Advice built around the complete record.
A cyber incident can become a legal, operational and government matter within hours. The first decisions—who leads, what is preserved, whether systems are isolated, how facts are recorded and which authorities or partners are notified—shape the investigation that follows. We establish a privileged response structure while technical teams contain the event and determine what actually occurred.
The practice handles ransomware, business-email compromise, insider events, data exfiltration, vendor compromise, payment diversion and attacks affecting compliance or screening systems. Counsel defines the forensic questions, coordinates evidence preservation, reviews communications and maps notification or cooperation duties. For financial institutions and payment businesses, the response also considers suspicious activity, fraud, sanctions, information sharing and regulator expectations without exposing protected information.
Outside an incident, we advise on data inventories, retention, access, vendor terms, cross-border transfers, privacy notices, incident plans, tabletop exercises and board governance. The objective is not a policy library. It is a system that identifies sensitive data, limits unnecessary access, produces reliable evidence and assigns decisions before pressure is highest.
Who we advise
We advise banks, fintechs, crypto businesses, charities, NGOs, technology providers, boards and executives. Incident response is tailored to the organization’s systems, jurisdictions, customers and government relationships. A global payment platform and a humanitarian organization face different data, safety and continuity consequences.
The legal team works with qualified forensic, communications, insurance and local-law advisers through defined scopes. Technical findings are translated into facts that decision-makers can use, while uncertainty remains explicit until evidence supports a conclusion.








