Back to TRA Insights

Forensic Tech Risk

The exhibit you write yourself

A New South Wales law firm runs discovery for its clients every day. Whether it could survive discovery run against itself is a different question. Readiness is not the software a firm buys but four disciplines it rehearses, and the sharpest trap is that the forensic report a firm commissions after its own breach can become the other side's best evidence.

·13 min read

A law firm is the one client in the room that already knows how discovery works. It runs preservation, collection and production for other people for a living. So the natural assumption is that a firm, of all businesses, is ready for the digital version of its own trade. That assumption is where the trouble starts.

Readiness is not tested on a quiet afternoon. It is tested inside a bad week, on a live court deadline, during a breach. The real question is whether a New South Wales practice could do four things at once: place a defensible legal hold within hours, collect from cloud and mobile sources without destroying evidence, notify a regulator inside a statutory window, and defend the privilege of its own forensic report. Few firms below the top tier can currently show all four.

And the fourth is the one almost nobody plans for. When a firm is breached and commissions an investigation to understand the damage, it assumes the resulting report is protected. The Australian courts have just shown, in the most-watched data case in the country, that this assumption is wrong. The document a firm writes to understand its own failure can become the plaintiff's sharpest exhibit against it.

So the spine of the matter is this. Preparedness for eDiscovery and digital investigations is not a tool a firm buys. It is a set of disciplines it rehearses before the clock starts, and the firm that owns every platform can still hold none of them.

Five ways it bites, ranked

The detail is below, but here is the bottom line first, worst first.

1. Losing privilege over your own breach report. The most distinctive risk, and the least reversible. When a firm commissions a post-incident forensic review, it assumes legal professional privilege will shield it. In the Medibank consumer class action the company was refused leave to appeal and ordered to hand three Deloitte reports to the applicants, because those reports served mixed legal, operational, regulatory and public-relations purposes. Structure the engagement wrongly on day one and the investigation into your own failure becomes discoverable against you.

2. Ransomware and client-file theft, mid-matter. The signature event for a law firm is the encryption and leak of client files. Professional services now sit among the most-targeted sectors globally, the average legal-sector data breach costs around US$5.08 million, and a compromised trust account turns a single spoofed settlement email into a six-figure loss. One South Australian conveyancing firm had a client defrauded of $338,000 through a fraudulent invoice after its email was compromised.

3. Failing to preserve, then facing an adverse inference. If a NSW firm's client is ordered to give discovery and key custodian mailboxes were never placed on hold while auto-deletion ran, the client faces adverse-inference arguments and cost sanctions, and the firm faces a negligence exposure. A defensible legal hold, issued the moment a dispute becomes likely, is the single most cost-effective control in the whole field, and preservation failures are rarely recoverable once deletion has run.

4. Losing client data through a vendor you never audited. Legal work is parcelled out to eDiscovery platforms, cloud hosts, transcription services and offshore review teams, and each is a route in. In February 2026 a court-transcription provider exposed sensitive Australian federal and state court files after subcontracting work offshore in breach of government contracts. A firm can secure its own perimeter perfectly and still surrender a client's entire document universe through the supplier running its review.

5. Filing an AI-hallucinated authority in a NSW court. The fastest-moving risk. Since Practice Note SC Gen 23 took effect in February 2025, AI-assisted chronologies, indexes and summaries are permitted only where confidentiality is preserved and every citation is independently verified. Firms that skip the check are already being sanctioned: in December 2025 a federal family-law court referred a solicitor and two counsel to their regulators and ordered $10,000 in costs thrown away over AI-generated authorities.

The trade you run for others, and the one you cannot survive

A law firm carries a double exposure that almost no other business does. It holds vast quantities of privileged, discoverable client material that attackers want and courts can compel, and at the same time it must run discovery and forensic investigations for clients to a standard the courts now police closely. The same electronic material a firm is ethically bound to protect is the material it will one day have to preserve, produce and stand behind in court.

Attackers follow value density, and few sectors hold more per gigabyte than legal services. A single practice may hold merger terms, litigation strategy, trust-account details, identity documents and privileged advice for hundreds of clients. That concentration is now measurable rather than anecdotal: professional services ranked among the top three most-targeted industries globally through 2025 and held a top-five position into 2026, and the economics of attacking them have sharpened fast, with the average ransom demanded of a legal-sector organisation climbing about 60 per cent in a single year.

Legal-sector ransom demand (US$'000) 2025 611 2024 383
Source: QBE Cyber Threats report, via Insurance Business, May 2026.

Note. The average ransom demanded of a legal-sector organisation rose about 60 per cent in a year, while attack volume against the sector rose 54 per cent. Law firms are now worth the effort.

