Legal Cyber Academy
All insights

Mediating a Data Breach Dispute: What Makes These Cases Different

By the Legal Cyber Academy editorial team ·

What makes data breach mediation different from ordinary commercial mediation

Mediating a data breach dispute differs from ordinary commercial mediation because the central factual question — how the intrusion happened and which records left the network — is a technical question the parties usually cannot resolve between themselves, and the forensic report that answers it is frequently being litigated as work product at the same time. Add a cyber insurer that controls settlement authority, a putative class whose damages resist aggregation, and regulators operating on their own timetable, and the negotiation runs on four tracks rather than one.

The causation fight is technical, and it is genuinely contested

In a breach case, "what happened" is not a narrative dispute about who said what in a meeting. It is a dispute about log retention windows, lateral movement, credential reuse, whether an exfiltration was confirmed or inferred from netflow volume, and whether the data in the staged archive was encrypted at rest. Two competent experts looking at the same evidence can reach materially different conclusions about scope — the number of affected records, a primary driver of the settlement range.

That matters at mediation because the ordinary mediator move — bracket the number and split it — assumes both sides are pricing the same underlying event. In a breach case they often are not. One side may be pricing every notified individual; the other is pricing the far smaller subset for whom exfiltration is actually evidenced. A mediator who cannot read a forensic timeline has no way to test either position and defaults to splitting a difference between two numbers that were never commensurable. Legal Cyber Academy's Data Disputes: Navigating Data Breach Mediation treats mediator selection as a substantive decision for exactly this reason.

The forensic report is the most valuable document in the room — and the least stable

Federal Rule of Civil Procedure 26(b)(3)(A) provides that ordinarily "a party may not discover documents and tangible things that are prepared in anticipation of litigation or for trial by or for another party or its representative (including the other party's attorney, consultant, surety, indemnitor, insurer, or agent)." Defendants routinely assume that routing an incident-response engagement through outside counsel places the resulting report inside that protection. Two discovery decisions say otherwise on their facts, and they get there by different tests.

In the Capital One MDL, the magistrate judge applied the Fourth Circuit's "because of" standard and its inquiry into "the driving force behind the preparation of each requested document," found that Capital One had not carried its burden, and granted the motion to compel in part — ordering production of the Mandiant report under the protective order, while denying the request for "related materials" without prejudice as not yet ripe. The facts that mattered were structural, not rhetorical: Capital One had a master services agreement with Mandiant dating to 2015 and a January 2019 statement of work with a paid retainer covering 285 hours of incident-response services, all predating the breach; the post-breach letter agreement signed with outside counsel described the same services on the same payment terms; the retainer had been designated a "Business Critical" expense in February 2019 and only re-designated as a legal expense that December; and the report was distributed to approximately fifty Capital One employees, four financial regulators (the FDIC, the Federal Reserve Board, the CFPB, and the OCC), and the company's outside auditor, with no explanation of why each recipient received it. On Rule 72 objections the district judge overruled the objections, held the order neither clearly erroneous nor contrary to law, affirmed it, and ordered production under the protective order.

In the Rutter's litigation, a magistrate judge in the Middle District of Pennsylvania reached the same result under the Third Circuit's stricter "primary motivating purpose" formulation, in an unreported discovery order, and did so largely on the four corners of the statement of work. The SOW said "[t]he overall purpose of this investigation will be to determine whether unauthorized activity within the Rutter's systems environment resulted in the compromise of sensitive data, and to determine the scope of such a compromise if it occurred." The court reasoned that, without knowing whether a breach had occurred, the company could not be said to have held the unilateral belief that litigation would result. The corporate designee's Rule 30(b)(6) testimony — that he was not contemplating forthcoming lawsuits when the work was done, and was unaware of anyone else at the company who was — reinforced that conclusion. The court separately rejected attorney-client privilege because the report and communications were factual, and because the consultant was tasked with working "alongside" the company's IT personnel on remediation, a service performed with no mention of attorney involvement and therefore not the provision of legal assistance.

Both courts addressed In re Experian Data Breach Litigation, where the report went to outside litigation counsel and was not given to the company's own incident response team. Distribution was part of what separated those cases from Experian — in Capital One, members of the company's own cyber and information security teams received the report and it was used for business and regulatory purposes. But neither court rested there. Capital One identified the "one significant difference" from Experian as a pre-report fact: an existing statement of work and MSA that was effectively transferred to outside counsel after the breach. Rutter's decided the question on the SOW's stated purpose, also fixed before any report existed. The analysis reaches both how the engagement was structured and what happened to the report afterward.

