Digital Arbitration, Real Risks: Building Cybersecurity Into the Process

  • Anjna Raj

    Anjna Raj

    • Sep 25, 2026

    • 17 min Read

Cybersecurity in Arbitration

Arbitration may happen behind closed doors, but its data travels through cloud drives, inboxes and AI tools with the windows wide open. From phishing and poorly regulated cloud platforms to Open-Source AI assistants, here we unravel the weak links hiding inside modern dispute resolution.


A tribunal secretary uploads witness statements to a shared drive an hour before a hearing. Counsel forwards case documents to a personal e-mail account to work from home. An arbitrator pastes a confidential submission into a general-purpose AI assistant to draft a summary. Five years ago, none of this would have raised an eyebrow. Today, each is a documented route to a data breach in international arbitration.

Arbitration has always sold itself on privacy and confidentiality. That promise now rests on infrastructure that is no different from any other cross-border business process: cloud storage, e-mail, video conferencing, AI copilots, etc. In the age of data gold rush, that infrastructure is a target, and the global arbitration community has only recently started realising it.

Why Confidentiality Is Now a Cybersecurity Problem

Confidentiality in arbitration is a procedural expectation, not a technical guarantee. Parties choose arbitration partly to keep disputes out of public court records, but that says nothing about how securely documents are stored, transmitted, or shared among counsel, arbitrators, experts, and institution staff across jurisdictions.

Recognising this gap, the International Council for Commercial Arbitration, the New York City Bar Association, and the International Institute for Conflict Prevention and Resolution jointly issued the Cybersecurity Protocol for International Arbitration, first in 2020 and updated in 2022. The Protocol frames cybersecurity as reasonable measures tailored to each case rather than a fixed checklist, and its 2022 edition added a sample data-breach response plan because data breach incidents were no longer a theoretical risk, but a practical reality. Confidentiality clauses in arbitral rules are only as strong as the security practices behind them.

How Exposed Is Arbitration to Cyberattacks?

The answer: more than most legal practitioners assume. The FBI’s Internet Crime Complaint Centre recorded over 859,000 complaints in 2024, with losses exceeding $16.6 billion (USD) – a 33% jump from 2023 and the highest figure on record. Personal data breaches and phishing remains among the top complaint categories.

Europe’s picture, drawn from ENISA’s Threat Landscape 2025 report covering nearly 4,900 verified incidents between July 2024 and June 2025, is similarly hostile: phishing accounted for roughly 60% of initial intrusions, ransomware remained the most economically damaging threat type, and public administration bodies – a category that includes many state-affiliated arbitral users – remained the single most targeted sector.

The financial dimension is stark for any organisation handling sensitive case files. IBM’s 2025 Cost of a Data Breach Report, based on Ponemon Institute research across 600 organisations, puts the global average cost of a breach at $4.44 million (USD), with professional and business services averaging around $4.56 million (USD), and breaches taking 241 days on average to identify and contain. Arbitral institutions, law firms, and corporate legal departments sit inside that exposure window, often holding sensitive, unpublished material for years.

Cloud Platforms: Convenience Versus Control

Case management platforms, virtual data rooms, and e-filing systems have replaced physical bundles and courier deliveries across nearly every arbitral institution. This solves logistical problems but raises new ones: where is data physically stored, which law governs access requests to it, who among the vendors can see it, and what happens if the platform itself is compromised.

These questions are not academic. DLA Piper’s GDPR Fines and Data Breach Survey, published in January 2026, recorded approximately €1.2 billion (EUR) in fines issued by European authorities in 2025 alone, taking cumulative fines since 2018 past €7.1 billion (EUR). The same survey found authorities receiving an average of 443 personal breach notifications per day, a 22% increase and the first time that figure has crossed 400 since the regulation took effect. Institutions and cloud vendors processing personal data of EU-connected parties operate inside this enforcement environment, regardless of the arbitral seat.

The practical response is to treat platform due diligence as part of case security – not a procurement formality. Before adopting a platform across a case, institutions should scrutinise the vendor’s security certifications, data-residency commitments, encryption standards, subcontracting arrangements and obligations relating to government or third-party access. The question is not simply whether a platform is secure, but whether its security, jurisdictional and access controls are sufficiently clear to withstand scrutiny when sensitive arbitral data is on the line.

AI Tools: A New Attack Surface

Adoption of AI in arbitration has moved from cautious experimentation to near-consensus expectation. The 2025 Queen Mary/White & Case Survey, the largest of its kind with 2,402 respondents, found close to 91% expect to use AI for legal research, data analytics, and document review over the next five years. This is a sharp upward trend, compared to the reluctance recorded in earlier editions. Saving time was cited by 54% as the leading driver.

But the same survey identified confidentiality and data-breach risk as the second most cited obstacle to wider AI use, at 47%, just behind concerns about undetected errors and bias at 51%. The concern is specific: feeding confidential submissions into open, consumer-grade AI tools can mean data leaves the arbitral institution’s controlled environment entirely, potentially retained on infrastructure outside any agreed confidentiality regime. Respondents repeatedly flagged closed, enterprise-grade deployments, versus open-source tools used without safeguards, as the decisive factor in whether AI use is safe or reckless.

Electronic Evidence: Authenticity and Chain of Custody

Electronic evidence – e-mails, contracts, financial records, forensic images, chat logs – now forms the bulk of the evidentiary record in most commercial disputes. Its integrity depends on demonstrable chain of custody: metadata preservation, tamper-evident storage, and a documented trail from collection to submission.

