Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What happens when a law firm cannot prove…
Governance, Ownership & Risk

What happens when a law firm cannot prove who accessed sensitive data?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Governance, Ownership & Risk

When access cannot be attributed to a specific person, the firm loses a key layer of legal and operational accountability. Investigations become slower, compliance evidence weakens, and liability becomes harder to contain. In practice, this means the firm may know data was exposed but struggle to show how it happened, who was involved, or whether controls worked.

When a firm cannot prove who accessed sensitive data, the issue is not only forensic. It affects the firm’s ability to assign responsibility, test whether access was appropriate, and demonstrate that controls worked as intended. Without attributable access records, the organisation may be able to detect exposure but still be unable to tie the event to a person, action, or decision.

That gap matters because legal teams need evidence that survives scrutiny, not just an incident narrative. In practice, the absence of attribution weakens auditability, slows root-cause analysis, and creates ambiguity around whether access was authorised, excessive, or potentially abusive.

Where investigations and containment break down

Attribution failures usually reveal a control chain problem: logs are incomplete, identities are shared, sessions are not uniquely tied to users, or access paths are too indirect to reconstruct confidently. When that happens, investigators lose the ability to separate legitimate access from misuse, and containment decisions become less precise.

This is also where NIST AI 600-1 GenAI Profile becomes relevant as a governance reference for provenance and incident handling, because the same accountability problem appears whenever records are too weak to explain what occurred. For access-heavy environments, NIST Cybersecurity Framework 2.0 also reinforces the need for governance, identification, protection, detection, response, and recovery to work as one chain.

What good evidence looks like for sensitive-data access

Good evidence is not just that a login happened. It is a clear chain from a named user or accountable identity to the system, the dataset, the time, the action taken, and the approval or policy basis for that access. The stronger the data sensitivity, the more important it becomes to retain logs, session records, and access review evidence that can be independently verified.

That is why access governance is usually assessed together with authentication and audit controls. NIST SP 800-53 Rev 5 Security and Privacy Controls is useful here because its access control, identification and authentication, and audit families map directly to attributable access. For stronger authentication evidence, NIST SP 800-63 Digital Identity Guidelines helps define how confident the organisation can be that the person behind the session is the intended user.

Risk and Threat Considerations

When access cannot be attributed, the firm is exposed to both control failure and adversarial abuse. A malicious insider, compromised account, or misconfigured shared credential can all hide inside weak attribution, which means the organisation may not know whether a disclosure was accidental, negligent, or deliberate.

Failure mechanism: Shared accounts, weak audit trails, poor session linkage, or incomplete identity proofing break the evidentiary chain between the data event and the responsible actor, so investigators cannot reliably reconstruct who did what.

Impact: The firm faces slower containment, weaker defensibility in litigation or regulatory review, and higher exposure to repeated misuse because the true access path may remain open.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 and GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-01 — Organizational ContextSensitive-data attribution depends on knowing accountability and legal context.
PR.AA-05 — Managed Access ControlAttributable access requires controlled and reviewable access decisions.
Recommendation — Define accountability and evidentiary expectations for access to sensitive records. Enforce and review access so each sensitive-data action ties to an accountable identity.
NIST SP 800-53 Rev 5AC-2 — Account ManagementNamed, governed accounts are essential for proving who accessed data.
AU-2 — Event LoggingAudit records are the primary evidence for reconstructing sensitive-data access.
IA-2 — Identification and Authentication (Organizational Users)Strong user authentication raises confidence that access belonged to the stated person.
Recommendation — Use individual account management so sensitive access is never effectively anonymous. Log sensitive access events with enough detail to support attribution and investigation. Use strong user authentication for access to sensitive legal data.
ISO/IEC 27001:2022A.5.15 — Access controlAccess control governance is central to proving and reviewing sensitive-data access.
A.8.15 — LoggingLogs are needed to reconstruct access and support accountability.
A.8.16 — Monitoring activitiesMonitoring supports detection of suspicious or unexplainable access paths.
Recommendation — Define and enforce access control rules for sensitive legal information. Retain logs that can reconstruct who accessed sensitive data and when. Monitor access patterns to spot unattributed or unusual sensitive-data use.
GDPRArticle 5 — Principles relating to processing of personal dataAttributable access supports accountability and data minimisation principles for personal data.
Article 32 — Security of processingSecurity of processing requires controls that can evidence and protect access decisions.
Recommendation — Keep access handling accountable and demonstrable for personal data processing. Implement security measures that preserve access accountability for personal data.

Practitioner Guidance

What to verify: Confirm that every sensitive-data access path produces an attributable record, including the identity used, the session or transaction identifier, and the dataset touched. If any of those elements is missing, treat the control as unproven even if the system shows a successful login.

What to prioritise: Focus first on eliminating shared or opaque access paths, then on tightening logging and access-review evidence. In legal and regulated environments, the priority is not maximum logging volume, but evidence that can support a specific accountability question under pressure.

Practitioner takeaway: If you cannot connect access to a specific accountable identity, you do not truly know who handled the data, only that the data was reachable.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org