Skip to content

Services / Respond

Digital Forensics

Chain-of-custody forensic examination of endpoints, servers, cloud tenancy and mobile devices, producing evidence that survives legal challenge.

What you receive

  • Documented chain of custody from acquisition
  • Timeline reconstruction and attribution assessment
  • Expert witness statement and testimony
  • Insurer and regulator liaison

When you need this

Three situations that call for it. If none of them is yours, it probably is not the right spend.

  • 01

    A departing employee took something with them

    Cloud sync, personal mail and a USB device leave different traces, and the ones that matter expire quickly. If the matter reaches a tribunal or a civil claim, how the copy was made will be attacked long before what it contains.

  • 02

    Your insurer has appointed its own expert

    In a coverage dispute your findings are read by someone paid to find the weak joint in them. Method, hashing and chain of custody are what get tested first, which is why they are the product rather than the paperwork around it.

  • 03

    You need to prove what did not happen

    Showing that a particular dataset was never accessed is a narrower and harder question than showing an intrusion occurred. It depends entirely on whether the logging existed, was complete, and covered the window in question.

How it runs

  1. 01

    Scoping call

    Thirty minutes with an engineer, not a sales development rep. We establish what you actually need and tell you plainly if it is not us.

  2. 02

    Written proposal

    Fixed scope, fixed price, named delivery team, and the rules of engagement in writing before anyone touches a system.

  3. 03

    Delivery

    Weekly written status and a direct channel to the delivery lead. Critical findings are escalated the moment they are confirmed, never held back for the report.

  4. 04

    Readout and retest

    A working session with your team, an executive summary for your board, and a remediation retest included in the original scope rather than quoted separately.

No lock-in

Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.

Who turns up

The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.

Scope

What this does not cover

  • If the intrusion is still live, containment comes first — that is Incident Response, and forensics runs alongside or after it.

  • We do not provide legal representation or advocacy; the report and any testimony are evidence for your counsel to use as they see fit.

  • We cannot recover what was never retained — where logging was disabled or has expired, we record the gap rather than infer across it.

Measured against

ISO/IEC 27037:2012
Guidelines for identifying, collecting, acquiring and preserving digital evidence so that its integrity can be demonstrated.
ISO/IEC 27042:2015
Guidance on analysing and interpreting digital evidence, including how findings and their limitations should be expressed.
ACPO/NPCC Good Practice Guide for Digital Evidence (England and Wales)
Four principles: original data is not changed; where access to it is unavoidable, the person must be competent and able to explain what they did and why; an audit trail is kept that a third party could follow and repeat; and the officer in charge is responsible for compliance.

If the scope is wrong

Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.

Questions

The ones we are actually asked.

Will your report hold up in our jurisdiction?

Admissibility rules differ by court and we do not practise law in yours. We work to a documented, repeatable method so the evidence is defensible on its own terms and your counsel can argue the rest.

Our IT team already copied the files. Is that a problem?

Often, yes. A copy made without write-blocking, hashing or a record of who handled it is not worthless, but its weight falls the moment an opposing expert asks how it was produced.

How long does an examination take?

Longer than incident response, because here the method is the product. Scope decides it — a single endpoint is a narrower question than a cloud tenancy with mobile devices and months of logs. We would rather give you a duration after scoping than before it, because rushing the method is what gets findings excluded.

Next step

See what an attacker sees

We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.

30 min

A scoping call, with an engineer rather than a sales rep.

What it costs

Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.

Under attack now?

Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.