Focused post-incident review

Data Breach Forensic Investigation

An independent overview for mixed or still-uncertain cyber incidents, bringing the principal chronology, systems, identities and evidence gaps into one review for organisations, insurers, counsel and response partners.

Direct access to Alistair Ewing · Free initial consultation · Written estimate before work

Reconstruct what happened and state what remains uncertain

After immediate containment and recovery, decision-makers may need a reliable account of the incident: when material activity occurred, which records support it, what systems or identities were affected and whether available evidence bears on suspected data access or removal.

Alistair provides a focused forensic investigation or independent review. This is not a 24/7 security operations centre or emergency monitoring service. If an incident remains active, the organisation should use its emergency response plan and an appropriate live-response provider; forensic work can then be agreed around preserved sources and specific questions.

Findings separate observed records, technical inference and unverified hypotheses. The review can support lawyers, insurers, loss adjusters, internal teams or a larger incident-response provider without presenting one examiner as a full managed-response operation.

Questions a focused review may address

  • When relevant authentication, execution, persistence, access or transfer activity appears to have occurred.
  • Which user identities, endpoints, mailboxes, cloud resources or network records are implicated by the available evidence.
  • Whether observed activity is consistent with a proposed entry route or whether other explanations remain viable.
  • Whether available logs support, qualify or do not resolve a suspected data-access or exfiltration scenario.
  • Which evidence gaps, retention limits or response actions affect the confidence of the chronology.

Sources that may be relevant

  • Identity, authentication, Microsoft 365 or other available cloud audit records.
  • Endpoint images, security telemetry, event logs and relevant application artefacts.
  • Firewall, VPN, proxy, DNS, email-gateway and network records within their retention windows.
  • Incident-response notes, alert exports, containment times and system-change records.
  • Defined business-system or file-access records relevant to the suspected impact.

What a post-breach review may not resolve

  • Log retention, collection gaps, clock differences and post-incident changes may prevent a complete chronology.
  • Use of an account, address or tool does not automatically identify the individual responsible.
  • Network transfer volume may support an inference without identifying the precise content transferred.
  • A vulnerability or exposed service does not by itself establish the route actually used.
  • The review does not replace legal advice, regulatory assessment, crisis communications or continuing security monitoring.

Information needed for an incident review

  • Organisation, insurer, adviser and relevant party names for the conflict check.
  • Whether the incident is contained and who is responsible for live response.
  • The specific chronology, root-cause, access or exfiltration questions to be addressed.
  • A high-level source inventory, retention limits, approximate volumes and existing response reports.
  • Board, insurer, legal, regulatory or reporting deadlines and the required deliverable.

Please do not attach evidence, passwords or confidential case papers to the public enquiry. A secure route is agreed only after the conflict check.

How conflict checks, quotations and evidence transfer work

Frequently asked questions

What if the incident is still active?

Use the organisation’s emergency response route and a suitable live-response provider. Compute Forensics can discuss a separately defined preservation, reconstruction or independent-review task when responsibilities and immediate risks are clear.

Can the review determine exactly what data left the network?

Sometimes records support a specific conclusion, but logging may show only access, archive creation, connection or volume. The report distinguishes observed content from inference and unresolved gaps.

Read all questions about fees, timing, evidence and instructing Alistair

Initial enquiry

Need an independent view after a cyber incident?

Outline the incident window, affected systems, containment already performed, records retained and the decision the review must inform. Urgent evidence handling is agreed directly, not through file upload.

Discuss a breach review