Bottom line: Slack messages and emails from the first hours of a cyberattack are often not considered privileged in court, even if the legal department was reading along, and thus become incriminating evidence in later proceedings.
What security teams write in Slack, Teams, or via email in the first 24 hours after a breach often resurfaces months or years later as evidence in lawsuits and regulatory proceedings. The belief that adding legal to a thread automatically protects all its contents is a legal misconception with costly consequences.
In the chaotic first hours after a security incident is discovered, an extensive written record emerges: Slack messages, emails, technical summaries of the attacker’s approach, patch timelines, and internal incident reports. According to practitioners involved in cyber litigation, the outcome of legal disputes often hinges not just on the incident itself, but on what teams documented and wrote during it. Many organizations mistakenly assume that including the legal department (“Legal”) in an email or Slack channel automatically triggers attorney-client privilege or work-product protection. According to the article, however, courts examine whether the predominant purpose of a communication was actually to seek or provide legal advice — not merely whether Legal was copied. Technical timelines, forensic summaries, or incident reports created primarily for operational reasons are frequently deemed discoverable, even if General Counsel reviewed them afterward. The Sedona Conference, whose working groups publish widely cited legal guidance on cybersecurity and electronic information, notes, according to the article, that courts are increasingly scrutinizing exactly this question: was the communication for the purpose of legal advice, or was it ordinary business documentation that happened to pass through the legal department.
What matters for CISOs is where privilege claims tend to fail in practice: not primarily due to technical forensics or a flawed security program, but where internal filters break down under pressure. In a 40-person Slack channel where legal is also reading along, a searchable record is created that can be used against the company in a dispute. Statements such as “We should have fixed this six months ago,” “Nobody here takes this seriously,” or “We knew this was a risk” are, according to the article, among the phrasings that surface as evidence in litigation through discovery proceedings. Simply adding a lawyer to an incident-specific channel or labeling the channel title “ACP” (Attorney-Client Privilege) does not automatically provide protection, according to well-established case law. The more people involved in a conversation, the weaker the privilege claim becomes — and when operational and legal strategy discussions are mixed within a single channel, the risk increases that careless wording ends up in the record. Courts do not necessarily limit disclosure obligations to the current incident; opposing counsel can also draw on earlier communications.
For practice, this means: incident response processes should be structured so that legally protected communication (targeted requests to Legal for legal advice) is clearly separated from operational documentation (technical timelines, forensic notes, status updates) — ideally in separate channels with a limited group of participants. Wording in chat messages and emails during an ongoing incident should be chosen as if it would later be read aloud in court, since that is exactly what can happen. CISOs should work with the legal department in advance to determine which communication channels are actually privileged in an emergency, rather than relying afterward on a blanket privilege claim.
Source: www.csoonline.com · Published August 18, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.