[Webcast Transcript] From Breach to Legal Crisis: The Hours that Define Your Exposure
Editor’s Note: It starts, as these things often do, with a phone call nobody wanted to make, and from there, the clock never really stops. In this HaystackID® webcast, moderated by Michael Sarlo, three seasoned responders, Anya Korolyov, Gabe Landau, and Nate Latessa, walked through what actually happens inside an organization in the hours and days after a breach is discovered, from the scramble to confirm what’s real to the quiet, high-stakes decisions about when to bring in legal, what to preserve, and what never to say out loud too soon. Along the way, the panel shared war stories of companies that came back online too fast and got hit again, of evidence destroyed in the name of speed, and of executives forced to make consequential calls with only half the picture. What emerged isn’t a checklist so much as a portrait of two very different kinds of companies: the ones who prepared, and the ones who are learning everything in real time while the story is still unfolding. Generative AI (GenAI) was at the center of the conversation as a genuine turning point, not a magic fix, but a tool that’s quietly cut notification timelines nearly in half for teams willing to keep a human in the loop. Read the transcript below to learn why security keys need to be rotated even after a breach appears contained, and how outside counsel changes the questions an organization asks itself in the first 24 hours.
Expert Panelists
+ Anya Korolyov
Executive Vice President, Cyber and LDI Strategy, HaystackID
+ Gabe Landau
Senior Vice President – eDiscovery & Incident Response Solutions, HaystackID
+ Nate Latessa
Chief Revenue Officer, HaystackID
+ Michael Sarlo [Moderator]
Chief Innovation Officer and President of Global Investigations and Cyber Incident Response Services, HaystackID
[Webcast Transcript] From Breach to Legal Crisis: The Hours that Define Your Exposure
By HaystackID Staff
The call usually comes in the same way: a system that shouldn’t be down is down, or a file that shouldn’t be moving is moving, and within minutes an organization’s ordinary Tuesday becomes something else entirely. What happens next, who picks up the phone, who gets looped in, and how quickly, often matters more than the breach itself. That’s the premise behind this HaystackID webcast, hosted by EDRM, where moderator Michael Sarlo sits down with three people who have dedicated their careers to handling that exact moment: Anya Korolyov, Gabe Landau, and Nate Latessa.
Between them, the panelists have handled incidents ranging from quiet business email compromises to sprawling, multi-jurisdictional ransomware events with data scattered across dozens of systems and regulatory regimes. Korolyov brings the legal and data-mining perspective, having spent nearly a decade guiding organizations through notification and reporting obligations. Landau offers a front-row view of how technical teams, counsel, and panicked executives all try to move in sync, or don’t. And Latessa, drawing on more than two decades in information governance and privacy, makes the case that the real work of incident response starts long before any incident occurs, in the unglamorous business of knowing your own data.
What follows is a candid, occasionally unscripted conversation about the decisions that quietly determine how expensive, how public, and how painful a breach becomes. The panelists don’t offer a single formula, but a set of hard-earned instincts: preserve everything, document every decision as it’s made, resist the urge to declare victory too early, and treat data governance not as bureaucracy but as the fastest path through a crisis.
Watch the webcast recording and read the transcript below for their full discussion, including the mistakes they see organizations make again and again, and the small handful of things that consistently separate the companies that weather a breach from the ones still cleaning up a year later.
Transcript
Mary Mack
Thank you for joining today’s HaystackID webcast, From Breach to Legal Crisis: The Hours that Define Your Exposure. Hosted by the Electronic Discovery Reference Model. I’m Mary Mack, CEO and chief legal technologist of the EDRM. Today’s expert panel is moderated by Michael Sarlo, the Chief Innovation Officer and President of Global Investigations and Cyber Incident Response Services at HaystackID, and includes other HaystackID experts, including Anya Korolyov, Gabe Landau, and Nate Latessa. We are recording today’s webcast for future on-demand access. And as with all HaystackID webcasts hosted by EDRM, the recording will remain available on the EDRM global webinar channel throughout the next quarter to support your continued learning and reference needs. And before turning it over to Michael for a fuller introduction and the agenda, Holley Robinson of the EDRM will share a few brief notes on the webinar console. Over to you, Holley.
Holley Robinson
Thanks, Mary. If you look at the top of your screen, you’ll see the HaystackID logo, which you can click on to learn more about HaystackID. You’ll also see an option to contact Team HaystackID directly, along with speaker bios where you can learn more about today’s presenters. Moving down, you’ll see the Q&A box where you can type in your questions for today’s panelists, and we highly encourage you to do so. We’ll be answering questions during and after the webcast. Below the Q&A, you’ll find today’s resources, including the slide deck, a link to learn more about HaystackID’s cybersecurity services, and a link to register for HaystackID’s next webcast, Getting AI Right in eDiscovery: Quality, Validation, and Results, happening on September 23rd at 12:00 PM Eastern. We’d love to have you join us again. Lastly, you’ll see some emojis down at the bottom of your screen. Please feel free to use them and react throughout the webcast. Back to you, Mary.
Mary Mack
Thanks, Holley. And our moderator, Michael Sarlo, the chief innovation officer and president of global investigations and cyber incident response services at HaystackID works very, very closely with the team’s software development and data science teams and the clients to deliver best in class data collection, eDiscovery, and review solutions that allow legal teams to act on data types not normally conducive to collection review or production in the context of eDiscovery. He also leads a cross-functional team of HaystackID experts that regularly assist insurers, breach coaches, and their corporate clients when a breach occurs. And without further ado, Michael, please take us away.
