Digital Forensics & Investigation Support

Digital Forensics and Investigation Support

We support authorized corporate investigations: planning preservation so evidence is not lost, analysing the disk, file, memory and log evidence in scope, maintaining custody records and reporting findings that an examiner has reviewed.

Every engagement starts with scope and authorization. We confirm what you are permitted to examine, and that a suitable examiner is available, before any evidence changes hands.

When this helps

Situations we are usually called into

  • A departing employee is suspected of taking data and you need to establish what actually happened.
  • You are responding to an incident and need the right evidence preserved before systems are rebuilt.
  • An internal policy or misconduct investigation needs a factual technical record.
  • Counsel has asked for technical analysis to support a dispute or insurance claim.
  • You need to understand how an account was accessed and what was touched afterwards.

Scope & deliverables

What the engagement covers

Preservation planning

The first hour matters. We help you stop evidence being overwritten before analysis begins.

  • Identify likely evidence sources and retention risk
  • Guidance on isolating rather than wiping or rebuilding systems
  • Acquisition planning for in-scope devices and cloud sources
  • Documented decisions about what is and is not preserved

Evidence analysis

Analysis of the supported evidence types agreed in scope.

  • Disk and file system analysis, including deleted-file artefacts where recoverable
  • File metadata, external device and data-transfer artefacts
  • Memory image analysis where a memory capture is available
  • Log analysis across endpoints, servers, network and cloud services

Custody and documentation

A record that stands up to review by people who were not in the room.

  • Chain-of-custody records for items received and returned
  • Hashing and verification of acquired images where applicable
  • Contemporaneous notes of examination steps and tooling
  • Clear statement of scope limitations and unanswered questions

Findings and reporting

Plain-language findings with the technical detail behind them.

  • Timeline reconstruction of the relevant activity
  • Factual findings separated from interpretation
  • Examiner review before any report is released
  • Briefing for leadership, HR or counsel as agreed

What you receive

  • Written scope and authorization confirmation before evidence is accepted
  • Preservation plan and acquisition records for in-scope sources
  • Chain-of-custody documentation for every item handled
  • Timeline reconstruction of relevant activity with supporting artefacts
  • Examiner-reviewed report separating fact from interpretation, including limitations
  • Verbal briefing for the recipients you nominate

Scope and limitations

Capabilities, examiner availability and any case-specific credential requirements are confirmed before an engagement is accepted. Data recovery depends on the device, encryption and condition of the evidence. Court admissibility is determined by the relevant tribunal; coordinate legal requirements with counsel. Response times and supported evidence types are agreed in writing.

How we work

A five-step engagement

  1. Step 01

    Confirm scope and authorization

    Establish what happened at a high level, what you are authorized to examine, who the recipients are and whether an examiner is available.

  2. Step 02

    Preserve

    Plan and document preservation of in-scope evidence, with custody records from the moment items are received.

  3. Step 03

    Analyse

    Examine the agreed disk, file, memory and log evidence, recording each step and the tooling used.

  4. Step 04

    Reconstruct

    Build a timeline from corroborated artefacts, separating what the evidence shows from what it merely suggests.

  5. Step 05

    Report and brief

    Deliver an examiner-reviewed report with limitations stated, then brief your nominated recipients.

Working together

What we need from you, and how we handle your data

Your responsibilities

  • Confirm you are authorized to have the systems, accounts and devices examined, and involve counsel or HR where employment or privacy issues arise.
  • Avoid rebuilding, reimaging or wiping affected systems until preservation is agreed.
  • Name a small group of recipients for findings and keep distribution tight.
  • Provide the account, device and access context we need to interpret artefacts correctly.

Data handling

  • Do not send evidence, passwords, sensitive logs or personal data through the website enquiry form.
  • After scope and authorization are confirmed, we agree an appropriate evidence-transfer and handling process for the matter.
  • Evidence and working copies are held only for the retention period agreed in writing, then returned or destroyed with a record.
  • Case details are excluded from our website analytics and marketing systems.

How we use enquiry information is set out in our privacy policy.

FAQ

Digital Forensics & Investigation Support: common questions

Can you unlock a locked phone?

No. We do not offer passcode bypass or device unlocking. Where mobile evidence matters, we work with data you are able to provide lawfully, such as backups, exports or account records, and tell you if a specialist is needed.

Can you guarantee deleted files will be recovered?

No. Recoverability depends on the storage medium, encryption, how much has been written since deletion and whether the device was in use. We tell you what is realistic after seeing the evidence, and we report honestly when something cannot be recovered.

Will your report be accepted in court?

Admissibility is decided by the tribunal, on advice from your counsel. What we can do is work to a documented method, keep custody records and contemporaneous notes, separate fact from interpretation and state limitations clearly, so the work can be reviewed.

How quickly can you start?

It depends on examiner availability and the authorization position. We confirm both before accepting a matter. We do not advertise round-the-clock response, and we would rather tell you to seek help elsewhere than accept a matter we cannot staff properly.

What should we do right now to avoid losing evidence?

Isolate rather than rebuild affected systems, avoid logging into the account under investigation, preserve relevant logs before retention windows expire and keep a note of who has touched what. Then contact us with a brief, non-sensitive summary.

How confidential is an engagement?

Matters are handled on a need-to-know basis, findings go only to the recipients you name, and case detail is kept out of our analytics and marketing systems. Where the matter is legally sensitive, we can work at the direction of your counsel.

Discuss a confidential case

Share a brief, non-sensitive description of the situation. We will confirm scope, authorization and examiner availability before anything else.

Share a brief, non-sensitive description. Do not upload evidence, passwords or sensitive logs here. We confirm scope and authorization before arranging an appropriate evidence-transfer process.

Stay Updated. Stay Ahead.

Subscribe to receive the latest business insights, technology updates, company news, and useful ideas delivered to your inbox.

We respect your privacy. Unsubscribe at any time.