Digital Forensics & Investigations

Understand what happened

Evidence, a plain-language explanation of potential business impact, and prioritised next steps within an agreed scope.

Examine available evidence to establish what can be confirmed, what may be affected, and what needs further investigation.

What's included

Investigation of suspicious activity - logins, emails, transactions, system behaviour
Log analysis and timeline reconstruction of the event
Evidence collection and preservation for legal or insurance purposes
Attribution assessment - opportunistic scan or targeted attack?
Plain-language executive report - no jargon, clear business impact
Concrete recommendations to prevent recurrence

How it works

01

Scope

You tell us what looks wrong. We define what data and systems we need to examine and preserve evidence immediately.

02

Investigate

We analyse logs, correlate events, and reconstruct exactly what happened, when, and how far it went.

03

Report

You receive a clear written report: what happened, business impact, and prioritised next steps - readable by both your board and your engineers.

What you get

Deliverables, coverage, access, fees, and response or reporting times are agreed in your proposal. Testing requires written authorisation. Findings reflect the agreed scope and available evidence; they are not a guarantee against a breach.

Deliverable 01Written investigation report
Deliverable 02Event timeline reconstruction
Deliverable 03Preserved evidence package
Deliverable 04Prevention recommendations

Find out what attackers already know about your business.

Tell us what matters to your business. We will agree the right scope and next step.

Discuss your business risks