Forensic Tech Risk

The exhibit you write yourself

A New South Wales law firm runs discovery for its clients every day. Whether it could survive discovery run against itself is a different question. Readiness is not the software a firm buys but four disciplines it rehearses, and the sharpest trap is that the forensic report a firm commissions after its own breach can become the other side's best evidence.

TheRiskAgent5 August 202612 min read

eDiscovery and digital-investigation readiness for legal-services firms in New South Wales, Australia.

A law firm is the one client in the room that already knows how discovery works. It runs preservation, collection and production for other people for a living. So the natural assumption is that a firm, of all businesses, is ready for the digital version of its own trade. That assumption is where the trouble starts.

Readiness is not tested on a quiet afternoon. It is tested inside a bad week, on a live court deadline, during a breach. The real question is whether a New South Wales practice could do four things at once: place a defensible legal hold within hours, collect from cloud and mobile sources without destroying evidence, notify a regulator inside a statutory window, and defend the privilege of its own forensic report.

And the fourth is the one almost nobody plans for. When a firm is breached and commissions an investigation to understand the damage, it assumes the resulting report is protected. The Australian courts have shown, in the Medibank class action, that this assumption can be wrong. The document a firm writes to understand its own failure can become the plaintiff's sharpest exhibit against it.

So the spine of the matter is this. Preparedness for eDiscovery and digital investigations is not a tool a firm buys. It is a set of disciplines it rehearses before the clock starts, and the firm that owns every platform can still hold none of them.

Five ways it bites, ranked

The detail is below; the bottom line comes first, worst first.

1. Losing privilege over a firm's own breach report. The most distinctive risk, and the least reversible. When a firm commissions a post-incident forensic review, it assumes legal professional privilege will shield it. In the Medibank consumer class action three Deloitte reports were found not to be privileged, and the company was refused leave to appeal, because the court found the reports also served governance, regulatory and public-facing purposes, so legal advice was not the dominant one. Where the engagement is not structured for a legal purpose from the outset, the resulting report can be discoverable.

2. Ransomware and client-file theft, mid-matter. The signature event for a law firm is the encryption and leak of client files, and a compromised trust account turns a single spoofed settlement email into a direct financial loss.

3. Failing to preserve, then facing an adverse inference. If a NSW firm's client is ordered to give discovery and key custodian mailboxes were never placed on hold while auto-deletion ran, the client faces adverse-inference arguments and cost sanctions, and the firm faces a negligence exposure. A defensible legal hold, issued the moment a dispute becomes likely, is the single most cost-effective control in the whole field, and preservation failures are rarely recoverable once deletion has run.

4. Client data lost through an unaudited vendor. Legal work is parcelled out to eDiscovery platforms, cloud hosts, transcription services and offshore review teams, and each is a route in. In June 2026 the Federal Court and the Federal Circuit and Family Court issued notices about data privacy incidents at a court transcription provider. A firm can secure its own perimeter perfectly and still surrender a client's entire document universe through the supplier running its review.

5. Filing an AI-hallucinated authority in a NSW court. The fastest-moving risk. Since Practice Note SC Gen 23 took effect in February 2025, AI-assisted chronologies, indexes and summaries are permitted subject to conditions on confidentiality and the verification of citations. Courts have already made costs orders where AI-generated authorities were filed; one example is Mertz & Mertz (No 3) [2025] FedCFamC1A 222.

The trade a firm runs for others

A law firm carries a double exposure that almost no other business does. It holds vast quantities of privileged, discoverable client material that attackers want and courts can compel, and at the same time it must run discovery and forensic investigations for clients to a standard the courts now police closely. The same electronic material a firm is ethically bound to protect is the material it will one day have to preserve, produce and stand behind in court.

Attackers follow value density, and few sectors hold more per gigabyte than legal services. A single practice may hold merger terms, litigation strategy, trust-account details, identity documents and privileged advice for hundreds of clients.

Buy the full report

Forensic Tech Risk

Am I Prepared for eDiscovery and Digital Investigations?