The decision points this creates

  • Papering. A post-breach engagement that copies the scope, deliverables, and payment terms of a pre-existing retainer is the fact pattern that lost in both Capital One and Rutter's. In both, the party asserting protection bore the burden and could not show the work would have been done differently absent the prospect of litigation.
  • Distribution. Every recipient outside the litigation team is an argument the report served a business or regulatory purpose. In Capital One the court also noted that the defendant failed to address what restrictions, if any, were placed on recipients as to discussing, copying, or forwarding the report.
  • The parallel investigation. Capital One did run an internal investigation parallel to Mandiant's, but the record did not establish its nature, extent, or how the results were used, and the company had not specified which internal investigations it would produce. The point survives as a caution rather than a safe harbor: in the Premera line the court found persuasive, an independent company investigation mattered because it had actually been produced in discovery.
  • The underlying artifacts. In a footnote, and while expressly declining to reach substantial need or waiver, the Capital One court observed that the event logs and network diagrams Mandiant reviewed appeared to be available to the plaintiffs. That observation cuts against the showing Rule 26(b)(3)(A)(ii) requires — substantial need plus inability, without undue hardship, to "obtain their substantial equivalent by other means" — and it is a reminder that the technical record often exists in discoverable form whether or not the report itself is produced.
  • The log. Rule 26(b)(5)(A) requires a party withholding material on privilege or work-product grounds to expressly make the claim and to describe the withheld documents, communications, or tangible things in a manner that, without revealing protected information, enables other parties to assess the claim. A thin log invites the motion.

For counsel, the practical consequence is that a breach mediation frequently happens while a motion to compel the forensic report is pending. That motion is itself a settlement variable: its expected outcome is worth real money to both sides, and it is often the cleanest thing in the case to trade.

Bringing the report into the room without losing it

Defendants who want credit for what the report says face an obvious problem, and two mechanics bear on it — with an important limit.

Federal Rule of Evidence 502(d) lets a federal court order "that the privilege or protection is not waived by disclosure connected with the litigation pending before the court — in which event the disclosure is also not a waiver in any other federal or state proceeding." Rule 502(e) provides that an agreement on the effect of disclosure in a federal proceeding "is binding only on the parties to the agreement, unless it is incorporated into a court order" — which is why a clawback stipulation without a 502(d) order is materially weaker protection. The limit is that Rule 502(d) addresses waiver by disclosure. It does not answer the antecedent question whether the material was protected in the first place. Where a court has already held a forensic report is not work product, as in Capital One and Rutter's, a 502(d) order does nothing for it.

Separately, 28 U.S.C. § 652(d) provides that, until rules are adopted under chapter 131 of title 28, each district court shall by local rule adopted under § 2071(a) provide for the confidentiality of alternative dispute resolution processes and prohibit disclosure of confidential dispute resolution communications. The applicable protection is therefore local-rule specific and worth reading before the session rather than after.

Rule 408(a) is narrower than it is often assumed to be. It makes compromise offers and "conduct or a statement made during compromise negotiations about the claim" inadmissible to prove or disprove the validity or amount of a disputed claim, or to impeach by a prior inconsistent statement or a contradiction — with a carve-out written into 408(a)(2) itself for statements made in negotiations of a claim by a public office exercising regulatory, investigative, or enforcement authority, when offered in a criminal case. Rule 408(b) then permits a court to admit the same evidence "for another purpose, such as proving a witness's bias or prejudice, negating a contention of undue delay, or proving an effort to obstruct a criminal investigation or prosecution." Rule 408 is a rule of admissibility for specified purposes. It is not a confidentiality rule, and it is not a substitute for one.

The insurer is effectively a third party at the table

Cyber coverage is usually the source of the money, which makes the carrier's coverage position, not the defendant's risk tolerance, the real constraint on authority. Under Rule 16(c)(1), a represented party must authorize at least one of its attorneys to make stipulations and admissions about all matters that can reasonably be anticipated for discussion at a pretrial conference, and, "[i]f appropriate, the court may require that a party or its representative be present or reasonably available by other means to consider possible settlement." That rule governs pretrial conferences before the court; attendance at a private mediation runs instead through the district's local ADR rules or the order referring the case, which is one more reason to read them in advance.

