
About LanCologne
Expert consultancy and forensic laboratory for digital evidence
LanCologne is a specialist consultancy and forensic laboratory based in Cologne. We specialise in IT forensics, the forensic preservation and analysis of digital evidence, and the transparent technical assessment of complex digital issues.
We assist courts, law enforcement agencies, solicitors and defence lawyers, businesses, insurance companies and private individuals with matters where digital evidence needs to be secured, reconstructed, examined or professionally assessed.
We do not view IT forensics as the collection of as much digital data as possible. What is crucial is to secure the information relevant to a specific issue using appropriate methods, to verify it technically, and to assess its actual evidential value in a transparent manner.
Experience in digital forensics
Forensic case management since 2015
LanCologne has been active in the field of digital forensics since 2015. During this time, the firm has examined a wide variety of digital evidence and technical issues – ranging from smartphones and computer systems to data storage media and cloud data, through to complex cases where information from multiple digital sources had to be cross-referenced.
Our clients come from the institutional, private and commercial sectors. These include, amongst others, courts and the judiciary, law enforcement agencies, solicitors and criminal defence lawyers, companies, insurance firms and private individuals.
The requirements vary considerably. Whilst, for example, the authenticity or chronological context of a single digital artefact may be crucial in one investigation, other enquiries require the reconstruction of complex sequences of events from multiple devices and data sources. This practical case work forms the basis of how we work today.
Qualifications and continuous professional development
Digital forensics is constantly evolving. Operating systems, encryption methods, file systems, mobile platforms, cloud services and applications are constantly changing. A technically sound investigation therefore requires not only practical experience but also regular professional development.
Our qualifications include, amongst other things:
- IT Forensic Mobile Expert – TÜV Rheinland (Certificate No. 2948573, valid until 02/2027)
- IT Forensics Windows Expert – TÜV Rheinland (Certificate No. 2958376, valid until 02/2027)
- MOBILedit Forensic Professional Certified (valid indefinitely)
- OSF Triage Certification Exam (OSForensics)
- Certified training partner of Belkasoft and SUMURI Premium Partner
- specialist qualifications and practical experience in the field of mobile forensics
- Experience in the forensic examination of Apple, Windows, Android and other digital systems
- regular professional development and further training
Both certificates are publicly available: Certification on Certipedia (TÜV Rheinland)
Furthermore, we are constantly exploring new forensic methods, changes to operating systems and the development of digital artefacts. We do not view professional competence as a status achieved once and for all, but as an ongoing process.
In-house forensic laboratory in Cologne
Digital evidence remains under our control
Forensic investigations are carried out in our own laboratory in Cologne. This enables us to carry out key stages of evidence preservation, data recovery and forensic analysis within our own technical infrastructure.
Depending on the subject under investigation, specialised workstations and procedures are available for, amongst other things:
- Mobile forensics
- Computer forensics
- forensic data storage backup
- Data recovery
- Analysis of flash and storage media
- Chip-off and JTAG methods
- read-only forensic backup
- controlled testing of mobile devices
These include, amongst other things, write-blocker stations, Faraday cages and specialised workstations for data recovery and hardware-based forensic analysis.
The test material remains under our responsibility throughout the entire process and is not passed on to third parties. We provide every client with a written non-disclosure agreement (NDA). Particularly in the case of sensitive data or data relevant as evidence, we regard the controlled handling of the test material as an essential part of forensic work.



These photographs were taken at our laboratory in Cologne. They show the cleanroom workbench for data recovery, hardware write blockers and imaging systems for forensic backup, as well as the electronics workstation for hardware analysis. We describe the different work areas and their purposes on a separate page.
How we work
Transparent, open-ended and independent
A forensic investigation begins with a question – not with a desired outcome. Our task is to establish facts that can be verified by technical means and to assess their significance.
The artefacts relevant to the respective investigation are analysed – regardless of whether they confirm or refute an initial working hypothesis. In doing so, we distinguish between technically verifiable facts, conclusions that can be logically derived from them, and assumptions that cannot be substantiated on the basis of the available data.
Even the absence of evidence can constitute a relevant finding of the investigation. Where the available digital traces do not permit a conclusive conclusion to be drawn, this limitation is stated.
