Alert

The Cyber Crossfire: Navigating Breach Responses Amid Congressional Scrutiny

October 6, 2026

A significant cyber incident rarely remains a single-track response. Companies often must simultaneously manage forensic investigations, engage law enforcement, notify regulators, and manage executive communications before they fully understand what occurred. Initial statements, early preservation decisions, and document-creation practices can all shape the course of subsequent inquiries.

While companies may expect to engage with regulators or national security agencies depending on the nature of the event, there is another investigative body that is poised to scrutinize large-scale cybersecurity incidents: Congress. 

Indeed, in recent years, congressional committees have launched high-profile investigations into more than a dozen cyber incidents, as well as non-public inquiries that are equally important to the target companies. Congress has focused on cyber events affecting critical infrastructure, tech and telecom providers, defense contractors, and consumer services companies, among other sectors. These probes are often triggered by media coverage, which may contain inaccuracies or be based on incomplete information.

Congressional investigations present challenges that differ from traditional regulatory inquiries. Congress generally takes the position that common-law privileges and privacy laws do not limit its ability to obtain information. Congressional committees often do not defer to a company’s internal investigation or a parallel regulatory or law enforcement review. And even though a company is the victim of a cyberattack, the focus of a congressional investigation is often anchored around potential consumer harms and constituent concerns, which may channel attention to perceived deficiencies in a company’s security approach or incident response.

Simply put, when there is a major cyber incident, companies should expect Congress to probe what happened, what may have gone wrong, and what corrective actions may be needed. Companies should therefore factor congressional oversight risk into their overall response strategy from the outset.

As Cybersecurity Awareness Month gets underway, this alert examines the challenges congressional investigations may pose in the wake of a cybersecurity incident, key considerations that can help companies mitigate these unique risks, and common pitfalls to avoid.

Key Considerations

For companies considering how they would handle a major cybersecurity incident – while seeking to mitigate the risks of a congressional probe – keep the following key steps in mind:

  • Implement a Centralized Incident-Governance Structure

As a general matter, companies responding to a cyber event should establish a centralized incident-governance structure that includes cybersecurity counsel, technical experts, communications professionals, and representatives from key business units. When congressional investigations may be implicated, companies should consider engaging experienced congressional investigations counsel who can help guide strategic interactions and negotiations with the Hill. Clear reporting lines and a coordinated response team are essential to an effective resolution.

  • Maintain Consistency Across Parallel Proceedings

Information and documents provided to regulators, federal agencies like the Cybersecurity and Infrastructure Security Agency (CISA), state Attorneys General, impacted customers, or shareholders may later be scrutinized for consistency with congressional testimony or other submissions to Congress. Additionally, materials furnished to Congress could become public through hearings, reports, letters, or other congressional actions. Companies should endeavor to maintain a coordinated factual record that avoids inadvertently signaling inconsistencies in disclosures to different audiences. This is especially important with congressional investigators, who routinely instruct parties that they are legally required to provide truthful information under 18 U.S.C. § 1001.

  • Pressure-Test Third-Party Oversight Protocols

Although a congressional inquiry into a cyber incident often starts with a look at the company’s internal governance and security protocols, it may quickly expand in scope. Companies should be prepared to explain how cybersecurity responsibilities were allocated among vendors, managed service providers, cloud providers, and other third parties. While congressional investigators may examine a third-party vendor’s actions, that does not mean they will forgo scrutiny of the company’s diligence and monitoring practices.

  • Preserve Privilege and Pursue Accommodations

Congressional committees generally take the position that common-law privileges, like the attorney-client privilege or work-product doctrine, do not constrain Congress’ ability to obtain information. Further complicating matters, a company that produces privileged information to Congress may risk waiving its ability to protect that information in a parallel proceeding. Internal communications, board materials, forensic reports prepared under counsel’s direction, draft disclosures, and incident-response documentation may all fall under the scope of a congressional oversight request. In practice, counsel is often able to negotiate with committee staff to reach accommodations around privileged materials. Nevertheless, companies should not assume Congress will stand down from seeking privileged materials.

  • Safeguard Sensitive Information

Congressional oversight requests may encompass materials containing personally identifiable information, including protected health information. Congressional committees generally have established protocols to safeguard sensitive materials, but they also frequently take the position that Congress is not subject to specific privacy regulations, such as HIPAA. As such, companies should carefully evaluate the authority behind any request seeking sensitive personal information and the availability of potential accommodations. Separately, congressional investigators may also probe whether an organization collected, retained, or provided access to sensitive information beyond what was reasonably necessary. Data retention policies and access controls can therefore become important aspects of both preparedness and post-incident scrutiny.

