Breaking profile: the lawyer building a command center for the breach room BreachRx launched its agentic-AI Rex Platform in June 2026 Breaking profile: the lawyer building a command center for the breach room BreachRx launched its agentic-AI Rex Platform in June 2026

Person / Founder / Cybersecurity

Anderson Lunsford Is Turning the Breach Room Into a System

A privacy lawyer watched companies improvise their way through cyber crises. Then he spent years turning the scramble - the calls, clocks, playbooks and proof - into software.

The interesting part of a data breach, Anderson Lunsford likes to say, is often not how the attacker got in. It is what the company does next. A technical alert becomes a legal question. The legal question starts a clock. Communications wants language, executives want options, the board wants a picture of risk, and somebody must remember which regulator expects which form in which jurisdiction. The breach does not stay inside the security operations center. It tours the whole organization.

Lunsford spent much of his first career near that second act. Before he became a software founder, he worked for 15 years in privacy law and large-scale commercial litigation. Eleven of those years were at Beacon Group, where he served as director and general counsel. The vantage point was unusually useful: he could watch capable people respond to serious incidents while their tools - static plans, email, conference calls and scattered spreadsheets - made coordination harder than it needed to be.

BreachRx, the company he co-founded with cybersecurity product veteran Matt Hartley, grew from that operational gap. Its premise is plain enough to fit on an index card. A cyber incident is not only a technical event. It is an enterprise event, and the enterprise needs one place to assign work, calculate obligations, preserve evidence and see the response as it unfolds.

“If you don't document your response, you can't prove you acted responsibly.”Anderson Lunsford

Privacy, before it was a product

The path to that idea began with books, not code. Lunsford spent some early years in Southern California and most of his childhood in Fayetteville, Arkansas, a college town in the Ozarks. In high school, two favorite novels - George Orwell's 1984 and Aldous Huxley's Brave New World - made privacy feel less like an abstract preference and more like a right worth protecting.

At Washington and Lee University, his favorite class was Philosophy of Law. The course traced the right to privacy through criminal codes, civil codes and Supreme Court decisions. Lunsford followed the thread into a senior honors thesis on privacy, technology and law. He later earned a law degree from the University of Arkansas and an MBA from Wharton, completing the unusual three-part toolkit he now brings to BreachRx: a philosopher's question, a lawyer's attention to proof and a manager's interest in repeatable process.

His early professional stops included a judicial clerkship and a brief role in compliance at Walmart. Then came Beacon Group and the long apprenticeship in what happens after a company is pulled into a complex dispute. Breaches were once treated as rare black swans. Over time they became ordinary business risk, while the rules multiplied and deadlines tightened. GDPR's 72-hour reporting clock made the mismatch especially visible. A plan in a binder could describe responsibility in theory. It could not coordinate a live response at two in the morning.

The missing coordination layer

BreachRx was founded in 2017. By 2019, Lunsford was presenting it at Finovate as software that generated tailored breach-response plans after an incident and let the many involved business functions collaborate in one place. The company had raised $500,000 from friends and family. Its pitch focused on recovery, not prevention - an important distinction in a market crowded with products designed to keep attackers out.

The breach room has a different job. Once an event begins, someone must establish the facts without losing the legal context. Teams must preserve attorney-client privilege where it applies while keeping a clean factual record of actions taken. They must identify relevant laws, contracts and notification duties, then turn them into owned tasks. The response has to move quickly without becoming impossible to reconstruct later.

An incident's trip through the enterprise
Security
finds facts
Legal
maps duties
Comms
shapes notice
Leaders
make decisions
The attacker crosses systems. The response crosses departments. BreachRx is built around the handoffs.

Lunsford argues against the old reflex to write nothing down. His preferred model separates two tracks: privileged legal discussions stay protected, while factual actions are documented clearly. The distinction turns recordkeeping into a form of defense. It shows regulators, auditors, boards and customers not just what happened, but whether the organization acted responsibly after it happened.

