Incident Investigation & Forensics
When you need to know exactly what happened, how, and prove it - not just contain it - forensic investigation gives you the evidence.
What is digital forensics?
Digital forensics is the disciplined collection, preservation and analysis of evidence after a security incident - establishing what happened, how attackers got in, what they touched, and building a chain of custody that holds up for legal, regulatory or insurance purposes.
It goes deeper than incident response: where response focuses on containment and recovery, forensics focuses on the evidence trail left behind, often continuing after the incident itself is already contained.
What's included
Evidence Collection
Evidence collection and preservation with documented chain of custody.
Timeline Reconstruction
Root-cause and timeline reconstruction of the incident.
Forensic Analysis
Memory, disk and log forensic analysis.
Malware Analysis
Malware analysis where applicable.
Findings Reports
Findings reports suitable for legal, regulatory or insurance use.
Litigation Support
Expert support for litigation or regulatory enquiries.
How it works
Preserve
Secure and image affected systems before evidence can be altered or lost.
Investigate
Analyse logs, memory and disk artefacts to trace what happened.
Reconstruct
Build a timeline establishing root cause, entry point and scope.
Report
Deliver findings in a form suitable for leadership, regulators or legal proceedings.
Questions we get asked first
How is this different from incident response?
Incident response focuses on containing and recovering from an active incident; forensics focuses on the evidence trail - what happened, how, and proving it - often continuing after the incident itself is contained.
Is the evidence admissible for legal proceedings?
Chain-of-custody procedures are followed throughout collection and analysis specifically so findings can support legal, regulatory or insurance processes where needed.
Do we need this for every incident?
No - forensics is typically engaged for significant incidents where root cause, scope or legal and regulatory exposure needs to be firmly established, not routine, low-impact events.
Need to establish exactly what happened?
Tell us about the incident and we'll come back with a scoped proposal within two working days.
