For directors, HR, insurers and advisers
Corporate Digital Investigations and Evidence Preservation
Independent support for directors, HR, insurers, data protection officers, advisers and corporate counsel who need to preserve digital evidence and establish facts. Scope follows the case, available evidence and required decision.
Question-led scope · Proportionate preservation · Findings with clear technical limits
Act on the evidence risk, not an assumption
Situations that may require a controlled response
Employee data movement
Suspected USB use, personal email, cloud transfer, bulk access, deletion or activity around departure.
Business email compromise
A mailbox, lookalike domain or payment-diversion sequence needs independent reconstruction.
Ransomware or mixed cyber incident
Initial access, affected systems, spread, impact and retained incident records need to be aligned.
Suspected data exfiltration
Access, staging, removable media, cloud use or network transfer needs a source-by-source assessment.
Online exposure or impersonation
Public information, breach references, external services or a lookalike site may need lawful review.
Disputed communications or records
Email, messages, documents or system records need provenance, sequence or completeness testing.
Questions the evidence may address
- What relevant activity is recorded, in what sequence and across which systems?
- Are there artefacts consistent with removable-media use, copying, synchronisation, access or deletion?
- Which accounts, endpoints, mailboxes, cloud sources or logs contain useful evidence?
- What supports or weakens a proposed entry route, compromised account or data-movement theory?
- Which conclusions remain unresolved because records are absent, expired or ambiguous?
Sources that may be relevant
- Computers, forensic images, mobile devices and removable media.
- Email, Microsoft 365, Google Workspace, cloud storage and available audit records.
- Identity, remote-access, endpoint, network and security logs.
- Documents, browser records, application data and existing exports.
- Policies, authority records, incident notes and the dates that define the question.
Preserve before routine change
Collection matched to source state and risk
A collection may use full imaging, a targeted export, remote acquisition or attendance. Where suitable, a live system may use an encrypted collection agent. A switched-off system may be started from a controlled bootable USB or CD. The method, authority, operator steps, verification, encryption and hand-off are agreed in writing.
Do not assume that every incident requires immediate shutdown or continued operation. Record the current state and obtain source-specific advice before taking an action that may change volatile, encrypted or business-critical evidence.
Relevant career experience
More than 70 cyber-breach investigations
Alistair has worked on more than 70 cyber-breach investigations as a managing consultant or technical lead, with regional responsibility across Europe, Africa and the Middle East.
This experience helps focus the examination on the incident timeline, affected systems, account activity and possible data movement.
Practical outputs
Turn the available records into clear technical findings
- Preservation or collection record with the agreed source and method.
- Focused chronology of relevant observed activity and evidence gaps.
- Technical findings note or report with alternative explanations and limitations.
- Conference with authorised representatives, counsel or insurers.
- Independent expert report only where appropriate and properly instructed.
UK based, with worldwide travel
Remote delivery is considered where it meets the required assurance. Alistair is available for worldwide travel, including across EMEA, by agreement. Legal authority, cross-border data movement, safety, timetable, equipment movement and cost are assessed before attendance.
Technical and practical boundaries
- Digital artefacts do not automatically identify a person or prove their intent.
- Technical findings do not decide employment action, legal liability or regulatory notification duties.
- Incomplete logging, retention or later remediation may prevent a complete chronology.
- No recovery, attribution, containment or business outcome is guaranteed.
What to include in an initial enquiry
- Organisation and relevant party names for conflict checking.
- The event, questions to be answered and people authorised to instruct.
- Affected or relevant source types, approximate volumes and locations.
- Known preservation risks, business constraints and actions already taken.
- Any insurer, legal, regulatory or fixed reporting timetable.
Preserve what may matter
Discuss a corporate preservation or investigation need
Describe the event, affected systems, preservation risk and questions to be answered. Do not upload evidence, credentials or personal data.

