
Krish Thakker on what legal defensibility actually looks like before, during, and after a breach — and why AI is widening the gap faster than the law can close it. Photography by Michelle Colon.
The boom
Krish Thakker has a vocabulary for the moment a crisis hits. He calls it the boom. “The boom is, like, the millisecond a crisis happens,” he explains. In his world, that is the instant ransomware is deployed, the exfiltration of data at massive scale, a government subpoena landing on counsel’s desk, or a threat actor exploiting a system through an undecommissioned API token.
Everything that happens in the corporate boardroom or in risk management sits on one side of that moment or the other. There is a left of boom, and there is a right of boom, and where a company chooses to live between the two tells you almost everything about how much legal exposure it is carrying.
The left of boom
The left is where Krish has built his practice. “It’s the prep, the architecture, the governance phase,” he says. “It’s everything that we do to ensure the boom just never happens, or if it does, you know, you’re technically, legally insulated.” That is the discipline of getting legal involved during design or proof-of-concept rather than after launch: validating third-party vendor access, executing fiduciary pre-mortems, mapping data flows, implementing multi-factor authentication. The goal is to build an auditable source of truth with continuous monitoring factored in, so there is evidence a system is secure before anyone thinks to question it.
Most companies fail here for a predictable reason. They fall into what he calls the build-it-first trap — giving priority to engineering velocity over audit-trail defensibility, leaving unmapped vulnerabilities sitting in the code.
The right of boom
The reactive side is the far more common default. When the crisis lands, the organization is suddenly doing damage control — and Krish is blunt about the cost. It is inefficient, it forecloses smart resource allocation, and it pulls focus away from emerging threats. It also invites repeat targeting: if threat actors understand reactivity is a company’s culture, “they know that you’re gonna have vulnerabilities when there’s already an attack.” In practice, the reactive path means forensic teams, breach coaches, consultants and litigators; heavy outside-legal spend; and the whole downstream machinery of notifying regulators, activating policies, and coordinating underwriters, claims handlers, brokers and vendors.
The governance test boards are failing
Krish points to a shift already in the numbers: a rise in denied insurance claims turning on whether a control such as MFA was actually enforced at the time of a breach, rather than merely existing on paper. That is forcing boards into a 180-degree pivot, “from compliance checking to continuous forensic validation.” He cites a supply-chain incident to make the point that liability does not end when the crisis appears to: an organization breached through a legacy credential negotiated with its attacker — and then the attacker group was itself hacked by another group that re-extorted the same victims. “If an organization doesn’t do the 180 on how it’s governing third-party access, the liability never goes away.” For the underlying numerics he points to IBM’s Cost of a Data Breach report and the publications of ISACA.
Where AI widens the gap
Ask Krish where AI is opening the defensibility gap fastest, and he frames it as both a weapon and a shield at once. On defense, data inventory and mapping that were once painfully manual can now be automated across systems, vendors and jurisdictions. On offense, threat actors use the same tools to penetrate systems and commit breaches. “It’s a push and pull with AI. It’s yet to be seen which one has more chutzpah.”
The deeper problem is speed. AI systems “are making decisions, influencing outcomes, and scaling actions that manual structures were never designed to handle,” and the technology moves faster than internal compliance reviews can respond. That creates a massive blind spot, where “a legal consequential decision was made by a machine way before a human even touches it.” Regulators, insurers and enforcement bodies have shifted from stated intent to operational proof: “They don’t accept high-level principles on a paper-based system. You can’t just check the box.” If a company cannot produce the immutable audit logs showing how a model reached a decision, that missing evidence is the defensibility gap. The exposure compounds when organizations embed complex third-party models they did not build and cannot interpret — “they’re also absorbing the legal liability of all of the AI’s outputs.”
The independent path
Krish built his practice to remain conflict-free and independent — a hybrid of outside and in-house counsel, and a deliberately strategic move: a way to get visibility across “all sorts of weird and wonderful companies globally” and a diverse set of legal areas. He acts as a fractional general or product counsel on engagements running from a single month to two years — deeply embedded while openly independent and non-exclusive, managing his own conflicts. The payoff has been depth: privacy, cybersecurity, AI governance, ethics and legal tech, worked at the intersection of vendor integration and implementation.
Writing in public
Krish has been writing since before law school. His first published article appeared in the King’s College School magazine under a title that still anchors him: “Nothing is permanent but change.” That philosophy shows up in his LinkedIn cadence, which reaches founders, CTOs, CFOs, CEOs, general counsel and compliance leaders. No reader absorbs the full weight of an idea like the build-it-first trap from a single post; the value is in the repetition. Over time, “you train your network to think about different risks in different ways.” Cadence, as he puts it, “is what shifts presence from an opinion to owning that lane.”
The decentralized brain trust
Krish describes the broader community of independent practitioners as “essentially a decentralized brain trust.” Operating independently requires you to be hyper-specialized — but technology risk does not exist in a vacuum. By tapping the community, and through leadership circles in organizations like the South Asian Bar Association, practitioners share real-time market signals on everything “from AI governance to zero-day vulnerabilities.” The network lets independent counsel “punch far above our weight class” and deliver Big Law caliber strategic insight with the agility modern technology companies actually need: not just a legal memo, but “a strategic partner who can sit seamlessly alongside their product and engineering teams.”
Where the work is going
Ask Krish where the cybersecurity and legal advisory space is heading, and he describes a shift already underway: “from reactive compliance to proactive product defensibility.” With the explosion of AI-driven vulnerabilities and shifting regulatory mandates, legal and cyber risk are now permanently intertwined and embedded directly into the product lifecycle. He is clear about who he most wants to reach: “the builders and the decision-makers” — the product leaders, tech founders, CISOs and general counsel moving fast enough to need the framework before a crisis forces it on them.
Legal defensibility isn’t the Department of No; it is a continuous design discipline that protects their revenue, their board, and their reputation left of boom — long before a crisis ever hits.
Krish Thakker, Founder & Principal, Independent Cybersecurity & Legal Advisory Practice
Connect with Krish Thakker on LinkedIn.

