Incident Response & Digital Forensics
Digital Forensics & Investigation
Defensible evidence, and an answer to what actually happened.
The situation
What the client receives
Schedule of deliverables
- Forensically sound acquisition of disk, memory, cloud and mobile evidence
- Timeline reconstruction and root cause analysis
- Malware triage and behavioural analysis
- Data exfiltration scope determination (critical for breach notification)
- Insider investigation support with employment-law-aware handling
- Expert report suitable for legal and regulatory proceedings
Frameworks and standards
Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.
- ISO/IEC 27037 / 27041 / 27042 / 27043
- ACPO principles
- NIST SP 800-86
Related services
Discuss this engagement
Tell us about the question that has to be answered and the evidence available and we will set out the scope, the method and the reporting format.