From the Fall 2026 Issue

From Containment to Consequence: The New Cyber Incident Lifecycle

Chris Pogue
Adjunct Professor of Professional Practice | Oklahoma State University

For years, we treated incident response as a largely technical exercise. Detect the attacker. Figure out how they got in. Contain the intrusion. Eradicate persistence. Restore the business. Learn what went wrong and move on.

That model is no longer sufficient.

The technical response may be stabilizing just as the legal, regulatory, insurance and law-enforcement response accelerates.

Evicting the threat actor may simply mark the point where the incident changes shape. The technical response may be stabilizing just as the legal, regulatory, insurance and law-enforcement response accelerates. Many of those tracks are already running in parallel while the forensic investigation is still underway.

Just look at 2026:

ADT publicly disclosed a cybersecurity incident on April 24 involving unauthorized access to a limited set of customer and prospective-customer records, including names, phone numbers, and addresses; a small percentage also included dates of birth and the last four digits of Social Security or Tax ID numbers. The first proposed class action was filed April 28.[1]  Frontier Airlines began notifying affected individuals on July 9 after a breach exposed sensitive personal information, including names, Social Security numbers, addresses, dates of birth, and government-issued identification details; its first class action was filed July 13.[2]  WilmerHale notified affected clients on July 10 that unauthorized actors had accessed personal information in its systems, including names and Social Security numbers and was sued July 14 – all suits were filed four days later.[3]

Four days.

The point is not that every breach ends in a massive class action. It is that the legal response is no longer something that starts months after the cybersecurity team finishes its work. It can begin while the investigation is still unfolding.

Containment Changes the Audience

Once sensitive data may have been accessed, the questions change. The security team wants to know how the attacker got in, what they touched and whether they are still there. General counsel wants to know what can be substantiated and safely disclosed. Regulators want to know what safeguards were in place and whether compliance obligations were met. Insurers want evidence supporting the claim. Customers want answers. Plaintiffs’ attorneys want to know whether there is a case. Law enforcement may want evidence that connects the intrusion to other victims, infrastructure or threat actors. All of them may be asking before the forensic investigation is complete.

Containment does not end the incident. It changes the audience.

I have worked enough investigations to know that evidence collected for one purpose can quickly become important for another. An IP address, malware configuration file, domain, credential, cryptocurrency wallet or attacker communication that looks minor in one case can become enormously valuable when correlated with evidence from other investigations. That information can support intelligence sharing, attribution, infrastructure disruption, indictment or prosecution. The quality of the investigation therefore matters long after the attacker leaves.

Poor logging is more than a technical inconvenience. It can leave an organization unable to prove what happened (or what didn’t happen). Weak evidence preservation can undermine conclusions, complicate litigation and reduce the intelligence value of an investigation.

Response teams also need to ask a harder question: how will this evidence, and the decisions surrounding it, look to someone paid to challenge us later?

Opposing counsel, a regulator or an opposing expert may frame those same facts as negligence.

An investigator may see an incomplete log, poorly worded email or unsupported conclusion as a mistake made during a fast-moving response. Opposing counsel, a regulator or an opposing expert may frame those same facts as negligence. A missed escalation can become an argument that warnings were ignored. An imprecise report can become evidence that management lacked control. A casual chat message can become a deposition exhibit.

In extreme cases, the exposure can become personal. Former Uber security chief Joe Sullivan was criminally convicted after prosecutors argued his handling and concealment of Uber’s 2016 breach obstructed an FTC investigation.[4]   The SEC later named SolarWinds CISO Timothy Brown individually in a civil enforcement action, alleging that internal cybersecurity concerns were inconsistent with the company’s public disclosures.  The case was dismissed with prejudice.[5] The decision to pursue a CISO personally should get every security executive’s attention.

 The lesson is not to stop documenting. It is to document well, be precise, preserve the evidence and separate facts from assumptions. Record why decisions were made and assume the audience may eventually extend far beyond the incident-response team.

Then the Bills Start Arriving

We still talk about cybersecurity spending as if there are two choices: spend the money on security or accept the risk and save the money.

That is the wrong comparison.

After a serious breach, you may end up buying the same things you deferred beforehand anyway: digital forensics and incident response retainers, penetration tests, gap assessments, compliance validation, identity reviews, improved logging, XDR, segmentation, security awareness training, tabletop exercises and managed security services.

Except now you are buying them under pressure, and on top of breach counsel, class-action defense, regulatory counsel, forensic experts, eDiscovery, notification, credit monitoring, crisis communications, deductibles, penalties and settlements.

The numbers add up quickly. Comcast agreed to establish a $117.5 million settlement fund arising from its 2023 breach. Capital Health’s $4.5 million settlement received final approval in July 2026. Fidelity’s $2.5 million breach settlement was approved in July, after Massachusetts separately imposed a $1.25 million fine and required additional cybersecurity measures.

And those numbers still do not capture everything: the organization’s own outside counsel, internal staff time, remediation, brand and reputation damage, customer confidence, lost market share, delayed projects and lost opportunities.

Attackers Steal Attention

Every hour a CEO, CIO, CISO, general counsel, CMO or senior executive spends managing a breach is an hour not spent on customers, employees, products, sales, strategy or growth. Projects slow down. Sales conversations become risk conversations. Customer confidence erodes. Leadership moves from opportunity to damage control.

The most expensive resource consumed by a major breach may not be technology. It may be leadership attention.

Your competitors do not stop executing because you are responding to an incident. The most expensive resource consumed by a major breach may not be technology. It may be leadership attention.

Buy Optionality

Cybersecurity is not only about preventing loss. It is about preserving choices.

Before an incident, you choose when the work happens, who performs it, what gets prioritized, how quickly you remediate and which risks the business is willing to accept. After the breach, outside counsel, insurers, regulators, customers and courts may begin shaping those decisions for you.

Preventive security spending buys optionality. Reactive security spending often comes with obligation.

Spend the money while you still control how it is spent. Do the assessment. Test the environment. Exercise the response plan. Establish the DFIR relationship before you need it. Fix the basics while you still control the schedule.

Cybersecurity will always cost money. The question is whether you spend it deliberately, on your terms, or after an attacker has started making some of those decisions for you.

Buy yourself optionality. lock

Justin Petitt
Larry Letow

Leave a Comment