Cybersecurity · Forensics & investigations
Forensics & investigations. Evidence that holds up.
When something has gone wrong, you need to know exactly what happened, and be able to prove it. We investigate incidents, fraud and misuse with chain-of-custody discipline and reports built for boards, lawyers and courts.
You get the facts, preserved as evidence, and a report that non-specialists can follow.
What's included. From first response to court.
Evidence collection
Forensic acquisition and preservation, with a documented chain of custody.
Internal investigations
Fraud, conflicts of interest and misuse of systems.
Email & endpoint forensics
In-depth analysis of mailboxes, computers and servers.
Malware analysis
What the malicious code did, how it got in and what it touched.
Incident reconstruction
A precise timeline of what happened, when and how.
Litigation support
Expert witness preparation, working with your legal counsel.
Regulatory support
Input for breach notifications and questions from regulators.
Executive reporting
Technical findings translated for the board and non-specialists.
What you receive. Facts, documented.
Every conclusion is traceable to evidence, and every piece of evidence to how it was collected.
Executive summary
What happened and what it means, for the board and counsel.
Forensic report
Findings, evidence, method and a detailed timeline.
Recommendations
Fixes and controls to prevent a repeat, phased by urgency.
Chain of custody
A complete record of how every item of evidence was handled.
How it runs
- Start
- Urgent cases start straight away through the 24/7 incident line.
- Team
- Forensic analysts led by a senior investigator.
- From you
- A named contact, your legal counsel where relevant, and access to the systems and devices involved.
- Confidentiality
- Handled on a need-to-know basis under NDA. Findings go only to the people you name.
Standards
- ISO/IEC 27037
- ISO/IEC 27035
- NIST SP 800-86
- RFC 3227
Frequently asked questions
Should we switch off the affected computer?
Not before talking to us. Switching off can destroy evidence held in memory. Disconnect it from the network if you can, and call the incident line.
Can your findings be used in court?
We follow recognised evidence-handling standards and document the chain of custody. Whether evidence is admitted is for the court to decide.
Is the investigation confidential?
Yes. We work under NDA, on a need-to-know basis, and share findings only with the people you designate.
Talk to a specialist
Find out what happened.
For an active incident, call the 24/7 line. For an investigation, tell us what you need to establish.