majority, 716 of them, were malicious or criminal, with cyber hacking the leading cause. For a solicitor, this is the difference between a rare event to insure against and a live operational hazard.
Two things make the timing decisive rather than merely unwelcome. Public concern is now near-universal, with one 2026 survey finding 82 per cent of Australians worried about data breaches, up from 74 per cent in 2023, which raises the stakes sharply for a profession built on confidentiality. And the trend line points the wrong way at exactly the moment enforcement, a new privacy tort and court scrutiny of AI are all tightening together. A statutory tort for serious invasions of privacy commenced on 10 June 2025, giving individuals a direct cause of action with damages for distress and even exemplary damages. Firms treating readiness as a discretionary project are misreading the moment.
Note. The highest annual total since the scheme began in 2018, up 8 per cent on the year before. The majority, 716 of them, were malicious or criminal, with cyber hacking the leading cause.
Your own report, the other side's exhibit
Return to the trap at the centre of all this, because it is where the confident firm gets caught. The instinct after a breach is to commission a forensic investigation quickly, route it through a lawyer, and assume privilege has attached. The Full Federal Court has now shown that instinct to be dangerous. It refused Medibank leave to appeal a finding that three Deloitte reports were not privileged, and ordered them produced in the consumer class action, because obtaining legal advice was not their dominant purpose.
What makes the ruling instructive rather than merely alarming is what survived. Medibank kept privilege over narrower reports from firms such as CyberCX, Coveware, CrowdStrike and Threat Intelligence, precisely because those were confined to a legal purpose. Same company, same breach, opposite outcomes, and the deciding factor was not who signed the engagement letter but what each report was scoped to do.
The lesson for a NSW firm advising a breached client, or cleaning up after its own incident, is concrete. Retain the specialist through counsel, fix the dominant purpose as legal advice or anticipated litigation in writing at the outset, and keep operational remediation, regulator liaison and public relations on separate workstreams. Reusing one tidy report for board comfort and press lines is exactly what sank the Deloitte documents. Privilege is not something a firm assumes. It is something it engineers, on day one, before a single fact is gathered.
| Post-incident report | Commissioned for | Outcome in court |
|---|---|---|
| Three Deloitte reports | Mixed legal, operational, regulatory and public-relations purposes | Ordered into production in the consumer class action |
| CyberCX, Coveware, CrowdStrike, Threat Intelligence reports | Confined to a dominant legal purpose | Privilege upheld |
Note. Same company, same breach, opposite results. What decided it was not who commissioned each report but the purpose it was scoped for on day one.
The clock starts before anyone briefs the partners
The second thing firms routinely misjudge is time. Under the national notifiable-data-breach scheme, the obligation to assess and notify begins when any employee becomes aware of a suspected eligible breach, not when it reaches partners or general counsel. A firm that treats the clock as starting once management is briefed can be non-compliant before it has even convened, and the regulator penalises delay.
Other clocks run just as fast. A business with turnover of $3 million or more that pays a ransom must report to the signals agency within 72 hours, a duty now actively enforced. Preservation obligations attach the moment litigation becomes reasonably anticipated, well before proceedings are filed. And a grace period on new automated-decision-making transparency rules, relevant to any firm using automated tooling in document review, ends on 10 December 2026. The practical failure is not ignorance of these duties but the absence of anyone who owns them before the event, so the firm meets each deadline by improvisation rather than rehearsal.
| Trigger | What it starts | The deadline |
|---|---|---|
| An employee suspects an eligible data breach | Assessment and notification duty | Assess within 30 days; notify the OAIC once a belief is formed |
| A ransom is paid (firm turnover $3m or more) | Mandatory report to the signals agency | Within 72 hours |
| Litigation becomes reasonably anticipated | Preservation duty and legal hold | At once, before any proceedings are filed |
| A court orders discovery | Technology and format obligations, SC Gen 07 | The discovery plan must meet the court's protocol |
| Automated tools triage or decide client matters | Transparency duty, 2024 privacy reforms | Grace period ends 10 December 2026 |
Note. None of these clocks waits for a partner to be briefed. Several start the moment a junior employee forms a suspicion, or the moment a dispute becomes likely.
The vendor you never audited
The most under-managed exposure is not the firm's own network but the chain of providers who touch litigation data: managed-review platforms, transcription services, forensic collectors and offshore document-review teams. Attackers have worked this out, and a single upstream compromise can hand them several firms at once. The clearest recent illustration is domestic: a court-transcription provider confirmed in February 2026 that sensitive Australian federal and state court files were exposed after work was subcontracted offshore in breach of government contracts.
For eDiscovery this is the crux. A firm can run RelativityOne or Nuix Discover impeccably in-house and still surrender a client's entire document universe through a downstream reviewer or hosting vendor it never audited. The 2023 HWL Ebsworth incident, which radiated to an estimated 65 or more Commonwealth and state agencies through one firm, remains the reference point for how far a single legal-sector compromise can travel. Contractual bans on unapproved subcontracting, data-residency clauses and audit rights are the mechanisms that keep discoverable material inside a firm's control.
When a breach becomes the plaintiff's ammunition
A breach in a law firm rarely produces a single, contained loss. Client trust rests on confidentiality, so a leak strikes the core promise, and the damage is measurable rather than reputational hand-waving: breached datasets feed real fraud downstream. Corporate clients increasingly audit their panel firms' security, and a single leak-site listing can cost a firm its place on those panels.
There is a quieter trap in the insurance layer too. Much cyber cover is triggered by encryption or system failure, but pure data-theft extortion may lock nothing at all, which raises a live question of whether a firm's policy responds when an attacker simply steals and threatens to publish. The firm that has not read its own cover against that scenario is underpricing the exposure that hits it hardest.
