Quote

Court-ready DFIR. Daubert-aligned.

Digital incidents can become legal proceedings. Our forensic work acquires evidence in line with ISO/IEC 27037, maintains a documented chain of custody, uses validated techniques, and includes analyst testimony where required to support admissibility and expert scrutiny. The court makes the final admissibility determination.

ISO/IEC 27037ISO/IEC 27035ISO/IEC 27041NIST SP 800-86Daubert principlesGDPR Art. 33/34NIS2 / DORASEC Cyber
ACTIVE INCIDENT?

Do not power off systems or delete files. Our emergency response team is available 24/7/365. Contact us immediately to preserve evidence and limit adversary dwell time.

Emergency Contact →
STANDARDS, LAW & REGULATION

Documentation designed for courtroom scrutiny.

International Standards

  • ISO/IEC 27037:2012 · identification, collection, acquisition, and preservation of digital evidence
  • ISO/IEC 27035-1:2023 · incident management principles and structured response process
  • ISO/IEC 27041:2015 · assurance for digital evidence investigation methods and tools
  • NIST SP 800-86 · integration of forensic techniques into incident response
  • RFC 3227 · guidelines for evidence collection, archiving, and order of volatility
  • SWGDE Standards · Scientific Working Group for Digital Evidence best practices

Court & Legal Admissibility

  • Reproducible methodology · documented, repeatable techniques aligned to ISO/IEC 27037 and relevant Daubert principles, with method and tool limitations recorded for expert review
  • Expert witness capability · expert-witness support where instructed by counsel, subject to the applicable court or tribunal accepting the proposed expert and evidence
  • Legal hold & preservation notices · drafting support, litigation hold procedures, and e-discovery coordination
  • International tribunal readiness · documentation structured for counsel review in cross-border arbitration and other international proceedings
  • Attorney-client privilege · engagement structured at counsel’s direction where privilege is sought; availability and scope of privilege depend on applicable law

Regulatory Notification

  • GDPR Art. 33 / 34 · factual incident timelines and technical evidence to support client and counsel notification decisions
  • SEC cyber disclosure · factual technical summaries to support client and counsel materiality analysis and Form 8-K / 10-K drafting
  • NIS2 / DORA · technical facts and incident timelines prepared for client and counsel reporting workflows
  • HIPAA Breach Rule · factual breach-analysis documentation to support client and counsel risk assessment and notification work
  • US state notification laws · technical facts organised for client and counsel jurisdictional analysis
  • Direct liaison with internal and external legal counsel throughout all notification timelines and regulator correspondence
EVIDENCE INTEGRITY

Chain of custody, end to end.

Evidence handling follows a documented, auditable protocol from first contact through certified disposal. It is designed to support scrutiny under the requirements of the applicable proceeding and jurisdiction.

Acquisition

  • Hardware write-blockers · used for supported physical media where appropriate; the acquisition method and any unavoidable source-system changes are documented by evidence type
  • Bit-for-bit forensic imaging with validated tools selected for the evidence type, with tool versions and relevant limitations recorded
  • Dual cryptographic hash verification · SHA-256 (authoritative) and MD5 (retained only for legacy-tool interoperability) computed and recorded at acquisition and at every subsequent transfer
  • Volatile memory acquired before any shutdown using platform-appropriate acquisition tooling
  • Full acquisition metadata logged: analyst identity, UTC timestamp, hardware identifiers, tool name and version

Custody & Storage

  • Tamper-evident seals and unique evidence reference numbers applied to all physical media immediately upon acquisition
  • AES-256 encrypted evidence containers · Access is restricted to named analysts. Shared credentials are not used
  • Air-gapped analysis workstations: investigation infrastructure is never connected to client production networks
  • Immutable audit trail · every access, transfer, and analysis action logged with analyst identity and UTC timestamp
  • Physical evidence stored in access-controlled, environmentally monitored secure storage for the duration of the engagement

Verification & Disposition

  • Hash re-verification at each analysis phase confirms evidence integrity has not been altered since acquisition
  • Analysis is performed on working copies; originals remain preserved under evidence controls
  • Formal evidence receipt and transfer documentation signed by all parties at each handoff
  • Retention schedule defined per engagement agreement or court order; no open-ended storage
  • Certified secure destruction · of evidence copies at end of retention, with witnessed destruction certificate provided to client
WHAT WE INVESTIGATE

Ransomware, intrusions, fraud, and multi-source forensics.