  • Evaluate Securities Disclosure and Materiality

Public companies must evaluate disclosure obligations while technical investigations are still developing. Materiality assessments, SEC disclosure decisions, voluntary disclosures, and any requests for delayed disclosure based on national security or public safety considerations may be scrutinized by Congress after the fact. Disclosure decisions should be carefully documented and coordinated among legal, executive, technical, investor relations, and communications stakeholders.

Common Pitfalls to Avoid

Recent congressional investigations into cyber events demonstrate that scrutiny frequently focuses not just on the sophistication of the threat actor, but also on a company’s governance, preparedness, and security fundamentals. Investigators often examine whether leadership had visibility into cyber risk, whether security weaknesses were known and addressed, whether sensitive information was appropriately protected, and whether stakeholders received timely and accurate information.

Although every incident is fact-specific, organizations should pay particular attention to avoid the following:

  • Inconsistent Communications

As noted above, perceived delays or inconsistencies across public statements, regulatory communications, investor disclosures, and congressional responses can undermine credibility, even when differences merely reflect evolving facts. They can also catalyze a congressional investigation into whether a company was attempting to conceal information from the public.

  • Gaps in Security Controls

The perceived failure to adopt and execute on foundational controls, such as multi-factor authentication, patch management, and vulnerability remediation, can lead to sustained congressional scrutiny. This is especially true if company records suggest there was internal awareness of potential vulnerabilities that went unaddressed. Taking corrective action before a cyber incident occurs – and before congressional investigators open a probe – can help prevent significant disruption down the road.

  • Documentation and Preservation Missteps

Congressional investigators often seek to reconstruct an organization’s decision-making before, during, and after an incident. Companies should promptly preserve emails, collaboration-platform communications, logs, and incident-response records, and they should ensure any relevant ephemeral messages are maintained. While this is a general best practice when an investigation is reasonably foreseeable or pending, a company’s document preservation practices can take on a life of their own in a congressional probe. For instance, in a Senate investigation of a major data breach, a notable portion of the inquiry centered on the adequacy of a company’s legal hold and its alleged failure to preserve a complete record of the events surrounding the breach. 

  • Governance and Escalation Deficiencies

Congressional scrutiny often intensifies when investigators obtain evidence suggesting a company knew, or should have known, about cybersecurity vulnerabilities before an incident occurred. Perceived failures to elevate concerns – or a perceived lack of urgency from senior leadership when concerns are elevated – can become focal points of an investigation. Even where a breach stems from a sophisticated external actor, investigators may question whether earlier action could have reduced the impact of the incident. To help avoid these critiques, companies can proactively evaluate their cybersecurity governance and incident-response frameworks, ensuring that risks are effectively escalated, remediation efforts are documented, and key stakeholders understand their responsibilities before an incident arises.

  • Lax Oversight of Agentic AI

Congressional investigators have also begun examining the role that artificial intelligence (AI) systems, particularly agentic AI systems capable of autonomous action, may play in cybersecurity incidents. Following an incident, investigators may seek to understand who authorized the system’s deployment, what safeguards were implemented to constrain its behavior, whether adequate human oversight existed, and how risks were identified, tested, and monitored. Even where an AI agent acts in unexpected ways or is manipulated by a threat actor, Congress may focus on whether the organization exercised appropriate diligence in deploying and supervising the technology. Organizations should therefore establish clear governance structures, document oversight and approval processes, maintain auditable records of AI-related decision-making, and integrate AI-specific scenarios into cybersecurity and incident-response planning.

Key Takeaway

Major cyber incidents are increasingly governance events that require a coordinated response across multiple venues – including Congress. Organizations that anticipate these parallel demands, maintain disciplined governance throughout the response, and create a clear record of their technical, legal, and business decisions are generally best positioned to navigate this scrutiny effectively.

* * *

Wiley’s Privacy, Cyber & Data Governance and Congressional Oversight and Investigations practices regularly advise clients facing complex cyber incidents, government inquiries, congressional oversight, and other parallel proceedings arising from significant security events. Please reach out to the authors with any questions.

Read Time: 8 min
Jump to top of page

Wiley Rein LLP Cookie Preference Center

Your Privacy

When you visit our website, we use cookies on your browser to collect information. The information collected might relate to you, your preferences, or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. For more information about how we use Cookies, please see our Privacy Policy.

Strictly Necessary Cookies

Always Active

Necessary cookies enable core functionality such as security, network management, and accessibility. These cookies may only be disabled by changing your browser settings, but this may affect how the website functions.

Functional Cookies

Always Active

Some functions of the site require remembering user choices, for example your cookie preference, or keyword search highlighting. These do not store any personal information.

Form Submissions

Always Active

When submitting your data, for example on a contact form or event registration, a cookie might be used to monitor the state of your submission across pages.

Performance Cookies

Performance cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek