Skip to content

Cybersecurity · Forensics & investigations

Forensics & investigations. Evidence that holds up.

When something has gone wrong, you need to know exactly what happened, and be able to prove it. We investigate incidents, fraud and misuse with chain-of-custody discipline and reports built for boards, lawyers and courts.

You get the facts, preserved as evidence, and a report that non-specialists can follow.

What's included. From first response to court.

  • Evidence collection

    Forensic acquisition and preservation, with a documented chain of custody.

  • Internal investigations

    Fraud, conflicts of interest and misuse of systems.

  • Email & endpoint forensics

    In-depth analysis of mailboxes, computers and servers.

  • Malware analysis

    What the malicious code did, how it got in and what it touched.

  • Incident reconstruction

    A precise timeline of what happened, when and how.

  • Litigation support

    Expert witness preparation, working with your legal counsel.

  • Regulatory support

    Input for breach notifications and questions from regulators.

  • Executive reporting

    Technical findings translated for the board and non-specialists.

What you receive. Facts, documented.

Every conclusion is traceable to evidence, and every piece of evidence to how it was collected.

  • Executive summary

    What happened and what it means, for the board and counsel.

  • Forensic report

    Findings, evidence, method and a detailed timeline.

  • Recommendations

    Fixes and controls to prevent a repeat, phased by urgency.

  • Chain of custody

    A complete record of how every item of evidence was handled.

How it runs

Start
Urgent cases start straight away through the 24/7 incident line.
Team
Forensic analysts led by a senior investigator.
From you
A named contact, your legal counsel where relevant, and access to the systems and devices involved.
Confidentiality
Handled on a need-to-know basis under NDA. Findings go only to the people you name.

Standards

  • ISO/IEC 27037
  • ISO/IEC 27035
  • NIST SP 800-86
  • RFC 3227

Frequently asked questions

Should we switch off the affected computer?

Not before talking to us. Switching off can destroy evidence held in memory. Disconnect it from the network if you can, and call the incident line.

Can your findings be used in court?

We follow recognised evidence-handling standards and document the chain of custody. Whether evidence is admitted is for the court to decide.

Is the investigation confidential?

Yes. We work under NDA, on a need-to-know basis, and share findings only with the people you designate.

Talk to a specialist

Find out what happened.

For an active incident, call the 24/7 line. For an investigation, tell us what you need to establish.

Review build · draft copy
Base
Render