Published: 5 August 2026
53 pages38 checked sources

Country
Australia
State or Territory
New South Wales
Industry
Legal Services

This published copyUSD 19.99

Buy this reportConfigure this report new at today’s date (USD 49)

The record year, and why the timing is the point

The clearest recent signal is volume. Data-breach notifications to the national regulator reached 1,205 in 2025, the highest annual total since the scheme began in 2018 and an 8 per cent rise on the year before. The majority, 716 of them, were malicious or criminal, with cyber hacking the leading cause. For a solicitor, this is the difference between a rare event to insure against and a live operational hazard.

Two things make the timing decisive rather than merely unwelcome. Public concern is now near-universal, with one 2026 survey finding 82 per cent of Australians worried about data breaches, up from 74 per cent in 2023, which raises the stakes for a profession built on confidentiality.

And the trend points the wrong way just as enforcement, a new privacy tort and court scrutiny of AI tighten together. A statutory tort for serious invasions of privacy commenced on 10 June 2025, giving individuals a direct cause of action with damages for distress and even exemplary damages.

Data-breach notifications (all sectors) 2025 1205 2024 1112
Figure 1. Data breach notifications to the OAIC, all sectors, calendar years 2024 and 2025. Source: OAIC, Notifiable Data Breaches statistics, 6 July 2026.

Note. The highest annual total since the scheme began in 2018, up 8 per cent on the year before. The majority, 716 of them, were malicious or criminal, with cyber hacking the leading cause.

A firm's own report as the other side's exhibit

Return to the trap at the centre of all this, because it is where the confident firm gets caught. The instinct after a breach is to commission a forensic investigation quickly, route it through a lawyer, and assume privilege has attached. In March 2026 the Full Federal Court dismissed Medibank's application for leave to appeal a finding that three Deloitte reports were not privileged, because obtaining legal advice was not their dominant purpose (Medibank Private Limited v McClure [2026] FCAFC 38).

What makes the ruling instructive is what survived. Medibank kept privilege over two CrowdStrike reports and two Threat Intelligence reports, which had been commissioned through lawyers to support legal advice. Same company, same breach, opposite outcomes.

In [2025] FCA 167 the reports that kept privilege were those commissioned through lawyers to support legal advice. The Deloitte reports, whose scope was shaped with APRA and announced publicly as a learning exercise, did not. The court weighed Medibank's public statement of 7 November 2022 that it would "learn from this event" against the claim to privilege.

One breach, opposite privilege outcomes: the Medibank litigation
Post-incident reportCommissioned forOutcome in court
Three Deloitte reportsLegal, governance, regulatory and public-facing purposesNot privileged; leave to appeal refused
Two CrowdStrike and two Threat Intelligence reportsCommissioned through lawyers to support legal advicePrivilege upheld
Table 1. Privilege outcomes for post-incident reports commissioned by Medibank after its 2022 data breach, as decided in the consumer class action in 2025 and 2026. Source: McClure v Medibank Private Limited [2025] FCA 167; Medibank Private Limited v McClure [2026] FCAFC 38.

Note. Same company, same breach, opposite results. The reports that kept privilege were those commissioned through lawyers to support legal advice.

The clock starts before anyone briefs the partners

The second thing firms routinely misjudge is time. Under the national notifiable-data-breach scheme, the obligation to assess and notify begins when any employee becomes aware of a suspected eligible breach, not when it reaches partners or general counsel. A firm that treats the clock as starting once management is briefed can be non-compliant before it has even convened.

Other clocks run just as fast. A business with turnover of $3 million or more that pays a ransom must report to the signals agency within 72 hours, under section 27 of the Cyber Security Act 2024. Preservation obligations attach the moment litigation becomes reasonably anticipated, well before proceedings are filed. And from 10 December 2026, APP 1 requires an organisation's privacy policy to disclose where computer programs use personal information to make decisions that could significantly affect individuals.

The practical failure is not ignorance of these duties but the absence of anyone who owns them before the event, so the firm meets each deadline by improvisation rather than rehearsal.