Buy the full report

Forensic Tech Risk

Am I Prepared for eDiscovery and Digital Investigations?

53 pages

Country
Australia
State or Territory
New South Wales
Industry
Legal Services
Buy the full report - USD 19.99Or configure a fresh version (USD 49)

The record year, and why the timing is the point

The clearest recent signal is volume. Data-breach notifications to the national regulator reached 1,205 in 2025, the highest annual total since the scheme began in 2018 and an 8 per cent rise on the year before. The majority, 716 of them, were malicious or criminal, with cyber hacking the leading cause. For a solicitor, this is the difference between a rare event to insure against and a live operational hazard.

Two things make the timing decisive rather than merely unwelcome. Public concern is now near-universal, with one 2026 survey finding 82 per cent of Australians worried about data breaches, up from 74 per cent in 2023, which raises the stakes sharply for a profession built on confidentiality. And the trend line points the wrong way at exactly the moment enforcement, a new privacy tort and court scrutiny of AI are all tightening together. A statutory tort for serious invasions of privacy commenced on 10 June 2025, giving individuals a direct cause of action with damages for distress and even exemplary damages. Firms treating readiness as a discretionary project are misreading the moment.

Data-breach notifications (all sectors) 2025 1205 2024 1112
Source: Office of the Australian Information Commissioner, July 2026.

Note. The highest annual total since the scheme began in 2018, up 8 per cent on the year before. The majority, 716 of them, were malicious or criminal, with cyber hacking the leading cause.

Your own report, the other side's exhibit

Return to the trap at the centre of all this, because it is where the confident firm gets caught. The instinct after a breach is to commission a forensic investigation quickly, route it through a lawyer, and assume privilege has attached. The Full Federal Court has now shown that instinct to be dangerous. It refused Medibank leave to appeal a finding that three Deloitte reports were not privileged, and ordered them produced in the consumer class action, because obtaining legal advice was not their dominant purpose.

What makes the ruling instructive rather than merely alarming is what survived. Medibank kept privilege over narrower reports from firms such as CyberCX, Coveware, CrowdStrike and Threat Intelligence, precisely because those were confined to a legal purpose. Same company, same breach, opposite outcomes, and the deciding factor was not who signed the engagement letter but what each report was scoped to do.

The lesson for a NSW firm advising a breached client, or cleaning up after its own incident, is concrete. Retain the specialist through counsel, fix the dominant purpose as legal advice or anticipated litigation in writing at the outset, and keep operational remediation, regulator liaison and public relations on separate workstreams. Reusing one tidy report for board comfort and press lines is exactly what sank the Deloitte documents. Privilege is not something a firm assumes. It is something it engineers, on day one, before a single fact is gathered.

One breach, opposite privilege outcomes: the Medibank litigation
Post-incident reportCommissioned forOutcome in court
Three Deloitte reportsMixed legal, operational, regulatory and public-relations purposesOrdered into production in the consumer class action
CyberCX, Coveware, CrowdStrike, Threat Intelligence reportsConfined to a dominant legal purposePrivilege upheld
Source: Allens; Clifford Chance, on Medibank v McClure [2026] FCAFC 38.

Note. Same company, same breach, opposite results. What decided it was not who commissioned each report but the purpose it was scoped for on day one.

The clock starts before anyone briefs the partners

The second thing firms routinely misjudge is time. Under the national notifiable-data-breach scheme, the obligation to assess and notify begins when any employee becomes aware of a suspected eligible breach, not when it reaches partners or general counsel. A firm that treats the clock as starting once management is briefed can be non-compliant before it has even convened, and the regulator penalises delay.

Other clocks run just as fast. A business with turnover of $3 million or more that pays a ransom must report to the signals agency within 72 hours, a duty now actively enforced. Preservation obligations attach the moment litigation becomes reasonably anticipated, well before proceedings are filed. And a grace period on new automated-decision-making transparency rules, relevant to any firm using automated tooling in document review, ends on 10 December 2026. The practical failure is not ignorance of these duties but the absence of anyone who owns them before the event, so the firm meets each deadline by improvisation rather than rehearsal.

The statutory clocks a NSW firm is already running
TriggerWhat it startsThe deadline
An employee suspects an eligible data breachAssessment and notification dutyAssess within 30 days; notify the OAIC once a belief is formed
A ransom is paid (firm turnover $3m or more)Mandatory report to the signals agencyWithin 72 hours
Litigation becomes reasonably anticipatedPreservation duty and legal holdAt once, before any proceedings are filed
A court orders discoveryTechnology and format obligations, SC Gen 07The discovery plan must meet the court's protocol
Automated tools triage or decide client mattersTransparency duty, 2024 privacy reformsGrace period ends 10 December 2026
Source: OAIC; Cyber Security Act 2024; NSW Supreme Court Practice Note SC Gen 07.

