No Pre-Established Legal / Breach Coach Contact
- Category
- Third-Party & Insurance Readiness
- Published
- Aug 17, 2026
- Updated
- Aug 28, 2026
The Failure
No legal counsel specialized in cyber incidents — the role often called a “breach coach” — is identified before an incident occurs: no contact established, no engagement framework, not even a first conversation.
This is structural: the function belongs to no one. The organization’s usual legal counsel (contracts, employment, commercial) is not an incident specialist; the technical team doesn’t think “legal” until forced to; and engaging a specialist “for nothing” looks like an unjustified expense until something actually burns. The result: counsel gets chosen under pressure, with no room for comparison, at the exact moment the organization is least able to assess what’s being offered.
Why It Matters
Three mechanisms are at play, two of which are poorly understood by technical teams:
- deadlines are already running: obligations triggered by an incident — notification to competent authorities, informing affected individuals, contractual obligations toward clients — start from precise moments and are hard to qualify correctly in the heat of the moment. Notifying too late creates exposure; notifying too broadly causes needless damage; misqualifying creates both exposures at once. Specialized counsel resolves these questions in hours; an unprepared team deliberates for days;
- structuring the investigation: counsel engaged early can frame who retains whom and how findings circulate, in a way that protects the work and the communications — a structure that cannot be put in place retroactively;
- written records persist: communications produced during the incident, internal and external alike, have a long legal life. Drafting them without specialized input costs the organization long after remediation is complete.
How to Identify It
Three questions to ask the people who would actually manage the incident:
- if large-scale encryption were discovered tonight, which specialized counsel would you call — a name and a number, not just an intention? And does that counsel know you exist?
- do you know the notification obligations that apply to your situation — jurisdictions, clients’ industries, contractual commitments — without having to research them during the incident?
- if the organization is insured: is the insurer’s panel counsel identified, and do you know whether the policy allows choosing a different one?
Three vague answers confirm the pattern. A common variant: counsel exists “somewhere” — in the insurance policy, in a master agreement — but the operational respondents are unaware of it, which produces the same outcome on the night of the incident.
Fix Before the Incident
The core effort takes about half a day, split as follows:
- identify specialized counsel and hold a first conversation while things are calm — one hour is enough: scope, emergency contact details, engagement terms. A pre-negotiated framework with no paid retainer is common practice;
- if the organization is insured: cross-check against the insurer’s panel (see MFL-005), so incompatibility isn’t discovered mid-crisis;
- map out, calmly, the applicable notification obligations — registers, deadlines, thresholds — and file the summary in the response plan;
- add the legal contact to the first-hours quick-reference sheet, on the same footing as technical contacts: calling counsel is not a later step, it’s a first step;
- include counsel in at least one exercise (see MFL-011): the first real contact should not happen under adrenaline.
If You’re Already in an Incident
Engaging counsel now remains far better than not doing so: notification deadlines may already be running, and every day without legal framing produces uncontrolled written records.
Fast paths, in order of effectiveness:
- the insurer’s panel, if the organization is insured — a call to the claims line;
- a recommendation from an incident response provider already engaged, who works with such counsel routinely;
- professional associations and networks in the legal field.
While engagement is being arranged: timestamp key findings (detection, characterization, decisions), route external communications through a single person, and hold off on hasty written conclusions — improvised legal characterizations, assignments of responsibility, promises to clients. Keep the two registers separate: facts get written down, timestamped and without interpretation — this is the material for the investigation and the protection of everyone involved. Characterizations — the legal nature of the incident, attribution of responsibility, commitments to clients — wait for counsel. An improvised characterization long outlives its correction.
Related Controls
- CIS Controls v8 — 17.2
- NIST CSF 2.0 — RS.CO-02
- ISO 27001:2022 — A.5.5
- ISO 27001:2022 — A.5.6
- ISO 27001:2022 — A.5.24