Find Out What Really Happened
Digital and Cyber Forensics
When there has been a breach, fraud or misuse, you need the facts and you need them to hold up. Our forensic team preserves the evidence, reconstructs what happened and explains it clearly, in a report that stands up to scrutiny.
See the engagement path, 5 phasesSee the full Managed Services service index
Overview
Digital and cyber forensics gives you a defensible answer to what happened, how and by whom. We preserve evidence properly from the first moment, acquire it under a documented chain of custody, and analyse it to reconstruct the timeline. Whether you are dealing with a ransomware attack, insider misuse or a dispute, we deliver clear findings you can act on and, where needed, support them as an expert. The priority throughout is accuracy and integrity, so your evidence survives challenge.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
5 Phases, 5 Named Handovers
Flow
Flow chart of the Digital and Cyber Forensics engagement, 5 phases in order, each one selectable. Phase 1, Engagement and Preservation. We move quickly to preserve volatile and stored evidence before it is lost or altered, and agree the scope and legal considerations with you. Activities: Instruct your team to stop altering the affected systems; Capture volatile memory and live network state first; Secure logs and backups before retention windows expire; Agree scope, legal privilege and reporting lines. Hands over Preservation Notice and Scope Agreement. Phase 2, Acquisition with Chain of Custody. We take forensic images of the relevant systems and media under a documented chain of custody, so every item is accounted for and defensible. Activities: Image disks with a verified write blocker; Hash every image and verify it against the source; Collect cloud and mobile data through documented exports; Log each item handled with time, place and handler. Hands over Chain of Custody Record. Phase 3, Analysis. We examine the acquired data for the artefacts that matter, from logs and files to memory and network traces, following the evidence wherever it leads. Activities: Recover deleted files and examine file system artefacts; Analyse memory images for injected code and credentials; Correlate authentication, endpoint and network logs; Identify malware, exfiltration paths and persistence. Hands over Analysis Findings with Supporting Artefacts. Phase 4, Reconstruction. We build a clear timeline of what happened, in what order and through which actions, separating fact from assumption. Activities: Build the incident timeline from artefacts; Establish the entry point and the attacker's dwell time; Determine what data was accessed, copied or destroyed; State clearly what the evidence cannot answer. Hands over Incident Timeline. Phase 5, Reporting and Expert Support. We deliver a clear, defensible report, and where a matter goes further we support it with expert testimony and evidence you can rely on. Activities: Write findings for both technical and legal readers; Reference every conclusion to its underlying artefact; Brief your counsel, insurer and leadership; Provide expert testimony if the matter proceeds. Hands over Forensic Report. Each phase begins from the artefact the phase before it produced.
Phase 01 Engagement and Preservation
We move quickly to preserve volatile and stored evidence before it is lost or altered, and agree the scope and legal considerations with you.
What Happens In This Phase
- Instruct your team to stop altering the affected systems
- Capture volatile memory and live network state first
- Secure logs and backups before retention windows expire
- Agree scope, legal privilege and reporting lines
The Handover
Preservation Notice and Scope Agreement
The next phase starts from this.
Phase 01 Engagement and Preservation
We move quickly to preserve volatile and stored evidence before it is lost or altered, and agree the scope and legal considerations with you.
What Happens In This Phase
- Instruct your team to stop altering the affected systems
- Capture volatile memory and live network state first
- Secure logs and backups before retention windows expire
- Agree scope, legal privilege and reporting lines
The Handover
Preservation Notice and Scope Agreement
The next phase starts from this.
- 01
Engagement and Preservation
We move quickly to preserve volatile and stored evidence before it is lost or altered, and agree the scope and legal considerations with you.
OutputPreservation Notice and Scope AgreementActivities
- Instruct your team to stop altering the affected systems
- Capture volatile memory and live network state first
- Secure logs and backups before retention windows expire
- Agree scope, legal privilege and reporting lines
- 02
Acquisition with Chain of Custody
We take forensic images of the relevant systems and media under a documented chain of custody, so every item is accounted for and defensible.
OutputChain of Custody RecordActivities
- Image disks with a verified write blocker
- Hash every image and verify it against the source
- Collect cloud and mobile data through documented exports
- Log each item handled with time, place and handler
- 03
Analysis
We examine the acquired data for the artefacts that matter, from logs and files to memory and network traces, following the evidence wherever it leads.
OutputAnalysis Findings with Supporting ArtefactsActivities
- Recover deleted files and examine file system artefacts
- Analyse memory images for injected code and credentials
- Correlate authentication, endpoint and network logs
- Identify malware, exfiltration paths and persistence
- 04
Reconstruction
We build a clear timeline of what happened, in what order and through which actions, separating fact from assumption.
OutputIncident TimelineActivities
- Build the incident timeline from artefacts
- Establish the entry point and the attacker's dwell time
- Determine what data was accessed, copied or destroyed
- State clearly what the evidence cannot answer
- 05
Reporting and Expert Support
We deliver a clear, defensible report, and where a matter goes further we support it with expert testimony and evidence you can rely on.
