Forensics

Digital Forensics & IR

Forensic acquisition and analysis to reconstruct and contain incidents.

What it is

Forensic investigation that stands up when it matters — to a regulator, an insurer, or a court. We acquire evidence defensibly, maintain chain of custody throughout, reconstruct what happened from the artefacts rather than assumption, and report in language a non-technical decision maker can rely on.

How we do it

  1. 1

    Evidence preservation

    Forensic imaging with hash verification, and volatile memory captured before anything is powered down.

  2. 2

    Chain of custody

    Documented handling from acquisition onward, because evidence handled casually is evidence that can be challenged.

  3. 3

    Timeline reconstruction

    File system, registry, event log and application artefacts correlated into a single defensible sequence.

  4. 4

    Artefact analysis

    Execution evidence, persistence, deleted file recovery, browser and USB history as the case requires.

  5. 5

    Attribution and scope

    What was accessed, by whom, when, and whether data left the environment.

  6. 6

    Reporting and testimony

    Findings written for the audience that will act on them, with expert testimony available where proceedings follow.

What's included

  • Forensically sound imaging with hash verification
  • Documented chain of custody throughout
  • Memory and disk analysis
  • Timeline reconstruction from artefacts
  • Data exfiltration assessment
  • Reporting suitable for legal or regulatory use

Who needs it

  • Organisations facing insider incidents or IP theft
  • Businesses with a regulatory notification decision to make
  • Legal teams needing technical evidence assessed independently

Deliverables

  • Forensic images retained under agreed custody terms
  • Evidence-referenced incident timeline
  • Assessment of what data was accessed or exfiltrated
  • Expert report, with testimony available if required

Compliance relevance

ISO 27037GDPRHIPAAACPO Guidelines

Frequently asked questions

Preserve first and investigate second. Do not let anyone use the device, do not image it casually, and involve HR and legal before acquisition — how the evidence is obtained determines whether you can rely on it later.
Frequently, yes, and often the metadata proving deletion matters more than the content. Success depends on the file system, elapsed time and whether the device has been used since.
It is prepared to that standard — defensible acquisition, documented custody, and conclusions stated only to the confidence the evidence supports. We will not overstate a finding to help a case.
New to managed detection?

Our guide covers how SOC, MSSP, MDR and SIEM actually differ, build vs buy, and the metrics that matter.

Read the guide

Related services

Incident Response

Rapid containment, eradication, and recovery led by senior responders.

Learn More

Malware Analysis

Static and dynamic reverse engineering of suspicious binaries.

Learn More

Threat Hunting

Hypothesis-driven hunts surfacing threats that evade automated tooling.

Learn More