The statutory clocks a NSW firm is already running
TriggerWhat it startsThe deadline
An employee suspects an eligible data breachAssessment and notification dutyAssess within 30 days; notify the OAIC once a belief is formed
A ransom is paid (firm turnover $3m or more)Mandatory report to the signals agencyWithin 72 hours
Litigation becomes reasonably anticipatedPreservation duty and legal holdAt once, before any proceedings are filed
A court orders discoveryTechnology and format obligations, SC Gen 07The discovery plan must meet the court's protocol
Computer programs use personal information to make decisions that could significantly affect individualsPrivacy policy disclosure under APP 1, 2024 privacy reformsCommences 10 December 2026
Table 2. Statutory and procedural time limits that apply to a NSW law firm after a data breach, ransom payment or dispute, as in force in 2026. Source: OAIC; Cyber Security Act 2024 (Cth) s 27; NSW Supreme Court Practice Note SC Gen 07.

Note. None of these clocks waits for a partner to be briefed. Several start the moment an employee forms a suspicion, or the moment a dispute becomes likely.

The unaudited vendor

The most under-managed exposure is not the firm's own network but the chain of providers who touch litigation data: managed-review platforms, transcription services, forensic collectors and offshore document-review teams. A single upstream compromise can reach several firms at once. A domestic illustration: in June 2026 the Federal Court and the Federal Circuit and Family Court issued notices about data privacy incidents at a court transcription provider.

For eDiscovery this is the crux. A firm can run its review platform impeccably in-house and still surrender a client's entire document universe through a downstream reviewer it never audited. The 2023 HWL Ebsworth incident affected 62 Australian Government entities and a large number of state and territory entities, according to the National Office of Cyber Security's lessons-learned review. It remains the reference point for how far a single legal-sector compromise travels. Contractual bans on unapproved subcontracting, data-residency clauses and audit rights are the contractual means of keeping discoverable material inside a firm's control.

When a breach becomes the plaintiff's ammunition

A breach in a law firm rarely produces a single, contained loss. Client trust rests on confidentiality, so a leak strikes the core promise.

There is a quieter trap in the insurance layer. Much cyber cover is triggered by encryption or system failure, but pure data-theft extortion may lock nothing at all, so whether a policy responds when an attacker simply steals and threatens to publish is a live question.

Not every matter needs a forensic firm

Readiness is not the same as outsourcing everything. A single-custodian discovery of a few thousand documents, an encrypted lost laptop, or a phishing email caught early can be handled with existing tools and a competent supervising solicitor. The trigger for outside help is a step-change in volume, stakes or uncertainty: multi-custodian collections, a live preservation risk, a suspected reportable breach, active ransomware, or any matter where the firm's own conduct is in question.

Above that threshold, the specialists involved typically include privacy counsel, digital-forensics or incident-response firms and eDiscovery providers. In the Medibank litigation, the reports that kept privilege were those commissioned through lawyers to support legal advice.

The exposure changes with the courtroom

A NSW firm's exposure is defined less by where it is sued than by whose data it holds and which courts it appears in. New South Wales runs a restrained discovery model, with staged disclosure and, in the Equity Division, none until after evidence is served. In the Federal Court the regime tightens: nothing the parties agree binds the court, and a discovery plan must be approved. In United States litigation it expands again, into broad party-to-party discovery, formal litigation holds and spoliation sanctions.

The practical implication is that a boutique Sydney practice running a single cross-border matter can inherit preservation duties far broader than its domestic caseload ever generates, imported through one foreign proceeding or a US-domiciled client. A firm that has calibrated its readiness only to the NSW baseline can be badly wrong-footed the first time an American court's expectations arrive on its desk.

Preservation intensity climbs with the courtroom
JurisdictionDisclosure breadthPreservation dutyPressure on a NSW firm
NSW (UCPR / SC Eq 11)Narrow, stagedImplied, matter-specificModerate
Federal Court (GPN-TECH)Court-supervisedExplicit, via an approved planHigh
United States (FRCP)Very broadFormal holds; spoliation sanctionsVery high on cross-border work
Table 3. Discovery breadth and preservation duties under the rules of three jurisdictions in which a NSW firm may appear, as in force in 2026. Source: Judicial Commission of NSW; Federal Court of Australia, Technology and the Court Practice Note (GPN-TECH); US Federal Rules of Civil Procedure.