Michael Sarlo
Thanks so much, Mary, and a special thank you to EDRM for hosting us today. Before we get started, even though this is a webinar, we’d love for these to be interactive. So please don’t be shy about asking questions, commentary. We’ll do our best to get them, usually live as they’re happening, or if for some reason we need to kick it to the end because it might just be more suited to, we will. So in short, don’t be shy because that’ll certainly make things a bit more fun. So kicking it off here, we’d like to introduce the rest of our esteemed panelists. I may participate a little bit as a panelist since I can’t truly resist. But first off, and most importantly, is Anya Korolyov. Anya, can you go ahead and introduce yourself, please?
Anya Korolyov
Hi everyone. Thank you for joining us. I’m Anya Korolyov. I’m the EVP of Cyber Incident Response and LDI Strategy at HaystackID. I’ve been in the industry for about 15, 16 years. Prior to joining the cyber incident response, I was focusing on antitrust investigations, second requests, and large litigation matters, and have been working exclusively in the cyber incident response matters for the last going on seven years now. I am a Relativity master. I am an attorney. I work very closely with DataBridge Council on formulating incident response, notification, and reporting with all the fun that comes along with it.
Michael Sarlo
Anya is also up for a Relativity Innovation Award in education and continuing education. She’s spent a lot of time working with different groups in the industry.
Anya Korolyov
Thank you, Mike.
Michael Sarlo
Gabe, you’re up next.
Gabe Landau
Yeah. Hey, thanks, Mike. My name is Gabriel Landau. I’m the Senior Vice President of eDiscovery and Incident Response here at HaystackID. I’ve been here for about nine years, and work really with counsel, corporate clients, and insurance carriers in cyberspace as it relates to navigating a complex landscape with the technical capabilities enhancing and changing all the time, the regulatory environment changing, [inaudible 00:05:21] US. I also help really navigate and keep calm in the storm and motivate the internal teams, as these are kind of really on the clock from day one and help navigate expectations and workflows. Prior to this, I was a reality TV producer. And happy to be here. Thanks, Mike.
Michael Sarlo
Gabe is also up for a Relativity Innovation Award for customer experience. Got a lot of innovators here at HaystackID. Last but not least is Nate Latessa. Introduce yourself, Nate.
Nate Latessa
Hi, I’m Nate Latessa. Yeah, Nate Latessa. I’m the Chief Revenue Officer here at HaystackID. I’ve spent more than 25 years working across eDiscovery, information governance, privacy, and cybersecurity. A lot of my focus today is on helping organizations connect those disciplines, especially around understanding their data before an incident, responding defensively to those incidents when something happens, and then managing the legal and privacy [inaudible 00:06:26].
Michael Sarlo
Thanks for that, Nate. And again, I’m Mike Sarlo, Chief Innovation Officer. By way of background, I’ve been with HaystackID pretty much since the dawn of time. Come from an IT background as well. And really from a discipline and technology standpoint, I’m a digital forensics examiner. And I’m blessed to work with the best team in the world here at HaystackID, solving complex cyber incidents. So let’s kick it off here. And a lot of our work at HaystackID, by the nature of things, is fairly reactive around cyber breaches. We have a robust preparation and pre-breach [inaudible 00:07:14] practice, but unfortunately, clients typically don’t fully engage here, oftentimes until they experience an incident. And so we see that with the way we deal with different organizations when they come to us when they’re experiencing a breach of various size and scale. And some organizations are more tuned to handle a business email compromise is their maximum limit. We see other organizations that can fluidly handle a ransom event. And like Nate, you spend a lot of time dealing with organizations in this vein on the advisory side. And so I guess what jumps out to me when I think about it is the different types of profiles we see. Two companies, they suffer essentially the same incident. One handles it calmly. The other is chaos. And I would say there’s always a little bit of chaos in any type of breach incident. What did the first company probably do over the past year or earlier that the second one didn’t?
Nate Latessa
Well, I think before the incident happens, incident response starts long before the incident. And the companies that successfully manage that have been prepping for these incidents. The ones that are positioned well to respond, they’ve already figured out who’s in charge, who has decision-making authority, when legal gets involved, who their outside counsel and forensics partners are, how issues get escalated during a breach, how decisions get documented, which is often overlooked, and how they’ll communicate if normal systems are unavailable. But one other thing I’d really add too that often gets overlooked in this whole process is that those companies that do well during response also understand their data before they’re trying to investigate an incident. So during a breach, one of the first questions quickly becomes what information was potentially accessed or taken? And if you don’t know where your sensitive information resides, who owns it, how long you’ve retained it, or what systems contain that information, that question becomes a lot harder and more expensive to answer. So from a privacy perspective, that matters because, look, the nature of the data can drive the entire response. PII, PHI, financial information, customer data, employee data, intellectual property, other sensitive information- it can all create a very different legal, regulatory, and notification consideration. So good governance isn’t bureaucracy during an incident. It actually creates speed. And good data governance gives you a much faster path to understanding your real exposure.
Michael Sarlo
Totally. Gabe, you’re oftentimes one of the people who is getting that first call. As you kind of hear Nate going through this, what do you wish clients knew before they ever had to call you?
Gabe Landau
Yeah. I mean, the biggest thing that we see is clients really don’t know what’s in their data. They’re just relying on custodial interviews still. And oftentimes the information that we’re getting is only top-line. And what we’re seeing in the data doesn’t match their expectations because humans are humans, and people say things and create information. And without enforcement of procedures and policies, then sometimes people go off channel with them.
Michael Sarlo
I’m like, Nate, what’s one decision you absolutely do not want people debating for the first time during the breach? Let’s assume they have an incident response playbook. They’re actually finally experiencing a breach. Where do you see things going most off the rails from a communication standpoint? We talk about preparation.
Nate Latessa
Yeah, I think a lot of that is just who’s in charge of what. During a breach, there’s a lot of chaos. You really need good lines of communication, knowing exactly who’s responsible for what, and making sure that all those communications are very coordinated so you’re just not overwhelming one person with this information. So I say to myself, that’s one of the most important things is good communication throughout that process and knowing who’s responsible.