OutputForensic ReportActivities
- Write findings for both technical and legal readers
- Reference every conclusion to its underlying artefact
- Brief your counsel, insurer and leadership
- Provide expert testimony if the matter proceeds
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
What Is Examined, and What it Is Measured Against
Map
Map of the Digital and Cyber Forensics scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Autopsy, FTK Imager, Volatility, Magnet AXIOM, Wireshark, X-Ways Forensics, plaso / log2timeline, KAPE. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: NIST SP 800-86, ISO 27037, ACPO Good Practice Guide, SWGDE guidelines, NIST SP 800-101.
What We Run
8 tools
- Autopsy
- FTK Imager
- Volatility
- Magnet AXIOM
- Wireshark
- X-Ways Forensics
- plaso / log2timeline
- KAPE
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
5 standards
- NIST SP 800-86
- ISO 27037
- ACPOGood Practice Guide
- SWGDEGuidelines
- NIST SP 800-101
Deliverables
What You Receive
- Forensically sound evidence acquisition
- Documented chain of custody
- Timeline reconstruction of the incident
- Clear, defensible forensic report
- Expert support if the matter proceeds
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
What should we do in the first hour, and what should we avoid?
Stop changing the affected systems, and do not wipe or reimage them. The instinct after a breach is to rebuild the host and get back to work, but a reimage destroys the evidence that would have told you how far the intruder reached and what they took. Isolate the machine at the network rather than powering it off, because memory holds running processes, connections and credentials that disappear on shutdown. Keep other people from logging in to look around, since each session writes new artefacts over older ones, and write down who noticed what and when while it is still fresh. Extend or freeze log retention on identity, endpoint and firewall systems before the window rolls, and check whether your backups are on a delete schedule. Then call us: our first phase is engagement and preservation, and it begins by telling your team what to leave alone. Evidence that is gone does not come back.
How is the evidence handled, and what does chain of custody actually mean here?
Chain of custody means each item of evidence is logged with the time, the place and the person who handled it, and that log is a named deliverable, the Chain of Custody Record. Disks are imaged through a verified write blocker so the source is not altered, images are hashed and verified against the source, and cloud and mobile data is collected through documented exports rather than screenshots. It matters because the first question from anyone contesting your findings is whether the evidence could have changed between the incident and the report. A hash that still matches, alongside an unbroken handling log, answers that without argument. The handling is measured against published standards including ISO 27037 and NIST SP 800-86, and against the ACPO and SWGDE guidance. If the matter later reaches counsel, an insurer or a tribunal, that record is what makes the rest of the report usable.
What can realistically be recovered, and what cannot?
Deleted files are often recoverable; overwritten ones generally are not. On a system reached early, file system artefacts, memory and correlated logs together usually show what ran, what left the network and how the intruder held on. What defeats recovery is time and overwriting: a disk that kept running for weeks, a log that aged out of its retention window, a cloud service that keeps only thirty days of sign-in records, or a device reimaged before anyone called. Encrypted volumes without keys, and remote systems you do not control, sit outside reach. Attribution to a named human is usually beyond what technical evidence alone can carry; it can place an account and a device at an action. Our reconstruction phase states plainly what the evidence cannot answer, rather than filling gaps with plausible narrative. A report that separates proven fact from inference is the one that survives a hostile reading.
Will the findings be usable by our insurer, our counsel or a regulator?
They are written to be read by all three. The forensic report ties conclusions back to the underlying artefact, so a reader can follow a statement to the log line, file or memory structure it rests on, and technical and legal readers are served by the same document. The incident timeline sets out the entry point, the dwell time and what data was accessed, copied or destroyed, which is the substance an insurer or counsel works from. We brief your counsel, insurer and leadership directly, and provide expert testimony if the matter proceeds. On the regulatory side, CERT-In directions require certain incidents to be reported within six hours of noticing them, and the DPDP Act carries its own breach notification duties. Those obligations sit with you and your counsel. Forensics supplies the facts a notification has to rest on; the filing and the legal judgement are not ours to make.
How does an engagement start, and what is not included?
It starts with a scoping call. You tell us about the environment, the systems involved and any deadlines you are working to, and we come back with scope, effort and a start date. In an active incident we agree the preservation steps on that call, so evidence is protected while the paperwork is settled, along with legal privilege and who the findings are reported to. You supply access to the affected systems and the relevant logs and exports, and the sooner those are made available the more of them still exist. Not included: we do not give legal advice, we do not make regulatory filings for you, and rebuilding or hardening the environment afterwards is separate work, though the report tells you what needs attention. Analysis is done by hand, and findings are reproduced before they are written down. SecureRoot is ISO/IEC 27001:2022 certified, certificate IN60432E, and ISO 9001:2015 certified.
Keep Moving Through Managed Services
Service 9 of 9 in this practice area
Practice Area
More in Managed Services
- Red Team AssessmentGoal-based adversary simulation across people, process and technology
- SOC as a ServiceA 24/7 security operations centre run by our analysts
- Attack Surface ManagementRecurring discovery of what you expose to the internet, and what is wrong with it
- Dark Web MonitoringAnalyst-validated monitoring for leaked credentials, documents and brand abuse
- vCISOSenior security leadership on demand, without a full-time hire
- vDPOA data protection officer as a service for the DPDP Act and beyond
- Phishing SimulationsSafe, realistic phishing tests that build lasting instincts
- Awareness TrainingsSecurity training your people actually remember and use