Digital evidence can provide critical insight into what occurred, when it occurred and which accounts, devices or individuals may have been involved. A digital forensics investigation may be appropriate following:

  • Suspected employee fraud or misconduct
  • Theft of confidential information or intellectual property
  • Unauthorised copying or transfer of company data
  • Concerns involving departing employees
  • Data breaches or unauthorised system access
  • Business email compromise
  • Phishing and social engineering incidents
  • Deletion, alteration or concealment of records
  • Disputes involving emails, messages or electronic documents
  • Breaches of confidentiality agreements or restrictive covenants
  • Misuse of company systems, accounts or devices
  • Internal investigations and whistleblowing allegations
  • Civil litigation, employment proceedings or regulatory enquiries

Early advice can help identify the relevant evidence, protect it from alteration and determine the most appropriate forensic response.

Digital forensics is the structured identification, preservation, examination and analysis of electronically stored information. Unlike an ordinary IT review, a forensic investigation applies documented methods designed to protect the original data, maintain evidence continuity and record how information was collected and examined.

Depending on the instruction, digital evidence may help establish:

  • Who accessed a device, account or document
  • When relevant activity occurred
  • Whether files were created, changed, copied or deleted
  • Whether external storage devices were connected
  • Whether information was uploaded, emailed or transferred
  • Which accounts, systems or applications were used
  • Whether browser, email or messaging activity is relevant
  • Whether attempts were made to conceal activity
  • The sequence of events surrounding an incident
  • Whether the evidence supports or contradicts an allegation

The conclusions available will depend on the condition of the evidence, system configuration, retention periods and the actions taken before forensic preservation.