Michael Sarlo
And so obviously there’s this tension, Nate, between an incident happens, and we know there’s an incident, but hey, we’re an active business. We need to keep servicing our customers. However, we need to make sure our customers’ data is safe and we aren’t actually creating more risks. So I think what we oftentimes get is some natural pressure from the executive team. The CEOs, my question is usually, are we safe? Can we keep operating? And the forensic team is saying, “Don’t touch anything yet.” How do you manage those competing instincts in the first few hours?
Nate Latessa
Well, look, I mean, you’ve got to make sure that you’re documenting everything. I mean, that defensibility is so critical through this whole process. But in order to make sure that you’re managing that appropriately, I would stress that tabletop exercises are crucial to this process because you’re going to run through that. You’re going to see a lot of these issues, and a lot of those are going to surface through that process. So you know what critical systems you have and which ones can be shut down. When does legal get involved? When do you notify the CEO? When does the board get notified? What happens if your email or Teams is compromised, and how do you communicate? Who communicates with customers and insurers and regulators and employees? All that stuff needs to be worked out well ahead of time. And that’s where I think the tabletops come in, and you can run through those scenarios and see exactly, like I said, where those gaps are and where you need to focus your time and energy on closing those.
Gabe Landau
Let me actually add one thing to that, in addition to everything you said. I think it’s not just checking the box that you have backup tapes or some backup systems that you could restore, but actually testing them on a regular basis that they work.
Michael Sarlo
One thing that I think I see too, obviously we want to confirm the incident. And I always tell folks, your internal IT teams, they may have their own kind of understanding of what an incident looks like. Don’t fully rely on that. It’s so important to engage expert outside firms because firms like HaystackID and others, highly reputable incident response providers, are in the field; they’re handling these incidents on a day-to-day basis. And the mechanisms and the way that these threat actors operate, they’re constantly staying ahead of the curve. So what was repeatable yesterday isn’t necessarily understood today. This is so true in the era of artificial intelligence, especially when we have open-weight models that the DeepSeeks of the world and whatnot are being weaponized when we start talking about zero-day vulnerabilities. And for anybody who doesn’t know what a zero-day vulnerability is, usually something that, in short, nobody’s seen before. And so really important to have that kind of stable of your incident response players built out really at the start of the incident. And preserving evidence is critical. And there’s some tension there between getting the business back up and running and up to speed as opposed to preserving evidence. One thing that I think a lot of organizations miss sometimes is they assume, hey, we’ve been breached, we’ve closed it out. When in fact, the dwell time of the threat actor was much longer than they think. And perhaps they’ve been in there, and they’ve been exfiltrating data. Most cyber incidents of significance that occur always come with some type of data exfiltration these days. Back a few years ago, organizations would be ransomed, and their IT operations weren’t that great at coming up quickly. So getting those business elements back online was a huge problem. And sometimes you had lost systems and critical systems. And organizations have become much more hardened in their ability to come back online even during a breach, with obviously fully replicated infrastructure, backups that come alive, faster cloud operations. What happens is they come up very quickly. They assume the dwell time is short. They assume there’s no exfiltrated data. And the biggest mistake they make is they do not rotate all their security keys fast enough. And they come back, the threat actors, weeks later, months later, and they hit you again. They hit you much, much, much harder. We’re seeing that a lot right now just in the community. And so really important that, even though you’re preserving evidence, you’re also protecting yourself and you’re changing all the locks. I think that’s a common mistake I see in all manner of enterprises. And of course, on the documentation side of things here, document. And this goes back to having good outside counsel relationships. We didn’t fully dig in here. And make sure that outside counsel is involved because privilege does matter. And there’s a lot of things that can go wrong. And it’s so important really to have a centralized manner in which you communicate with the outside world about the incident early on. Things that get leaked that are incorrect, these all create exposure. Saying the wrong thing early, it creates exposure and creates unnecessary anxiety. So really having that PR plan in place makes a lot of sense. Anya, on the subject of outside counsel, you work with so many different firms, big and small. What do you see that, really for corporate clients- corporations that suffer a breach where they already have their outside counsel tuned up, ready to go as part of their playbook versus an organization that’s going to be working with a new outside counsel for the first time running through a breach? And what are some elements of that? What do you look out for? Where do you know that you might need to fill in gaps? What works and what doesn’t?
Anya Korolyov
Yeah, I do want to mention something before the outside counsel gets even engaged that I think a lot of organizations forget and not necessarily remember to do in the moment, and that is to reach out to their cyber insurance or their insurance carrier overall. They might not have a cyber policy necessarily, but they might have some provisions, and their policies might dictate which outside counsel they can work with, which forensics vendors, and other types of vendors they can work with. And that’s very important because they might have spent a ton of money, and then realized none of that is going to be covered. So that is step number one. Outside counsel. I do agree that you should probably do that homework before, and that should be part of the plan. And based on our experience, the corporations that have an outside counsel lined up, that have done their homework, that have spoken to many firms, move through the incident with much less stress. A lawyer is not a lawyer that fits all needs. I might know privacy, but I cannot go and represent somebody in the divorce courts, obviously. So counsel for a corporation is a general counsel. They know enough to keep the matters moving. But a privacy counsel, a breach counsel that works in this area that knows exactly the pitfalls to look out for and the questions to ask is going to get you through the incident with much less stress.
