INCIDENT EVIDENCE · A GUIDE FOR UK LAWYERS
Preserving Evidence After a Cyber-Attack or
Ransomware Incident
Recovering the Business Without Destroying the Case
COMPUTER FORENSICS LAB
§ ABOUT THE AUTHOR
PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM
ESTABLISHED 2007 · LONDON ISO 17025-ALIGNED PROCEDURES INCIDENT EVIDENCE PRESERVATION
INTRUSION TIMELINE RECONSTRUCTION CPR PART 35 EXPERT REPORT S
FULL CHAIN-OF-CUSTODY DOCUMENTATION
§ CONTENTS
In this guide
01 Executive summary
02 The problem in plain English: recovery eats evidence
03 The first hours: what to preserve before anything is rebuilt
04 The intrusion evidence map: entry, movement, exfiltration, impact
05 Working with insurers, IR firms and the preservation gap
06 The legal audiences and their clocks: ICO, regulators, subjects, courts
07 From incident to litigation: the uses the estate must support
08 Source architecture: where else the evidence lives
09 Worked examples
10 Common mistakes and technical limitations
11 Questions to ask · Suggested wording
12 Checklist and red flags · When to involve a digital forensic expert
13 Frequently asked questions
14 Glossary · References · Disclaimer · How a specialist laboratory can assist
§ 01 · ORIENTATION
Executive summary
THE HEADLINE POINT: PRESERVEBEFOREYOUREBUILD: IMAGES, VOLATILEDATAAND
LOGSCAPTUREDINTHEFIRSTHOURSSERVEEVERYAUDIENCETHEINCIDENTCREATES:
ANDTHERECOVERYTHATSKIPSPRESERVATIONANSWERSREGULATORS, INSURERSAND
COURT S FROM MEMORY
§ 02 · FIRST PRINCIPLES
The problem in plain English: recovery eats evidence
§ 03 · THE FIRST HOURS
The first hours: what to preserve before anything is rebuilt