Skip to Content
Counsel Collective

Cover Stories

Left and Right of Boom

Krish Thakker on what legal defensibility actually looks like before, during, and after a breach — and why AI is widening the gap faster than the law can close it. Photography by Michelle Colon.

The boom

Krish Thakker has a vocabulary for the moment a crisis hits. He calls it the boom. “The boom is, like, the millisecond a crisis happens,” he explains. In his world, that is the instant ransomware is deployed, the exfiltration of data at massive scale, a government subpoena landing on counsel’s desk, or a threat actor exploiting a system through an undecommissioned API token.

Everything that happens in the corporate boardroom or in risk management sits on one side of that moment or the other. There is a left of boom, and there is a right of boom, and where a company chooses to live between the two tells you almost everything about how much legal exposure it is carrying.

The left of boom

The left is where Krish has built his practice. “It’s the prep, the architecture, the governance phase,” he says. “It’s everything that we do to ensure the boom just never happens, or if it does, you know, you’re technically, legally insulated.” That is the discipline of getting legal involved during design or proof-of-concept rather than after launch: validating third-party vendor access, executing fiduciary pre-mortems, mapping data flows, implementing multi-factor authentication. The goal is to build an auditable source of truth with continuous monitoring factored in, so there is evidence a system is secure before anyone thinks to question it.

Most companies fail here for a predictable reason. They fall into what he calls the build-it-first trap — giving priority to engineering velocity over audit-trail defensibility, leaving unmapped vulnerabilities sitting in the code.

The right of boom

The reactive side is the far more common default. When the crisis lands, the organization is suddenly doing damage control — and Krish is blunt about the cost. It is inefficient, it forecloses smart resource allocation, and it pulls focus away from emerging threats. It also invites repeat targeting: if threat actors understand reactivity is a company’s culture, “they know that you’re gonna have vulnerabilities when there’s already an attack.” In practice, the reactive path means forensic teams, breach coaches, consultants and litigators; heavy outside-legal spend; and the whole downstream machinery of notifying regulators, activating policies, and coordinating underwriters, claims handlers, brokers and vendors.

The governance test boards are failing

Krish points to a shift already in the numbers: a rise in denied insurance claims turning on whether a control such as MFA was actually enforced at the time of a breach, rather than merely existing on paper. That is forcing boards into a 180-degree pivot, “from compliance checking to continuous forensic validation.” He cites a supply-chain incident to make the point that liability does not end when the crisis appears to: an organization breached through a legacy credential negotiated with its attacker — and then the attacker group was itself hacked by another group that re-extorted the same victims. “If an organization doesn’t do the 180 on how it’s governing third-party access, the liability never goes away.” For the underlying numerics he points to IBM’s Cost of a Data Breach report and the publications of ISACA.

Where AI widens the gap

Ask Krish where AI is opening the defensibility gap fastest, and he frames it as both a weapon and a shield at once. On defense, data inventory and mapping that were once painfully manual can now be automated across systems, vendors and jurisdictions. On offense, threat actors use the same tools to penetrate systems and commit breaches. “It’s a push and pull with AI. It’s yet to be seen which one has more chutzpah.”

The deeper problem is speed. AI systems “are making decisions, influencing outcomes, and scaling actions that manual structures were never designed to handle,” and the technology moves faster than internal compliance reviews can respond. That creates a massive blind spot, where “a legal consequential decision was made by a machine way before a human even touches it.” Regulators, insurers and enforcement bodies have shifted from stated intent to operational proof: “They don’t accept high-level principles on a paper-based system. You can’t just check the box.” If a company cannot produce the immutable audit logs showing how a model reached a decision, that missing evidence is the defensibility gap. The exposure compounds when organizations embed complex third-party models they did not build and cannot interpret — “they’re also absorbing the legal liability of all of the AI’s outputs.”

The independent path

Krish built his practice to remain conflict-free and independent — a hybrid of outside and in-house counsel, and a deliberately strategic move: a way to get visibility across “all sorts of weird and wonderful companies globally” and a diverse set of legal areas. He acts as a fractional general or product counsel on engagements running from a single month to two years — deeply embedded while openly independent and non-exclusive, managing his own conflicts. The payoff has been depth: privacy, cybersecurity, AI governance, ethics and legal tech, worked at the intersection of vendor integration and implementation.

Writing in public

Krish has been writing since before law school. His first published article appeared in the King’s College School magazine under a title that still anchors him: “Nothing is permanent but change.” That philosophy shows up in his LinkedIn cadence, which reaches founders, CTOs, CFOs, CEOs, general counsel and compliance leaders. No reader absorbs the full weight of an idea like the build-it-first trap from a single post; the value is in the repetition. Over time, “you train your network to think about different risks in different ways.” Cadence, as he puts it, “is what shifts presence from an opinion to owning that lane.”

