eDiscovery and digital-investigation readiness for legal-services firms in New South Wales, Australia.
A law firm is the one client in the room that already knows how discovery works. It runs preservation, collection and production for other people for a living. So the natural assumption is that a firm, of all businesses, is ready for the digital version of its own trade. That assumption is where the trouble starts.
Readiness is not tested on a quiet afternoon. It is tested inside a bad week, on a live court deadline, during a breach. The real question is whether a New South Wales practice could do four things at once: place a defensible legal hold within hours, collect from cloud and mobile sources without destroying evidence, notify a regulator inside a statutory window, and defend the privilege of its own forensic report.
And the fourth is the one almost nobody plans for. When a firm is breached and commissions an investigation to understand the damage, it assumes the resulting report is protected. The Australian courts have shown, in the Medibank class action, that this assumption can be wrong. The document a firm writes to understand its own failure can become the plaintiff's sharpest exhibit against it.
So the spine of the matter is this. Preparedness for eDiscovery and digital investigations is not a tool a firm buys. It is a set of disciplines it rehearses before the clock starts, and the firm that owns every platform can still hold none of them.
Five ways it bites, ranked
The detail is below; the bottom line comes first, worst first.
1. Losing privilege over a firm's own breach report. The most distinctive risk, and the least reversible. When a firm commissions a post-incident forensic review, it assumes legal professional privilege will shield it. In the Medibank consumer class action three Deloitte reports were found not to be privileged, and the company was refused leave to appeal, because the court found the reports also served governance, regulatory and public-facing purposes, so legal advice was not the dominant one. Where the engagement is not structured for a legal purpose from the outset, the resulting report can be discoverable.
2. Ransomware and client-file theft, mid-matter. The signature event for a law firm is the encryption and leak of client files, and a compromised trust account turns a single spoofed settlement email into a direct financial loss.
3. Failing to preserve, then facing an adverse inference. If a NSW firm's client is ordered to give discovery and key custodian mailboxes were never placed on hold while auto-deletion ran, the client faces adverse-inference arguments and cost sanctions, and the firm faces a negligence exposure. A defensible legal hold, issued the moment a dispute becomes likely, is the single most cost-effective control in the whole field, and preservation failures are rarely recoverable once deletion has run.
4. Client data lost through an unaudited vendor. Legal work is parcelled out to eDiscovery platforms, cloud hosts, transcription services and offshore review teams, and each is a route in. In June 2026 the Federal Court and the Federal Circuit and Family Court issued notices about data privacy incidents at a court transcription provider. A firm can secure its own perimeter perfectly and still surrender a client's entire document universe through the supplier running its review.
5. Filing an AI-hallucinated authority in a NSW court. The fastest-moving risk. Since Practice Note SC Gen 23 took effect in February 2025, AI-assisted chronologies, indexes and summaries are permitted subject to conditions on confidentiality and the verification of citations. Courts have already made costs orders where AI-generated authorities were filed; one example is Mertz & Mertz (No 3) [2025] FedCFamC1A 222.
The trade a firm runs for others
A law firm carries a double exposure that almost no other business does. It holds vast quantities of privileged, discoverable client material that attackers want and courts can compel, and at the same time it must run discovery and forensic investigations for clients to a standard the courts now police closely. The same electronic material a firm is ethically bound to protect is the material it will one day have to preserve, produce and stand behind in court.
Attackers follow value density, and few sectors hold more per gigabyte than legal services. A single practice may hold merger terms, litigation strategy, trust-account details, identity documents and privileged advice for hundreds of clients.
Buy the full report
Forensic Tech Risk
Am I Prepared for eDiscovery and Digital Investigations?
Published: 5 August 2026
53 pages38 checked sources
- Country
- Australia
- State or Territory
- New South Wales
- Industry
- Legal Services
This published copyUSD 19.99
Buy this reportConfigure this report new at today’s date (USD 49)The record year, and why the timing is the point
The clearest recent signal is volume. Data-breach notifications to the national regulator reached 1,205 in 2025, the highest annual total since the scheme began in 2018 and an 8 per cent rise on the year before. The majority, 716 of them, were malicious or criminal, with cyber hacking the leading cause. For a solicitor, this is the difference between a rare event to insure against and a live operational hazard.
