Legal Cyber Academy
All insights

Privilege Over Incident Response Reports: What the Capital One Line of Cases Changed

By the Legal Cyber Academy editorial team ·

What the Capital One line of cases changed

Privilege over an incident response report turns less on who signed the engagement letter than on whether the report would have been written anyway. In In re Capital One Consumer Data Security Breach Litigation, the Eastern District of Virginia ordered production of a Mandiant report because Capital One already held a statement of work covering identical services before the breach. Courts applying District of Columbia, Ninth Circuit, and Third Circuit law have since reached the same result on comparable records.

The question every court actually reaches

Federal Rule of Civil Procedure 26(b)(3)(A) protects "documents and tangible things that are prepared in anticipation of litigation or for trial by or for another party or its representative (including the other party's attorney, consultant, surety, indemnitor, insurer, or agent)." The fight is rarely over that sentence; it is over a second question the rule does not state.

In the Fourth Circuit, where a document may be used for both litigation and business purposes, the court must identify "the driving force behind the preparation of" it, and materials produced in the ordinary course of business do not qualify (National Union Fire Insurance Co. of Pittsburgh, Pa. v. Murray Sheet Metal Co., 967 F.2d 980, 984 (4th Cir. 1992)). Courts there apply a two-prong formulation from RLI Insurance Co. v. Conseco, Inc., 477 F. Supp. 2d 741, 747–48 (E.D. Va. 2007): whether the document was created when litigation was "a real likelihood," rather than merely a possibility, and whether it would have been created in essentially the same form absent litigation.

Magistrate Judge John F. Anderson found the first prong plainly met: after the breach announcement, "there was a very real potential that Capital One would be facing substantial claims." The company lost on the second. On Rule 72 objections, District Judge Anthony J. Trenga rejected the argument that the driving-force test ends once litigation is foreseeable, holding that the second prong "captures one of the core inquiries identified by the Fourth Circuit."

The framing differs elsewhere; the operative question does not. The D.C. Circuit's "because of" test denies protection where a document would have been created "in substantially similar form" regardless of litigation (FTC v. Boehringer Ingelheim Pharmaceuticals, Inc., 778 F.3d 142, 149 (D.C. Cir. 2015)), which is how Judge James E. Boasberg resolved Wengui v. Clark Hill, PLC, 338 F.R.D. 7 (D.D.C. 2021). The Ninth Circuit asks the same under the totality of the circumstances (United States v. Richey, 632 F.3d 559, 568 (9th Cir. 2011)), the test applied in Leonard v. McMenamins Inc. The Third Circuit standard is harder still: litigation must have been the "primary motivating purpose behind the creation of the document" (United States v. Rockwell International, 897 F.2d 1255, 1266 (3d Cir. 1990)), the test applied in In re Rutter's Data Security Breach Litigation.

The pattern across the compelled-production cases is that the anticipation prong is satisfied and the motion turns entirely on the second question. It is not a uniform pattern — In re Experian Data Breach Litigation and In re Target Corp. Customer Data Security Breach Litigation both denied production, and part of the Samsung record was held privileged — but in each case below, the evidence on the second question decided it.

What the contract says outweighs who signed it

Capital One signed a master services agreement with FireEye, Inc., doing business as Mandiant, on November 30, 2015, and a January 7, 2019 statement of work entitling it to 285 hours of incident response services. It covered computer security incident response support; digital forensics, log, and malware analysis support; and incident remediation assistance, and required a detailed final report with results and remediation recommendations.

After the breach was confirmed, Capital One retained Debevoise & Plimpton on July 20, 2019, and on July 24 signed a letter agreement with Mandiant describing the same three service areas on the same payment terms. A July 26 addendum added penetration testing of systems and endpoints. Judge Trenga found "the primary difference between the 2019 SOW and the Letter Agreement is a specific reference in the Letter Agreement to the Cyber Incident and the role Debevoise would play." Under the letter agreement the work was directed by counsel and the deliverables went to counsel rather than to Capital One — and that was not enough.

Rutter's shows how much a scope description can cost. The statement of work stated that "[t]he overall purpose of this investigation will be to determine whether unauthorized activity within the Rutter's systems environment resulted in the compromise of sensitive data, and to determine the scope of such a compromise if it occurred." Magistrate Judge Karoline Mehalchick read that conditional language as showing no unilateral belief that litigation would follow: the company did not yet know a breach had happened. The contract was not the only evidence. Rutter's corporate designee — the Vice President of Technology who signed the Kroll engagement — testified that he was not contemplating lawsuits when Kroll did its work and knew of no one at the company who was.