The decentralized brain trust

Krish describes the broader community of independent practitioners as “essentially a decentralized brain trust.” Operating independently requires you to be hyper-specialized — but technology risk does not exist in a vacuum. By tapping the community, and through leadership circles in organizations like the South Asian Bar Association, practitioners share real-time market signals on everything “from AI governance to zero-day vulnerabilities.” The network lets independent counsel “punch far above our weight class” and deliver Big Law caliber strategic insight with the agility modern technology companies actually need: not just a legal memo, but “a strategic partner who can sit seamlessly alongside their product and engineering teams.”

Where the work is going

Ask Krish where the cybersecurity and legal advisory space is heading, and he describes a shift already underway: “from reactive compliance to proactive product defensibility.” With the explosion of AI-driven vulnerabilities and shifting regulatory mandates, legal and cyber risk are now permanently intertwined and embedded directly into the product lifecycle. He is clear about who he most wants to reach: “the builders and the decision-makers” — the product leaders, tech founders, CISOs and general counsel moving fast enough to need the framework before a crisis forces it on them.

Legal defensibility isn’t the Department of No; it is a continuous design discipline that protects their revenue, their board, and their reputation left of boom — long before a crisis ever hits.

Krish Thakker, Founder & Principal, Independent Cybersecurity & Legal Advisory Practice

Connect with Krish Thakker on LinkedIn.

We will be happy to hear your thoughts

Leave a reply

Counsel Collective
Logo
Krish Thakker
Left of BoomPrep · Architecture · Governance
Right of BoomBreach · Damage Control · Exposure
Counsel Collective  /  In Conversation

Left andRight ofBoom.

Krish Thakker on what legal defensibility actually looks like before, during, and after a breach — and why AI is widening the gap faster than the law can close it.

The Boom

He has a vocabulary for the millisecond a crisis hits.

Krish Thakker calls it the boom. "The boom is, like, the millisecond a crisis happens," he explains. In his world, that is the instant ransomware is deployed, the exfiltration of data at massive scale, a government subpoena landing on counsel's desk, or a threat actor exploiting a system through an undecommissioned API token.

Everything that happens in the corporate boardroom or in risk management sits on one side of that moment or the other. There is a left of boom, and there is a right of boom, and where a company chooses to live between the two tells you almost everything about how much legal exposure it is carrying.

← Left of Boom

The proactive, preventative work — the prep, the architecture, the governance phase. Everything done to ensure the boom never happens, or if it does, you are technically and legally insulated.

Right of Boom →

The reactive default — "if it ain't broken, don't fix it," until the crisis lands and the organization is doing risk mitigation in damage-control mode, all hands on deck, everything else dropped.

The Left of Boom

Getting legal in the room before the code ships.

The left is where Krish has built his practice. "It's the prep, the architecture, the governance phase," he says. "It's everything that we do to ensure the boom just never happens, or if it does, you know, you're technically, legally insulated."

That is the discipline of getting legal involved during design or proof-of-concept rather than after launch: validating third-party vendor access, executing fiduciary pre-mortems, mapping data flows, implementing multi-factor authentication. The goal is to build an auditable source of truth with continuous monitoring factored in, so there is evidence a system is secure before anyone thinks to question it.

Most companies fail here for a predictable reason. They fall into what he calls the build-it-first trap — giving priority to engineering velocity over audit-trail defensibility, leaving unmapped vulnerabilities sitting in the code.

The Right of Boom

The expensive comfort of "if it ain't broken."

The reactive side is the far more common default. When the crisis lands, the organization is suddenly doing damage control — and Krish is blunt about the cost. It is inefficient, it forecloses smart resource allocation, and it pulls focus away from emerging threats. It also invites repeat targeting: if threat actors understand reactivity is a company's culture, "they know that you're gonna have vulnerabilities when there's already an attack."

In practice, the reactive path means forensic teams, breach coaches, consultants and litigators; heavy outside-legal spend; and the whole downstream machinery of notifying regulators, activating policies, and coordinating underwriters, claims handlers, brokers and vendors. Good margins for the responders — expensive insurance against a problem that discipline on the left could have prevented.

They know that you're gonna have vulnerabilities when there's already an attack.
Krish Thakker
The Governance Test Boards Are Failing

From checking the box to continuous forensic validation.

Krish points to a shift already in the numbers: a rise in denied insurance claims turning on whether a control such as MFA was actually enforced at the time of a breach, rather than merely existing on paper. That is forcing boards into a 180-degree pivot, "from compliance checking to continuous forensic validation."

He cites a supply-chain incident to make the point that liability does not end when the crisis appears to. An organization breached through a legacy credential negotiated with its attacker — and then the attacker group was itself hacked by another group that re-extorted the same victims. His takeaway is unsparing: "If an organization doesn't do the 180 on how it's governing third-party access, the liability never goes away." For the underlying numerics, he points to IBM's Cost of a Data Breach report and the publications of ISACA.

Where AI Widens the Gap

A weapon and a shield, moving faster than review.