Two things make the timing decisive rather than merely unwelcome. Public concern is now near-universal, with one 2026 survey finding 82 per cent of Australians worried about data breaches, up from 74 per cent in 2023, which raises the stakes for a profession built on confidentiality.
And the trend points the wrong way just as enforcement, a new privacy tort and court scrutiny of AI tighten together. A statutory tort for serious invasions of privacy commenced on 10 June 2025, giving individuals a direct cause of action with damages for distress and even exemplary damages.
Note. The highest annual total since the scheme began in 2018, up 8 per cent on the year before. The majority, 716 of them, were malicious or criminal, with cyber hacking the leading cause.
A firm's own report as the other side's exhibit
Return to the trap at the centre of all this, because it is where the confident firm gets caught. The instinct after a breach is to commission a forensic investigation quickly, route it through a lawyer, and assume privilege has attached. In March 2026 the Full Federal Court dismissed Medibank's application for leave to appeal a finding that three Deloitte reports were not privileged, because obtaining legal advice was not their dominant purpose (Medibank Private Limited v McClure [2026] FCAFC 38).
What makes the ruling instructive is what survived. Medibank kept privilege over two CrowdStrike reports and two Threat Intelligence reports, which had been commissioned through lawyers to support legal advice. Same company, same breach, opposite outcomes.
In [2025] FCA 167 the reports that kept privilege were those commissioned through lawyers to support legal advice. The Deloitte reports, whose scope was shaped with APRA and announced publicly as a learning exercise, did not. The court weighed Medibank's public statement of 7 November 2022 that it would "learn from this event" against the claim to privilege.
| Post-incident report | Commissioned for | Outcome in court |
|---|---|---|
| Three Deloitte reports | Legal, governance, regulatory and public-facing purposes | Not privileged; leave to appeal refused |
| Two CrowdStrike and two Threat Intelligence reports | Commissioned through lawyers to support legal advice | Privilege upheld |
Note. Same company, same breach, opposite results. The reports that kept privilege were those commissioned through lawyers to support legal advice.
The clock starts before anyone briefs the partners
The second thing firms routinely misjudge is time. Under the national notifiable-data-breach scheme, the obligation to assess and notify begins when any employee becomes aware of a suspected eligible breach, not when it reaches partners or general counsel. A firm that treats the clock as starting once management is briefed can be non-compliant before it has even convened.
Other clocks run just as fast. A business with turnover of $3 million or more that pays a ransom must report to the signals agency within 72 hours, under section 27 of the Cyber Security Act 2024. Preservation obligations attach the moment litigation becomes reasonably anticipated, well before proceedings are filed. And from 10 December 2026, APP 1 requires an organisation's privacy policy to disclose where computer programs use personal information to make decisions that could significantly affect individuals.
The practical failure is not ignorance of these duties but the absence of anyone who owns them before the event, so the firm meets each deadline by improvisation rather than rehearsal.
| Trigger | What it starts | The deadline |
|---|---|---|
| An employee suspects an eligible data breach | Assessment and notification duty | Assess within 30 days; notify the OAIC once a belief is formed |
| A ransom is paid (firm turnover $3m or more) | Mandatory report to the signals agency | Within 72 hours |
| Litigation becomes reasonably anticipated | Preservation duty and legal hold | At once, before any proceedings are filed |
| A court orders discovery | Technology and format obligations, SC Gen 07 | The discovery plan must meet the court's protocol |
| Computer programs use personal information to make decisions that could significantly affect individuals | Privacy policy disclosure under APP 1, 2024 privacy reforms | Commences 10 December 2026 |
Note. None of these clocks waits for a partner to be briefed. Several start the moment an employee forms a suspicion, or the moment a dispute becomes likely.
The unaudited vendor
The most under-managed exposure is not the firm's own network but the chain of providers who touch litigation data: managed-review platforms, transcription services, forensic collectors and offshore document-review teams. A single upstream compromise can reach several firms at once. A domestic illustration: in June 2026 the Federal Court and the Federal Circuit and Family Court issued notices about data privacy incidents at a court transcription provider.
For eDiscovery this is the crux. A firm can run its review platform impeccably in-house and still surrender a client's entire document universe through a downstream reviewer it never audited. The 2023 HWL Ebsworth incident affected 62 Australian Government entities and a large number of state and territory entities, according to the National Office of Cyber Security's lessons-learned review. It remains the reference point for how far a single legal-sector compromise travels. Contractual bans on unapproved subcontracting, data-residency clauses and audit rights are the contractual means of keeping discoverable material inside a firm's control.
