IT security intelligence. Since 2006.Cloudflare services ↗
Investigations & digital forensics

Incident response & digital forensics

Establish what happened, preserve relevant evidence, and plan recovery. We support organisations investigating suspected compromise, data loss, and misuse of digital systems.

Discuss your requirements
Digital evidence examined on a forensic workbench with a write-blocker

Preserve the evidence that matters

An investigation begins with context: the reported event, affected systems, available logs, and who is authorised to request the work. We plan evidence acquisition and handling so the investigation can be explained and reviewed. Depending on scope, sources may include workstations, servers, cloud services, email, and other digital records.

Collection is limited to the agreed purpose and access authority. We document how evidence was obtained and handled, and coordinate with your legal advisers where proceedings or regulatory issues may be involved.

Build a supported account of the incident

We correlate relevant records, examine suspicious activity, and reconstruct a timeline. Findings distinguish observed facts from interpretations and unresolved questions. Where useful, automated analysis assists triage; conclusions require review against the underlying evidence.

The engagement can include recommendations for containment, recovery, and preventing recurrence. Technical reports and expert analysis can support internal, legal, or disciplinary review, while admissibility and legal conclusions remain matters for the relevant advisers and authorities.

Coordinate decisions during an active incident

We agree who leads the response, which services matter most and who can approve operational changes. An initial evidence map covers endpoints, identities, email, network and cloud systems, alongside records held by providers. We prioritise collection with the response team and document actions that may alter the environment. Availability, safety and evidence preservation must be considered together, with responsibilities visible to everyone involved.

Scope the impact without overstating certainty

The investigation examines the supported incident window, affected identities and systems, and evidence of access, alteration or transfer. We distinguish confirmed findings from scenarios that remain possible. Where logs are missing or evidence has changed, the report explains which questions cannot be answered. Management, counsel and the client’s privacy or insurance advisers receive the technical facts needed for their own decisions and processes.

Investigate the cause and validate recovery

We connect the chronology to the weaknesses that enabled or prolonged the incident, where the evidence supports a causal link. Containment and remediation are tracked separately from analysis so their effect can be evaluated. Recovery checks can address restored systems, compromised credentials, residual access paths and monitoring. The business owner makes the return-to-service decision using agreed technical criteria and operational priorities.

Plan specialist work and a useful handover

Some questions require a deeper workstream: device examination, mailbox reconstruction, malware analysis, corporate investigation or electronic evidence preparation. We define those tasks and their dependencies within the overall response. The handover includes an executive account, detailed findings, evidence references and a prioritised improvement plan. A lessons-learned session turns the incident into changes in ownership, controls, logging and exercises.

Separate urgent response from the investigation question

An active compromise may require immediate operational decisions while the full cause remains uncertain. We establish the incident lead, affected business services and the evidence needed for the next decision. For example, restoring an email service and determining whether sensitive attachments were accessed are related but different tasks. Recording that distinction helps organise response work without presenting an early assumption as a final finding.

Prepare a useful initial incident brief

A first discussion is more productive with an approximate discovery time, affected systems, visible symptoms and a record of actions already taken. Identify the people who can authorise access and approve changes, together with any legal, insurance or outsourced-IT contacts already involved. Agree a secure evidence channel with the team; the website enquiry form is intended for an initial description, not incident logs or credentials.

Make the report useful to different readers

Management may need a concise impact statement and decision record, while technical owners need a chronology, evidence references and recovery tasks. We agree the intended readers and separate confirmed observations, supported inferences and unanswered questions. A clear record of scope and data availability allows another professional to understand both the conclusions and what the investigation could not determine.

What you receive

  • Evidence acquisition and handling plan
  • Documented findings and event timeline
  • Technical report with limitations and supporting evidence
  • Containment, recovery, and prevention recommendations
  • Initial incident brief with priorities, responsibilities and evidence gaps
  • Separate management findings and technical follow-up actions

Common questions

What should we do before an investigation?

Record what was observed and when, identify an incident lead, and contact your response team. Coordinate changes to affected systems with responders because changes can alter evidence.

Can a forensic report support legal proceedings?

A report can provide documented technical findings. The required methodology, scope, and handling should be agreed with your legal advisers for the specific matter.

Can you investigate an incident after systems have been restored?

Potentially. Remaining endpoint, cloud, identity and backup records may still answer important questions. The elapsed time and changes made during recovery affect what is available, so we assess evidence coverage before promising a particular conclusion.

What affects the duration of an investigation?

The number of systems, accessibility of records, time period, competing explanations and required reporting depth all matter. We can agree staged reporting so urgent decisions receive attention before the complete analysis is finished.

Further reading: CISA ransomware response guidance

What’s your next
technology challenge?

Talk to our team