The attorney-client claim failed on the same document. The court found the scope of services inherently factual except for one item, Kroll's undertaking to "work alongside Rutter's IT personnel to identify and remediate any potential vulnerabilities" — and that item involved no lawyer, so it was not the provision of legal assistance.

Three drafting consequences run through these opinions. Copying the standing incident response scope into the counsel-directed engagement is what sank Capital One and Dominion Dental. Remediation, monitoring, and restoration commitments in the litigation-support contract cut against protection in Rutter's and McMenamins. And where the standing contract already requires the same deliverable, courts have found nothing left for the second engagement to have changed.

The pre-existing retainer is the fact most often cited

Capital One designated the Mandiant retainer a "Business Critical" expense rather than a "Legal" one in February 2019. The breach work was paid first out of that retainer, then from the cyber budget, and only re-designated as a legal expense in December 2019. The court in In re Dominion Dental Services USA, Inc. Data Breach Litigation, 429 F. Supp. 3d 190 (E.D. Va. 2019), reached the same result where the description of services in the pre-breach statement of work was "almost identical" to the post-breach one, and the "under the direction of Counsel" designation appeared designed to help shield the report from disclosure.

Told the order was unworkable for heavily regulated companies, Judge Trenga wrote that the contention "ignores the alternatives available to produce and protect work product, either through different vendors, different scopes of work and/or different investigation teams." That is as close to a roadmap as the opinions offer: a different firm for the counsel-directed work, or at minimum a genuinely different scope and staffing.

A clean vendor is not sufficient on its own. In In re Samsung Customer Data Security Breach Litigation, the forensic firm had performed no prior services for the company or its counsel relating to the breach — the special master listed the extent of any pre-existing relationship as one of the factors bearing on the analysis — and most of the claim still failed on other grounds.

A two-track investigation counts only if the business track leaves a record

Defendants routinely invoke In re Target Corp. Customer Data Security Breach Litigation, where a non-privileged track let the company learn how the breach happened and respond appropriately while a separate team informed counsel. The recurring problem is proof.

In Wengui, the ordinary-course vendor produced no findings at all; its trail went cold on the day the counsel-retained consultant arrived, and the firm's own interrogatory answers said its understanding of the incident was based "solely" on outside counsel and consultants retained by outside counsel. In McMenamins, the defendant asserted a parallel internal investigation, but its discovery responses said nothing about what that investigation entailed or found; it answered an interrogatory seeking breach facts by pointing to its notice letter. In Samsung, the special master called a two-sentence certification "the sum total" of the company's description of its internal investigation, with no indication it had generated a separate, non-privileged report for business use.

Where a business track is real, these opinions suggest what makes it provable: its own scope document, its own deliverable, and an account that holds up in a Rule 30(b)(6) deposition — the point on which Rutter's turned. That is a question for the standing ransomware and incident response playbook rather than something assembled after an alert fires.

Distribution is read as evidence of purpose, not only waiver

The Mandiant report reached roughly fifty Capital One employees, the Board of Directors, four financial regulators, and the company's outside auditor. Individuals within the company anticipated using it for disclosures required under the Sarbanes-Oxley Act, and it was referenced in draft FAQs — which Capital One characterised as investor relations "talking points" — prepared by a senior vice president for finance before the public announcement. Judge Anderson noted the opposition never addressed what restrictions were placed on recipients. Judge Trenga held that "post-production disclosures are appropriately probative of the purposes for which the work product was initially produced" — the circulation list is evidence of why the report was written, before waiver is ever reached.

The forensic firm in Samsung delivered thirteen PowerPoint presentations between August 13 and October 7, 2022 to company personnel who included a Senior Director of Consumer Driven Marketing and a Senior Product Manager of Consumer Driven Marketing, and a one-page cloud and host analysis went to fifteen high-level executives. That breadth, the special master held, undermined the position that the firm was retained only to provide technical interpretation for the benefit of counsel.

Two record-keeping points follow from those rulings. Distribution was decisive in both cases, and in Capital One the absence of any evidence about restrictions on recipients counted against the company. Logging matters too: in McMenamins, the report, engagement letter, and scopes of work the company withheld never appeared on its privilege log, and the log did not identify attachments to the communications it did list — a Rule 26(b)(5)(A) problem, since a party withholding must "expressly make the claim" and describe the materials well enough to let other parties assess it. Where regulatory disclosure will draw on the same facts, that path raises separate questions, as with securities disclosure obligations. Rule 26(b)(3)(A) also names the insurer among the representatives whose materials can qualify, which is one reason coordination with cyber insurers belongs in the same conversation.

