Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Part of Managed Services9 services in this practice area

Find Out What Really Happened

Digital and Cyber Forensics

When there has been a breach, fraud or misuse, you need the facts and you need them to hold up. Our forensic team preserves the evidence, reconstructs what happened and explains it clearly, in a report that stands up to scrutiny.

See the engagement path, 5 phasesSee the full Managed Services service index

Overview

Digital and cyber forensics gives you a defensible answer to what happened, how and by whom. We preserve evidence properly from the first moment, acquire it under a documented chain of custody, and analyse it to reconstruct the timeline. Whether you are dealing with a ransomware attack, insider misuse or a dispute, we deliver clear findings you can act on and, where needed, support them as an expert. The priority throughout is accuracy and integrity, so your evidence survives challenge.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

5 Phases, 5 Named Handovers

Flow

Flow chart of the Digital and Cyber Forensics engagement, 5 phases in order, each one selectable. Phase 1, Engagement and Preservation. We move quickly to preserve volatile and stored evidence before it is lost or altered, and agree the scope and legal considerations with you. Activities: Instruct your team to stop altering the affected systems; Capture volatile memory and live network state first; Secure logs and backups before retention windows expire; Agree scope, legal privilege and reporting lines. Hands over Preservation Notice and Scope Agreement. Phase 2, Acquisition with Chain of Custody. We take forensic images of the relevant systems and media under a documented chain of custody, so every item is accounted for and defensible. Activities: Image disks with a verified write blocker; Hash every image and verify it against the source; Collect cloud and mobile data through documented exports; Log each item handled with time, place and handler. Hands over Chain of Custody Record. Phase 3, Analysis. We examine the acquired data for the artefacts that matter, from logs and files to memory and network traces, following the evidence wherever it leads. Activities: Recover deleted files and examine file system artefacts; Analyse memory images for injected code and credentials; Correlate authentication, endpoint and network logs; Identify malware, exfiltration paths and persistence. Hands over Analysis Findings with Supporting Artefacts. Phase 4, Reconstruction. We build a clear timeline of what happened, in what order and through which actions, separating fact from assumption. Activities: Build the incident timeline from artefacts; Establish the entry point and the attacker's dwell time; Determine what data was accessed, copied or destroyed; State clearly what the evidence cannot answer. Hands over Incident Timeline. Phase 5, Reporting and Expert Support. We deliver a clear, defensible report, and where a matter goes further we support it with expert testimony and evidence you can rely on. Activities: Write findings for both technical and legal readers; Reference every conclusion to its underlying artefact; Brief your counsel, insurer and leadership; Provide expert testimony if the matter proceeds. Hands over Forensic Report. Each phase begins from the artefact the phase before it produced.

Phase 01 Engagement and Preservation

We move quickly to preserve volatile and stored evidence before it is lost or altered, and agree the scope and legal considerations with you.

What Happens In This Phase

  • Instruct your team to stop altering the affected systems
  • Capture volatile memory and live network state first
  • Secure logs and backups before retention windows expire
  • Agree scope, legal privilege and reporting lines

The Handover

Preservation Notice and Scope Agreement

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Engagement and Preservation

    We move quickly to preserve volatile and stored evidence before it is lost or altered, and agree the scope and legal considerations with you.

    OutputPreservation Notice and Scope Agreement

    Activities

    • Instruct your team to stop altering the affected systems
    • Capture volatile memory and live network state first
    • Secure logs and backups before retention windows expire
    • Agree scope, legal privilege and reporting lines
  2. 02

    Acquisition with Chain of Custody

    We take forensic images of the relevant systems and media under a documented chain of custody, so every item is accounted for and defensible.

    OutputChain of Custody Record

    Activities

    • Image disks with a verified write blocker
    • Hash every image and verify it against the source
    • Collect cloud and mobile data through documented exports
    • Log each item handled with time, place and handler
  3. 03

    Analysis

    We examine the acquired data for the artefacts that matter, from logs and files to memory and network traces, following the evidence wherever it leads.

    OutputAnalysis Findings with Supporting Artefacts

    Activities

    • Recover deleted files and examine file system artefacts
    • Analyse memory images for injected code and credentials
    • Correlate authentication, endpoint and network logs
    • Identify malware, exfiltration paths and persistence
  4. 04

    Reconstruction

    We build a clear timeline of what happened, in what order and through which actions, separating fact from assumption.

    OutputIncident Timeline

    Activities

    • Build the incident timeline from artefacts
    • Establish the entry point and the attacker's dwell time
    • Determine what data was accessed, copied or destroyed
    • State clearly what the evidence cannot answer
  5. 05

    Reporting and Expert Support

    We deliver a clear, defensible report, and where a matter goes further we support it with expert testimony and evidence you can rely on.

