These are the questions visitors ask most often, each one answered in full from the wording of the published guides rather than a single FAQ line.
What does the client get after the visit?
traceable to CONTEXT?* Yes.
* *At least one short verbatim quotation?* Yes ("every exhibit, reference, seal and location").
*
Sources: Planning An On Site Digital Evidence Collection, Browser History And Internet Artefacts, The First EDisclosure Meeting 50 Questions Lawyers Should Ask
Put this to the assistantDo we need to tell staff what is happening?
Whether you need to tell staff what is happening is a lawyer's decision made during the planning stage, balancing transparency with the risk of tipping off suspects.
According to the
Sources: Planning An On Site Digital Evidence Collection, The First EDisclosure Meeting 50 Questions Lawyers Should Ask, Investigating Suspected Employee Data Theft, Technical Preparation For A Disclosure Case Management Conference
Put this to the assistantWhat if we find devices on site that are not on the schedule?
If you discover devices on site that are not on the schedule, the standard contingency is to record them, preserve them, and immediately refer the scope question to the designated decision-
Sources: Planning An On Site Digital Evidence Collection
Put this to the assistantShould devices be imaged on site or taken to the laboratory?
The decision to image devices on site or take them to the laboratory must be made per device and by plan, depending on hardware health, business needs, and the context of
Sources: Planning An On Site Digital Evidence Collection, Remote Employee Collection, Should A Computer Be Imaged While Running Or Switched Off
Put this to the assistantCan the business keep working while we collect?
The business can largely keep working during a collection, provided that careful planning has been put in place beforehand.
To minimise operational impact, user machines can be lifted
Sources: Planning An On Site Digital Evidence Collection, Remote Employee Collection, Investigating Suspected Employee Data Theft
Put this to the assistantHow long does an on-site collection take?
An on-site collection typically takes a single day for a handful of machines, two to three days for a small office, and requires a planned campaign for anything larger
Sources: Planning An On Site Digital Evidence Collection
Put this to the assistantCan the employee just consent to us collecting their device abroad?
An employee's consent can sometimes allow you to collect their device abroad, but it cannot be assumed to be a complete legal basis on its own.
When
Sources: Custodian Abroad Cross Border Collection, Remote Employee Collection, Remote Forensic Collection When Can It Be Defensible
Put this to the assistantWhat do we tell the English court if foreign law blocks disclosure?
If foreign law blocks disclosure, you must inform the English court candidly and early, providing evidence of the constraint and demonstrating that you are doing the lawful maximum to comply.
The
Sources: Custodian Abroad Cross Border Collection, Control Of Electronic Documents What Lawyers Need To Investigate, Electronic Disclosure Explained A Practical Guide For UK Lawyers
Put this to the assistantCan cloud-side collection avoid the whole problem?
Cloud-side collection can avoid much of the problem when data resides in a UK-controlled corporate account, but it does not completely eliminate local law considerations.
Sources: Custodian Abroad Cross Border Collection, Can We Collect Only Relevant Data Instead Of Imaging Everything, Remote Employee Collection
Put this to the assistantIs moving the data to England just a logistics question?
Moving data to England is not just a logistics question, as it constitutes a restricted international transfer under the UK GDPR that requires a lawful transfer mechanism.
Bringing personal data from abroad
Sources: Custodian Abroad Cross Border Collection, Coordinating Forensic Collection Across Multiple Offices And Countries
Put this to the assistantWhat is a blocking statute and why does it matter so much?
A blocking statute is a foreign law that criminalises the gathering or exporting of evidence located in that country for use in foreign proceedings outside of official channels.
It
Sources: Custodian Abroad Cross Border Collection, Collecting Without The Password
Put this to the assistantThe court has ordered disclosure. Can we just image the custodian's device abroad?
No, an English court order does not make it lawful to collect and export data located in another country.
The data is governed by the laws of the country where it
Sources: Custodian Abroad Cross Border Collection, BYOD And Disclosure, EDisclosure Or Digital Forensics Choosing The Correct Approach
Put this to the assistantCan we prove data was NOT taken?
It is sometimes possible to prove that data was not taken, but this relies entirely on capturing the evidence immediately after an incident.
