§ Guide, full text

Damaged Computers And Data Recovery

Physically broken devices rarely mean empty ones. Much data survives damage and can be recovered using techniques from board repair to chip-level extraction. The pattern and timing of damage often indicate whether it was accidental or a deliberate attempt to destroy evidence, providing crucial insights for UK litigators and investigators.

17 pages · 26 min read

Loading the PDF reader

Page 1

DAMAGEDMEDIA · A GUIDE FOR UK LAWYERS Damaged Computers and Data Recovery Physically Broken Devices, the Recovery That Is Possible, and the Damage That Is a Clue COMPUTER FORENSICS LAB

§ ABOUT THE AUTHOR PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM ESTABLISHED 2007 · LONDON ISO 17025-ALIGNED PROCEDURES DAMAGED-DEVICE RECOVERY CHIP-LEVEL EXTRACTION CPR PART 35 EXPERT REPORT S FULL CHAIN-OF-CUSTODY DOCUMENTATION

§ CONTENTS In this guide 01 Executive summary 02 The problem in plain English: broken does not mean empty 03 Types of damage and what each does to the data 04 The recovery techniques: from board repair to chip-off 05 Recovering defensibly: integrity, encryption and honest limits 06 Accidental or deliberate: reading the damage as evidence 07 Deployment: spoliation, insurance and the estate around the wreckage 08 Source architecture: where else the evidence lives 09 Worked examples 10 Common mistakes and technical limitations 11 Questions to ask · Suggested wording 12 Checklist and red flags · When to involve a digital forensic expert 13 Frequently asked questions 14 Glossary · References · Disclaimer · How a specialist laboratory can assist

§ 01 · ORIENTATION Executive summary THE HEADLINE POINT: ABROKENDEVICEISRARELYANEMPTYONE: MUCH DATA SURVIVESPHYSICALDAMAGEANDCANBERECOVEREDBYTECHNIQUESFROMBOARD REPAIRTOCHIP - LEVEL EXTRACTION, ANDTHEPATTERNANDTIMINGOFTHEDAMAGE OFTENTELLTHEIROWNSTORYABOUTWHETHERITWASACCIDENTORADELIBERATE ATTEMPTTODESTROYEVIDENCE

§ 02 · FIRST PRINCIPLES The problem in plain English: broken does not mean empty

§ 03 · TYPESOFDAMAGE Types of damage and what each does to the data

Page 2

§ 04 · THERECOVERYTECHNIQUES The recovery techniques: from board repair to chip-off

§ 05 · RECOVERINGDEFENSIBLY Recovering defensibly: integrity, encryption and honest limits

§ 06 · ACCIDENTALORDELIBERATE Accidental or deliberate: reading the damage as evidence

§ 07 · DEPLOYMENT Deployment: spoliation, insurance and the estate around the wreckage

§ 08 · THEWIDERMAP Source architecture: where else the evidence lives QUESTION COUNTERPART EVIDENCE LOCAL- DAMAGED CLOUD SERVER-SIDE DEVICE BACKUP PLATFORM S SYNCED / PHYSICAL DELETED / COPIES LAYER ONLY

§ 09 · IN THE WILD Worked examples EXAMPLE1 · THELAPTOPTHATWOULDNOTPOWERONANDHELDEVERYTHING EXAMPLE2 · THEHOUSEFIRETHATWASREALLYAHAMMER EXAMPLE3 · THEGENUINELYDESTROYEDDRIVEANDTHEESTATETHATSAVEDTHECASE

Page 3

§ 10 · WHEREITGOESWRONG Common mistakes and technical limitations Common mistakes Technical limitations

§ 11 · INTERROGATORIES & DRAFTING AIDS Questions to ask · Suggested wording Ask your client Ask your opponent Ask your e Discovery / forensic provider DA M AG EANA LY SIS

§ 12 · QUICK CONTROL Checklist and red flags · When to involve a digital forensic expert The damaged-device checklist Red flags When to involve a digital forensic expert

§ 13 · COMMON QUESTIONS Frequently asked questions The laptop will not turn on. Is the data gone? The phone was smashed or soaked. Can anything be recovered? How can you tell if a device was broken deliberately? Does recovering a damaged drive also decrypt it? Is recovered data admissible, given the device was broken? The drive is genuinely destroyed. Is the case lost?

§ 14 · REFERENCE Glossary Sources and authoritative references 35 and CrimPR Part 19 reporting): cflab.uk/digital-forensics-services · guides library: cflab.uk/guides DISCLAIMER

§ HOW A SPECIALIST LABORATORY CAN ASSIST Working with Computer Forensics Lab Speak to a forensic examiner, not a salesperson. INSTRUCTTHELAB NEWENQUIRIESEMAILE - DISCOVERY

Cite as: Joseph Naghdi, Damaged Computers And Data Recovery, Computer Forensics Lab, https://e-discovery.uk/library/damaged-computers-and-data-recovery/pdf.

Instruct the practice

Bring us in early. Defensibility is built, not retrofitted.

Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.

WhatsApp