Note. A boutique Sydney practice can inherit preservation duties far broader than its domestic caseload, imported through a single cross-border matter or a US-domiciled client.

Preparedness is four things at once

Readiness resolves into a short list of capabilities that must exist before a dispute, breach or regulator's notice arrives, because every one degrades sharply once the clock is running. A prepared firm can preserve fast and defensibly, through a written legal-hold protocol that suspends routine deletion. It can produce electronic documents to the court's technology standard without a scramble. It can image a compromised system before that system is rebuilt. It can verify every AI-assisted citation against the primary source before filing. And it knows which statutory clock runs to which deadline.

The failures cluster around people, process and money rather than software: an unwritten hold that lives in the IT director's head, a partner whose matter data is all on a personal laptop, AI tools adopted without supervision, a vendor contract silent on where privileged material physically resides.

What it comes down to

The honest reading is that most NSW practices are only partially prepared. The risk sits at High for a typical mid-sized commercial or litigation practice, and higher for any firm holding government or health data, running unsupervised generative AI, or lacking a tested incident-response and legal-hold process.

The reassuring story a firm tells itself is that it does discovery for a living, so it must be ready. The question a court, the regulator or an insurer actually asks is never whether a firm intended to do the right thing. It is whether the firm can demonstrate, with contemporaneous records, that it preserved, investigated and produced defensibly, and kept its own investigation on the right side of privilege.

So the line draws itself. Firms that treat readiness as four rehearsed disciplines, wrapped around disciplined data governance and a vetted vendor chain, will handle a bad week as an incident. Firms that hold only the software will handle it as a casualty investigation, and may find the most damaging exhibit in the room is the one they wrote themselves.

Figures drawn from TheRiskAgent's risk briefing on eDiscovery and digital-investigation readiness for legal services in New South Wales (August 2026); figures checked against the issuing official sources in October 2026. Produced with AI research tools and reviewed before release; reference material, not advice.

Create your own Risk report

Pick a report type, configure it to your situation, and receive a fully sourced briefing. Research, not advice.

Pick the specific risk question you want a report on.

The following fields are optional. Providing them produces a more tailored report. Leave as "No preference" for a general report.

Your report download link will be sent to this email.

Secure payment via StripeDelivered within 40 minutes to 4 hours

Your career is a risk position

byAxeRocket

Career and job-loss risk is researched by AxeRocket, TheRiskAgent's sister platform. The Client Report is a complete executive-grade strategic dossier, built from your own answers and delivered to your inbox.

  • Up to 65 adaptive questions an intelligent intake that branches around your answers.
  • 122 industries, 1,258 sub-sectors we pinpoint exactly where you sit, never a vague category.
  • 41 professions, 351 specific roles your actual job title, not a job family.
  • Every country and jurisdiction, 470 states and regions intelligence local to where you are, or where you are headed next.
  • 36 specialist AI agents each section written by a purpose-built model, not one generic prompt.

Your Report: 8 parts, up to 29 sections, 50 to 70 pages

  1. 1Understanding Your Situation
  2. 2Global Industry Intelligence
  3. 3Global Profession Intelligence
  4. 4AI and the Future of Work
  5. 5Career Risk Assessment
  6. 6Strategic Career Options
  7. 7Personal Action Plan
  8. 8Local Resources and Support

Every claim fully referenced, with the source URLs provided.

USD 49

One-time, sold by AxeRocket. Includes 12 months of Client Zone access.

Generate your Client ReportHow the Client Report works

This link opens AxeRocket. Research, not advice.

#eDiscovery#legal services#digital forensics#privilege#data breach#New South Wales#cybersecurity
More TRA Insights

Insights are short summaries that introduce a paid research asset. They are not a substitute for the underlying report. Always consult a qualified adviser before acting on contents.