Forensic readiness & evidence preservation planning
Make important questions answerable before an incident happens. We help organisations prepare the logs, responsibilities, evidence handling and response exercises needed for a more effective investigation.
Discuss your requirements
Design around realistic investigation questions
Readiness starts with scenarios that matter to your organisation: a compromised finance mailbox, suspected document theft, a cloud administrator incident or ransomware affecting a critical service. For each scenario, we identify the decisions management would need to make and the evidence required to support them. This produces a focused set of requirements rather than an indiscriminate plan to retain everything.
Map evidence coverage and practical gaps
We review relevant endpoint, identity, network, cloud and business-system sources. The assessment considers which events are recorded, how long records remain accessible, whether clocks can be reconciled and who can retrieve them. We verify export permissions, supplier dependencies and separation from compromised administrative accounts. A configured log source is useful only if the necessary records can actually be obtained and interpreted.
Create workable preservation procedures
The plan defines triggers, authorised decision-makers, collection responsibilities, secure storage and a record of evidence transfers. Legal advisers guide retention obligations and holds; technical procedures translate those decisions into system-specific actions. Data minimisation and access restrictions are built into the process. We identify which volatile or provider-held sources require early specialist attention without prescribing a single action for every incident.
Exercise the process with the people who use it
A tabletop or controlled collection exercise brings together IT, security, management, legal and relevant providers. Participants practise escalation, permissions, evidence requests and decision recording against a realistic scenario. We test the hand-offs as well as the technology: who can approve an export, how a provider responds and whether a backup team can validate the required source. The exercise records gaps and owners for follow-up.
Keep readiness current as systems change
Cloud migrations, new AI tools, acquisitions and changes in service providers can introduce new evidence sources or remove existing ones. We provide a review cadence and change checklist so readiness remains part of operations. The final roadmap prioritises gaps by likely business impact and effort, with clear acceptance criteria for confirming that a corrective action has worked.
Test whether a future question could be answered
Readiness can be assessed with a practical scenario: a supplier payment is diverted, a privileged account is misused or a confidential file appears outside the organisation. We map the evidence needed to investigate that scenario and compare it with actual source coverage. The exercise reveals whether the relevant records exist, can be collected and can be connected into a useful chronology.
Review retention, clock alignment and provider access
Evidence readiness depends on more than enabling a log source. The team must understand how long relevant records remain available, which time references they use and who can retrieve them. Outsourced systems may require a provider request or a separate permission. We document these dependencies and test an agreed collection path so practical gaps are visible before an incident.
Exercise handover from IT to investigators and advisers
A preservation procedure should identify the trigger, authorising person, collector, storage arrangement and intended recipients. A tabletop or controlled technical exercise can test whether the right people can follow that sequence without an improvised exchange of sensitive files. The outcome is a set of corrections to ownership, access and procedure, with a date to review their completion.
What you receive
- Scenario-based evidence requirements and source matrix
- Logging, retention and access gap assessment
- Preservation and chain-of-custody procedures
- Exercise materials, observations and assigned actions
- Prioritised readiness roadmap and review checklist
- Scenario-to-evidence coverage assessment
- Tested preservation handover and tracked readiness improvements
Common questions
Does readiness mean keeping every log forever?
No. Retention should be justified by purpose, risk, legal requirements and operational needs. We help define proportionate coverage with your responsible teams.
Can you assess evidence held by outsourced providers?
Yes. We review the relevant contract provisions, responsibilities and demonstrated export capabilities with authorised contacts.
How is success measured?
By practical tests: whether required records can be retrieved, interpreted and handled within the agreed process, with gaps assigned to an owner.
Can readiness work use our existing monitoring tools?
Yes. We can assess existing source coverage and retrieval processes before recommending changes. The question is whether the records can support the agreed investigation scenario, not how many tools are installed.
How often should the readiness plan be reviewed?
The review schedule should reflect the organisation and its risks, with additional review after significant system, provider or responsibility changes. We agree the relevant triggers and owners in the plan.
Plan the next step
Explore all investigations Understand the evidence process Public bodies & local authoritiesRelated established services
COMPLIANCE SERVICESConnected expertise
All services
Incident response & forensics
Investigate incidents with structured evidence collection, clear timelines, and practical recovery recommendations.
Explore service
Email & cloud investigations
Investigations across Microsoft 365, Google Workspace and cloud environments, including business email compromise, access and data sharing.
Explore service
Security operations & MDR
Bring security signals together, investigate suspicious activity, and define a response process your team can act on.
Explore service