Recently, Array and Relativity came together for a practical discussion on one of the most challenging periods in incident response: the first 30 days after a data breach.
The conversation brought together legal, review, and technology perspectives to explore how teams can move from incomplete information and mounting deadlines to reliable, defensible answers. Throughout the discussion, one theme remained consistent: the goal isn't simply to move faster. It's to get to the right answers sooner, while building a process that can withstand scrutiny later.
For those who couldn't join us live, we've distilled the key themes and takeaways from the conversation.
The webinar featured experts from Array, Relativity, and Norton Rose Fulbright:
One of the strongest themes throughout the discussion was the importance of upfront scoping and triage.
Breach data is rarely a clean collection of emails waiting to be reviewed. Matt described datasets containing everything from XML and unfamiliar file types to proprietary HR systems and structured data that may require very different approaches to analyze.
Before launching into full review, teams need to understand what they're dealing with:
That upfront work can ultimately accelerate the response rather than slow it down.
As Matt and Imran both emphasized during the discussion, taking time at the beginning to understand the objectives, data, search strategy and intended outputs can prevent costly rework later.
The panel also explored how technology can provide useful intelligence before full review begins.
Hannah explained that once data enters RelativityOne, teams can begin enriching the dataset and identifying directional insights, including document summaries, potential personal information, and concentrations of sensitive content. This early intelligence can help teams determine where human review is most needed and where large portions of the dataset may not require full review.
In fact, Hannah noted that in typical breach matters, only around 5–20% of the original dataset may ultimately require review, meaning that up to 80% or more may not be relevant to the core review objectives.
That early visibility can also help counsel make decisions in parallel.
Initial information about data types, language, geography, and potential exposure can help legal teams anticipate jurisdictions, resource requirements, communications, and potential regulatory obligations while the more detailed review continues.
Rather than waiting for one complete answer before beginning the next step, teams can start parallelizing the response.
The composition of breach data itself is also changing.
The panel discussed the growing prevalence of images, scanned forms, handwritten information, voice messages, videos, and other content that historically required significant manual effort to review.
Hannah highlighted newer AI capabilities that can analyze image-based and handwritten content, including structured documents such as forms, scans of passports and driver's licenses, and handwritten notes.
The significance goes beyond simply finding sensitive information.
The real objective is to connect information to the right individual and the right context. As Hannah explained, identifying personal information is one step, but linking that information to an affected individual is what allows teams to move towards actionable notification decisions.
Another important takeaway was that breach response isn't always just about identifying personal information for notification.
The same dataset may also contain sensitive business information, intellectual property, source code, credentials, or other confidential material that creates a different type of risk.
Hannah described examples where teams may need to identify things such as source code or API keys as part of the response. Those findings can require immediate business action even when they don't relate directly to individual notification.
That can create multiple workstreams within the same incident, each with different objectives and review requirements.
The panel's broader point was that teams need to understand what they're looking for and why before applying a single review methodology across an entire dataset.
Perhaps one of the most important legal takeaways from the discussion was that defensibility isn't about having a perfect answer immediately.
Imran explained that clients can sometimes feel pressure to leave “no stone unturned” and produce a perfect output as quickly as possible. In practice, the focus is on being able to demonstrate reasonable effort and a sound methodology.
That means documenting how the data was ingested, how different types of content were processed, where technology was used, where human review was introduced, and how findings were validated.
The process should also be able to accommodate new information.
As the panel discussed, breach investigations can evolve as new information surfaces. A defensible workflow needs to make it possible to revisit findings, reconcile new information, and understand how previous decisions were reached.
The panel also addressed one of the risks that can arise when teams are under pressure: over-notification.
Imran described the decision-making process as having a clear-notifiable category, a clear-not-non-notifiable category, and a more complicated “grey zone” where context, aggregation, and jurisdiction can affect the outcome.
That is why early intelligence and careful review methodology matter.
The objective isn't simply to produce the largest possible notification population. It's to give counsel enough reliable information to make the right decision.
By the end of the discussion, the panel outlined a consistent approach to navigating the first 30 days:
The panel also returned to one simple idea: the time spent getting organized at the beginning can ultimately save significant time later.
As Imran put it, teams should resist the instinct to simply “go fast” if doing so creates rework. Refining search terms, conducting spot checks, aligning with the review team, and understanding the tools upfront can materially accelerate the overall response.
Matt reinforced that point with a practical example from the review side. Historically, breach review could involve approximately five to 10 documents per hour. With more upfront organization and the use of AI-assisted technology, the team has seen review rates of approximately 30 to 40 documents per hour when documents require review.
A strong breach response isn't about eliminating uncertainty. It's about creating a process that can operate effectively because uncertainty exists.
The first 30 days require legal strategy, data intelligence, technology, human judgment, and clear communication working together. When those pieces are aligned, teams can move from incomplete information to increasingly reliable answers while maintaining the documentation and defensibility needed to support those decisions later.
The goal isn't simply to complete review faster. It's to help legal teams get to reliable, defensible answers sooner, while the clock is still running.
Watch the full First 30 Days After a Data Breach webinar on demand.