Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of Managed Services7 services in this practice area

Find Out What Really Happened

Digital and Cyber Forensics

When there has been a breach, fraud or misuse, you need the facts and you need them to hold up. Our forensic team preserves the evidence, reconstructs what happened and explains it clearly, in a report that stands up to scrutiny.

See the engagement path, 5 phasesSee the full Managed Services service index

Overview

Digital and cyber forensics gives you a defensible answer to what happened, how and by whom. We preserve evidence properly from the first moment, acquire it under a documented chain of custody, and analyse it to reconstruct the timeline. Whether you are dealing with a ransomware attack, insider misuse or a dispute, we deliver clear findings you can act on and, where needed, support them as an expert. The priority throughout is accuracy and integrity, so your evidence survives challenge.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

5 Phases, 5 Named Handovers

Flow

Flow chart of the Digital and Cyber Forensics engagement, 5 phases in order, each one selectable. Phase 1, Engagement and Preservation. We move quickly to preserve volatile and stored evidence before it is lost or altered, and agree the scope and legal considerations with you. Activities: Instruct your team to stop altering the affected systems; Capture volatile memory and live network state first; Secure logs and backups before retention windows expire; Agree scope, legal privilege and reporting lines. Hands over Preservation Notice and Scope Agreement. Phase 2, Acquisition with Chain of Custody. We take forensic images of the relevant systems and media under a documented chain of custody, so every item is accounted for and defensible. Activities: Image disks with a verified write blocker; Hash every image and verify it against the source; Collect cloud and mobile data through documented exports; Log each item handled with time, place and handler. Hands over Chain of Custody Record. Phase 3, Analysis. We examine the acquired data for the artefacts that matter, from logs and files to memory and network traces, following the evidence wherever it leads. Activities: Recover deleted files and examine file system artefacts; Analyse memory images for injected code and credentials; Correlate authentication, endpoint and network logs; Identify malware, exfiltration paths and persistence. Hands over Analysis Findings with Supporting Artefacts. Phase 4, Reconstruction. We build a clear timeline of what happened, in what order and through which actions, separating fact from assumption. Activities: Build the incident timeline from artefacts; Establish the entry point and the attacker's dwell time; Determine what data was accessed, copied or destroyed; State clearly what the evidence cannot answer. Hands over Incident Timeline. Phase 5, Reporting and Expert Support. We deliver a clear, defensible report, and where a matter goes further we support it with expert testimony and evidence you can rely on. Activities: Write findings for both technical and legal readers; Reference every conclusion to its underlying artefact; Brief your counsel, insurer and leadership; Provide expert testimony if the matter proceeds. Hands over Forensic Report. Each phase begins from the artefact the phase before it produced.

Phase 01 Engagement and Preservation

We move quickly to preserve volatile and stored evidence before it is lost or altered, and agree the scope and legal considerations with you.

What Happens In This Phase

  • Instruct your team to stop altering the affected systems
  • Capture volatile memory and live network state first
  • Secure logs and backups before retention windows expire
  • Agree scope, legal privilege and reporting lines

The Handover

Preservation Notice and Scope Agreement

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Engagement and Preservation

    We move quickly to preserve volatile and stored evidence before it is lost or altered, and agree the scope and legal considerations with you.

    OutputPreservation Notice and Scope Agreement

    Activities

    • Instruct your team to stop altering the affected systems
    • Capture volatile memory and live network state first
    • Secure logs and backups before retention windows expire
    • Agree scope, legal privilege and reporting lines
  2. 02

    Acquisition with Chain of Custody

    We take forensic images of the relevant systems and media under a documented chain of custody, so every item is accounted for and defensible.

    OutputChain of Custody Record

    Activities

    • Image disks with a verified write blocker
    • Hash every image and verify it against the source
    • Collect cloud and mobile data through documented exports
    • Log each item handled with time, place and handler
  3. 03

    Analysis

    We examine the acquired data for the artefacts that matter, from logs and files to memory and network traces, following the evidence wherever it leads.

    OutputAnalysis Findings with Supporting Artefacts

    Activities

    • Recover deleted files and examine file system artefacts
    • Analyse memory images for injected code and credentials
    • Correlate authentication, endpoint and network logs
    • Identify malware, exfiltration paths and persistence
  4. 04

    Reconstruction

    We build a clear timeline of what happened, in what order and through which actions, separating fact from assumption.

    OutputIncident Timeline

    Activities

    • Build the incident timeline from artefacts
    • Establish the entry point and the attacker's dwell time
    • Determine what data was accessed, copied or destroyed
    • State clearly what the evidence cannot answer
  5. 05

    Reporting and Expert Support

    We deliver a clear, defensible report, and where a matter goes further we support it with expert testimony and evidence you can rely on.

    OutputForensic Report

    Activities

    • Write findings for both technical and legal readers
    • Reference every conclusion to its underlying artefact
    • Brief your counsel, insurer and leadership
    • Provide expert testimony if the matter proceeds

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the Digital and Cyber Forensics scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Autopsy, FTK Imager, Volatility, Magnet AXIOM, Wireshark, X-Ways Forensics, plaso / log2timeline, KAPE. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: NIST SP 800-86, ISO 27037, ACPO Good Practice Guide, SWGDE guidelines, NIST SP 800-101.

What We Run

8 tools

  • Autopsy
  • FTK Imager
  • Volatility
  • Magnet AXIOM
  • Wireshark
  • X-Ways Forensics
  • plaso / log2timeline
  • KAPE

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

5 standards

  • NIST SP 800-86
  • ISO 27037
  • ACPOGood Practice Guide
  • SWGDEGuidelines
  • NIST SP 800-101
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Forensically sound evidence acquisition
  • Documented chain of custody
  • Timeline reconstruction of the incident
  • Clear, defensible forensic report
  • Expert support if the matter proceeds

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Will your findings hold up in court or a tribunal?

Yes. We work to recognised forensic standards, maintain a documented chain of custody and write reports designed to withstand scrutiny, so your evidence stands up when it matters.

How fast can you start after an incident?

Quickly, because early action preserves evidence that fades. Contact us as soon as you suspect a problem, and avoid changing the affected systems until we have imaged them.

Can you investigate insider misuse discreetly?

Yes. We handle sensitive internal matters confidentially, preserve evidence without tipping off the subject where appropriate, and report only to the people you nominate.

Keep Moving Through Managed Services

Service 7 of 7 in this practice area