Page 1
INCIDENT EVIDENCE · A GUIDE FOR UK LAWYERS Preserving Evidence After a Cyber-Attack or Ransomware Incident Recovering the Business Without Destroying the Case COMPUTER FORENSICS LAB
§ ABOUT THE AUTHOR PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM ESTABLISHED 2007 · LONDON ISO 17025-ALIGNED PROCEDURES INCIDENT EVIDENCE PRESERVATION INTRUSION TIMELINE RECONSTRUCTION CPR PART 35 EXPERT REPORT S FULL CHAIN-OF-CUSTODY DOCUMENTATION
§ CONTENTS In this guide 01 Executive summary 02 The problem in plain English: recovery eats evidence 03 The first hours: what to preserve before anything is rebuilt 04 The intrusion evidence map: entry, movement, exfiltration, impact 05 Working with insurers, IR firms and the preservation gap 06 The legal audiences and their clocks: ICO, regulators, subjects, courts 07 From incident to litigation: the uses the estate must support 08 Source architecture: where else the evidence lives 09 Worked examples 10 Common mistakes and technical limitations 11 Questions to ask · Suggested wording 12 Checklist and red flags · When to involve a digital forensic expert 13 Frequently asked questions 14 Glossary · References · Disclaimer · How a specialist laboratory can assist
§ 01 · ORIENTATION Executive summary THE HEADLINE POINT: PRESERVEBEFOREYOUREBUILD: IMAGES, VOLATILEDATAAND LOGSCAPTUREDINTHEFIRSTHOURSSERVEEVERYAUDIENCETHEINCIDENTCREATES: ANDTHERECOVERYTHATSKIPSPRESERVATIONANSWERSREGULATORS, INSURERSAND COURT S FROM MEMORY
§ 02 · FIRST PRINCIPLES The problem in plain English: recovery eats evidence
§ 03 · THE FIRST HOURS The first hours: what to preserve before anything is rebuilt
Page 2
§ 04 · THEINTRUSION ' SSTORY The intrusion evidence map: entry, movement, exfiltration, impact
§ 05 · THECROWDEDBRIDGE Working with insurers, IR firms and the preservation gap
§ 06 · THECLOCKS The legal audiences and their clocks: ICO, regulators, subjects, courts
§ 07 · THELONGTAIL From incident to litigation: the uses the estate must support
§ 08 · THEWIDERMAP Source architecture: where else the evidence lives QUESTION PLATFORM CLEARED / END POINT NETWORK SECURIT Y EXTERNAL LAYER LAYER TOOLING LAYER IDENTIT Y / ATTACKER- LOGS LOST
§ 09 · IN THE WILD Worked examples EXAMPLE1 · THE72 - HOURREPORTWRITTENFROMEVIDENCE EXAMPLE2 · THEREBUILDTHATERASEDTHESUPPLIERCLAIM EXAMPLE3 · THENEGATIVETHATWASWORTHPROVING
Page 3
§ 10 · WHEREITGOESWRONG Common mistakes and technical limitations Common mistakes Technical limitations
§ 11 · INTERROGATORIES & DRAFTING AIDS Questions to ask · Suggested wording Ask your client (in the first hours) Ask the IR firm / insurer panel Ask third parties (suppliers, MSPs, providers) SUGGESTED WORDING · PRESERVATION M AN DATE FOR THEIR ENGAGEMENT
§ 12 · QUICK CONTROL Checklist and red flags · When to involve a digital forensic expert The incident-preservation checklist Red flags When to involve a digital forensic expert
§ 13 · COMMON QUESTIONS Frequently asked questions Won't preservation slow down our recovery when every hour of d own time costs money? Should we pay the ransom, and does forensics bear on it? How can we possibly know within 72 hours what data was affected? The attackers cleared the server logs. Is the investigation over? Our insurer's IR firm is handling everything. Do we need our own forensic adviser? Can we prove data was NOT taken?
§ 14 · REFERENCE Glossary Sources and authoritative references DISCLAIMER
§ HOW A SPECIALIST LABORATORY CAN ASSIST Working with Computer Forensics Lab Speak to a forensic examiner, not a salesperson. INSTRUCTTHELAB NEWENQUIRIESEMAILE - DISCOVERY
Cite as: Joseph Naghdi, Preserving Evidence After A Cyber Attack Or Ransomware Incident, Computer Forensics Lab, https://e-discovery.uk/library/preserving-evidence-after-a-cyber-attack-or-ransomware-incident/pdf.
