Back to Full Team
Shawn Fleury Headshot

Shawn Fleury

Managing Director

Biography

Shawn Fleury is a Managing Director at Aletheian Labs and a digital investigations and forensic practitioner with nearly 30 years of experience working across litigation, investigations, and cybersecurity matters.

His work focuses on understanding how systems were secured, how they were used, and whether those practices were reasonable given the circumstances. That often means looking beyond what happened to assess why it happened and how decisions around security, controls, and operations shaped the outcome.

Shawn has worked extensively on matters involving data breaches, business email compromise, and disputes where the adequacy of security measures is in question. He serves as a testifying expert, offering opinions on security practices, business processes, and how organizations manage risk in practice.

He began his career as a computer crimes investigator with the U.S. military and has since held senior roles at Kivu Consulting, Palo Alto Networks’ Unit 42, and Alvarez & Marsal, where he led incident response, forensic investigations, and advisory engagements across a range of industries.

Areas of Focus
  • Evaluation of security controls and governance practices
  • Reasonable security analysis in litigation and disputes
  • Data breach and business email compromise matters
  • Assessment of system use, access, and data handling
  • Expert witness and advisory services
Representative Matters

Served as a testifying expert in a business email compromise matter involving a seven-figure fraudulent wire transfer, providing opinions on security controls, business practices, and industry standards

Evaluated cybersecurity controls for a global financial services company in connection with data breach litigation, including how those controls functioned at the time of the incident

Provided expert opinions in data breach litigation regarding whether security measures in place were reasonable at the time of the incident, based on the organization's size, structure, and risk profile

Led incident response and forensic investigation efforts following network intrusions, including analysis of attacker activity and data exposure

Conducted risk and control assessments for large organizations, including evaluation of cybersecurity programs and how those programs aligned with real-world use and expectations

Supported matters involving government inquiries and regulatory review, including defining scope and providing technical analysis