Defensible collection

Targeted Forensic Data Collection for Legal Matters

Documented on-site or remote collection of defined computers, mobile devices, mailboxes, cloud data and storage for legal, regulatory and internal investigations.

Direct access to Alistair Ewing · Free initial consultation · Written estimate before work

Collect what is needed and record what was done

A defensible collection connects the issues to the custodians, sources, dates and data types that should be preserved. It also records authority, source state, method, verification, exclusions and transfer so the receiving team can understand the result.

The scope may combine full forensic imaging of a defined device with targeted collection from mailboxes, cloud storage, collaboration systems or user folders. On-site and remote methods are considered against access, security, business disruption, data volume and the assurance required.

Where the instruction and device are suitable, remote collection may be possible from a live system through an encrypted collection agent, or from a switched-off system started from a controlled bootable USB or CD. Authority, operator steps, encryption, verification and hand-off are agreed before collection.

Alistair is UK based and available for worldwide travel, including across EMEA, by agreement. Feasibility depends on legal authority, data-transfer restrictions, safety, timetable, equipment movement and cost.

If collection sits within a wider eDiscovery exercise, strategy, preservation planning, review coordination and production can be scoped separately. For device-specific acquisition methods, see the computer forensic imaging page.

Collection planning questions

  • Which custodians, devices, accounts, repositories and date ranges are linked to the instructed issues?
  • Which sources are at risk of routine deletion, synchronisation, reassignment or other change?
  • Is a full forensic image necessary, or can a targeted collection preserve the relevant data and metadata?
  • Can a live or switched-off system be collected remotely using a suitable controlled method, or is attendance required?
  • What manifest, verification, encryption and hand-off format does the legal or review team require?

Sources that may be within scope

  • Windows, macOS or Linux computers and defined internal or external storage.
  • Microsoft 365 or Google Workspace mailboxes, cloud storage and available audit records.
  • Company or employee mobile devices where collection is authorised and proportionate.
  • Shared drives, collaboration locations, removable media and selected user folders.
  • Existing exports, forensic images, preservation instructions and collection requirements.

Preserving cloud evidence for legal proceedings

Cloud material can change while the dispute is being scoped. Identify the accounts, services, relevant dates and any known retention or deletion deadline early. A downloaded folder may omit version history, access records, shared links or other service-side information, so the collection method should be chosen for the question rather than convenience.

Alistair can help define an authorised, proportionate collection and document its coverage. The plan distinguishes live content, retained versions and available audit records, with exceptions recorded. Legal hold decisions belong to the legal team; administrators or an agreed collection provider implement the authorised controls. For tenant-wide work, see Microsoft 365 preservation, eDiscovery and technical hand-off.

Limits of collection

  • Collection cannot preserve material that has already expired, been overwritten or sits outside available authority and control.
  • Provider interfaces, retention, licences and account permissions can restrict export content and metadata.
  • A targeted collection is assessed against its documented scope, not every record that may ever have existed.
  • Privilege, relevance, disclosure and employment-law decisions remain with the legal or authorised decision-making team.
  • Not every device or environment is suitable for guided remote collection. Location, attendance timing and method are confirmed for each instruction rather than promised as a fixed service level.

Information needed to plan a collection

  • Party, entity and custodian names for conflicts and collection planning.
  • Source types, quantities, approximate volumes, locations and administrator access.
  • The issues, date ranges, users and data types that define the proposed scope.
  • Any imminent departure, retention expiry, device reissue or other preservation risk.
  • Required collection date, export format, hand-off destination and security requirements.

Please do not attach evidence, passwords or confidential case papers to the public enquiry. A secure route is agreed only after the conflict check.

How conflict checks, quotations and evidence transfer work

Frequently asked questions

Can a forensic collection be completed remotely?

It may be possible. A live system can use an encrypted collection agent where suitable, while a switched-off system may be started from a controlled bootable USB or CD. The estimate records the method, operator steps, encryption, validation and hand-off.

Is collection the same as document review?

No. Collection preserves and transfers defined source data. Legal relevance, privilege review, disclosure decisions, hosting and production are separately scoped responsibilities.

Read all questions about fees, timing, evidence and instructing Alistair

Initial enquiry

Plan an on-site or remote collection

Describe the sources, locations, live or switched-off state, authority, access, timescale and receiving team. The written plan identifies the operator, method, checks and hand-off.

Discuss a collection plan