That view has also shaped Lunsford's work with The Sedona Conference, the law-and-policy institute where he has helped develop best practices around privilege in cybersecurity incident response. It appears in the patent record, too. He is named as an inventor on multiple BreachRx patents covering playbooks, task assignments, proof of completion and the updating of response plans when regulations change. The legal reasoning did not disappear when he became a founder. It became product architecture.

“You shouldn't have to memorize the world's privacy laws to do the right thing.”Anderson Lunsford

The years of explaining

The problem with arriving early is that the market does not applaud your timing. It asks for another explanation. Lunsford has described the early company-building years as “punching through brick walls” while customers caught up to the idea. Breach response sat between budgets and professional identities. Security owned the incident, except when legal did. Communications entered late. Executives wanted reports, but the source material lived in chat threads. The pain was real; the category was not yet settled.

BreachRx and others began calling the layer Cybersecurity Incident Response Management, or CIRM. Category language can sound like marketing furniture, but here it names a concrete difference: detection tools identify threats; CIRM organizes the enterprise-wide work of responding to them. The distinction gives an owner and a budget to the space between the alert and the final report.

2017BreachRx founded
$15MSeries A announced in May 2025
100+Customers reported at the Series A

By May 2025, the explanation had begun to compound. BreachRx announced an oversubscribed $15 million Series A led by Ballistic Ventures, bringing its reported total funding to more than $23 million. The company said annual recurring revenue had grown more than threefold for the second year in a row and that its customer list had passed 100, including public companies and members of the Fortune 500.

The round added two pointed connections. Kevin Mandia, who built Mandiant around frontline incident response, joined the board. Nicole Perlroth, whose reporting made the consequences of digital conflict legible to a wide public, became a board observer. Their presence echoed Lunsford's original framing: the breach room is simultaneously technical, operational, legal and reputational.

From one incident to many

In June 2026, BreachRx launched Rex, an agentic-AI incident command center. The platform assumes the old model of one major incident at a time is becoming less useful. AI can make attackers faster and cheaper; enterprises can also create new kinds of incidents through their own over-permissioned agents or manipulated models. Meanwhile, the corporate network used for normal coordination may itself be compromised.

Rex runs out of band and organizes specialized agents under an orchestration agent called Maestro. One assesses severity and affected assets. Another keeps playbooks moving. A regulatory agent maps disclosure duties. A reporting agent drafts situation reports and executive summaries. The design resembles Lunsford's career in miniature: take a crisis that sprawls across specialties, preserve the distinctions, then coordinate the work.

The useful part of this AI story is not that a chatbot can write a memo. It is that shared context becomes scarce when incidents overlap. A system can watch deadlines, dependencies and evidence while people concentrate on judgment. The aspiration is operational muscle memory: not a PDF policy pulled from a shelf, but practiced actions with owners, clocks and an audit trail.

Lunsford calls himself a lifelong learner and says the speed of change in cybersecurity energizes him. He also describes strategic problem-solving as one of his favorite activities. Both traits fit a field where today's playbook begins aging the moment it is approved. His through-line, however, is stable. Privacy first interested him as a human right. Litigation showed him what happens when that right collides with a corporate crisis. BreachRx is his attempt to make the response worthy of the stakes.

There is a compact founder lesson in the journey. Repeated confusion is information. If skilled people confront the same messy handoffs under pressure, the missing product may not be another expert opinion. It may be a system that makes expertise executable. Lunsford found his product brief in the gap between a company's incident plan and the night it actually needs to use it.

Underneath the clocks and audit trails is a moral argument Lunsford has carried since his student days. When asked what simple movement he would inspire, he chose the golden rule: treat other people as you would want to be treated, because we rarely know what someone else is carrying. His criticism of cyber regulation follows the same instinct. A company can be both a victim of an attacker and accountable for its response; punishing the people asked to defend it may drive talented leaders away from the work. The better standard, in his view, rewards preparation, candor and evidence of responsible action. That is why BreachRx's vocabulary so often returns to “defending the defenders.” The software is commercial, but the aspiration is institutional: make disciplined response easier for the people who must make consequential decisions with incomplete facts and a clock already running.