Michael Sarlo
Totally agreed. And I think that’s a really important distinction. Not all outside counsel is tuned for running cyber response. And some firms that have a robust privacy practice to cyber response may not truly be engaged in an incident response on the regular. And so it’s really important, I think, to have your stable of outside counsel. And so we think about the containment stage of an incident, just we talk about we want to preserve. I think as we get into very large enterprises, SIMs, I’ve seen SIMs, I’ve seen logging in the petabytes of range as far as the amount of data that organizations are journaling in this day and age. And so really important to make sure that those logs are not falling off and to double-check. Because implementation is changing all the time. New systems are being added all the time. And so just like when we say in regular eDiscovery, some of the basics here really still matter. Make sure your logs aren’t rolling off. Make sure you have chain of custody around who’s accessing systems during a breach. Make sure that your cloud evidence, again, oftentimes cloud workloads can come and go with the needs of the business from a deployment standpoint. Make sure you’re snapshotting those things. Endpoint artifacts, super important. We start to get closer to where we think the breach has occurred or the modality. Actually preserving those endpoints in full digital forensics imaging beyond just your logs. And then documenting pathways around the entire way that you went and hit evidence, what you accessed, and who accessed it. This is all going to be important downstream in the event that there’s an investigation, there’s some type of regulatory investigation, or there’s some type of class action. Class actions are so much more common at the end of a data breach now. It’s a really great business for plaintiff law firms, and so they do come knocking. And so being extra bulletproof is so important here.
Nate Latessa
Can I just add one more point to that, Mike?
Michael Sarlo
Yeah, please go ahead. Yeah.
Nate Latessa
I agree on all that. I mean, documenting, retaining your logs, and making sure that you’ve got all that information. The other thing I think that gets overlooked in this process too is documenting decisions that were made during this whole process. Because the facts change and evolve as the incident happens. So you do want to capture things like what you knew and when, what decision was made, who made it, why they made that decision, what information supported it, and what assumptions are still being investigated. Because there are a lot of things during this process, like I said, you’re going to have facts, and you’re going to have to make assumptions. But from a defensibility standpoint, you want to make sure that all of this is documented because, again, it’s going to evolve. Things that you knew at 9:00 AM on the day of a breach could be very different by 4:00 PM. And it doesn’t necessarily mean that earlier decision was wrong. It means the decision was based on the information that was available at that time when you had to do something about it. And good documentation preserves all of that context. So six months later, nobody remembers exactly what happened at 2:00 in the morning, but that decision log becomes the institutional memory of that incident.
Michael Sarlo
Totally critical. Things change so quickly during a breach. And I’ve never seen a single large-scale incident that actually concluded the way it began whatsoever or what we thought about it. And sometimes those conclusions aren’t drawn for a year-plus. Gabe, you’re oftentimes kind of stuck in the middle. And I think when we get into the containment stage, outside counsel, a client, everybody has their own needs. Everybody is looking for something. How do you balance getting everybody on the same page during an incident and being that mediator? And what are some strategies that listeners can do to rein in solid project management workflows around this type of communication that Nate just mentioned and recording, obviously, decision tracking?
Gabe Landau
Sure. Yeah. I mean, I think what we’re talking about is ultimately a big part of it is almost like litigation readiness at the beginning of the incident. And I think when you’re thinking of the end goal or the end possibilities first, it helps ground the conversation and your workflows and decisions that you make from there. And a big part of it is almost, I don’t want to say you’re being like a therapist, but you have to have empathy. This is the client’s worst day of their life. You’ve done this a lot. And so people are looking to you for expertise or for us for expertise. So if we are freaking out, imagine being on a boat, and the captain starts freaking out; you’re going to freak out. But if the captain is cool, calm, and collected, no matter if a storm is coming, then you’re going to feel much better and at ease. And I think that’s kind of key to it. And giving everybody the ability to speak, but then also helping guide in a constructive way, not a destructive way, is very helpful. I mean, we deal with these all the time. And so rarely are events happening that we haven’t seen before. The only thing that changes is perhaps the regulations, the privacy regulations, the specific needs of the client in the case, and sometimes the data, but not even that so much anymore. So just understanding that you do this all the time. This is some people’s worst day of their professional lives is very helpful and grounding.
Michael Sarlo
Totally. And I find too, being the outside IT guy, that that can always be a challenge is getting the security professionals to trust us and see them as a part of our team and form those relationships. So I think those interpersonal relationships, you hit it on the head. This is oftentimes the worst day of some folks’ lives from a professional standpoint. And I think this opens up next [inaudible 00:26:03]. We’ve been talking a lot about the technical aspects, but the organization inside a breach that usually gets crushed more than anybody in this day and age is the legal department, as we see. I think there are a lot of legal teams that aren’t fully prepared for what this really looks like in a full company ransom event, take down, massive exfiltration. There are so many folks that are co-opted into the breach response, or it’s outside their job role just from a pure resourcing standpoint. And so we get this thing we see where technical teams are moving and going, and they have their own policies, and they’re moving through their own kind of playbook. But at a certain point, there’s a time where legal needs to get involved, and they usually need to be involved right away. Anya, what’s the danger in saying, let the technical team figure out what happened first and then we’ll call legal?
Anya Korolyov
Yeah. So I think Mike, you actually said something very important. Outside of the technical, there are so many parties involved in an incident response. And documentation is not just important to remember what happened six months from now, nine months from now; it’s also important 24 hours later. So you have the IT team, you have the forensics vendors, you have the counsel at the corporation, you also have the board. You have all kinds of parties at the company that need to report this sideways up. And that communication is always going to be slightly different because you cannot use the same language across all of these parties. So I think outside counsel is going to play the major role here in that they’re going to be able to drive all of this and keep it all in the format that it needs to be. So legal is not going to take over what the forensics response is. They’re going to work in parallel. So while the forensics team is looking at this, and they’re kind of asking the questions of what happened and how did the attackers get in and are they still in the environment, what is compromised, all of that, the outside counsel is going to ask very similar, different, but very similar and overlapping questions. So they’re going to ask questions phrased slightly differently. What information was potentially affected? What evidence supports that conclusion? What obligation might be triggered? What needs to be preserved? And the most important is what can we responsibly say right now? Outside of the pressures that Gabe just talked about, you also have the pressures of the outside world. Because it’s not just about the PII and the PHI. A lot of times it’s the reputation of the company. You could have a dentist that suffered an incident, but you could also have a company that supports something very public, or a county or a city. So there are a lot of outside forces that are playing a huge role. And for that purpose alone, you need to have legal advice. You need to have somebody watching the entire process and kind of overseeing. Yes, privilege is a concern. There is a difference between saying, oh, we have 10,000 records that got exfiltrated versus, well, generally what was taken. So there are a lot of questions that are happening by a lot of parties all at the same time, and you need counsel to drive that whole thing forward.
