Digital Forensics and Incident Investigation

Digital forensics is the careful collection and analysis of digital evidence to establish what happened during an incident. After a breach, fraud or data leak, management needs facts: how the attacker got in, what they did and which data was affected. Those facts shape decisions on containment, notifying regulators and customers, insurance claims and, sometimes, legal action.

When should you call a forensic team?

As early as possible, ideally while the incident is still unfolding. Some evidence, such as the contents of a computer’s memory or short-lived logs, disappears quickly. Well-meant clean-up by IT staff can also destroy it.

Typical cases include cyberattacks, data breaches, theft of intellectual property, insider misconduct and fraud. We usually work with the CISO, legal counsel, HR or internal audit, who need an independent and defensible account of events.

What happens during an investigation

Take a common scenario. Your team receives a report of a data breach and suspects someone has gained unauthorized access to the network.

We first identify the affected systems and the accounts used, and isolate them if needed. We then collect evidence, including log files, network traffic, memory and disk images. Volatile evidence, which is lost when a machine is switched off, is captured first.

Each forensic copy is given a hash, a digital fingerprint that proves it has not been altered since collection. It is stored securely and recorded in a chain of custody, a log of who handled the evidence and when. Investigators then rebuild the timeline: how the attacker got in, what they did and what data was taken.

The findings go to the incident response team, management and, where required, legal counsel and regulators, together with recommendations. Your organization then puts the improvements in place to prevent a repeat.

Standards we follow

Evidence handling follows ISO/IEC 27037, the international guideline for identifying, collecting, acquiring and preserving digital evidence. We also follow NIST SP 800-86 on building forensic techniques into incident response. Investigations can cover computers, servers, networks, cloud services and mobile devices.

What you receive

  • An investigation report with the timeline, root cause and the data affected.
  • Chain-of-custody records and evidence hashes.
  • Indicators of compromise (technical traces the attacker left behind), for your monitoring and threat hunting.
  • Remediation recommendations and, where needed, input for regulatory breach notifications.

Contact us for a forensic investigation to preserve evidence and establish the facts.