Note. None of these clocks waits for a partner to be briefed. Several start the moment a junior employee forms a suspicion, or the moment a dispute becomes likely.

The vendor you never audited

The most under-managed exposure is not the firm's own network but the chain of providers who touch litigation data: managed-review platforms, transcription services, forensic collectors and offshore document-review teams. Attackers have worked this out, and a single upstream compromise can hand them several firms at once. The clearest recent illustration is domestic: a court-transcription provider confirmed in February 2026 that sensitive Australian federal and state court files were exposed after work was subcontracted offshore in breach of government contracts.

For eDiscovery this is the crux. A firm can run RelativityOne or Nuix Discover impeccably in-house and still surrender a client's entire document universe through a downstream reviewer or hosting vendor it never audited. The 2023 HWL Ebsworth incident, which radiated to an estimated 65 or more Commonwealth and state agencies through one firm, remains the reference point for how far a single legal-sector compromise can travel. Contractual bans on unapproved subcontracting, data-residency clauses and audit rights are the mechanisms that keep discoverable material inside a firm's control.

When a breach becomes the plaintiff's ammunition

A breach in a law firm rarely produces a single, contained loss. Client trust rests on confidentiality, so a leak strikes the core promise, and the damage is measurable rather than reputational hand-waving: breached datasets feed real fraud downstream. Corporate clients increasingly audit their panel firms' security, and a single leak-site listing can cost a firm its place on those panels.

There is a quieter trap in the insurance layer too. Much cyber cover is triggered by encryption or system failure, but pure data-theft extortion may lock nothing at all, which raises a live question of whether a firm's policy responds when an attacker simply steals and threatens to publish. The firm that has not read its own cover against that scenario is underpricing the exposure that hits it hardest.

Fraud events from two breached datasets (thousands) Optus data 300 Medibank data 11
Source: ACS Information Age.

Note. A breach is not only an IT event. Breached legal-sector data feeds real fraud, and the reputational damage that follows can cost a firm its place on a client's panel.

Not every matter needs a forensic firm

Readiness is not the same as outsourcing everything. A single-custodian discovery of a few thousand documents, an encrypted lost laptop, or a phishing email caught before compromise can be handled with existing review tools and a competent supervising solicitor. The trigger for outside help is a step-change in volume, stakes or uncertainty: multi-custodian or cloud and mobile collections, a live preservation or spoliation risk, a suspected reportable breach, active ransomware, or any matter where the firm's own conduct is in question.

Above that threshold, the common and costly error is engaging the wrong specialist, or only one. The recurring pattern that works for a mid-sized NSW practice is a privacy-counsel lead who directs a digital-forensics or incident-response firm, with an eDiscovery provider brought in where the same event turns into litigation. Engaging forensic experts through counsel is also what preserves the privilege the Medibank rulings put at risk.

Which specialist, and when to call them
ExpertEngage whenWhat they add
eDiscovery / managed reviewLarge or complex discovery; TAR or tight exchange deadlinesDefensible collection and production on court-accepted platforms
Digital-forensics firmSuspected intrusion, insider misuse, device imagingForensically sound acquisition that survives challenge
Incident-response providerActive ransomware or live compromiseContainment and evidence preservation under pressure
Privacy / cyber counselAny suspected notifiable breach; privilege strategyNotification calls and an engagement structured to hold privilege
External litigation counselThe firm's own conduct or privilege in issueIndependent judgement where a firm cannot mark its own homework
Source: TheRiskAgent, eDiscovery readiness briefing (NSW legal services).

Note. Below a threshold, disciplined internal process is enough. Above it, engaging the wrong specialist, or only one, is a common and costly error.

The exposure changes with the courtroom

A NSW firm's exposure is defined less by where it is sued than by whose data it holds and which courts it appears in. New South Wales runs a comparatively restrained discovery model, with staged disclosure and, in the Equity Division, no disclosure until after evidence is served. Step up to the Federal Court and the regime tightens: nothing the parties agree between themselves binds the court, and a discovery plan must be approved. Step across to United States litigation and the obligation expands again, into broad party-to-party discovery, formal litigation holds and spoliation sanctions.

The practical implication is that a boutique Sydney practice running a single cross-border matter can inherit preservation duties far broader than its domestic caseload ever generates, imported through one foreign proceeding or a US-domiciled client. A firm that has calibrated its readiness only to the NSW baseline can be badly wrong-footed the first time an American court's expectations arrive on its desk.