Cybersecurity failures compromise this in two directions. A breach can alter or destroy evidence before it reaches the tribunal, and inadequate access logging can make it impossible to prove evidence was not altered, undermining its weight even where no tampering occurred. Evidence-handling platforms belong inside the security perimeter, not treated as a separate IT concern.

Access Controls: The Weakest Link Is Usually Human

Technical defences are frequently undone by access failures – shared logins, indefinite access retained after a party or expert exits a case, weak or reused passwords, and unrestricted forwarding of case materials. Since phishing drives most initial intrusions recorded by both ENISA and the FBI, the most cost-effective controls are often the simplest: multi-factor authentication (MFA), role-based access control (RBAC) tied to a matter’s actual participant list, prompt deprovisioning at case close, and encrypted channels for sensitive exchanges. None of this requires exotic technology; it requires discipline that many arbitration teams, accustomed to ad hoc e-mail threads and shared folders, are yet to adopt.

Incident Response: Planning for When, Not If

The ICCA-NYC Bar-CPR Protocol’s sample data-breach response plan reflects a shift in thinking: incidents are a matter of probability, not possibility. An effective plan identifies who is notified and when, how affected parties and regulators are informed where required, how the proceeding continues or is paused, and how exposed privileged material is handled afterward. Institutions that build this into case management before a dispute arises, rather than negotiating it mid-arbitration, are markedly better positioned when an incident occurs.

Frequently Asked Questions

1. Do individual arbitral institutions have their own cybersecurity rules, or is this left to soft-law guidance?

A growing number do. The LCIA’s 2020 Rules were the first among major institutions to add a binding provision, Article 30A, requiring tribunals to consider information-security and data-protection measures early in a case. HKIAC requires filings through a secured online repository, the ICC has rolled out its own platform for secure file sharing, and the American Arbitration Association’s ICDR requires panel arbitrators to complete cybersecurity training. Coverage is uneven across institutions, which is why cross-institutional soft law such as the ICCA-NYC Bar-CPR Protocol still fills the gaps.

2. Can a cybersecurity breach affect whether an arbitral award gets enforced?

Potentially. Under Article V of the New York Convention, courts can refuse enforcement where a party was unable to present its case, or where enforcement would violate public policy. A breach that compromises evidence or disrupts a party’s ability to participate could be argued as grounds for a due-process challenge at the enforcement stage, though no substantial body of case law has yet developed on this specific point.

3. Are virtual hearings a bigger security risk than in-person ones?

They introduce different risks rather than simply larger ones. Video-conferencing platforms can be accessed by uninvited parties if hearing links are shared carelessly or credentials are weak, and screen-sharing or recording features create new points where confidential material can leak. The safeguard is procedural as much as technical: unique, non-forwardable access credentials, waiting-room controls, and a clear attendance record for each session.

4. Does mandatory data-breach notification under laws like the GDPR override arbitral confidentiality?

Generally yes, especially where personal data of EU-connected individuals is involved. Statutory notification duties to regulators, and in some cases affected individuals, operate independently of any confidentiality undertaking in the arbitration agreement. Parties handling personal data need a notification protocol that meets statutory deadlines without disclosing more than is legally necessary.

The Path Forward

Cybersecurity in arbitration is no longer a back-office IT concern; it is a procedural safeguard as fundamental as confidentiality itself. Institutions still treating it as an afterthought will find out, expensively, what it costs to get wrong. Justice Accelerator builds that security in from day one. Talk to us at Justice Accelerator before the next breach makes the decision for you.

Sources

ICCA, NYC Bar, CPR – Cybersecurity Protocol for International Arbitration (2022 Edition): https://www.arbitration-icca.org/cybersecurity-international-arbitration-icca-nyc-bar-cpr-working-group

Queen Mary University of London / White & Case – 2025 International Arbitration Survey: https://www.whitecase.com/insight-our-thinking/2025-international-arbitration-survey

FBI Internet Crime Complaint Center – 2024 Internet Crime Report: https://www.ic3.gov

ENISA – Threat Landscape 2025: https://www.enisa.europa.eu/publications/enisa-threat-landscape-2025

IBM / Ponemon Institute – Cost of a Data Breach Report 2025: https://www.ibm.com/reports/data-breach

DLA Piper – GDPR Fines and Data Breach Survey, January 2026: https://www.dlapiper.com/en/insights/publications/2026/01/dla-piper-gdpr-fines-and-data-breach-survey-january-2026

LCIA – 2020 Arbitration Rules, Article 30A (data protection and information security): https://www.lcia.org/dispute-resolution-services/lcia-arbitration-rules-2020.aspx

United Nations – Convention on the Recognition and Enforcement of Foreign Arbitral Awards (New York Convention 1958), Article V: https://uncitral.un.org/en/texts/arbitration/conventions/foreign_arbitral_awards

  • Anjna Raj
  • Anjna Raj

    Anjna Raj is a skilled content writer with a background in journalism and mass communication. While she currently crafts engaging narratives in the legal tech space, she’s also a poet at heart, fueled by her love for music, cats, and a fascination with human behavior. She believes good writing doesn’t just inform – it connects, lingers, and sometimes makes you smile when you least expect it.

It’s time to

the Judiciary

Be a part of our community and never miss a beat in legal innovation