ThreeShield's founder, Chris Nowell (CISSP, CISA), serves as an expert witness for law firms in Alberta in matters of information security and cybercrime before the Court of King's Bench of Alberta. Independent expert reports, technical analysis, and testimony — delivered with the impartiality the court expects and in language a judge can follow.
Information-security disputes turn on details that are easy to get wrong and hard to explain: what a log actually shows, whether reasonable safeguards were in place, how a breach happened and how far it reached. The value of an expert is not just knowing the answer, but setting it out clearly and impartially enough that a court can rely on it. That is the work.
Whether an organization's information-security safeguards were reasonable for its size, sector, and the data it held, measured against recognized frameworks rather than hindsight.
How an incident occurred, what data was exposed, how far it reached, and whether the response was adequate and timely.
What the logs, configurations, and controls actually demonstrate — and, just as important, what they do not — explained so the court can weigh them.
Analysis in matters involving unauthorized access, misuse of systems, and related conduct, grounded in how the technology genuinely behaves.
How obligations under Canadian and Alberta frameworks — such as PIPA, HIA, and PIPEDA — bear on the security questions in dispute.
Independent review of an opposing expert's report to test its methods, assumptions, and conclusions.
An expert's overriding duty is to assist the court impartially, and that duty prevails over the interests of the party who retains the expert. We take instructions from counsel and answer the questions put to us, but the opinion is our own and is given honestly. If the evidence does not support a position, we say so early — while it is still useful to know, and long before it becomes a problem under cross-examination.
CISSP and CISA — credentials that require examination, verified experience, and adherence to formal codes of professional ethics.
Chris Nowell established the computer-assisted audit techniques programs at United Technologies Corporation and at the Office of the Auditor General of Alberta, and wrote the Windows and Unix security analyzers later licensed to Ernst & Young, Deloitte, KPMG, NASA, Pratt & Whitney and Sikorsky.
Through the Office of the Auditor General of Alberta, he assessed the information security of nearly every Government of Alberta entity — the kind of disciplined, evidence-based assessment a court expects.
The report is written for a judge, not for engineers: the facts relied on, the analysis, and the opinion, in plain language, with the technical detail available to support it.
| Stage | What happens |
|---|---|
| 1. Conflict & scope check | Tell us the general nature of the matter and the timeline. We confirm availability, independence, and the absence of conflicts before you share anything privileged. |
| 2. Retainer | Counsel retains ThreeShield, typically under the firm's engagement terms, with scope and the expert's independent duty confirmed in writing. |
| 3. Analysis & report | We review the technical evidence and prepare an expert report setting out the facts relied on, the analysis, and the opinion. |
| 4. Testimony | Where required, the expert is available for questioning and to give oral evidence, and to prepare rebuttals to opposing reports. |
ThreeShield's founder, Chris Nowell, serves as the expert. He holds the CISSP and CISA credentials, established the computer-assisted audit techniques programs at United Technologies Corporation and at the Office of the Auditor General of Alberta, and wrote the Windows and Unix security analyzers later licensed to Ernst & Young, Deloitte, KPMG, NASA, Pratt & Whitney and Sikorsky. He is retained through ThreeShield and serves as an expert witness for law firms in Alberta in matters of information security and cybercrime.
Engagements have involved matters of information security and cybercrime before the Court of King's Bench of Alberta. Typical subjects include the standard of care for safeguarding information, the cause and scope of a data breach, the adequacy of an organization's response, and the interpretation of security controls, logs, and technical evidence for the court.
An expert's duty is to the court, not to the party who retains them, and that duty overrides the interests of either side. We take instructions from counsel and address the questions put to us, but the opinion is our own and is given impartially. If the evidence does not support a position, we will say so before it becomes a problem in the box.
Usually a written expert report setting out the facts relied on, the analysis, and the opinion in language a judge can follow, along with the supporting technical work. Where required, the expert is available for questioning and to give oral testimony. Early-stage consulting — for example, reviewing the other side's report or helping counsel frame the technical questions — is also available.
Counsel retains ThreeShield, typically under the firm's engagement terms, and we confirm scope, independence, and any conflicts in writing before work begins. Contact us with the general nature of the matter and the timeline, and we will confirm availability and fit before you share anything privileged.
No. ThreeShield provides technical expert analysis and opinion on information security and cybercrime; it does not provide legal advice, and nothing here creates a solicitor-client relationship. Legal strategy remains with counsel.
Tell us the general nature of the dispute and the timeline. We will confirm availability, check for conflicts, and confirm the expert's independent duty before you share anything privileged.
Contact ThreeShieldIndependent · Impartial duty to the court · Alberta-wide