Proving a negative is highly valuable when achievable
Sources: Preserving Evidence After A Cyber Attack Or Ransomware Incident, The Missing Evidence Problem, Can You Prove Who Deleted A File, Data Exfiltration To Cloud Storage
Put this to the assistantOur insurer's IR firm is handling everything. Do we need our own forensic adviser?
It is prudent to retain your own forensic adviser for evidence preservation, even when an insurer's incident response firm is handling containment and recovery.
The insurer's
Sources: Preserving Evidence After A Cyber Attack Or Ransomware Incident, Coordinating Forensic Collection Across Multiple Offices And Countries, Digital Forensics In Corporate Fraud Investigations
Put this to the assistantThe attackers cleared the server logs. Is the investigation over?
No, the investigation is not over because log-clearing is considered expected tradecraft during a cyber incident.
When attackers clear server logs, they are attempting
Sources: Preserving Evidence After A Cyber Attack Or Ransomware Incident, Forensic Collection From Corporate File Servers, Website Web Server And Application Logs
Put this to the assistantHow can we possibly know within 72 hours what data was affected?
You will often only know partially what data was affected within 72 hours, but the regulatory regime anticipates this reality.
The initial report to the Information Commissioner'
Sources: Preserving Evidence After A Cyber Attack Or Ransomware Incident
Put this to the assistantShould we pay the ransom, and does forensics bear on it?
Whether to pay a ransom is a legal-strategic decision taken under professional advice, and digital forensics provides the factual inputs to make that decision informed.
Sources: Preserving Evidence After A Cyber Attack Or Ransomware Incident
Put this to the assistantWon't preservation slow down our recovery when every hour of d own time costs money?
Preservation will only slow down your recovery marginally because the work is conducted in parallel with containment efforts, rather than serially.
Imaging designated systems and exporting logs
Sources: Preserving Evidence After A Cyber Attack Or Ransomware Incident, Should Backup Systems Be Searched For Disclosure
Put this to the assistantDo hashes help us find our document on the other side's systems?
Yes, providing an examiner with a file and its hash allows them to find any bit-identical copy across an estate by its fingerprint, regardless of its filename or location.
This
Sources: What Is A Forensic Hash And Why Does It Matter
Put this to the assistantWhat is dual hashing, and is it necessary?
Dual hashing is the process of computing two different algorithm values over the same data acquisition, and while it is not strictly necessary, it is standard laboratory practice.
Computing two algorithms
Sources: What Is A Forensic Hash And Why Does It Matter
Put this to the assistantWhat can be done if hashes were never taken?
If hashes were never taken, you should compute them immediately and be honest about the fact that they only establish integrity from this point forward.
As explained in the practice
Sources: What Is A Forensic Hash And Why Does It Matter
Put this to the assistantShould we insist on SHA-256 every where?
Review against constraints:**
* *One direct sentence answering the question?* Yes.
* *Two to four short paragraphs of supporting detail?
Sources: What Is A Forensic Hash And Why Does It Matter
Put this to the assistantCan a hash be reversed to reveal the document's contents?
The provided guides do not explain whether a hash can be reversed to reveal a document's contents, but they do detail how hashes are used to identify and verify documents in digital forensics
Sources: A Privileged Document Has Been Disclosed What Happens Next, Detecting Backdated Or Manipulated Documents, Digital Redaction That Cannot Be Reversed
Put this to the assistantCan two different files ever share the same hash?
In theory, two different files can share the same hash, but for a court's purposes, no two meaningfully different files have ever been found to share a SHA-
Sources: What Is A Forensic Hash And Why Does It Matter
Put this to the assistantDoes it matter which of AWS, Azure or Google Cloud we use?
The core principles of forensic evidence collection are identical across AWS, Azure and Google Cloud, although the specific service names, log formats and export tools will differ per platform.
When
Sources: Forensic Evidence From Cloud Infrastructure AWS Azure Google Cloud
Put this to the assistantHow long do we have before the evidence disappears?
You often have less time than you think, as many data sources will disappear within hours, days, or weeks due to automated retention policies.
According to
Sources: Forensic Evidence From Cloud Infrastructure AWS Azure Google Cloud, Finding The Evidence A Lawyers Map Of Modern Electronic Data Sources, The Missing Evidence Problem
Put this to the assistantA former engineer still had access to our cloud account. How serious is that?
