A useful tabletop exercise is uncomfortable. Participants say aloud that the backups were never tested, that no one owns vendor notification, that the CISO and the general counsel disagree about when to involve law enforcement. That candor is the point of the exercise. It is also the risk.
Everything recorded during an exercise can become evidence. If a real breach follows, a plaintiff or a regulator may seek the after-action report, the risk memo, and the notes. A document stating that detection was known to be weak is not a document any organization wants read aloud in a deposition. The question every serious program has to answer is whether that record can be kept confidential, and how.
Two protections, one goal
Two doctrines can shield security work from discovery. They are different, and the difference matters.
The attorney-client privilege protects confidential communications between a client and its lawyer made for the purpose of seeking or providing legal advice. It does not protect the underlying facts, and it can be waived by sharing the communication with the wrong third parties. The work-product doctrine, defined for federal cases by Rule 26(b)(3), protects materials prepared in anticipation of litigation, whether by counsel or by a non-lawyer at counsel's direction. A tabletop exercise run to improve operations is ordinary business activity. A tabletop run at the direction of counsel, to help counsel advise the organization on legal exposure, has a far stronger claim to protection.
The distinction is not a formality. Courts examine why the work was done, who directed it, and who saw it. When the honest answer is that an organization runs the exercise every year to improve, that is a business purpose, and the privilege claim is thin.
What the forensic-report cases teach
The clearest guidance does not come from tabletop disputes. It comes from a line of data-breach cases in which companies tried to shield post-incident forensic reports and lost. The same doctrine governs the records a tabletop produces, so the reasoning transfers directly.
The most cited decision is the Capital One breach litigation in the Eastern District of Virginia. A federal magistrate judge ordered Capital One to produce a forensic report prepared by Mandiant, rejecting the argument that the work-product doctrine shielded it. The court relied on a few facts. Capital One had a pre-existing statement of work with Mandiant that predated any litigation, the engagement was paid as a business expense rather than a legal one, and the finished report was distributed widely, reaching dozens of employees, four regulators, and an outside accounting firm. The court concluded the report would have been prepared in substantially similar form whether or not litigation followed, which defeated the claim.
Two more decisions reinforced the pattern. In Guo Wengui v. Clark Hill, the District Court for the District of Columbia ordered production of a forensic report even though the firm had used a two-vendor structure meant to separate business response from litigation preparation. The report failed the test of whether it was prepared because of anticipated litigation. In In re Rutter's, a magistrate judge in the Middle District of Pennsylvania reached the same result, quoting the vendor's statement of work, which described the purpose as determining whether a compromise occurred and the scope of any compromise. Because the company could not say it believed litigation would result at the time it engaged the firm, the court found litigation was not the primary motivating purpose.
Courts have protected reports when the structure genuinely supported a legal purpose. In the Target and Experian breach matters, a real two-track approach, or delivery of the report to counsel alone rather than to the response team, preserved protection. The through-line across all of these decisions is consistent. Protection turns on substance, not on form.
Where privilege breaks
Organizations lose these disputes more often than expected, and the reason is almost always the same. A lawyer is added to the chain, and the organization assumes that converts operational work into legal work. It does not. Privilege follows what the work was actually for and how it was actually used.
The recent trend has made the standard harder to meet. Commentary tracking the case law through 2025 describes courts growing more skeptical of privilege claims over breach investigations, in some instances scrutinizing communications simply because a forensic firm was copied on them. A 2025 decision in Australia involving Medibank ordered production of several vendor reports after finding that legal advice was a purpose of the reports but not the dominant one. Different courts apply different tests, and a claim that succeeds in one district can fail in another on similar facts.
The remediation tension
A quieter risk deserves a direct answer. Running security work under privilege can create pressure to treat findings as legal artifacts rather than engineering tickets, which can slow remediation. Privilege protects the candor of an assessment. It should never become a reason to leave a known gap open. The cases point to the discipline that resolves the tension. Courts look hard at whether a report was used for business, governance, or regulatory purposes, so a program should separate the legal analysis from the operational fix and close findings on the operational track while preserving the confidential legal record on its own.
How an exercise stays protected
A few practices matter most, and each maps to a fact the courts have weighed.
- Counsel directs the exercise, in writing, for the purpose of advising the organization on legal risk. The engagement should exist before the exercise, not be reconstructed after an incident, because a pre-existing business engagement is what sank the claim in Capital One.
- The confidential record stays confidential. Distribution is limited to those who need it for legal decision-making, privileged materials are marked, and the risk memo is not forwarded across the company. Wide distribution is repeatedly what waives the protection.
- The legal analysis is separated from the remediation task list. The finding that a vendor notification process is undefined can live in a privileged memo. The ticket to build a vendor notification runbook can live in the open, because it is an operational task, not a legal conclusion.
- Incident escalation to counsel is fast. When counsel is engaged early, counsel can direct any assessment work, define its legal purpose, and set the circle of trust that receives privileged material.
- Participants are trained on the ground rules before they speak. A room that understands the discussion is candid and confidential produces better information.
The record is the asset
A tabletop exercise operated as legal work product produces a risk memo, an after-action report, and facilitator notes that support counsel's advice rather than sitting in an operations folder. That structure is the difference between a record that strengthens an organization's position and a record that becomes a roadmap for a plaintiff.
Privilege is not automatic, and it is not a substitute for legal advice about a specific situation. Privilege determinations rest with counsel and turn on the facts of each case. A well-designed program makes the defensible path the default path, so a team gains the candor of an honest assessment without creating a discoverable map of its own weaknesses.