The questions worth resolving before the session, not during it, are: whether the carrier is defending under a reservation of rights and on what grounds; whether defense costs erode the limit; whether the relevant coverage part is sublimited; whether excess layers need to be triggered and whether those carriers have been noticed and invited; and whether the policy conditions consent to settle. A mediation that discovers late in the day that the person with authority is an adjuster on a lower layer with a modest sublimit has wasted it.

Class posture: the damages do not aggregate cleanly

Rule 23(b)(3) requires the court to find that questions of law or fact common to class members "predominate over any questions affecting only individual members," and that a class action "is superior to other available methods for fairly and efficiently adjudicating the controversy." Breach damages push against both.

In TransUnion LLC v. Ramirez, the Supreme Court held that of an 8,185-member class, the 1,853 members whose misleading credit reports were provided to third-party businesses had demonstrated concrete reputational harm, while the remaining 6,332 — whose internal credit files were not provided to third-party businesses during the relevant period — had not demonstrated concrete harm and lacked Article III standing to sue for damages on the reasonable-procedures claim. The Court rejected both a bare-inaccuracy theory and a risk-of-future-harm theory in a suit for damages, and it reversed the Ninth Circuit's contrary judgment and remanded. Applied to a breach class, that puts pressure on distinguishing members whose data was actually exfiltrated and misused from members who were merely notified.

Two structural consequences follow for mediation. First, Rule 23(c)(4) permits an action to be brought or maintained as a class action "with respect to particular issues" when appropriate, and tiered settlement structures — different consideration for members with documented fraud losses than for members with only notification — are often the way a deal is built to survive review. Second, a mediated agreement is not the end. Under Rule 23(e), the claims, issues, or defenses of a certified class, or of a class proposed to be certified for purposes of settlement, "may be settled, voluntarily dismissed, or compromised only with the court's approval," and approval requires a finding that the proposal is fair, reasonable, and adequate. Among the factors the court must consider are, under 23(e)(2)(C)(ii), "the effectiveness of any proposed method of distributing relief to the class, including the method of processing class-member claims," and under 23(e)(2)(D), whether "the proposal treats class members equitably relative to each other." Claims-rate design is therefore a merits issue at approval, not administrative detail.

The regulator's clock is not your clock

Civil exposure rarely runs alone. Following discovery of a breach of unsecured protected health information, a HIPAA covered entity must notify each affected individual "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach," except as provided in 45 C.F.R. § 164.412 — the law-enforcement delay provision, which allows a delay for the period specified in a written law-enforcement statement, or for no more than 30 days where the statement is oral.

A public-company registrant must, under Regulation S-K Item 106(b)(1), describe its processes, if any, for assessing, identifying, and managing material risks from cybersecurity threats "in sufficient detail for a reasonable investor to understand those processes," and, under Item 106(c)(1), describe the board of directors' oversight of risks from cybersecurity threats. Those descriptions become plaintiff exhibits, and statements a defendant makes to close the civil case can be read against them. Sequencing matters: a defendant that settles the class case before the regulatory posture is known may be buying peace it has to buy twice.

What a technically fluent mediator actually changes

Three things, concretely. First, the mediator can test each side's causation story against the artifacts rather than accepting both and averaging — which is what changes a number rather than a mood. Second, the mediator can price the privilege motion, because the outcome turns on facts (the scope of any pre-breach statement of work, the distribution list, whether a parallel investigation exists and has been produced) that a neutral can develop in caucus without either side conceding anything. Third, the mediator can propose process rather than only money: a limited production under a Rule 502(d) order, a stipulated technical fact set, or referral of the forensic dispute to a neutral expert or special master while the damages negotiation continues.

That last option connects to a separate body of practice. Where the technical dispute is large enough to need supervised process rather than a single session, the appointment mechanics, standards of review, and cost allocation are covered in Working With a Discovery Special Master, and in Maximizing Case Efficiency: Untapped Potential of Using Discovery Referees and Special Masters in ADR and the Attorney Rulebook for Working with Special Masters in Federal Court.

Learn more

This article is general information about legal process and is not legal advice; consult counsel about your specific matter. Court decisions discussed here are discovery rulings decided on their own records, and the two forensic-report cases are unreported orders that bind no other court.

Go deeper — courses on this

Keep reading

Get the next one by email

Plain-English analysis of the law-and-technology developments that change how you advise. No more than monthly, and you can leave whenever you like.