Unrevoked access to a cloud account by a former engineer is potentially very serious, as it allows a leaver to read, take or destroy the estate
Sources: Forensic Evidence From Cloud Infrastructure AWS Azure Google Cloud, Data Exfiltration To Cloud Storage, Who Accessed Or Downloaded A Confidential Document
Put this to the assistantWe think data was taken from cloud storage, but there is no access log. Is it hopeless?
It is not hopeless if access logs are missing, as alternative evidence sources within the cloud infrastructure can still prove that data was taken.
The absence of an access log is
Sources: Forensic Evidence From Cloud Infrastructure AWS Azure Google Cloud, Data Exfiltration To Cloud Storage, Forensic Collection From Corporate File Servers
Put this to the assistantSomeone deleted our production database. Can we prove who?
You can usually prove the identity of the account that deleted a production database, and often the specific person behind it.
The deletion of a database is typically a single control-plane
Sources: Forensic Evidence From Cloud Infrastructure AWS Azure Google Cloud, Can You Prove Who Deleted A File
Put this to the assistantOur systems are all in AWS. Can you image the server?
There is no server to image in the traditional sense, because the evidence resides within the cloud account itself rather than on a physical disk.
Traditional computer forensics relies
Sources: Forensic Evidence From Cloud Infrastructure AWS Azure Google Cloud
Put this to the assistantHow does this play in criminal and regulatory matters?
In criminal and regulatory matters, the handling of adverse documents and fraud investigations follows the same moral structure as civil cases but with sharper edges.
Under the CPIA
Sources: Known Adverse Documents In The Digital Age, Digital Forensics In Corporate Fraud Investigations
Put this to the assistantWe have just found something bad, late in the case. Now what?
If you discover an adverse document late in the case, you must preserve it exactly as found, escalate it to supervising counsel on the same day, and disclose it promptly
Sources: Known Adverse Documents In The Digital Age, How Lawyers Should Instruct A Digital Forensic Expert, The Missing Evidence Problem, A Privileged Document Has Been Disclosed What Happens Next
Put this to the assistantWhat if the adverse document is privileged?
If an adverse document is genuinely privileged, it is not disclosable and the duty to disclose known adverse documents does not override that privilege.
G
Sources: Known Adverse Documents In The Digital Age, A Privileged Document Has Been Disclosed What Happens Next
Put this to the assistantDo we have to go looking for adverse documents?
You do not have a freestanding search obligation to look for adverse documents, as the duty is framed around known documents.
However, knowledge must be assembled honestly by asking the relevant people
Sources: Known Adverse Documents In The Digital Age
Put this to the assistantWhose knowledge counts as the company "knowing"?
The provided materials do not answer whose knowledge counts as a company knowing, but they do answer the related question of which documents are considered to be within a company's control for
Sources: Control Of Electronic Documents What Lawyers Need To Investigate, BYOD And Disclosure, CRM Evidence Salesforce HubSpot
Put this to the assistantWhat makes a document "adverse"?
A document is considered adverse if it contradicts or materially damages your contended version of events on the issues in dispute, or supports your opponent's case.
The
Sources: Known Adverse Documents In The Digital Age
Put this to the assistantWhat should a client adopting Signal for business do this week?
Open with one direct sentence answering the question?* Yes.
* *Two to four short paragraphs of supporting detail?* Yes (3 paragraphs).
*
Sources: Signal And Ephemeral Messaging
Put this to the assistantDo adverse inferences really substitute for the messages themselves?
Yes, where destruction follows the duty and goes unexplained, tribunals will infer the tenor of the destroyed material from the destroyer's conduct.
Courts will draw an
Sources: Signal And Ephemeral Messaging, The Missing Evidence Problem, Known Adverse Documents In The Digital Age
Put this to the assistantA witness offers screenshots of expired chats. How much weight can they carry?
Screenshots of expired chats can carry substantial weight if properly authenticated, but unauthenticated screenshots are the weakest class of messaging evidence.
The difference in evidential value comes
Sources: Signal And Ephemeral Messaging, WhatsApp Evidence
Put this to the assistantThe opponent says the messages expired innocently under settings predating the dispute. Does that end it?
No, it does not end the matter, but rather shifts the focus to what happened after the duty to preserve arose.
While it is true that "pre
Sources: Signal And Ephemeral Messaging
Put this to the assistant