04 Investigation & advisory
Digital Forensics
After an incident, a departure or a dispute, the question is always the same: what actually happened, and can you prove it.
Start a pilotThe answer usually exists in devices, accounts and logs — but it degrades quickly and it is easy to destroy by accident. A well-meaning attempt to check whether a departing employee copied files can overwrite exactly the evidence that would have shown it.
We recover and examine digital evidence, reconstruct the timeline, and produce findings documented for use in disciplinary, civil or criminal proceedings. Where the picture is incomplete we set out what is missing and why, rather than filling the gap with inference.
01 What you receive
Deliverables.
Every engagement produces a written, sourced deliverable — not a dashboard login you will never open.
- Forensic examination
- Devices, accounts and logs examined under documented handling.
- Timeline reconstruction
- What happened, in what order, with the evidence for each step.
- Written findings
- Structured for disciplinary, civil or criminal proceedings.
- Chain of custody
- Documented handling from acquisition through analysis.
02 Method
How it runs.
- 01
Preserve
Before anything else. Evidence degrades, and investigating on a live device destroys it.
- 02
Acquire
Forensic images taken under documented chain of custody.
- 03
Examine
Analysis against the specific questions the matter turns on.
- 04
Report
Written findings, explicit about what the evidence does and does not establish.
04 Common questions
What should we do before you arrive?
As little as possible. Do not log in to the device, do not run searches on it, do not let IT "have a quick look". Isolate it, record who has had access, and preserve any relevant logs before retention windows expire. That single decision determines what remains recoverable.
Will the findings hold up in court?
They are prepared to that standard — documented chain of custody, reproducible method, and findings stated with their limits. Admissibility is ultimately a matter for the court and your legal advisers, and we work alongside them from the outset.
Can you work on a departing employee matter?
Yes. IP theft and data exfiltration around a departure is one of the more common instructions, and it is heavily time-sensitive because logs and backups age out quickly.
Tell us what you would want watched. We will scope a pilot on it, in writing, before anything is agreed.