Earlier quoted context omitted.
Morale hazard does play into what they can clam as damages. If reverting the defacement using there CMS system costs 500$ and results in 2,000 in lost profit NP. If it takes someone a few hours to verify that was the only change, NP. But, they can't claim time related to revoking his permissions because they should have done that in the first place. Ditto for performing a security audit ect. This is a normal user usi…
I'm only going on here because I'm worried I've been unclear about the nature of the damage here. If you're objecting to the idea that, having caused a breach, the convicted attacker is now on the hook for securing the application they broke, so that the attack they used is no longer viable, I agree. That is in no way fair. But that's not what's happening. Instead, having been breached, and only because they've been…
I accept that you feel an external audit is required. But, is it a reasonable expense directly incurred, no.
PS: As a parting piece of evidence. Was $10,206 to $13,147 likely to include DFIR audit and all other costs? No.