Incident Types

  • Ransomware & extortion · including double-extortion, ransomware-as-a-service operators, and data leak site negotiation
  • APT / nation-state intrusion · long-dwell, living-off-the-land, supply chain implant, and espionage campaigns
  • Business Email Compromise (BEC) · account takeover, wire fraud redirection, and executive impersonation
  • Insider threat & data exfiltration · privileged abuse, intellectual property theft, and sabotage investigations
  • Data breach & unauthorised access · lateral movement mapping and complete scope determination for notification purposes
  • Financial & cryptocurrency fraud · blockchain tracing, transaction forensics, and asset recovery support
  • Industrial & OT incidents · ICS/SCADA impact assessment and evidence preservation in operational technology environments

Forensic Capabilities

  • Memory forensics · live acquisition, malware detection, process injection, code injection, and rootkit identification
  • Disk & file system forensics · deleted artefact recovery, anti-forensic detection, and deep multi-source timeline reconstruction
  • Cloud forensics · cloud provider audit logs, SaaS platform event analysis, and control-plane investigation
  • Network forensics · full-packet capture analysis, C2 beacon identification, and lateral movement reconstruction from flow and PCAP data
  • Mobile forensics · iOS and Android acquisition (physical, logical, file-system) using validated mobile forensics tooling
  • Malware analysis · static disassembly, dynamic sandbox execution, C2 infrastructure mapping, and detection rule development
  • Threat actor attribution · TTP analysis mapped to MITRE ATT&CK, adversary infrastructure pivoting, and threat intelligence correlation
DELIVERABLES

Reports for engineers, lawyers, and regulators.

Technical Report

  • Complete attack timeline with UTC-anchored events across all evidence sources
  • Confirmed and assessed initial access vector(s)
  • Full lateral movement, privilege escalation, and persistence path reconstruction
  • Scope determination: confirmed affected vs. ruled-out systems and data
  • Structured IOC package · hashes, IPs, domains, TTPs in STIX 2.1 / MISP format
  • Custom YARA and Sigma detection rules for identified malware families and TTPs
  • MITRE ATT&CK navigator layer with full TTP mapping and threat actor profile

Legal & Regulatory

  • Court-ready evidentiary report · with documented methodology, tool validation records, and signed analyst declaration
  • Complete chain of custody log and evidence register for all acquired items
  • Expert witness brief and supporting affidavit prepared upon instruction of counsel
  • Technical breach scope and affected-data analysis to support client and counsel assessment of notification obligations
  • Draft regulatory factual summary (GDPR, SEC, NIS2, HIPAA) for client and counsel review before any submission
  • Forensic examination certificate with cryptographic hash verification record

Executive & Remediation

  • Executive summary: non-technical narrative suitable for board, regulator, and insurer communication
  • Root cause analysis and contributing security control failures
  • Prioritised containment and eradication checklist
  • Strategic remediation roadmap with risk-ranked recommendations to prevent recurrence
  • Post-incident lessons-learned facilitation session with technical and leadership teams
  • Cyber insurance claim support documentation where applicable
HOW WE ENGAGE

Emergency or retainer.

Emergency Engagement

  • Immediate triage · severity assessment and routing to a senior responder within 15 minutes; stakeholder identification and emergency NDA executed within the first hour
  • Out-of-band comms established · encrypted communication channel activated immediately; no incident-related information transmitted via client infrastructure
  • Volatile evidence preservation · immediate guidance on preservation actions; remote or on-site acquisition initiated to capture memory and live state before it degrades
  • Parallel containment guidance · containment recommendations issued concurrently with evidence collection to limit adversary dwell and blast radius without destroying evidence
  • Encrypted status cadence · secure briefings at agreed intervals throughout the incident; no gaps in communication during active crisis
  • Final delivery & handover · complete technical and legal deliverable package with structured remediation handover and debrief

Retainer Engagement

  • Contractual SLAs · acknowledgement, analyst assignment, and on-site response terms defined in the signed retainer or engagement agreement
  • Pre-executed documentation · NDA, engagement letter, and evidence handling agreements signed before any incident occurs
  • Environment familiarisation · asset inventory, crown jewels register, and network architecture reviewed and held in readiness prior to any incident
  • Annual tabletop exercise · IR simulation included; validates playbooks and stakeholder readiness against realistic threat scenarios
  • Priority queuing · retainer clients receive priority mobilisation over ad-hoc engagements during surge conditions
  • Unused hours credit · unconsumed retainer hours roll over or credit future engagements per contract terms
ACTIVE INCIDENT?→