    OutputForensic Report

    Activities

    • Write findings for both technical and legal readers
    • Reference every conclusion to its underlying artefact
    • Brief your counsel, insurer and leadership
    • Provide expert testimony if the matter proceeds

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the Digital and Cyber Forensics scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Autopsy, FTK Imager, Volatility, Magnet AXIOM, Wireshark, X-Ways Forensics, plaso / log2timeline, KAPE. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: NIST SP 800-86, ISO 27037, ACPO Good Practice Guide, SWGDE guidelines, NIST SP 800-101.

What We Run

8 tools

  • Autopsy
  • FTK Imager
  • Volatility
  • Magnet AXIOM
  • Wireshark
  • X-Ways Forensics
  • plaso / log2timeline
  • KAPE

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

5 standards

  • NIST SP 800-86
  • ISO 27037
  • ACPOGood Practice Guide
  • SWGDEGuidelines
  • NIST SP 800-101
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Forensically sound evidence acquisition
  • Documented chain of custody
  • Timeline reconstruction of the incident
  • Clear, defensible forensic report
  • Expert support if the matter proceeds

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

What should we do in the first hour, and what should we avoid?

Stop changing the affected systems, and do not wipe or reimage them. The instinct after a breach is to rebuild the host and get back to work, but a reimage destroys the evidence that would have told you how far the intruder reached and what they took. Isolate the machine at the network rather than powering it off, because memory holds running processes, connections and credentials that disappear on shutdown. Keep other people from logging in to look around, since each session writes new artefacts over older ones, and write down who noticed what and when while it is still fresh. Extend or freeze log retention on identity, endpoint and firewall systems before the window rolls, and check whether your backups are on a delete schedule. Then call us: our first phase is engagement and preservation, and it begins by telling your team what to leave alone. Evidence that is gone does not come back.

How is the evidence handled, and what does chain of custody actually mean here?

Chain of custody means each item of evidence is logged with the time, the place and the person who handled it, and that log is a named deliverable, the Chain of Custody Record. Disks are imaged through a verified write blocker so the source is not altered, images are hashed and verified against the source, and cloud and mobile data is collected through documented exports rather than screenshots. It matters because the first question from anyone contesting your findings is whether the evidence could have changed between the incident and the report. A hash that still matches, alongside an unbroken handling log, answers that without argument. The handling is measured against published standards including ISO 27037 and NIST SP 800-86, and against the ACPO and SWGDE guidance. If the matter later reaches counsel, an insurer or a tribunal, that record is what makes the rest of the report usable.

What can realistically be recovered, and what cannot?

Deleted files are often recoverable; overwritten ones generally are not. On a system reached early, file system artefacts, memory and correlated logs together usually show what ran, what left the network and how the intruder held on. What defeats recovery is time and overwriting: a disk that kept running for weeks, a log that aged out of its retention window, a cloud service that keeps only thirty days of sign-in records, or a device reimaged before anyone called. Encrypted volumes without keys, and remote systems you do not control, sit outside reach. Attribution to a named human is usually beyond what technical evidence alone can carry; it can place an account and a device at an action. Our reconstruction phase states plainly what the evidence cannot answer, rather than filling gaps with plausible narrative. A report that separates proven fact from inference is the one that survives a hostile reading.

Will the findings be usable by our insurer, our counsel or a regulator?

They are written to be read by all three. The forensic report ties conclusions back to the underlying artefact, so a reader can follow a statement to the log line, file or memory structure it rests on, and technical and legal readers are served by the same document. The incident timeline sets out the entry point, the dwell time and what data was accessed, copied or destroyed, which is the substance an insurer or counsel works from. We brief your counsel, insurer and leadership directly, and provide expert testimony if the matter proceeds. On the regulatory side, CERT-In directions require certain incidents to be reported within six hours of noticing them, and the DPDP Act carries its own breach notification duties. Those obligations sit with you and your counsel. Forensics supplies the facts a notification has to rest on; the filing and the legal judgement are not ours to make.

How does an engagement start, and what is not included?

It starts with a scoping call. You tell us about the environment, the systems involved and any deadlines you are working to, and we come back with scope, effort and a start date. In an active incident we agree the preservation steps on that call, so evidence is protected while the paperwork is settled, along with legal privilege and who the findings are reported to. You supply access to the affected systems and the relevant logs and exports, and the sooner those are made available the more of them still exist. Not included: we do not give legal advice, we do not make regulatory filings for you, and rebuilding or hardening the environment afterwards is separate work, though the report tells you what needs attention. Analysis is done by hand, and findings are reproduced before they are written down. SecureRoot is ISO/IEC 27001:2022 certified, certificate IN60432E, and ISO 9001:2015 certified.

Keep Moving Through Managed Services

Service 9 of 9 in this practice area