Ask Krish where AI is opening the defensibility gap fastest, and he frames it as both at once. On defense, data inventory and mapping that were once painfully manual can now be automated across systems, vendors and jurisdictions. On offense, threat actors use the same tools to penetrate systems and commit breaches. "It's a push and pull with AI. It's yet to be seen which one has more chutzpah."

The deeper problem is speed. AI systems "are making decisions, influencing outcomes, and scaling actions that manual structures were never designed to handle," and the technology moves faster than internal compliance reviews can respond. That creates a massive blind spot, where "a legal consequential decision was made by a machine way before a human even touches it."

He has watched the bar for proof rise in real time. There was a time when a well-drafted AI ethics policy satisfied InfoSec and vendor questionnaires. No longer. Regulators, insurers and enforcement bodies have shifted from stated intent to operational proof. "They don't accept high-level principles on a paper-based system. You can't just check the box." If a company cannot produce the immutable audit logs showing how a model reached a decision, that missing evidence is the defensibility gap.

The exposure compounds when organizations embed complex third-party models they did not build and cannot interpret — "they're also absorbing the legal liability of all of the AI's outputs." If an AI hiring tool inadvertently introduces bias, the HR system is exposed to Title VII claims, and "the whole we-didn't-build-this-algorithm argument goes out the door."

A legal consequential decision was made by a machine way before a human even touches it.
Krish Thakker
The Independent Path

Built to sit between two worlds.

Krish built his practice to remain conflict-free and independent — a hybrid of outside and in-house counsel, and a deliberately strategic move: a way to get visibility across "all sorts of weird and wonderful companies globally" and a diverse set of legal areas. In-house life confines you to one company; law-firm life, in his experience as a senior associate, means building a book in one narrow area while navigating partnership politics and the pressure to maximize profits per equity partner.

Instead he acts as a fractional general or product counsel on engagements running from a single month to two years — deeply embedded while openly independent and non-exclusive, managing his own conflicts. The payoff has been depth: privacy, cybersecurity, AI governance, ethics and legal tech, worked at the intersection of vendor integration and implementation. It has also given him autonomy over his schedule and the work he chooses, the freedom to work across cultures, jurisdictions and time zones, and to be with family in Europe.

Writing in Public

"Nothing is permanent but change."

Krish has been writing since before law school. His first published article appeared in the King's College School magazine under a title that still anchors him: "Nothing is permanent but change." Everything is constantly in motion, down to cells and DNA — and once a person accepts change as the only certainty, uncertainty becomes something to expand into rather than fear.

That philosophy shows up in his LinkedIn cadence, which reaches founders, CTOs, CFOs, CEOs, general counsel and compliance leaders. No reader absorbs the full weight of an idea like the build-it-first trap from a single post; the value is in the repetition. Over time, "you train your network to think about different risks in different ways," so that when a regulatory challenge arrives, the frameworks and vocabulary are already there. Consistency compounds visibility without compounding workload — a single interview repurposed into weeks of posts. He names the irony himself: somewhat TV shy, he has come to see exposure as a critical necessity. Cadence, as he puts it, "is what shifts presence from an opinion to owning that lane."

The Decentralized Brain Trust

Independent practice is not solo practice.

Krish describes the broader community of independent practitioners as "essentially a decentralized brain trust," and he is precise about why it matters. Operating independently requires you to be hyper-specialized — but technology risk does not exist in a vacuum. By tapping the community, and through leadership circles in organizations like the South Asian Bar Association, practitioners share real-time market signals on everything "from AI governance to zero-day vulnerabilities."

The effect is leverage. The network lets independent counsel "punch far above our weight class" and deliver Big Law caliber strategic insight with the agility and embedded partnership modern technology companies actually need. He believes the profession is heading toward this model for a simple reason rooted in what clients now want: not just a legal memo, but "a strategic partner who can sit seamlessly alongside their product and engineering teams."

Where the Work Is Going

From reactive compliance to proactive product defensibility.

Ask Krish where the space is heading, and he describes a shift already underway. The era where cybersecurity was just an IT problem or a box to check on an insurance application is ending. With the explosion of AI-driven vulnerabilities and shifting regulatory mandates, legal and cyber risk are now permanently intertwined and embedded directly into the product lifecycle.

He is clear about who he most wants to reach: "the builders and the decision-makers" — the product leaders, tech founders, CISOs and general counsel moving fast enough to need the framework before a crisis forces it on them.

Legal defensibility isn't the Department of No; it is a continuous design discipline that protects their revenue, their board, and their reputation left of boom — long before a crisis ever hits.
Krish Thakker  ·  Independent Consultant, Cybersecurity & Legal Advisory Practice  ·  Connect on LinkedIn ↗

Verbatim quotes from the recorded interview.  ·  Photography by Michelle Colon.
Counsel Collective  /  In Conversationcounselcollective.org →
Shopping cart