We methodically secure digital evidence, reconstruct the entire sequence of events, and provide a report that stands up to scrutiny by authorities and in court.
Evidence Preservation in Accordance with ISO 27037
Restarting systems, copying files, resetting passwords: What seems intuitively correct actually destroys the very traces that will be needed later.
Deadline for issuing an early warning to the authorities as soon as a reportable incident becomes known.
NIS 2 Directive, Article 23
Deadline for submitting a complete incident report, including an assessment and initial findings.
NIS 2 Directive, Article 23
A reboot clears the RAM, a copy operation changes timestamps, and overwritten logs cannot be recovered. Anyone who proceeds without a systematic approach makes legal action impossible.
Without a thorough analysis, it remains unclear how the attacker gained access. The vulnerability remains, and the next attack will follow the same path.
Reporting requirements, cyber insurance, and criminal prosecution require comprehensive documentation in accordance with recognized standards, not an internal assessment.
We secure and analyze digital evidence right where it is created. Every step is documented, and every finding is traceable.
Windows, Linux, and macOS—from laptops to domain controllers.
Microsoft 365, Azure, and AWS, including login and access logs.
Smartphones and tablets running iOS and Android, as well as connected devices.
Firewalls, server protocols, data traffic, and connected systems.
If it isn't documented,
it never happened in court.
That is why every step is documented, from the handover of the device to the final findings in the report.
A forensic investigation follows a set procedure. Any deviation can compromise the evidence, so there are no shortcuts.
You report the incident, and we'll tell you right away over the phone what to do and what you must not do under any circumstances.
You hand over or ship the affected devices securely and with a written record. Packaging and transport comply with forensic guidelines to ensure that the chain of custody remains unbroken.
RAM, read-only images, and log data are backed up. Checksums confirm that nothing has been altered.
We are reconstructing the entire sequence of events: the point of entry, the spread, the affected systems, and the actual scope.
Timeline, findings, chain of evidence, and recommendations for action in a single document, suitable for use by government agencies, courts, and insurance companies.
Upon request, we can assist with addressing the identified vulnerabilities and securing the affected systems.
The final report contains all the information required for submission to the authorities and is prepared in accordance with the statutory deadlines.
Discuss the caseForensics is not a field where "good enough" is acceptable. If you make a single mistake when backing up data, you won't be able to recover the evidence.
Ransomware, insider threats, and prolonged attacks: We’ve conducted forensic investigations into these types of incidents. We know from real-world experience what works.
Unbroken chain of evidence, cryptographically verified, documented in accordance with ISO 27037. Our reports have already been used in legal proceedings.
The report is structured so that the information required for early warning and incident reporting is included and available in a timely manner.
While we gather evidence, our team keeps operations running smoothly. No time is lost coordinating between two service providers.
Please call us. Do not shut down the affected systems, because the RAM contains data that will be permanently lost if the systems are shut down. Disconnect the systems from the network, do not delete anything, and do not change any settings until we assist you.
Don't do this without preparation. You must back up your system memory first; otherwise, the very traces that prove the attack will be missing. We'll guide you through this step over the phone.
Yes, provided that the backup was performed correctly in accordance with ISO 27037. The report documents the complete chain of evidence, all analysis steps, and the cryptographic verification of the evidence.
Yes. We structure it so that it includes the required information for the early warning within 24 hours and the incident report within 72 hours. Upon request, we can also assist with communication with the authorities.
Then give us a call. The areas listed cover the most common scenarios, but the key factor is what data the device actually stores. We can clarify that in just a few minutes over the phone.
After a brief phone call, you will receive instructions on how to properly package and transport the item, along with the address and a handover form. This ensures that the chain of custody is documented from the very beginning.
That depends on the scope of the project. A single device can often be secured and analyzed within one to two days. For multiple systems, cloud environments, or large-scale ransomware incidents, we estimate it will take five to ten days to complete the final report. We’ll provide a realistic estimate during the initial consultation.
To prevent the same method from working again, ongoing monitoring is necessary.
In an emergency, every hour counts. Talk to us about your case before evidence is lost.
We use cookies to operate this website and analyze its usage. You decide which categories to allow. You can adjust your settings at any time.