Incident Response & Digital Forensics

Digital Forensics & Investigation

Defensible evidence, and an answer to what actually happened.

The situation

Forensic investigation conducted to a standard that survives legal and regulatory challenge: sound acquisition, documented chain of custody, and analysis that distinguishes what the evidence shows from what it suggests.

Applied to breach investigation, insider data theft, fraud, employment disputes and regulatory enquiries, and reported for both technical and legal audiences.

What the client receives

Schedule of deliverables

  1. 01Forensically sound acquisition of disk, memory, cloud and mobile evidence
  2. 02Timeline reconstruction and root cause analysis
  3. 03Malware triage and behavioural analysis
  4. 04Data exfiltration scope determination (critical for breach notification)
  5. 05Insider investigation support with employment-law-aware handling
  6. 06Expert report suitable for legal and regulatory proceedings

Frameworks and standards

Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.

  • ISO/IEC 27037 / 27041 / 27042 / 27043
  • ACPO principles
  • NIST SP 800-86

Discuss this engagement

Tell us about the question that has to be answered and the evidence available and we will set out the scope, the method and the reporting format.

Contact us