Joey Victorino
Capability
Litigation Consulting
Lead
Joey Victorino — personally led
Basis
Retained by counsel · consulting only, not disclosed to the other side · conflicts cleared before scope

Cybersecurity litigation support whose opinion rests on the evidence, not the retainer.

Counsel needs a technical opinion it can rely on and that will not embarrass the case. I read the record myself, form the opinion myself, and sign it. The work is consulting only: I do not testify.

What I do

Written technical opinionsWritten analysis of what the forensic record shows: intrusion timelines, data access and exfiltration, the limits of attribution, and whether the evidence supports the claims being made. Memoranda are drafted for counsel’s use in strategy, not for disclosure to the other side.
Deposition & trial preparationConsulting support only, behind the privilege line. I brief counsel on the technical points before a deposition or hearing, draft the questions to ask the other side’s expert, and flag where a technical claim will not hold up. I do not appear as a witness.
Standard of care & reasonable securityAnalysis of whether a security program was reasonable for the organization, the data, and the period in question, measured against the practices and guidance that applied at the time rather than against hindsight. The same analysis serves contract disputes over security obligations and coverage disputes over what a policy required.
Review of the other side’s forensic workIndependent examination of opposing expert reports and the evidence beneath them: chain of custody, acquisition method, tool validation, whether each conclusion follows from the artifacts cited, and what was never collected. The output is a memorandum to counsel naming the specific gaps.

Who it is for

Litigators, general counsel, and coverage counsel in matters where a technical fact is contested: data breach class actions, contract disputes over security obligations, trade secret and insider theft, insurance coverage disputes, regulatory enforcement, and post-acquisition disputes over what a seller knew and when. I am retained by counsel, on either side, as a consulting expert only, behind the privilege line. Engagements usually begin when a complaint is filed, when a forensic report is produced in discovery, or before filing, when counsel needs to know whether the technical theory will survive contact with the evidence.

The opinions rest on the work itself. I led intrusion investigations at Microsoft DART, CrowdStrike, and IBM X-Force IRIS, and performed security testing and technical examination at NCC Group, much of it under privilege at counsel’s direction. I have acquired the images, built the timelines, and written the reports that end up as exhibits. That is the vantage point from which I read someone else’s.

When not to hire me

Do not retain me if you need a witness on the stand. This is a consulting role, and if the matter calls for testimony I will say so and help you find a testifying expert. Do not retain me if you need someone who will reach a conclusion the evidence does not support, or soften one that it does; I will tell counsel early if the technical theory is weak. I am not the right consultant for patent claim construction, for software engineering practice unrelated to security, or for the calculation of damages. If the matter needs a large team to process terabytes of discovery on a short clock, I will say so and help you find one. And I do not take engagements where a conflict check cannot be completed before I see the file.

What you get

A consultant who reads the actual evidence rather than the summary of it, forms an opinion that can be stated in one paragraph and defended in a room, and puts a name on it. Counsel gets early candor about the strengths and weaknesses of the technical case, a memorandum written for strategy rather than disclosure, preparation on the technical points before a deposition or hearing, and rebuttal of opposing work that names the gaps in specific terms: which artifacts were never collected, which tool output was taken on faith, and where the conclusion outran the record.

It arrives as a written conclusion in the format of the sample memorandum: the question, the evidence reviewed, the assumptions it rests on, the findings, the unknowns, and what to do next.

Questions people ask

What does a cybersecurity litigation consultant do?

A cybersecurity litigation consultant examines the technical evidence in a dispute, forms an independent opinion on what it shows, and puts that opinion in a written report or memorandum for counsel. The work is consulting only: it informs counsel's strategy and is not disclosed to the other side, and does not include deposition or trial testimony.

How much does cybersecurity litigation consulting cost?

Engagements are scoped and priced in writing after a short scoping call with counsel, and the terms are agreed before any evidence is reviewed. Contact me with the matter type, the parties for a conflict check, and the schedule, and I will respond with a written proposal.

Can you review the other side's forensic report?

Yes. That is a large part of the work. I examine the report against the evidence it cites, check the acquisition method and chain of custody, test whether each conclusion follows from the artifacts, and identify what was never collected. The result is a memorandum to counsel naming the specific gaps.

Related reading