IT security intelligence. Since 2006.Cloudflare services ↗
TRUST-IT / Practical guide

What a digital investigation should establish

A useful investigation answers a defined question with traceable evidence. This guide explains what to agree before collection and how to assess the report you receive.

Digital evidence and forensic acquisition equipment

Write the question before choosing a tool

“Find out what happened” needs to become a set of testable questions. Was a particular document accessed? Did an account send an instruction? What activity preceded an outage? State the relevant people, systems and period, and identify the decision the answer will support. This keeps collection proportionate and gives the investigator a basis for explaining what additional work would achieve.

Separate preservation, collection and analysis

Preservation aims to keep relevant material available. Collection produces the evidence set that will be examined. Analysis interprets that material in relation to the question. These are connected activities with different decisions and records. Ask what will be collected, why that method is suitable, what changes it may cause and how the source will remain traceable. A screenshot may be useful, but it rarely captures every relevant property of the original record.

Agree authority, recipients and handling

Before access, identify the person or entity entitled to authorise it and any instructions from legal or privacy advisers. Define reporting recipients, a secure exchange process and the treatment of unrelated sensitive material. Mixed personal and company information needs explicit boundaries. A case register should connect each item to its source, collection context and subsequent handling, so another reviewer can follow its history.

Expect correlation and alternative explanations

A timestamp, IP address or username rarely tells the whole story. Automated tasks, shared accounts, time-zone differences and incomplete logs can change the interpretation. A sound report explains how multiple sources support the chronology and examines plausible alternatives. It also distinguishes account activity from attribution to a person, and observed access from a claim about intent or onward disclosure.

Read the limitations as part of the result

Ask which sources were unavailable, which periods lack coverage and which methods could not be applied. Deleted data may not be recoverable, and an encrypted or damaged device may limit examination. NIST’s digital evidence overview describes the importance of reliable collection and the challenges posed by varied sources. A report that clearly states an unanswered question can be more useful than an unsupported definitive conclusion.

Commission outputs you can actually use

Agree an executive explanation, referenced findings, a timeline, relevant exhibits and a technical methods section appropriate to the matter. Ask how supporting material will be delivered and retained. If the investigation informs a legal dispute, counsel should direct the procedural requirements. If it informs recovery, connect recommendations to owners and verification steps. The value lies in the decisions the evidence can support.

Further reading

Put the guidance to work

Forensic examination of computers, phones, storage media and backups, with documented acquisition, timelines and evidence limitations.

Computer & mobile forensics

What’s your next
technology challenge?

Talk to our team