Cybersecurity › IT Forensics
IT Forensics

The attack is over.
The evidence isn't over yet.

We methodically secure digital evidence, reconstruct the entire sequence of events, and provide a report that stands up to scrutiny by authorities and in court.

Evidence Preservation in Accordance with ISO 27037

The Problem

The first few hours determine
whether evidence will be found later.

Restarting systems, copying files, resetting passwords: What seems intuitively correct actually destroys the very traces that will be needed later.

24 hours

Deadline for issuing an early warning to the authorities as soon as a reportable incident becomes known.

NIS 2 Directive, Article 23

72 hours

Deadline for submitting a complete incident report, including an assessment and initial findings.

NIS 2 Directive, Article 23

Evidence is unique

A reboot clears the RAM, a copy operation changes timestamps, and overwritten logs cannot be recovered. Anyone who proceeds without a systematic approach makes legal action impossible.

The cause remains unknown

Without a thorough analysis, it remains unclear how the attacker gained access. The vulnerability remains, and the next attack will follow the same path.


, a government agency and insurance company, want proof

Reporting requirements, cyber insurance, and criminal prosecution require comprehensive documentation in accordance with recognized standards, not an internal assessment.

What We're Investigating

From the hard drive
to the cloud.

We secure and analyze digital evidence right where it is created. Every step is documented, and every finding is traceable.

End-user devices and servers

Windows, Linux, and macOS—from laptops to domain controllers.

Cloud

Microsoft 365, Azure, and AWS, including login and access logs.

Mobile devices

Smartphones and tablets running iOS and Android, as well as connected devices.

Network

Firewalls, server protocols, data traffic, and connected systems.

Fuse
  • Back up the RAM before shutting down
  • Read-only images of the data carriers
  • Checksums as Proof of Integrity
Analysis
  • Complete Timeline of the Attack
  • Determine the entry point with certainty
  • Reconstructing the Spread on the Web
Documentation
  • Forensic Report in Accordance with ISO 27037
  • Suitable for government agencies and courts
  • All required information for the report

If it isn't documented,
it never happened in court.

That is why every step is documented, from the handover of the device to the final findings in the report.

Procedure

From the news item “
” to the report.

A forensic investigation follows a set procedure. Any deviation can compromise the evidence, so there are no shortcuts.

Reporting and Initial Security Measures

You report the incident, and we'll tell you right away over the phone what to do and what you must not do under any circumstances.

0–2 hours

Handover of the Equipment

You hand over or ship the affected devices securely and with a written record. Packaging and transport comply with forensic guidelines to ensure that the chain of custody remains unbroken.

by arrangement

Forensic Backup

RAM, read-only images, and log data are backed up. Checksums confirm that nothing has been altered.

2–8 hours

Analysis and Reconstruction

We are reconstructing the entire sequence of events: the point of entry, the spread, the affected systems, and the actual scope.

1–5 days

Final Report

Timeline, findings, chain of evidence, and recommendations for action in a single document, suitable for use by government agencies, courts, and insurance companies.

1–2 days

Follow-up Care

Upon request, we can assist with addressing the identified vulnerabilities and securing the affected systems.

optional

The final report contains all the information required for submission to the authorities and is prepared in accordance with the statutory deadlines.

Discuss the case
Why ITanic

Errors in the preservation of evidence
cannot be corrected.

Forensics is not a field where "good enough" is acceptable. If you make a single mistake when backing up data, you won't be able to recover the evidence.

Lessons Learned from Real-Life Cases

Ransomware, insider threats, and prolonged attacks: We’ve conducted forensic investigations into these types of incidents. We know from real-world experience what works.

Reports That Stand the Test of Time

Unbroken chain of evidence, cryptographically verified, documented in accordance with ISO 27037. Our reports have already been used in legal proceedings.

Designed to Meet Reporting Requirements

The report is structured so that the information required for early warning and incident reporting is included and available in a timely manner.

Reconnaissance and Operations in Parallel

While we gather evidence, our team keeps operations running smoothly. No time is lost coordinating between two service providers.

Frequently Asked Questions

What Matters in an Emergency.

We're under attack right now. What should we do immediately?

Please call us. Do not shut down the affected systems, because the RAM contains data that will be permanently lost if the systems are shut down. Disconnect the systems from the network, do not delete anything, and do not change any settings until we assist you.

Do we need to shut down the affected systems?

Don't do this without preparation. You must back up your system memory first; otherwise, the very traces that prove the attack will be missing. We'll guide you through this step over the phone.

Is the report really admissible in court?

Yes, provided that the backup was performed correctly in accordance with ISO 27037. The report documents the complete chain of evidence, all analysis steps, and the cryptographic verification of the evidence.

Does the report fulfill the legal reporting requirement?

Yes. We structure it so that it includes the required information for the early warning within 24 hours and the incident report within 72 hours. Upon request, we can also assist with communication with the authorities.

What if our device isn't on the list?

Then give us a call. The areas listed cover the most common scenarios, but the key factor is what data the device actually stores. We can clarify that in just a few minutes over the phone.

How do you receive a device?

After a brief phone call, you will receive instructions on how to properly package and transport the item, along with the address and a handover form. This ensures that the chain of custody is documented from the very beginning.

How long does an examination take?

That depends on the scope of the project. A single device can often be secured and analyzed within one to two days. For multiple systems, cloud environments, or large-scale ransomware incidents, we estimate it will take five to ten days to complete the final report. We’ll provide a realistic estimate during the initial consultation.

Being informed does not mean being protected.

To prevent the same method from working again, ongoing monitoring is necessary.

View Detection & Response

Clarify the incident.
Secure the evidence. Move on.

In an emergency, every hour counts. Talk to us about your case before evidence is lost.

Available even during an acute incidentEvidence preservation in accordance with ISO 27037Compliance with reporting requirements