Find Out What Really Happened
Digital and Cyber Forensics
When there has been a breach, fraud or misuse, you need the facts and you need them to hold up. Our forensic team preserves the evidence, reconstructs what happened and explains it clearly, in a report that stands up to scrutiny.
See the engagement path, 5 phasesSee the full Managed Services service index
Overview
Digital and cyber forensics gives you a defensible answer to what happened, how and by whom. We preserve evidence properly from the first moment, acquire it under a documented chain of custody, and analyse it to reconstruct the timeline. Whether you are dealing with a ransomware attack, insider misuse or a dispute, we deliver clear findings you can act on and, where needed, support them as an expert. The priority throughout is accuracy and integrity, so your evidence survives challenge.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
5 Phases, 5 Named Handovers
Flow
Flow chart of the Digital and Cyber Forensics engagement, 5 phases in order, each one selectable. Phase 1, Engagement and Preservation. We move quickly to preserve volatile and stored evidence before it is lost or altered, and agree the scope and legal considerations with you. Activities: Instruct your team to stop altering the affected systems; Capture volatile memory and live network state first; Secure logs and backups before retention windows expire; Agree scope, legal privilege and reporting lines. Hands over Preservation Notice and Scope Agreement. Phase 2, Acquisition with Chain of Custody. We take forensic images of the relevant systems and media under a documented chain of custody, so every item is accounted for and defensible. Activities: Image disks with a verified write blocker; Hash every image and verify it against the source; Collect cloud and mobile data through documented exports; Log each item handled with time, place and handler. Hands over Chain of Custody Record. Phase 3, Analysis. We examine the acquired data for the artefacts that matter, from logs and files to memory and network traces, following the evidence wherever it leads. Activities: Recover deleted files and examine file system artefacts; Analyse memory images for injected code and credentials; Correlate authentication, endpoint and network logs; Identify malware, exfiltration paths and persistence. Hands over Analysis Findings with Supporting Artefacts. Phase 4, Reconstruction. We build a clear timeline of what happened, in what order and through which actions, separating fact from assumption. Activities: Build the incident timeline from artefacts; Establish the entry point and the attacker's dwell time; Determine what data was accessed, copied or destroyed; State clearly what the evidence cannot answer. Hands over Incident Timeline. Phase 5, Reporting and Expert Support. We deliver a clear, defensible report, and where a matter goes further we support it with expert testimony and evidence you can rely on. Activities: Write findings for both technical and legal readers; Reference every conclusion to its underlying artefact; Brief your counsel, insurer and leadership; Provide expert testimony if the matter proceeds. Hands over Forensic Report. Each phase begins from the artefact the phase before it produced.
Phase 01 Engagement and Preservation
We move quickly to preserve volatile and stored evidence before it is lost or altered, and agree the scope and legal considerations with you.
What Happens In This Phase
- Instruct your team to stop altering the affected systems
- Capture volatile memory and live network state first
- Secure logs and backups before retention windows expire
- Agree scope, legal privilege and reporting lines
The Handover
Preservation Notice and Scope Agreement
The next phase starts from this.
Phase 01 Engagement and Preservation
We move quickly to preserve volatile and stored evidence before it is lost or altered, and agree the scope and legal considerations with you.
What Happens In This Phase
- Instruct your team to stop altering the affected systems
- Capture volatile memory and live network state first
- Secure logs and backups before retention windows expire
- Agree scope, legal privilege and reporting lines
The Handover
Preservation Notice and Scope Agreement
The next phase starts from this.
- 01
Engagement and Preservation
We move quickly to preserve volatile and stored evidence before it is lost or altered, and agree the scope and legal considerations with you.
OutputPreservation Notice and Scope AgreementActivities
- Instruct your team to stop altering the affected systems
- Capture volatile memory and live network state first
- Secure logs and backups before retention windows expire
- Agree scope, legal privilege and reporting lines
- 02
Acquisition with Chain of Custody
We take forensic images of the relevant systems and media under a documented chain of custody, so every item is accounted for and defensible.
OutputChain of Custody RecordActivities
- Image disks with a verified write blocker
- Hash every image and verify it against the source
- Collect cloud and mobile data through documented exports
- Log each item handled with time, place and handler
- 03
Analysis
We examine the acquired data for the artefacts that matter, from logs and files to memory and network traces, following the evidence wherever it leads.
OutputAnalysis Findings with Supporting ArtefactsActivities
- Recover deleted files and examine file system artefacts
- Analyse memory images for injected code and credentials
- Correlate authentication, endpoint and network logs
- Identify malware, exfiltration paths and persistence
- 04
Reconstruction
We build a clear timeline of what happened, in what order and through which actions, separating fact from assumption.
OutputIncident TimelineActivities
- Build the incident timeline from artefacts
- Establish the entry point and the attacker's dwell time
- Determine what data was accessed, copied or destroyed
- State clearly what the evidence cannot answer
- 05
Reporting and Expert Support
We deliver a clear, defensible report, and where a matter goes further we support it with expert testimony and evidence you can rely on.
OutputForensic ReportActivities
- Write findings for both technical and legal readers
- Reference every conclusion to its underlying artefact
- Brief your counsel, insurer and leadership
- Provide expert testimony if the matter proceeds
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
What Is Examined, and What it Is Measured Against
Map
Map of the Digital and Cyber Forensics scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Autopsy, FTK Imager, Volatility, Magnet AXIOM, Wireshark, X-Ways Forensics, plaso / log2timeline, KAPE. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: NIST SP 800-86, ISO 27037, ACPO Good Practice Guide, SWGDE guidelines, NIST SP 800-101.
What We Run
8 tools
- FTK Imager
- X-Ways Forensics
- plaso / log2timeline
- KAPE
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
5 standards
- ACPO
- SWGDE
Deliverables
What You Receive
- Forensically sound evidence acquisition
- Documented chain of custody
- Timeline reconstruction of the incident
- Clear, defensible forensic report
- Expert support if the matter proceeds
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
Will your findings hold up in court or a tribunal?
Yes. We work to recognised forensic standards, maintain a documented chain of custody and write reports designed to withstand scrutiny, so your evidence stands up when it matters.
How fast can you start after an incident?
Quickly, because early action preserves evidence that fades. Contact us as soon as you suspect a problem, and avoid changing the affected systems until we have imaged them.
Can you investigate insider misuse discreetly?
Yes. We handle sensitive internal matters confidentially, preserve evidence without tipping off the subject where appropriate, and report only to the people you nominate.
Keep Moving Through Managed Services
Service 7 of 7 in this practice area
Practice Area
More in Managed Services
- Red Team AssessmentGoal-based adversary simulation across people, process and technology
- SOC as a ServiceA 24/7 security operations centre run by our analysts
- vCISOSenior security leadership on demand, without a full-time hire
- vDPOA data protection officer as a service for the DPDP Act and beyond
- Phishing SimulationsSafe, realistic phishing tests that build lasting instincts
- Awareness TrainingsSecurity training your people actually remember and use