Focused post-incident review

Data Breach Forensic Investigation

A data breach forensic investigation examines what happened after an incident. Alistair reviews the retained records to assess how access was gained, which systems were affected and whether data may have left. The findings explain gaps and what cannot be established.

Direct access to Alistair Ewing · Free initial consultation · Written estimate before work

Reconstruct what happened and state what remains uncertain

After immediate containment and recovery, decision-makers may need a reliable account of the incident: when material activity occurred, which records support it, what systems or identities were affected and whether available evidence bears on suspected data access or removal.

Alistair provides a focused forensic investigation or independent review. This is not a 24/7 security operations centre or emergency monitoring service. If an incident remains active, the organisation should use its emergency response plan and an appropriate live-response provider; forensic work can then be agreed around preserved sources and specific questions.

Findings separate observed records, technical inference and unverified hypotheses. The review can support lawyers, insurers, loss adjusters, internal teams or a larger incident-response provider without presenting one examiner as a full managed-response operation.

Questions a focused review may address

  • When relevant authentication, execution, persistence, access or transfer activity appears to have occurred.
  • Which user identities, endpoints, mailboxes, cloud resources or network records are implicated by the available evidence.
  • Whether observed activity is consistent with a proposed entry route or whether other explanations remain viable.
  • Whether available logs support, qualify or do not resolve a suspected data-access or exfiltration scenario.
  • Which evidence gaps, retention limits or response actions affect the confidence of the chronology.

Sources that may be relevant

  • Identity, authentication, Microsoft 365 or other available cloud audit records.
  • Endpoint images, security telemetry, event logs and relevant application artefacts.
  • Firewall, VPN, proxy, DNS, email-gateway and network records within their retention windows.
  • Incident-response notes, alert exports, containment times and system-change records.
  • Defined business-system or file-access records relevant to the suspected impact.

What a post-breach review may not resolve

  • Log retention, collection gaps, clock differences and post-incident changes may prevent a complete chronology.
  • Use of an account, address or tool does not automatically identify the individual responsible.
  • Network transfer volume may support an inference without identifying the precise content transferred.
  • A vulnerability or exposed service does not by itself establish the route actually used.
  • The review does not replace legal advice, regulatory assessment, crisis communications or continuing security monitoring.

Information needed for an incident review

  • Organisation, insurer, adviser and relevant party names for the conflict check.
  • Whether the incident is contained and who is responsible for live response.
  • The specific chronology, root-cause, access or exfiltration questions to be addressed.
  • A high-level source inventory, retention limits, approximate volumes and existing response reports.
  • Board, insurer, legal, regulatory or reporting deadlines and the required deliverable.

Send a brief enquiry, without evidence or passwords. Secure transfer follows the conflict check.

How conflict checks, quotations and evidence transfer work

Frequently asked questions

What if the incident is still active?

Use the organisation’s emergency response route and a suitable live-response provider. Compute Forensics can discuss a separately defined preservation, reconstruction or independent-review task when responsibilities and immediate risks are clear.

Can the review determine exactly what data left the network?

Sometimes records support a specific conclusion, but logging may show only access, archive creation, connection or volume. The report distinguishes observed content from inference and unresolved gaps.

Fees, timing and instruction FAQs

Initial enquiry

Need an independent view after a cyber incident?

Outline the incident window, affected systems, containment already performed, records retained and the decision the review must inform. Urgent evidence handling is agreed directly, not through file upload.

Discuss a breach review