Preservation intensity climbs with the courtroom
JurisdictionDisclosure breadthPreservation dutyPressure on a NSW firm
NSW (UCPR / SC Eq 11)Narrow, stagedImplied, matter-specificModerate
Federal Court (GPN-TECH)Court-supervisedExplicit, via an approved planHigh
United States (FRCP)Very broadFormal holds; spoliation sanctionsVery high on cross-border work
Source: Judicial Commission of NSW; Federal Court GPN-TECH; US FRCP.

Note. A boutique Sydney practice can inherit preservation duties far broader than its domestic caseload, imported through a single cross-border matter or a US-domiciled client.

Preparedness is four things at once

Readiness resolves into a short list of capabilities that have to exist before a dispute, breach or regulator's notice arrives, because every one of them degrades sharply once the clock is running. A prepared firm can preserve fast and defensibly, through a written legal-hold protocol that suspends routine deletion. It can find and produce electronic documents to the court's technology standard without a scramble to convert formats. It can image a compromised system before that system is wiped or rebuilt. It can verify every AI-assisted citation against the primary source before it reaches a filing. And it knows which statutory clock runs to which deadline.

None of these is a tooling purchase, and the cheapest fixes come first. Multi-factor authentication and a payment-verification step blunt the business-email-compromise losses that hit smaller firms hardest. A one-page hold protocol with a named owner converts an ad hoc reaction into a defensible process. A standing rule that no AI-assisted authority is filed unchecked addresses the exact conduct now drawing costs orders. The failures cluster around people, process and money rather than software: an unwritten hold that lives in the IT director's head, a partner whose matter data is all on a personal laptop, a junior left to adopt AI tools with no supervision, a vendor contract silent on where privileged material physically resides.

What it comes down to

The honest reading of the evidence is that most NSW practices are only partially prepared, and the gap is widening faster than firms are closing it. The risk sits at High for a typical mid-sized commercial or litigation practice, and tips higher for any firm holding government or health data, running unsupervised generative AI, or lacking a tested incident-response and legal-hold process. High attack probability, severe and enforceable consequences, and thin firm-level capability is the definition of the exposure.

The reassuring story a firm tells itself is that it does discovery for a living, so it must be ready. That is precisely the story the evidence disproves. The question a court, the regulator or an insurer actually asks is never whether a firm intended to do the right thing. It is whether the firm can demonstrate, with contemporaneous records, that it preserved, investigated and produced defensibly, and kept its own investigation on the right side of privilege.

So the line draws itself. Firms that treat readiness as four rehearsed disciplines, wrapped around disciplined data governance and a vetted vendor chain, will handle a bad week as an incident. Firms that hold only the software will handle it as a casualty investigation, and may find the most damaging exhibit in the room is the one they wrote themselves.

Figures drawn from TheRiskAgent's risk briefing on eDiscovery and digital-investigation readiness for legal services in New South Wales (August 2026), which sources each one to a named publisher. Produced with AI research tools and reviewed before release; reference material, not advice.

Create your own Risk report

Pick a report type, configure it to your situation, and receive a fully sourced briefing. Research, not advice.

Pick the specific risk question you want a report on.

The following fields are optional. Providing them produces a more tailored report. Leave as "No preference" for a general report.

Your report download link will be sent to this email.

Secure payment via StripeDelivered within 4 hours

Your career is a risk position

byAxeRocket

Career and job-loss risk is researched by AxeRocket, TheRiskAgent's sister platform. The Client Report is a complete executive-grade strategic dossier, built from your own answers and delivered to your inbox.

  • Up to 65 adaptive questions an intelligent intake that branches around your answers.
  • 122 industries, 1,258 sub-sectors we pinpoint exactly where you sit, never a vague category.
  • 41 professions, 351 specific roles your actual job title, not a job family.
  • Every country and jurisdiction, 470 states and regions intelligence local to where you are, or where you are headed next.
  • 36 specialist AI agents each section written by a purpose-built model, not one generic prompt.

Your Report: 8 parts, up to 29 sections, 50 to 70 pages

  1. 1Understanding Your Situation
  2. 2Global Industry Intelligence
  3. 3Global Profession Intelligence
  4. 4AI and the Future of Work
  5. 5Career Risk Assessment
  6. 6Strategic Career Options
  7. 7Personal Action Plan
  8. 8Local Resources and Support

Every claim fully referenced, with the source URLs provided.

USD 49

One-time, sold by AxeRocket. Includes 12 months of Client Zone access.

Generate your Client ReportHow the Client Report works

This link opens AxeRocket. Research, not advice.

#eDiscovery#legal services#digital forensics#privilege#data breach#New South Wales#cybersecurity
More TRA Insights

Insights are short summaries that introduce a paid research asset. They are not a substitute for the underlying report. Always consult a qualified adviser before acting on contents.