When a breach becomes the plaintiff's ammunition
A breach in a law firm rarely produces a single, contained loss. Client trust rests on confidentiality, so a leak strikes the core promise.
There is a quieter trap in the insurance layer. Much cyber cover is triggered by encryption or system failure, but pure data-theft extortion may lock nothing at all, so whether a policy responds when an attacker simply steals and threatens to publish is a live question.
Not every matter needs a forensic firm
Readiness is not the same as outsourcing everything. A single-custodian discovery of a few thousand documents, an encrypted lost laptop, or a phishing email caught early can be handled with existing tools and a competent supervising solicitor. The trigger for outside help is a step-change in volume, stakes or uncertainty: multi-custodian collections, a live preservation risk, a suspected reportable breach, active ransomware, or any matter where the firm's own conduct is in question.
Above that threshold, the specialists involved typically include privacy counsel, digital-forensics or incident-response firms and eDiscovery providers. In the Medibank litigation, the reports that kept privilege were those commissioned through lawyers to support legal advice.
The exposure changes with the courtroom
A NSW firm's exposure is defined less by where it is sued than by whose data it holds and which courts it appears in. New South Wales runs a restrained discovery model, with staged disclosure and, in the Equity Division, none until after evidence is served. In the Federal Court the regime tightens: nothing the parties agree binds the court, and a discovery plan must be approved. In United States litigation it expands again, into broad party-to-party discovery, formal litigation holds and spoliation sanctions.
The practical implication is that a boutique Sydney practice running a single cross-border matter can inherit preservation duties far broader than its domestic caseload ever generates, imported through one foreign proceeding or a US-domiciled client. A firm that has calibrated its readiness only to the NSW baseline can be badly wrong-footed the first time an American court's expectations arrive on its desk.
| Jurisdiction | Disclosure breadth | Preservation duty | Pressure on a NSW firm |
|---|---|---|---|
| NSW (UCPR / SC Eq 11) | Narrow, staged | Implied, matter-specific | Moderate |
| Federal Court (GPN-TECH) | Court-supervised | Explicit, via an approved plan | High |
| United States (FRCP) | Very broad | Formal holds; spoliation sanctions | Very high on cross-border work |
Note. A boutique Sydney practice can inherit preservation duties far broader than its domestic caseload, imported through a single cross-border matter or a US-domiciled client.
Preparedness is four things at once
Readiness resolves into a short list of capabilities that must exist before a dispute, breach or regulator's notice arrives, because every one degrades sharply once the clock is running. A prepared firm can preserve fast and defensibly, through a written legal-hold protocol that suspends routine deletion. It can produce electronic documents to the court's technology standard without a scramble. It can image a compromised system before that system is rebuilt. It can verify every AI-assisted citation against the primary source before filing. And it knows which statutory clock runs to which deadline.
The failures cluster around people, process and money rather than software: an unwritten hold that lives in the IT director's head, a partner whose matter data is all on a personal laptop, AI tools adopted without supervision, a vendor contract silent on where privileged material physically resides.
What it comes down to
The honest reading is that most NSW practices are only partially prepared. The risk sits at High for a typical mid-sized commercial or litigation practice, and higher for any firm holding government or health data, running unsupervised generative AI, or lacking a tested incident-response and legal-hold process.
The reassuring story a firm tells itself is that it does discovery for a living, so it must be ready. The question a court, the regulator or an insurer actually asks is never whether a firm intended to do the right thing. It is whether the firm can demonstrate, with contemporaneous records, that it preserved, investigated and produced defensibly, and kept its own investigation on the right side of privilege.
So the line draws itself. Firms that treat readiness as four rehearsed disciplines, wrapped around disciplined data governance and a vetted vendor chain, will handle a bad week as an incident. Firms that hold only the software will handle it as a casualty investigation, and may find the most damaging exhibit in the room is the one they wrote themselves.
Figures drawn from TheRiskAgent's risk briefing on eDiscovery and digital-investigation readiness for legal services in New South Wales (August 2026); figures checked against the issuing official sources in October 2026. Produced with AI research tools and reviewed before release; reference material, not advice.