Michael Sarlo
I think you really hit on it too. You have just a myriad of reporting obligations depending on the organizations. SEC, US public companies, four days; they have to actually assess too if a breach is material. We see with NYDFS, 72 hours; GDPR, 72 hours; FTC, 30 days; HIPAA, 60 days towards a full notification. How do you balance knowing what your potential exposure is when you’re dealing with multi-jurisdictional breaches where you think maybe you’re being told by a client, “Hey, we only have data subjects in this geography, or here or there, we’d have no minors,” blah, blah, blah. How do you balance those, and how do you prepare for the evolving nature of the incident, and what are some gotchas there?
Gabe Landau
Anya?
Michael Sarlo
I think we lost her.
Gabe Landau
Oh, we lost Anya? Well, all right. So I mean, part of the balance, while she comes back, is technology, right? You need to have technology that can look, give you a quick peek into what is potentially affected, and the communication and tracking and reporting. It is mission-critical to have the feedback loop open and running between counsel and provider at every step of the day. So sometimes you have daily calls, could be multiple times a day, or weekly, wherever you are, depending on the stage of the incident. But importantly, to get a quick peek to understand it specifically with these very, very short timeframes is really important. Also, relying on counsel to say when the clock starts, preparing the data for when you’re actually going to run the analysis, that becomes a real strategic decision as well.
Michael Sarlo
Totally. I think too, understanding your contractual obligations as well with your partners and your customers, that’s a critical exercise that oftentimes should be taken at really the pre-breach stage as you’re preparing and hardening. I see this as folks really trying to understand their reporting obligations, especially in a consulting setting or a law firm setting or a professional services setting where contracts vary so much from a kind of a relationship standpoint. This is usually something we see right away. Where we kind of start as well is we want to get a sense of our client’s customer list. Who are they? Where are they located? Where are your business people doing business? Super important. And that oftentimes will inform our thinking around more potential exposure. And then we start to prepare the client that we find, as Nate will tell you, most clients don’t know what’s in their data, or where their data is, or they know a piece of it. And usually we find that exposure is greater than they think. And so I think it’s really important to set expectations early on at the outset that we need to be casting a wider net. And Gabe, you mentioned a great piece. Technology, so critical. We live in a world where we can understand data, process data, know what’s out there faster than ever. Nate, you’ve kind of been doing this for quite a while. How has the technology changed just even year over year? And what was this like five years ago? What’s it like today? What do you see coming? What do you wish you’d had? Those types of- I’d love to get your feedback.
Nate Latessa
Yeah. I think, look, understanding- we’ve talked about this several times here- knowing what sensitive data you have, where it’s located, who has access to it, all those things. I mean, this is a blind spot for most organizations. And when you ask people in the organization who knows where that is, folks will sometimes point to the security folks like, well, they protect all our data, they must know where it’s at. Well, if you ask your cybersecurity team where our critical sensitive data is, I bet you’ll get different answers from all of them. Some will talk about where PII might be located, and they’ll talk about big systems, like if you have an HR system like Workday or SAP or something like that. That obviously contains that data. But there are other places in the organization that they really, it’s a blind spot. They’re not monitoring this stuff. They’re not looking for it because they don’t have the tools really to do that proactively. A lot of the tooling that cyber has is very reactive. They only get notified of sensitive data moving within the organization if it hits something like a data loss prevention filter, like it was emailed out or it moves from a file share to somewhere else. So it’s a massive blind spot. And in the past, I mean, we didn’t really have systems that you could analyze this data, at least economically. It was so expensive because we stored so much data. A lot of organizations have poor data retention policies, so data just piles up and grows at something like 65% a year. And without systems that are analyzing that data, it’s tough to say where that is. Today, I think now with AI, you’re starting to see more organizations being proactive about classifying data in place so we can understand where financial documents are, customer lists, PII, PHI, but other things that aren’t necessarily RegExable. Things like, like I said, intellectual property. And with the AI tools getting better and more economical, you’re seeing a lot more of that tooling being used to proactively classify this data. Data classification is the holy grail. Once you’ve classified it, now I can find it, track it, tell you everything about that data in near real time. And I think you’re starting to see more organizations that are investing in classification because of the tooling that we have available today.
Michael Sarlo
Totally. And we’re of course leveraging… Oh, let me ask a question. Is there a different approach when a client has a closed AI system versus open-source uses? From Mark Seltzer. So yes and no. I think that it really depends on the capabilities of the AI system and how it’s deployed. We see various implementations of artificial intelligence being used inside organizations. You have data classification capabilities that are built right into M365, and those have their own limits and costs for sure. Some of these aren’t cheap to run, especially depending on the models. We start thinking about closed-loop systems. We start to have to ask: to what level have they been trained? How smart are they? How reliable are their results? This is really for any AI system, but when we get more specific, closed systems that may use more machine learning-type capabilities around classification, I find those to be more risky than full summarization of concepts. And so it really just depends. It’s tough. Everything is kind of a flexible approach based on that system, and where it fits into an organization’s workflow for leveraging tooling that already lives behind their firewall.
Gabe Landau
I mean, but what we’re actually talking about-
Michael Sarlo
Yeah, go ahead.
