Litigation hold is the process of preserving potentially relevant records when an investigation, dispute, or legal proceeding is anticipated or underway. It suspends normal deletion or retention rules for specific data so organisations can retain evidence in a controlled, auditable manner.
Expanded Definition
Litigation hold is a targeted preservation obligation, not a general retention programme. It applies when records may become relevant to a dispute, investigation, audit, or proceeding, and it requires normal deletion, expiry, or cleanup routines to be paused for the specific material in scope.
The boundary that matters is scope. A hold should protect relevant emails, chat records, tickets, files, logs, and system exports without freezing unrelated content or turning temporary preservation into indefinite retention. Good practice also distinguishes the legal instruction from the technical method used to implement it, because one may require mailbox settings, archive rules, backup constraints, or manual custodial controls. Consensus is clear that the obligation is about preserving evidence, but implementation details vary by platform and jurisdiction.
For identity-heavy and cloud-native environments, a common misunderstanding is assuming that retention policy alone is enough. In reality, a hold often needs to override automated deletion across several systems at once, including collaboration tools and identity-related audit trails. That makes the hold a governance and systems problem, not just a records-management label.
Examples and Use Cases
Litigation hold appears in day-to-day operations wherever evidence may need to be preserved without altering normal business workflows. The exact mechanics depend on the system, but the underlying pattern is the same: preserve what may be relevant, document the scope, and avoid accidental loss.
- Preserving a departing employee’s mailbox, shared-drive content, and collaboration messages when a dispute is anticipated.
- Freezing security logs and administrator activity records during an internal investigation so the timeline can be reconstructed later.
- Holding ticketing history, change records, and approval trails that may show who authorised a sensitive action.
- Retaining chat transcripts or meeting artifacts when those systems carry operational decisions that are not captured elsewhere.
- Applying a limited hold to a defined custodian group while leaving standard deletion rules active for unrelated data.
The trade-off is practical: broader preservation reduces the chance of spoliation, but it also increases storage, eDiscovery overhead, and the operational burden of managing exceptions. Narrower holds are cheaper and easier to govern, but only when the scope is defensible and complete.
Security Implications
When litigation hold is mishandled, the result is often evidence loss, incomplete investigations, or the inability to reconstruct what happened after an incident or dispute. If relevant records are deleted too early, the organisation may lose timelines, attribution clues, decision trails, or proof of control execution.
The opposite failure matters too. Overbroad holds can create unnecessary data accumulation, preserve sensitive material longer than intended, and expand the amount of information exposed in future discovery or access requests. In security operations, that can also blur what is truly authoritative, because preserved copies and live systems may diverge over time.
A useful practitioner observation is that the riskiest gaps are often administrative rather than technical. Holds fail when they are not propagated to every relevant repository, when custodians are not identified accurately, or when teams assume backup retention is equivalent to a defensible hold. Those assumptions are especially dangerous where audit evidence, access logs, or account activity records may be needed to explain privileged actions.
Domain and Governance Relevance
In identity and cybersecurity programmes, litigation hold is part of evidence integrity and accountability. It ensures that access records, privileged activity, and operational logs remain available long enough to support investigation, legal review, and governance decisions. That matters because identity events often leave evidence across many systems rather than in one place.
For Non-Human Identity governance, the connection becomes more concrete. Service-account actions, API activity, automation logs, and token usage records may be central evidence when organisations need to understand what a workload or agent did, when it acted, and under whose authority. Preserving those records helps distinguish normal automation from misuse, misconfiguration, or compromise.
Litigation hold therefore sits at the intersection of records management, incident response, and identity assurance. It is not only about keeping data longer; it is about keeping the right evidence in a way that remains explainable, scoped, and auditable.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.DS — Data Security | Litigation hold protects relevant records from loss or premature deletion. |
| DE.CM — Continuous Monitoring | Held evidence often comes from monitoring and activity records. | |
| Recommendation — Preserve in-scope records under PR.DS and prevent normal deletion until the hold is released. Keep monitoring records available so investigators can reconstruct events without gaps. | ||
| CIS Controls v8 | 8 — Audit Log Management | Holds often depend on retaining logs and activity trails for investigations. |
| 3 — Data Protection | Holds require controlled preservation without unnecessary exposure or alteration. | |
| Recommendation — Retain and protect audit logs needed to support the hold and later evidence review. Limit access to held data while maintaining integrity and evidentiary traceability. | ||
| OWASP Non-Human Identity Top 10 | NHI-10 — Logging and Observability | NHI-related automation and token activity may need preserved logs as evidence. |
| Recommendation — Preserve machine-identity and automation logs so non-human activity remains auditable. | ||
Related resources from NHI Mgmt Group
- How should security teams govern SaaS integrations that hold delegated access?
- What breaks when agents hold long-lived credentials for tool access?
- How should VASPs build AML/CFT controls that hold up under AUSTRAC scrutiny?
- What should organisations do differently when password managers also hold secrets and shared vaults?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org