What survived in Samsung

The Samsung opinion, issued by Special Master Hon. Freda L. Wolfson (ret.) on July 31, 2024, is the most useful recent decision because it split. Surveying the national caselaw, and assessing the attorney-client claim on the case-by-case basis the Third Circuit requires, she delineated factors that shaped her determination: the type of services the consulting firm rendered to outside counsel; the purpose and scope of the investigation as evidenced by the investigative materials or the services contract; the existence of a two-track investigation commissioned by the company; the extent of any pre-existing relationship between the company and the firm; and the extent to which the firm's materials were shared inside the company or with outside entities, including the government. The work product analysis followed for substantially the same reasons.

The presentations, the analysis, and an update drafted for the FBI were ordered produced, the last with redactions the FBI directed to protect an ongoing criminal investigation. A draft memorandum was held protected by the attorney-client privilege: prepared in January 2023, "five months after litigation began," at counsel's request so counsel could advise the client, shown only in part to counsel on a video call, and never shared with any company personnel. The special master expressly did not reach whether it was also work product. The distinction is not the label but the sequence and the audience. That ruling came from a special master, so the parties had 21 days under Federal Rule of Civil Procedure 53(f) to object — which is worth understanding alongside how special masters handle discovery disputes.

Sharing with the government, and the CISA no-waiver provision

The special master held the FBI update was not itself privileged: the company did not explain how counsel's review of the draft before submission transformed non-privileged investigative facts and conclusions into attorney-client communications. She found no general waiver, though, applying 6 U.S.C. § 1504(d)(1), which provides that "[t]he provision of cyber threat indicators and defensive measures to the Federal Government under this subchapter shall not constitute a waiver of any applicable privilege or protection provided by law, including trade secret protection." She noted there was no case law interpreting the provision — indeed no decision discussing any provision of § 1504.

Two cautions. The statute prevents waiver; it does not create protection for a document that was never privileged, which is exactly how the FBI update came out. And the subchapter is time-limited: 6 U.S.C. § 1510(a) now runs through September 30, 2026, after Pub. L. 119-75 (Feb. 3, 2026) replaced the earlier September 30, 2025 date. Confirm its current status before relying on it.

Substantial need is the second front

Work product is not absolute. Under Rule 26(b)(3)(A), materials may be discovered if they are "otherwise discoverable under Rule 26(b)(1)" and the party "shows that it has substantial need for the materials to prepare its case and cannot, without undue hardship, obtain their substantial equivalent by other means." Even then, Rule 26(b)(3)(B) requires a court ordering discovery to "protect against disclosure of the mental impressions, conclusions, opinions, or legal theories of a party's attorney or other representative concerning the litigation" — so a substantial-need showing reaches the facts, not counsel's opinion work product.

In McMenamins, the court held in the alternative that the standard was met: the report was the only available account of how the breach occurred and what remediation followed, running more than a dozen pages of highly technical detail against a notice letter of "at most, a dozen vague sentences."

The counterweight is the underlying evidence. Judge Anderson observed that the event logs and network diagrams Mandiant reviewed appeared to be available to plaintiffs, and the Samsung special master said that had she reached the question she would most likely have found no substantial need, because plaintiffs could run their own expert analyses of the same material. Preserved and produced images, logs, and timelines are what keep the report from becoming the only route to the facts — and counsel on both sides should be able to read a forensic report closely enough to separate its facts from its conclusions.

A last observation from Capital One: the orders defendants most often cite are thin. Judge Anderson wrote that he "can divine no guidance" from the Arby's order, that the Target order provided "no assistance," and that Genesco offered "no substantive guidance." The party claiming the protection bears the burden of demonstrating it applies (Solis v. Food Employers Labor Relations Ass'n, 644 F.3d 221, 232 (4th Cir. 2011)), and unreasoned orders from other districts did not help carry it.

Learn more

Legal Cyber Academy faculty who teach in this area. The views in this article are not attributed to them.

  • Katherine Charonko, Partner and ESI Practice Group Leader, Bailey & Glasser
  • David Shonka, Partner and General Counsel, Redgrave LLP; Acting General Counsel of the FTC across three separate terms
  • Gail Gottehrer, VP, Global Litigation, Labor & Employment, and Government Relations, Fresh Del Monte Produce, Inc.
  • Aaron Tantleff, Partner, Foley & Lardner LLP
  • Tamara Snowdon, Head of Cyber Risk Wordings, Beazley
  • James Orenstein, Mediator, Arbitrator and Court-Appointed Neutral, JAMS (Hon., Ret.); U.S. Magistrate Judge, E.D.N.Y., 2004–2020

General information about published court decisions and rules, not legal advice. Discovery rulings on privilege are fact-specific and several of the decisions discussed here are unreported orders.

Go deeper — courses on this

Keep reading

Get the next one by email

Plain-English analysis of the law-and-technology developments that change how you advise. No more than monthly, and you can leave whenever you like.