Gabe Landau
…big time is AI governance. I mean, it is massively important when we’re talking about how to understand, again, where your data is, how it’s being used, who’s handling it and all that. AI governance is really, really important and still playing catch-up right now as folks are deploying at a rapid pace because of all that’s happening in the zeitgeist of our culture. So it’s a really good question, and I think it has to be flexible, depending on how it’s deployed.
Michael Sarlo
Totally needs to be flexible. And we could do a whole other discussion on just securing AI agents and classification around AI. I mean, this whole classification element is so critical to any modern organization as they deploy AI. I mean, you keep frequently hearing that the data layer is the most important layer as it relates to getting any value out of AI. It’s your own data that makes AI sing. Once you get it classified, as Nate mentioned, it’s the holy grail. And so the strategy for business owners or for folks that are working with different stakeholders in the organization is to get this data governance around from a cyber incident standpoint, is to really understand, yes, this does cost money, but you get all this other value when you start going through classification for the business beyond just knowing where your data is for breach. It opens up a whole new world of data pathways and analysis and business intelligence beyond just securing your sensitive data and reducing your exposure during an actual breach. And so there is a point in time when cyber incident response meets eDiscovery, and it meets eDiscovery right away in almost every case. And because in most scenarios, they’re large-scale events. There are certain times when smaller events are closed, they’re contained, somebody got in that didn’t really meet the level where we’re expecting litigation. But for larger events, there’s always the reasonable expectation of litigation. So when we start talking about litigation resonance, we need to be prepared. We need to know what we could be probed on, who could be coming at us besides plaintiffs, the government, and law enforcement. A lot of that goes into PR strategy, how you documented it, and legal holds. Legal holds extend beyond just why we did something. It also includes all of your internal communications, the text messages with Nate, the Slack communication with the security team, the emails with the third-party vendors, the emails between the board and different investors and stakeholders. These all become discoverable. And so again, having an internal communication strategy with how you handle any type of crisis, in particular for a breach, is super important, in addition to making sure that you get those legal holds out there soon enough, and not assuming that your burden for maintaining a legal hold ends when you believe it. We oftentimes find that these have a longer shelf life than a typical matter. And so that’s just something that we think about from a legal hold standpoint. Anya, you want to touch on data preservation, especially how we work with data sets coming from a client’s firewall versus from a threat actor. What does that look like when we get data from a threat actor or a leak site? How do we work with that data? How does that all tie together? Walk us through this process.
Anya Korolyov
Yeah. Yeah. Every incident is, of course, different. Sometimes we’re lucky enough that the corporation was able to contain it and they know exactly what was taken, and then we can just take the data from them. Sometimes not so much. Sometimes we have to pull the data from the dark web. As Mike mentioned, all of that is evidence down the line. All of that is going to become important during the litigation, and litigation could happen years from now. So documenting where the data came in, how it came in, where it lived, and what was done with it? We always scan the data, make sure that we’re catching all the potential threats in the data as well. All of that needs to be completely preserved and documented. The entire chain of custody of the data needs to be preserved and documented. Generally speaking, sometimes the threat actor just provides a list of files that they took, and we have to go in and collect. And again, every incident is different. Some incidents, the threat actor got in, took some data, reached out, said, “Hey, I have your data. Here’s kind of proof of life.” And that’s almost easier. Sometimes they halt their operations, and the forensics team has to get involved. Again, the variations of incidents are vast. And the most important thing is to preserve all evidence and preserve every single step that was taken.
Nate Latessa
Can I jump in real quick on there too? Because I think just to add on to what Anya’s saying, and one thing that I see that gets overlooked is that there’s a lot of pressure during an incident to move fast. And sometimes teams move so quickly to remediate that they destroy information that they need to investigate the incident later. And that’s problematic when you’re trying to determine whether data was actually accessed or exfiltrated. Without that evidence, you may have to assume a broader population was impacted because you can’t prove otherwise. So preservation isn’t just a forensics issue. It can directly affect privacy analysis, notification scope, and the overall cost. You can always decide later that you didn’t need a piece of evidence, but you can’t create evidence that’s gone.
Michael Sarlo
That is so true. And it’s just critical that preservation piece. Because the majority of your cost exposure comes from notification, which is why you need really good data mining that’s defensible. Anya, Gabe, can you talk a little bit about what post-incident or that notification face looks like? Since Nate just touched on it, we see a lot of exposure around actually understanding who was impacted, not how. What does that process look like, and where does it mirror standard eDiscovery processes and where does it differ?
Anya Korolyov
Yeah. It is very similar-
Gabe Landau
You can go ahead, Anya.
Anya Korolyov
…to eDiscovery. Sorry, Gabe, go ahead.
Gabe Landau
No, I said I was giving it to you, and I’ll add in color.
Anya Korolyov
It is very similar to eDiscovery. We collect the data, we process the data, we unpack it, we analyze it for privacy or business-sensitive information. We extract information from the data. And from those extractions, we create a draft notification list. And then if there are third parties, we’ll go and notify the third parties, let them make a decision whether they want to notify their impacted individuals. We also create, kind of, I’m going to use heat maps. Outside of just answering, okay, let’s notify the people. Let’s make sure that everybody who needs to know that this incident happened, their data’s out there; let’s do that. But also, this is a great situation- great is not the word I want to use- but this is a good situation where the company can use all of our efforts in the data mining to map their data for future potential incidents or for what have you. Many times we deal with companies that know their data so well. They know exactly what happened. The one thing that they forgot is they acquired five other companies, and they haven’t had a chance to map out their data, and they haven’t had a chance to take inventory of that data. So they have no idea what’s in there. So, well, now we know. And my one kind of big advice always is: let us map the data for you. Let us give you that feedback back outside of just this draft list that you’re going to use for the letters to be sent out. Let us do a full overview of your data for you so that you can use that later. Gabe, anything?