Note. A breach is not only an IT event. Breached legal-sector data feeds real fraud, and the reputational damage that follows can cost a firm its place on a client's panel.
Not every matter needs a forensic firm
Readiness is not the same as outsourcing everything. A single-custodian discovery of a few thousand documents, an encrypted lost laptop, or a phishing email caught before compromise can be handled with existing review tools and a competent supervising solicitor. The trigger for outside help is a step-change in volume, stakes or uncertainty: multi-custodian or cloud and mobile collections, a live preservation or spoliation risk, a suspected reportable breach, active ransomware, or any matter where the firm's own conduct is in question.
Above that threshold, the common and costly error is engaging the wrong specialist, or only one. The recurring pattern that works for a mid-sized NSW practice is a privacy-counsel lead who directs a digital-forensics or incident-response firm, with an eDiscovery provider brought in where the same event turns into litigation. Engaging forensic experts through counsel is also what preserves the privilege the Medibank rulings put at risk.
| Expert | Engage when | What they add |
|---|---|---|
| eDiscovery / managed review | Large or complex discovery; TAR or tight exchange deadlines | Defensible collection and production on court-accepted platforms |
| Digital-forensics firm | Suspected intrusion, insider misuse, device imaging | Forensically sound acquisition that survives challenge |
| Incident-response provider | Active ransomware or live compromise | Containment and evidence preservation under pressure |
| Privacy / cyber counsel | Any suspected notifiable breach; privilege strategy | Notification calls and an engagement structured to hold privilege |
| External litigation counsel | The firm's own conduct or privilege in issue | Independent judgement where a firm cannot mark its own homework |
Note. Below a threshold, disciplined internal process is enough. Above it, engaging the wrong specialist, or only one, is a common and costly error.
The exposure changes with the courtroom
A NSW firm's exposure is defined less by where it is sued than by whose data it holds and which courts it appears in. New South Wales runs a comparatively restrained discovery model, with staged disclosure and, in the Equity Division, no disclosure until after evidence is served. Step up to the Federal Court and the regime tightens: nothing the parties agree between themselves binds the court, and a discovery plan must be approved. Step across to United States litigation and the obligation expands again, into broad party-to-party discovery, formal litigation holds and spoliation sanctions.
The practical implication is that a boutique Sydney practice running a single cross-border matter can inherit preservation duties far broader than its domestic caseload ever generates, imported through one foreign proceeding or a US-domiciled client. A firm that has calibrated its readiness only to the NSW baseline can be badly wrong-footed the first time an American court's expectations arrive on its desk.
| Jurisdiction | Disclosure breadth | Preservation duty | Pressure on a NSW firm |
|---|---|---|---|
| NSW (UCPR / SC Eq 11) | Narrow, staged | Implied, matter-specific | Moderate |
| Federal Court (GPN-TECH) | Court-supervised | Explicit, via an approved plan | High |
| United States (FRCP) | Very broad | Formal holds; spoliation sanctions | Very high on cross-border work |
Note. A boutique Sydney practice can inherit preservation duties far broader than its domestic caseload, imported through a single cross-border matter or a US-domiciled client.
Preparedness is four things at once
Readiness resolves into a short list of capabilities that have to exist before a dispute, breach or regulator's notice arrives, because every one of them degrades sharply once the clock is running. A prepared firm can preserve fast and defensibly, through a written legal-hold protocol that suspends routine deletion. It can find and produce electronic documents to the court's technology standard without a scramble to convert formats. It can image a compromised system before that system is wiped or rebuilt. It can verify every AI-assisted citation against the primary source before it reaches a filing. And it knows which statutory clock runs to which deadline.
None of these is a tooling purchase, and the cheapest fixes come first. Multi-factor authentication and a payment-verification step blunt the business-email-compromise losses that hit smaller firms hardest. A one-page hold protocol with a named owner converts an ad hoc reaction into a defensible process. A standing rule that no AI-assisted authority is filed unchecked addresses the exact conduct now drawing costs orders. The failures cluster around people, process and money rather than software: an unwritten hold that lives in the IT director's head, a partner whose matter data is all on a personal laptop, a junior left to adopt AI tools with no supervision, a vendor contract silent on where privileged material physically resides.
What it comes down to
The honest reading of the evidence is that most NSW practices are only partially prepared, and the gap is widening faster than firms are closing it. The risk sits at High for a typical mid-sized commercial or litigation practice, and tips higher for any firm holding government or health data, running unsupervised generative AI, or lacking a tested incident-response and legal-hold process. High attack probability, severe and enforceable consequences, and thin firm-level capability is the definition of the exposure.
The reassuring story a firm tells itself is that it does discovery for a living, so it must be ready. That is precisely the story the evidence disproves. The question a court, the regulator or an insurer actually asks is never whether a firm intended to do the right thing. It is whether the firm can demonstrate, with contemporaneous records, that it preserved, investigated and produced defensibly, and kept its own investigation on the right side of privilege.
So the line draws itself. Firms that treat readiness as four rehearsed disciplines, wrapped around disciplined data governance and a vetted vendor chain, will handle a bad week as an incident. Firms that hold only the software will handle it as a casualty investigation, and may find the most damaging exhibit in the room is the one they wrote themselves.
Figures drawn from TheRiskAgent's risk briefing on eDiscovery and digital-investigation readiness for legal services in New South Wales (August 2026), which sources each one to a named publisher. Produced with AI research tools and reviewed before release; reference material, not advice.

