A pattern that has become hard to ignore in 2026: the data collected during a cyber incident response very often turns into evidence in something else - a regulatory notification, an insurance dispute, a civil claim, or an employment matter arising from how the breach happened. The handover between the IR team and the eDiscovery team has become a routine part of serious incidents.
Where Magnet Axiom Cyber sits
Magnet Forensics' Axiom Cyber is one of the tools driving this convergence. Built on the same engine as the long-established Axiom forensic suite, it is aimed squarely at remote acquisitions from corporate endpoints, cloud sources (Microsoft 365, Google Workspace, AWS) and mobile devices, with a workflow geared to incident timelines and corporate investigations rather than law-enforcement casework.
For an eDiscovery team picking up the work later, two features matter most: full forensic preservation of the source data, and case files that another examiner can open and re-run without going back to the live system.
What good handover looks like
The cases that go smoothly tend to share a few characteristics:
- Preservation happens once, defensibly. Axiom Cyber acquisitions are treated as the master copy, with hashes recorded. Subsequent eDiscovery processing works from those preserved images rather than re-collecting from systems that may have changed.
- Scope is written down. The IR team records which custodians, devices and date ranges were acquired and why. That record feeds straight into the disclosure narrative if litigation follows.
- Indicators of compromise are kept with the evidence. Where the IR team identified specific accounts, files or timestamps as relevant to the incident, those are passed across so the eDiscovery review can prioritise them.
Why this matters now
Two forces are pushing this together. First, regulators - including the ICO and the FCA in the UK - increasingly expect organisations to demonstrate not just that they responded to an incident, but that they preserved evidence to a standard that supports later analysis. The ICO's personal-data-breach guidance makes preservation expectations explicit. Second, cyber-insurance claims and follow-on litigation are now common enough that IR teams routinely assume their work product will be scrutinised by lawyers later.
Practical takeaways
For organisations: agree in advance, before an incident, who owns preservation, in what tool, and how the handover to eDiscovery will work. For legal teams: when an incident occurs, ask what was acquired, in what format, and what the chain of custody record looks like - before any further collection runs.
The Magnet Forensics blog publishes useful case-study material at magnetforensics.com/blog, and SANS DFIR continues to be a strong source of practitioner-level guidance on the IR / forensics overlap at sans.org/blog.
§ From the guide, latest version
Forensic Evidence From Cloud Infrastructure AWS Azure Google CloudCLOUD INFRASTRUCTURE · A GUIDE FOR UK LAWYERS Forensic Evidence from Cloud Infrastructure: AWS, Azure and Google Cloud Control-Plane Logs, Storage, Compute and the Evidence in the Account, Not the Server COMPUTER FORENSICS LAB
§ ABOUT THE AUTHOR PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM ESTABLISHED 2007 · LONDON ISO 17025-ALIGNED PROCEDURES CLOUD-INFRASTRUCTURE FORENSICS
§ CONTENTS In this guide 01 Executive summary 02 The problem in plain English: there is no server to image 03 The control plane: who did what to the infrastructure 04 The data plane: storage, databases and what the applications did 05 Compute, snapshots and the ephemeral-evidence problem 06 Preservation and collection: holds, exports and who controls access 07 Deployment: breaches, configuration disputes and the departing engineer 08 Source architecture: where else the evidence lives 09 Worked examples 10 Common mistakes and technical limitations 11 Questions to ask · Suggested wording 12 Checklist and red flags · When to involve a digital forensic expert 13 Frequently asked questions 14 Glossary · References · Disclaimer · How a specialist laboratory can assist
