Computer, mobile & digital media forensics
Establish what a device can tell you about an incident, disputed activity or loss of information. We examine authorised computers, mobile devices and digital media, connecting technical artefacts to clearly defined questions.
Discuss your requirements
Start with the question, the device and the authority
A departing employee, a lost laptop or a disputed document can raise very different questions. We define the relevant people, devices, accounts and period before choosing an examination method. The scope records who can authorise access, which material is relevant and how unrelated personal information will be handled. A focused investigation reduces unnecessary collection and gives the analysis a clear purpose.
Acquire and preserve a traceable evidence set
We assess device condition, encryption, available credentials, storage technology and the risk of changing data during collection. Depending on the case, the work may involve forensic images, targeted acquisition, supported mobile extraction or examination of existing backups. We document the method, source, timestamps, integrity checks where applicable, and each transfer. Working copies and access controls help preserve the collected material for subsequent review.
Reconstruct activity across artefacts
Analysis can cover file creation and modification, application use, browser activity, connected storage, account access and relevant communications available within the authorised collection. We correlate artefacts rather than relying on one timestamp or filename. Time zones, clock changes, synchronisation and automated processes can affect the interpretation. A file appearing on a device does not by itself establish who used it or why.
Address mobile, multimedia and specialist sources
For mobile devices, the examination depends on model, operating system, security state and available data. We assess relevant messages, application records and backups without promising access to every locked device. For images, recordings and documents, we can examine metadata, file history and consistency with other evidence. Content authenticity questions may require specialist methods; the report explains exactly which tests were performed and what they can establish. Connected-device or OT evidence is scoped with the responsible engineers to account for operational safety.
Deliver findings that another reviewer can follow
The report links each important conclusion to its supporting artefacts and separates observations from interpretations. It includes a timeline, relevant exhibits, methods and outstanding questions. Deleted or overwritten data may be unavailable; absence of a recovered artefact is not proof that an event never happened. We explain those limits and can support a technical review with the client’s legal or investigation team.
Examine file activity in its wider context
A question about a copied document may require analysis of file-system records, application activity, connected media and relevant cloud records. No single timestamp should be interpreted without understanding the source and the actions that can change it. We compare available artefacts and explain alternative interpretations, so the report distinguishes evidence of a file’s presence from evidence of a particular person’s action.
Address company devices and mixed personal use
A device used for both work and personal activity needs carefully defined examination boundaries. We agree the relevant people, time period, categories of material and reporting recipients with the authorised commissioning team. The collection method and review process should reflect those decisions. Where technical limitations prevent complete separation at acquisition, the handling and review controls need to be explicit.
Prepare devices for an agreed examination
Before arranging a handover, identify device type, condition, ownership, known encryption and any changes made since the concern arose. The team can then agree transport or collection arrangements and an evidence record. Avoid experimenting with recovery or cleaning tools before receiving case-specific guidance, because those actions may change information relevant to the agreed questions.
What you receive
- Collection scope, device inventory and handling record
- Acquisition documentation and integrity information where applicable
- Correlated activity timeline with referenced exhibits
- Findings, alternative explanations and recovery limitations
- Technical briefing and agreed retention or return plan
- Cross-device chronology with source references and interpretation limits
- Device handover record and agreed review boundaries
Common questions
Can you recover deleted files or unlock any phone?
Recovery depends on the device, encryption, storage behaviour, overwriting and available acquisition methods. We assess feasibility first and report what is accessible; recovery or unlocking is never guaranteed.
Can personal and company data be separated?
We agree a proportionate collection and review process, including date ranges, relevant accounts and restrictions on unrelated material. Mixed-use devices require particular care and appropriate authorisation.
Can you review an existing forensic report?
Yes. We can assess the supplied evidence, methods, traceability and whether the conclusions are supported, within an agreed independent technical review.
Can you compare evidence from a laptop and a phone?
Yes, where acquisition and authority cover both. We can correlate available artefacts while accounting for time zones, clock differences and gaps in each source. A correlation does not by itself establish who performed an action.
Can an examination focus on a defined date range?
The review and reporting scope can be limited to an agreed period. The acquisition method may still need to preserve a broader evidence set, depending on the device and the question.
Plan the next step
Explore all investigations Understand the evidence process Individuals & families High-net-worth individuals & public figuresRelated established services
COMPUTER FORENSICS SERVICESConnected expertise
All services
Email & cloud investigations
Investigations across Microsoft 365, Google Workspace and cloud environments, including business email compromise, access and data sharing.
Explore service
Corporate & insider investigations
Confidential technical investigations into suspected insider activity, IP loss, digital fraud and misuse of corporate information.
Explore service
eDiscovery & dispute support
Electronic evidence preservation, targeted collection, document processing, technical analysis and support for legal review.
Explore service