Michael Sarlo
Gabe, did you want to add anything?
Gabe Landau
Yeah, I was just going to say, I’d say there are some similarities, but the biggest difference is, of course, the end product, work product, which is going to a notification list as opposed to having to produce to another party and searching something for responsiveness. But this process is changing as we speak. Technology’s being brought in much earlier in the process to help really surface insights much more quickly than ever before. And I think it’s really important that we still have the best practices that we take from what Anya was describing with quality assurance, with human in the loop, with a de-duplication process that is repeatable, with a normalization process that can be interrogated. Because at the end of the day, yes, it’s a notification list, but you still want to be able to defend and attest to the process. So gone are the days of just a notification list. Now it’s regulators- very sophisticated regulators or aggressive plaintiff counsel- questioning how you arrived at that notification list. So while everything is speed and accuracy, it has to be fully, fully attestable and defensible.
Michael Sarlo
So not only do you need to document everything about the breach and how you arrived at different decisions, and all your communications and work product and logs, and every critical piece of evidence is a common theme here, but you also need to be documenting your entire data mining process. And so for folks who aren’t familiar with the word data mining, this is the process of looking at documents in eDiscovery context to extract basically the who and what was taken and where they’re located. So we could send them the lovely letter that we all have gotten probably 100 times now from various companies that have our personal data where they get breached that offers us some credit monitoring and a number to call with a nice kiss. And this is what we say when we refer to data mining. It needs to be documented. And I see a lot of insureds and even counsel not put enough attention into this process. And the smart carriers are waking up because their class action risk is starting to completely outperform their actual data mining and notification costs. So they want better work product. And how this has really changed even in the past year is that generative AI has made this process much easier. HaystackID acquired eDiscovery AI and has our own AI as well, like Protect Analytics that we use for sensitive data detection, normalization, and large document extraction. We’ve been able to marry these technologies. And the response time on an incident where we were- it was a nail-biter. Can’t tell you how many nail-biters on a HIPAA-covered event that we experienced. We’ve never missed a notification deadline, surprisingly. And we’ve done some really big events that are multi-jurisdictional. And our ability to complete incidents is probably about almost 50% faster with the use of generative AI. And also now to really understand what’s in that data. And this is something too, even for smaller data breaches, business email compromises where, Nate, you made a really good point earlier. The lack of evidence in a breach can obviously leave you with significant exposure. And so organizations sometimes, especially when we deal with email inboxes where you know something was accessed, but email just doesn’t have that same level of auditability around reads and individual message access that we would like as opposed to file systems and those types of events. Being able to use GenAI to draw out insights about the persons and who they’re communicating with and thinking beyond just around the personal data and the business sensitivity and the business-sensitive data, it’s been hugely impactful for our clients. Especially when we may even think about, hey, you know what? We’re so focused on personal data. Is there a critical IP that’s been taken? And it’s not uncommon for what appears to be a personal data, data shaming, the extortion event, could actually be a cover for what’s more of a complex IP theft exposure. So never ever think that IP isn’t something that threat actors are looking for and exploiting. And so something that I always try to remind people is that don’t forget about your actual IP and if it’s valuable to a third party. So we do have a question here from Rob Robinson. And Nate, maybe you could field this one. Once data is classified, how challenging is it to maintain that classification throughout the remainder of the information lifecycle?
Nate Latessa
So I guess the short answer is it’s getting easier. It’s still difficult. When you look at some of the classification technology, say five years ago, they were usually bolt-on third-party applications. They would have limited connectivity to where that data might travel. And usually that one system was the system of record. And if a piece of data moved outside that system, it would lose that classification. Now with M365, G Suite, a lot of these applications, that data is contained. If it’s contained inside that ecosystem, it’s a lot easier to track that. Also, some of the security tools are starting to evolve where they can read those things too. The new DLP term is data security posture management, where we’re analyzing that data in place and as it goes into motion, some of those can read those classifications and track that as it moves between those systems. So it’s not perfect right now, but it’s a lot better than it was.
Michael Sarlo
So much better. I think the ability for modern-day AI tooling to have stable and repeatable taxonomies. It used to take so much time to create these classification buckets. I’m seeing in my practice that, with different tooling, it’s much easier and useful to set up individual taxonomies that are unique to a specific organization, the way they do business, and the way they want to classify their documents broadly. I think of the clustering wheel, so to speak, that we’re all familiar with. And having to have those kinds of taxonomies persistent. So when new data is created or moved, they tend to fall into those buckets. So I think that’s where modern-day AI systems have really leapt from a repeatable standpoint. We talk about retraining. We have a great question from Melissa Heidrick. Hi, Melissa. I didn’t know you were on here. Nice to see you. GenAI workflows, useful in data subject list creation and aggregation. Anya?
Anya Korolyov
Absolutely. The keyword there is speed. So generative AI is really escalating the speed at which we can move the data and how quickly we can normalize and to duplicate that data. It doesn’t change the size of the data. It doesn’t change the output. But it most certainly escalates the speed with which we can grab the full individuals and all of their information. It really has come quite a long way in the last, I would say, two years. It’s quite remarkable from what we saw two years ago, the results we were seeing, to what we’re seeing today. The mapping is accurate. It’s grabbing all the most difficult documents that we used to struggle with, even with humans: your bad PDFs, your handwritten documents. So it really has come quite a long way, and I’m very impressed with the accuracy of it. Very happy it’s here, especially in the cyber incident situation.
Gabe Landau
And I would say where we’re seeing it really create massive efficiencies in terms of speed and accuracy is in the structured data field also. I mean, there’s this really big Salesforce or third-party Salesforce incident this year. And these become, historically, previously, this would’ve been extraordinarily challenging, laborious, and costly to get through. And we’ve crafted the workflow using technology and insights and workflows from Anya and her team where you’re taking the… Because it’s the free text fields that are the challenge. And having that go through GenAI really has been extremely valuable.
