Case File 97-JJI All posts
Case 97-JJIBlog

When "Who Is the Client?" Is the Hardest Question in the Room

Over the years, my teams and I worked a wide range of commercial cases: intellectual property theft, suicide enlightenment, incident response after a breach, internal investigations for insider threat concerns, and everything in between. No two of these engagements felt quite alike—not in their emotional weight, not in their legal terrain, and not in who was sitting across the table from us when the work was done. That variety is what makes commercial digital forensics genuinely interesting. It is also what makes it genuinely treacherous in ways that law enforcement practice is not.

In law enforcement, the legal architecture arrives pre-assembled. You get a search warrant. The Fourth Amendment defines what you can and cannot do with it. Chain of custody rules are codified. Courtroom procedures are known quantities. There is still enormous room for error—I've spent several weeks of this series documenting exactly how examiners get it wrong—but the framework is laid out before you touch the first drive. Commercial forensics dismantles that scaffolding entirely. In its place, you navigate a more complex web of relationships, privilege protections, licensing requirements, and obligations that can shift depending on the state, the nature of the engagement, and who retained you. The professional risk of getting that navigation wrong is real: evidence excluded, licenses revoked, civil liability, and—at the outer edge—criminal exposure...for you.

The starting question, which I put to students near the top of this lecture, is deceptively simple: who is the client?

In law enforcement, the answer is obvious. In commercial practice, it frequently is not. When a company suffers a data breach today, the typical sequence might run something like this: the company contacts their cyber insurer, the cyber insurer selects or approves the incident response firm, and the IR team shows up to work what looks like a standard engagement. The problem is that the insurer and the insured have interests that can diverge sharply. The insurer wants to establish scope of loss and minimize payout. The company wants to understand the breach, recover from its damage, preserve its legal options, and avoid downstream liability. You were retained by the insurer, are physically present at the company's facilities, and are producing findings that both parties will read with different objectives. Courts have found, in precisely these circumstances, that the communications flowing through that engagement may not be protected by attorney-client privilege—because the insurer is a third party, and privilege requires confidentiality from third parties. The engagement structure created the problem before a single artifact was examined.

Attorney-client privilege in the digital evidence context deserves honest treatment, because practitioners in commercial forensics will encounter it constantly and often misunderstand what it actually protects. The core principle is straightforward: confidential communications between an attorney and client, made in the context of seeking or providing legal advice, are protected from compelled disclosure. Electronic communications are no less protected than paper ones—the fact that digital data may be easier to intercept does not weaken the privilege. What makes commercial practice complex is that the circle of people touching the case has expanded dramatically through decades of judicial decisions. As a forensic examiner retained by outside counsel, your notes may be protected as work product under FRCP Rule 26(b)(3) even when your final report is not. Whether that protection holds depends heavily on how the engagement was structured from the beginning. A post-breach forensic report prepared primarily to help the company understand and remediate what happened—rather than to support anticipated litigation—was found unprotected by a federal court in Wengui v. Clark Hill (2021), precisely because it served an ordinary business purpose. How the engagement letter frames your scope of work matters enormously and cannot be fixed after the fact.

Internal investigations add another layer to the client identity question. When corporate counsel retains you to investigate an employee, you work for the corporation. The employee has no attorney-client protection with that counsel, and the company can share your findings with government investigators without the employee's consent. The ethical framework around this—codified in Upjohn Co. v. United States and the Upjohn warnings that flow from it—exists precisely because the confusion is foreseeable and consequential. For you as an examiner, the practical instruction is direct: do not have informal conversations with the subject employee that the employee might interpret as confidential, because they were not. That confusion, when it surfaces later, is your problem to manage.

The unintended findings problem deserves its own treatment, because it arises across every type of commercial engagement and carries obligations that exist independently of what your client wants you to do with them. Conducting an intellectual property theft investigation and you find evidence of embezzlement. Working an HR matter and you discover what appears to be a crime against a third party. Running a typical eDiscovery collection and you find child sexual abuse material that is federal contraband. Digital evidence does not respect engagement scope, and neither do the legal and ethical obligations that follow from what you find. The question of whether you are obligated to report, and to whom, does not have a universal answer—it depends on what you found, the jurisdiction, and your role in the engagement. What is universal is this: you cannot make that decision alone or informally. Stop, document, and escalate to counsel immediately. A client instruction to handle the matter "internally" does not override obligations that exist in statute or professional rules. Following such an instruction can expose you to criminal liability rather than shield you from it.

The PI licensing question is the one that most reliably surprises practitioners who crossed over from law enforcement, and it deserves more attention than it typically gets. Depending on the state, performing commercial digital forensics—particularly work that might end up in court—may require you to be a licensed private investigator operating under a registered private investigation business. The regulatory patchwork is genuinely incoherent: some states require it by statute, some exclude examiners explicitly, some have issued opinions pointing one direction without a definitive ruling, and some have not addressed the question at all. Virginia, a state I know well, implicitly required PI registration for forensic examiners until 2011, when the Commonwealth explicitly carved out computer forensics by statute. Not every state has made that move. The consequence of getting it wrong ranges from nothing—to having your evidence excluded—to misdemeanor or felony exposure for performing investigative services without a license. Working directly for an attorney typically resolves the issue, because most states exempt attorneys and their employees from PI requirements. Before accepting a commercial engagement in an unfamiliar jurisdiction, verify the rules in that state. Then revalidate them before every case. The regulatory picture shifted materially between every published study on the subject—2008, 2012, and 2022—and it will shift again.

The through-line across all of it is something I put on the screen near the top of this lecture: commercial forensics is the same as law enforcement forensics, and it is entirely different. The technical work—imaging, artifact analysis, documentation, report writing—is the same. The web of relationships, obligations, and legal exposure surrounding that work is not. Technical competence is the prerequisite. Understanding the legal and ethical terrain you are operating in is what determines whether that competence produces durable, defensible results.

For those working in commercial practice: where has the client identity question created the most unexpected complications in an engagement, and how did you navigate it?


This post is the ninth in a series based on my course, DFOR 671: Topics of Ethics and Law in Computer Forensics, that I have taught at George Mason University for the past fifteen years. Over the past nine articles, I've discussed the ethical, legal, and practical issues that sit underneath the work: bias, candor, privacy, professional responsibility, reporting, courtroom credibility, incident response pressure, and the messy human realities that never seem to fit neatly into a checklist.

First published on LinkedIn.