A data breach involves unauthorized access, acquisition, use, or disclosure of protected information. Statutory definitions vary, and some jurisdictions require actual acquisition while others treat unauthorized access as sufficient.

Common vectors include compromised credentials, phishing, ransomware, vendor compromise, and insider misuse.

Alternative Names:

Security Breach, Data Compromise

Why it Matters?

Law firms are attractive targets precisely because they aggregate confidential material from many clients, and a single firm compromise can expose multiple companies' litigation strategy simultaneously. Beyond the direct consequences, a breach implicates the ethical duty of confidentiality, triggers client notification obligations under most outside counsel guidelines, and may require notifying courts where sealed material was involved.

Frequently Confused with

Related terms

Frequently asked questions

Is every security incident a breach?

Is every security incident a breach?

No. A breach requires unauthorized access to or acquisition of protected information. Many incidents are contained before that threshold is met, which is why logging matters.

Must clients be notified?

Must clients be notified?

Usually yes. Ethical obligations and most outside counsel guidelines require notification, often on shorter timelines than statutory requirements.