Michael Sarlo
Let me add, though, that there is a cost associated with GenAI. And so token analysis and understanding is much less expensive than extraction of data out into a useful format. So when you start thinking about triaging a 15, 20 million notification list, it can get more expensive than you think to get clean data with an audit trail out of it. And so human in the loop is still so important when you leverage these tools. That’s the biggest thing. There is no autopilot for any of this, and it’s great. So we’re just about at the top of the hour. I’m going to just say for the group, final closing question, and this is a 30-second rapid fire. We’ll start with Gabe, Anya, and Nate. So tomorrow morning, someone watching this goes back to their organization and can fix exactly one thing before the next incident. What would each of you tell them to fix?
Gabe Landau
Classify your data.
Michael Sarlo
Got it. Anya?
Anya Korolyov
Documentation. Documentation is everything.
Michael Sarlo
Nate?
Nate Latessa
Yeah, look, most of the mistakes that increase your exposure aren’t because everybody’s not working hard to resolve the incident. It’s usually because the organization didn’t have the governance, data visibility, and decision-making structure in place beforehand. So the better you understand your data before the incident, the more confidently and defensively you can respond after one.
Michael Sarlo
For me, it would be practice, practice, practice. Tabletops, having IR playbooks that are actually vetted, and making sure that individuals are empowered so they’re not trapped in a 200-page playbook that doesn’t actually do anything. Actually make sure you have operationalizing documents, and you have the right people picked out to be leaders in their domain. So thank you all. Really appreciate it today. And hopefully you guys found this informative. Please feel free to reach out to the HaystackID cyber team at [email protected] or [email protected]. We are happy to answer any questions for you. And with that, I’ll kick it back off to EDRM. And of course, thank you to our panelists. And if you can, vote for Gabe and Anya for the Relativity Innovation Awards. Thank you.
Mary Mack
All right. With that political endorsement, we will say thank you again for joining today’s HaystackID webcast. And thank you to our panelists for sharing your expertise. And before closing, please mark your calendar for HaystackID’s next webcast, Getting AI Right in eDiscovery: Quality, Validation, and Results, happening on September 23rd at noon Eastern. You can find the registration link in today’s resources, and we hope to see you there. And on behalf of EDRM, sincere appreciation is extended to you for your participation today, and wishing everybody a productive day. Thank you.
Expert Panelists
+ Anya Korolyov
Executive Vice President, Cyber and LDI Strategy, HaystackID
Anya Korolyov, the Executive Vice President of Cyber Incident Response and Advanced Technologies Group at HaystackID, has 18 years of experience in the legal industry as a licensed attorney, including 15 years of experience in eDiscovery, focusing on data mining, complex integrated workflows, and document review. In her role at HaystackID, Korolyov works on developing and implementing the strategic direction of Cyber Incident Response. She is one of the industry’s leading experts on Data Breach Incident Response, Notification, and Reporting, with a solid understanding of machine learning, custom object development, regular expressions manipulation, and other technical specialties.
+ Gabe Landaua
Senior Vice President – eDiscovery & Incident Response Solutions, HaystackID
As the Vice President for eDiscovery and Incident Response Solutions at HaystackID, Landau’s professional focus lies at the intersection of law and technology, where he brings his expertise to deliver practical, defensible, and cost-efficient approaches for clients’ eDiscovery and Cyber Discovery requirements. Prior to his work in the legal sector, Landau garnered experience as an Emmy Award-Winning Producer and Director in the realm of reality TV. His achievements extended to receiving accolades such as the Telly, Davey, and Webby Awards. Drawing from his diverse background, Landau seamlessly integrated his skills into the legal field, enhancing client experiences in the legal sector through the application of advanced technology. He graduated Cum Laude from Ithaca University with a Bachelor of Sciences degree.
+ Nate Latessa
Chief Revenue Officer, HaystackID
Nate Latessa is the Chief Revenue Officer and Executive Vice President of Advisory Services at HaystackID. With over two decades of experience, he is a prominent figure in information governance and eDiscovery. Latessa has been instrumental in devising strategies for effective eDiscovery and information management, aiding corporations and law firms in handling electronic evidence. His expertise in using advanced eDiscovery tools has streamlined litigation processes, while his understanding of data and legal compliance has distinguished him in the field.
+ Michael Sarlo [Moderator]
Chief Innovation Officer and President of Global Investigations and Cyber Incident Response Services, HaystackID
Michael Sarlo works closely with HaystackID’s software development and data science teams to deliver best-in-class data collection, eDiscovery, and review solutions that allow legal teams to act on data types typically not conducive to collection, review, or production in the context of eDiscovery. Sarlo works closely with clients on the most challenging and complex regulatory, investigative, and civil litigation matters. Sarlo also oversees HaystackID’s Cyber Discovery and Incident Response Services division. He leads a cross-functional team of HaystackID experts that regularly assists insurers, breach coaches, and their corporate clients when a data breach occurs.
About HaystackID®
HaystackID® solves complex data challenges related to legal, compliance, regulatory, and cyber requirements. Core offerings include Global Advisory, Cybersecurity, Core Intelligence AI™, and ReviewRight® Global Managed Review, supported by its unified CoreFlex™ service interface and eDiscovery AI® technology. Recognized globally by industry leaders, including Chambers, Gartner, IDC, and Legaltech News, HaystackID helps corporations and legal practices manage data gravity, where information demands action, and workflow gravity, where critical requirements demand coordinated expertise, delivering innovative solutions with a continual focus on security, privacy, and integrity. Learn more at HaystackID.com.
Assisted by GAI and LLM technologies.
SOURCE: HaystackID