Digital Forensic Investigations

By Jonathan Krause | Founder, Forensic Control | Updated: 12 August 2026
Computer forensics, sometimes called digital forensics, is the practice of recovering, preserving and examining data from devices so that it can be relied upon in court, in a tribunal or in an internal investigation. If a laptop, phone or server in your organisation has just become part of a dispute, what happens to it in the next few hours will do more to decide the outcome than almost anything a specialist does later.
The field grew up inside law enforcement, and the range of cases it touches has only widened since. Where a machine has itself been attacked, through hacking or a denial of service incident, the device is the crime scene. More often it is the container of evidence about something that happened elsewhere: emails, browsing history, documents and deleted files connected to fraud, harassment, data theft or a contractual dispute.
Examiners look past the visible files to the metadata that sits behind them, the information about the information. Metadata can show when a document was created, edited, printed or copied, and under which user account each action took place. In many matters that timeline is the finding.
The commercial work we take on at Forensic Control follows much the same pattern as the criminal work I handled at the Met: intellectual property leaving with a departing employee, invoice fraud that began with a phishing email, and disagreements about what was known, by whom, and when. Where a matter is heading for disclosure, the forensic examination usually runs alongside eDiscovery, the collection and review of electronic material for legal proceedings, and the two disciplines share the same evidence-handling standards.
The reference point for handling digital evidence in the UK remains the Association of Chief Police Officers (ACPO) Good Practice Guide for Digital Evidence. ACPO itself was wound down in 2015, with its functions passing to the National Police Chiefs’ Council (NPCC), and the guide was last revised in 2012. Courts have carried on measuring evidence handling against its four principles regardless.
The principles condense to this: do nothing that changes data you may later rely on; if you must access original data, be competent and ready to explain what you did and why; keep an audit trail complete enough that an independent third party could repeat your steps and reach the same result; and make sure one named person carries responsibility for the whole exercise.
We have written a full companion guide to the ACPO guidelines and principles, covering where they came from and what courts do when they are breached. In nearly every challenge I have seen over two decades around contested evidence, the argument was about how the evidence was handled, not what was found.
A professional examination moves through readiness, evaluation, collection, analysis, presentation and review. The two that get skimped are the unbillable ones at either end, yet readiness determines what evidence exists to collect at all.
Collection is where most matters are won or lost. Devices are identified, documented and sealed in numbered tamper-evident bags, and storage is imaged, meaning an exact bit-for-bit copy is taken, usually through a write-blocker (hardware that physically prevents anything being written back to the original). A cryptographic hash, in effect a digital fingerprint of the copy, proves that the working copy matches the original.
Analysis extracts and interprets what was collected, and a careful examiner verifies significant findings with a second tool, so that a result found with one product can be reproduced with another. Presentation turns that work into a report a non-technical reader can follow, because the audience is a manager, a lawyer or a court, and rarely another examiner.
Readiness is the stage you control before anything has gone wrong, and it is worth an hour this week. Confirm that audit logging is enabled in Microsoft 365 (via Purview) or Google Workspace, and check how long events are retained, because the default window is shorter than most disputes are long. Change your leaver process so the account and laptop of anyone who leaves during a dispute are preserved rather than re-imaged and reissued. And make sure your asset register records who holds which device, since custody is questioned in a large share of the matters we take on.
The textbook approach is to image a device that is powered off. Sometimes that is exactly wrong. Encryption keys may exist only in the machine’s random access memory (RAM) and vanish at shutdown, a server may be too operationally important to take down, and evidence in a running cloud session may not survive a logout.
In those situations an examiner performs a live acquisition, running tools on the machine while it is still on and copying data out to their own storage. That does change the system, which sounds like a breach of the first ACPO principle, but handled properly it is not fatal: the changes are documented, the necessity explained, and courts have generally accepted evidence gathered this way.
Encrypted data is effectively unreadable without the key, and whether the key can be recovered often decides whether live acquisition should have been used in the first place. Keys turn up elsewhere on the device, on a second device the same person controls, or in RAM.
Cloud storage adds a jurisdiction problem on top of a technical one: the data sits on someone else’s servers, often in another country, under different legislation and with a slower, costlier route to lawful access.
Anti-forensics, meaning deliberate attempts to defeat examination through wiping, metadata tampering or file obfuscation, sounds more frightening than it usually proves. In our caseload it is rare to see these tools used consistently enough to hide both the evidence and the traces of their own use. Examiners also anticipate the legal arguments built on them, such as the claim that malware rather than the user was responsible for what a machine did.
There is no single qualifying body that licenses computer forensics practitioners in the UK, which means anyone can describe themselves as an expert. The cost of a poor choice usually surfaces late, when a report is challenged and there is no audit trail behind it.
Four questions separate providers quickly. Ask which tools they use and whether verifying significant findings with a second tool is standard practice. Ask what form their audit trail takes, since you may one day hand it to the other side’s lawyers. Ask who writes the report and whether that person has given evidence as an expert witness. And ask what they do if plainly illegal material surfaces in the middle of a commercial engagement, because the answer shows how well they know the legal ground they work on.
If a device has just become evidence in your organisation, the most useful thing you can do costs nothing: stop using it, do not charge it, do not let internal IT have a quick look first, and write down who has held it and when. Then contact us, and we will tell you honestly whether the matter needs an examiner at all.
Computer forensics is the recovery, preservation and examination of data from computers, phones and other devices, carried out so the results can be relied on in court, in a tribunal or in an internal investigation. Examiners work on exact copies of the original data and document every step, so findings can be independently repeated.
Largely usage. Digital forensics is the broader modern term covering all digital devices and sources, including computers, phones and cloud services, while computer forensics historically referred to computers specifically. UK providers, courts and buyers use the two interchangeably, and the same standards govern the work.
A computer forensic expert witness examines digital evidence and presents findings to a court, in a written report and, where required, in person under cross-examination. Their duty is to the court rather than to the party paying them, and they must be able to show their methods are repeatable, their tools tested and their handling of the evidence documented from collection onwards.
It depends on the volume of data and the questions asked. Imaging a single laptop is often completed within a day, while analysis commonly takes from a few days to several weeks. A focused question, such as whether a specific file was copied to a USB drive, resolves far faster than an open instruction to look at everything.
Most UK providers charge day rates, with the total driven by the number of devices, the volume of data and how contested the matter is. A single-device examination with a focused question sits at the lower end, while multi-device investigations with expert witness reporting cost substantially more. Ask any provider to scope the work in stages, so early findings can decide whether later stages are worth funding.
Safeguard your business with our expert cyber security solutions. Whether you require digital forensics, penetration testing or proactive security assessments, our team is ready to assist. Contact us today to discuss your security needs and take the first step towards a more secure future.