Debevoise & Plimpton’s Data Strategy & Security (DSS) team is pleased to contribute to the Legal 500 Country Comparative Guides: Data Protection & Cybersecurity with a new “Hot Topic” chapter examining key cyber trends and critical legal considerations for incident response.

In this chapter, the team explores how the cyber threat landscape evolved through 2025 and what organizations should expect in 2026. The discussion highlights the increasing prevalence of disruptive ransomware attacks, the growing use of AI – including deepfakes – in sophisticated fraud schemes, and the continued targeting of help desks, senior executives, and remote IT workforces. The chapter also provides practical, business-focused mitigation steps to help organizations strengthen resilience against these risks.

A second section addresses a developing issue: how to preserve attorney-client privilege and work-product protection in cyber incident response investigations. Drawing on recent U.S. case law, the authors outline the factors courts consider when evaluating whether incident response reports are protected, and offer concrete guidance on structuring investigations to maximize the likelihood of maintaining those protections.

Together, these insights underscore a central theme: effective cybersecurity today requires not only technical preparedness, but also careful legal planning – particularly in light of the significant litigation and enforcement risks that often follow major cyber incidents.

Read the full text of the article here.

***

To subscribe to the Data Blog, please click here.

Author

Luke Dembosky is a Debevoise litigation partner based in the firm’s Washington, D.C. office. He is Co-Chair of the firm’s Data Strategy & Security practice and a member of the White Collar & Regulatory Defense Group. His practice focuses on cybersecurity incident preparation and response, internal investigations, civil litigation and regulatory defense, as well as national security issues. He can be reached at ldembosky@debevoise.com.

Author

Erez is a litigation partner and a member of the Debevoise Data Strategy & Security Group. His practice focuses on advising major businesses on a wide range of complex, high-impact cyber-incident response matters and on data-related regulatory requirements. Erez can be reached at eliebermann@debevoise.com

Author

Robert Maddox is a partner in Debevoise & Plimpton LLP’s Data Strategy & Security practice, based in London. In 2021 he was named to Global Data Review’s “40 Under 40” and is described as “a rising star” in cyber law by The Legal 500 US (2022). His practice focuses on cybersecurity incident preparation and response, internal investigations and regulatory defence. Mr. Maddox also advises on data strategy and compliance in the context of emerging technologies, including AI, and operational resilience matters. He can be reached at rmaddox@debevoise.com.

Author

Jim Pastore is a Debevoise litigation partner and a member of the firm’s Data Strategy & Security practice and Intellectual Property Litigation Group. He can be reached at jjpastore@debevoise.com.

Author

H Jacqueline Brehmer is a Debevoise litigation associate and a member of the Data Strategy & Security Practice Group. She can be reached at hjbrehmer@debevoise.com.

Author

Martha Hirst is an associate in Debevoise's Litigation Department based in the London office. She is a member of the firm’s White Collar & Regulatory Defense Group, and the Data Strategy & Security practice. She can be reached at mhirst@debevoise.com.