Join our Newsletter — 33% off our NHI Course
Home Glossary Governance, Ownership & Risk Litigation Hold
Governance, Ownership & Risk

Litigation Hold

← Back to Glossary
By NHI Mgmt Group Updated September 7, 2026 Domain: Governance, Ownership & Risk

Litigation hold is the process of preserving potentially relevant records when an investigation, dispute, or legal proceeding is anticipated or underway. It suspends normal deletion or retention rules for specific data so organisations can retain evidence in a controlled, auditable manner.

Expanded Definition

Litigation hold is a targeted preservation obligation, not a general retention programme. It applies when records may become relevant to a dispute, investigation, audit, or proceeding, and it requires normal deletion, expiry, or cleanup routines to be paused for the specific material in scope.

The boundary that matters is scope. A hold should protect relevant emails, chat records, tickets, files, logs, and system exports without freezing unrelated content or turning temporary preservation into indefinite retention. Good practice also distinguishes the legal instruction from the technical method used to implement it, because one may require mailbox settings, archive rules, backup constraints, or manual custodial controls. Consensus is clear that the obligation is about preserving evidence, but implementation details vary by platform and jurisdiction.

For identity-heavy and cloud-native environments, a common misunderstanding is assuming that retention policy alone is enough. In reality, a hold often needs to override automated deletion across several systems at once, including collaboration tools and identity-related audit trails. That makes the hold a governance and systems problem, not just a records-management label.

Examples and Use Cases

Litigation hold appears in day-to-day operations wherever evidence may need to be preserved without altering normal business workflows. The exact mechanics depend on the system, but the underlying pattern is the same: preserve what may be relevant, document the scope, and avoid accidental loss.

  • Preserving a departing employee’s mailbox, shared-drive content, and collaboration messages when a dispute is anticipated.
  • Freezing security logs and administrator activity records during an internal investigation so the timeline can be reconstructed later.
  • Holding ticketing history, change records, and approval trails that may show who authorised a sensitive action.
  • Retaining chat transcripts or meeting artifacts when those systems carry operational decisions that are not captured elsewhere.
  • Applying a limited hold to a defined custodian group while leaving standard deletion rules active for unrelated data.

The trade-off is practical: broader preservation reduces the chance of spoliation, but it also increases storage, eDiscovery overhead, and the operational burden of managing exceptions. Narrower holds are cheaper and easier to govern, but only when the scope is defensible and complete.

Security Implications

When litigation hold is mishandled, the result is often evidence loss, incomplete investigations, or the inability to reconstruct what happened after an incident or dispute. If relevant records are deleted too early, the organisation may lose timelines, attribution clues, decision trails, or proof of control execution.

The opposite failure matters too. Overbroad holds can create unnecessary data accumulation, preserve sensitive material longer than intended, and expand the amount of information exposed in future discovery or access requests. In security operations, that can also blur what is truly authoritative, because preserved copies and live systems may diverge over time.

A useful practitioner observation is that the riskiest gaps are often administrative rather than technical. Holds fail when they are not propagated to every relevant repository, when custodians are not identified accurately, or when teams assume backup retention is equivalent to a defensible hold. Those assumptions are especially dangerous where audit evidence, access logs, or account activity records may be needed to explain privileged actions.

Domain and Governance Relevance

In identity and cybersecurity programmes, litigation hold is part of evidence integrity and accountability. It ensures that access records, privileged activity, and operational logs remain available long enough to support investigation, legal review, and governance decisions. That matters because identity events often leave evidence across many systems rather than in one place.

For Non-Human Identity governance, the connection becomes more concrete. Service-account actions, API activity, automation logs, and token usage records may be central evidence when organisations need to understand what a workload or agent did, when it acted, and under whose authority. Preserving those records helps distinguish normal automation from misuse, misconfiguration, or compromise.

Litigation hold therefore sits at the intersection of records management, incident response, and identity assurance. It is not only about keeping data longer; it is about keeping the right evidence in a way that remains explainable, scoped, and auditable.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.DS — Data SecurityLitigation hold protects relevant records from loss or premature deletion.
DE.CM — Continuous MonitoringHeld evidence often comes from monitoring and activity records.
Recommendation — Preserve in-scope records under PR.DS and prevent normal deletion until the hold is released. Keep monitoring records available so investigators can reconstruct events without gaps.
CIS Controls v88 — Audit Log ManagementHolds often depend on retaining logs and activity trails for investigations.
3 — Data ProtectionHolds require controlled preservation without unnecessary exposure or alteration.
Recommendation — Retain and protect audit logs needed to support the hold and later evidence review. Limit access to held data while maintaining integrity and evidentiary traceability.
OWASP Non-Human Identity Top 10NHI-10 — Logging and ObservabilityNHI-related automation and token activity may need preserved logs as evidence.
Recommendation — Preserve machine-identity and automation logs so non-human activity remains auditable.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 7, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org