In the recent data breach litigation of Savidge et al v. Pharm-Save, Inc. et al, W.D. Ky. 2023, the role of the Cybersecurity Expert Witness was pivotal in addressing complex questions of negligence and causation following a significant compromise of employee data. This case provides a clear illustration of how courts scrutinize the reliability and admissibility of expert testimony in cybersecurity matters.
Background and Parties
Plaintiffs Andrea Savidge and Beth Lynch, both former employees of Pharm-Save, Inc., initiated suit after a data breach resulted in the unauthorized disclosure of sensitive personal information. The breach occurred when cybercriminals, posing as company executives, deceived Pharm-Save employees into releasing confidential data. Plaintiffs alleged that Pharm-Save failed to implement adequate cybersecurity protocols, thereby enabling the breach and exposing employees to risk.
Role and Methods of the Cybersecurity Expert Witness
To substantiate their claims, the plaintiffs retained Vincent D’Agostino as their Cybersecurity Expert Witness. D’Agostino brought substantial credentials, including eleven years with the FBI and current leadership of Cyber Forensics and Incident Response at BlueVoyant, a prominent cyber defense firm. His qualifications were not contested by the defense, and the court acknowledged his extensive experience in cybersecurity forensics as sufficient to qualify him as an expert witness in this matter[1].
D’Agostino’s expert analysis focused on the adequacy of Pharm-Save’s cybersecurity measures and the foreseeability of the phishing attack. The defense challenged the reliability of his methodology, arguing that his conclusions were based primarily on a limited number of Google searches rather than independent technical investigation. Plaintiffs countered that D’Agostino’s opinions were grounded in his professional experience and industry knowledge, rather than novel research specific to the case.
Daubert and Reliability Analysis
The court conducted a thorough Daubert analysis to determine the admissibility of D’Agostino’s testimony. It found that his extensive background in cyber forensics and incident response provided a reliable foundation for his opinions regarding standard cybersecurity practices and the nature of the breach. The court emphasized that expert testimony may be based on specialized knowledge and experience, not solely on empirical research or testing, particularly in fields where practical expertise is paramount[1].
However, the court drew a clear boundary regarding the scope of admissible expert opinion. While D’Agostino was permitted to testify about the general adequacy of Pharm-Save’s cybersecurity protocols and the industry standards for preventing phishing attacks, the court excluded his opinion that a specific Pharm-Save employee was “grossly negligent.” The court held that such a conclusion constituted a legal determination reserved for the trier of fact, not an appropriate subject for expert testimony[1].
Impact on the Outcome
D’Agostino’s testimony was deemed admissible in part, allowing the jury to consider his expert assessment of Pharm-Save’s cybersecurity practices and the foreseeability of the phishing attack. His opinions were instrumental in framing the central issue of whether Pharm-Save’s conduct met the standard of care expected in the industry. By contrast, the exclusion of his opinion on gross negligence ensured that the jury, rather than the expert, would make the ultimate legal determination regarding the defendant’s culpability.
This case underscores the critical role of the Cybersecurity Expert Witness in data breach litigation, as well as the court’s gatekeeping function in ensuring that expert testimony is both reliable and appropriately limited. The court’s nuanced approach to the admissibility of expert evidence provides a model for future cases involving complex technical issues and evolving standards in cybersecurity.
Case citation: Savidge et al v. Pharm-Save, Inc. et al, W.D. Ky. 2023
Expert Witness Blog