Digital evidence preservation and chain of custody
In investigations where evidence is at stake, it is not only the outcome of the investigation that matters. Equally important is the question of how digital evidence is handled and on what basis a finding was reached.
Depending on the assignment, we therefore document, amongst other things:
- Receipt and condition of the test samples
- Identification of relevant devices and data storage media
- Handover and processing steps
- security procedures used
- Integrity values or hash values, where technically feasible
- Forensic tools used and their versions
- key analytical steps
- technical limitations
- relevant findings
The aim is to ensure that the chain of evidence is as transparent as possible, from the receipt of the digital evidence through to its technical assessment.
It is not the tool that determines the quality of an examination
We use a range of specialised forensic hardware and software solutions in our work. The choice of tool depends on the subject of the investigation and the specific issues to be addressed.
Forensic software can extract data, organise it and make it analysable. However, it does not replace the expert assessment of findings. Where results are relevant or contradictory, the underlying files, databases, metadata and system structures can therefore be examined further, and findings can be cross-checked against other data sources.
The quality of a forensic investigation does not depend on the number of software products available, but on methodology, technical analysis and a transparent interpretation of the results.
From securing the property to expert valuation
One of LanCologne’s particular strengths lies in its ability to combine different technical disciplines. Depending on the subject under investigation, we can carry out various steps as part of a coherent investigative process:
- Admission of evidence
- Forensic backup
- Data reconstruction
- Technical Analysis
- Correlation of different data sources
- Assessment of the findings
- Documentation or expert reports
This connection can be particularly important when an item under investigation has suffered technical damage or when data first needs to be reconstructed before a proper forensic analysis can be carried out.
Expert work
Presenting technical matters in a clear and comprehensible manner
Digital evidence can be technically complex. An expert’s role is therefore not merely to identify digital traces. The findings must be documented in such a way that the investigative process, the findings and the technical conclusions remain transparent.
Depending on the brief, we produce:
- technical investigation documentation
- forensic investigation reports
- expert opinions
- detailed IT forensic reports
In doing so, we ensure a clear distinction is made between the technical findings and their interpretation.
Passing on knowledge
Seminars and professional exchange
Practical experience gained from case work is also incorporated into our training and seminar programmes. LanCologne provides expertise in selected areas of IT and mobile forensics, covering both established investigative methods and the latest technical developments.
Teaching forensic methods is also an important part of our own professional work: methods must be explained in a way that is easy to follow, technically sound and open to critical scrutiny.
This also includes working as a lecturer in macOS, iOS and watchOS forensics.
Our specialist areas
Our work includes, in particular:
Mobile forensics
Forensic backup and analysis of iPhone, iPad and Android devices, as well as the associated data sources.
Computer forensics
Investigation of Windows, macOS and Linux systems, storage media, file systems and system artefacts.
Cloud forensics
Backing up and analysing relevant cloud data and correlating it with on-premises devices and user activities.
Digital evidence preservation
Transparent safeguarding of digital evidence, taking into account integrity and documentation.
Data recovery and data reconstruction
Technical recovery and reconstruction of data from logically or physically damaged storage media, insofar as this is technically feasible.
Expert report
Technical assessment of digital matters and a clear presentation of the findings for both judicial and extrajudicial matters.
Further technical qualifications
Our technical expertise is not limited to digital forensics. Thanks to our many years’ experience in the IT sector, we also possess qualifications and expertise in areas including network technology, firewall systems, WLAN infrastructures and IT security. These include, or have included, the manufacturer-specific qualifications Ubiquiti Enterprise Wireless Admin, Ubiquiti Broadband Wireless Admin, Certified Siklu Master and LANCOM Certified Specialist WLAN (2015–2017).
This expertise complements our forensic work, particularly in cases where network, infrastructure or security components need to be included in the technical assessment. However, the main focus of our current work is clearly on IT forensics, the preservation of digital evidence, expert witness services and data recovery.
LanCologne – IT forensics from Cologne
We do not claim to be able to promise a specific outcome for every issue. Our aim is to examine digital matters using appropriate technical methods and to present, in a transparent manner, what can be determined from the available digital evidence – and what cannot. This approach forms the basis of our work as a consultancy and forensic laboratory.
Would you like to have a digital matter investigated?
Please feel free to start by describing the circumstances and your specific enquiry to us. On this basis, we can assess which investigative options would be appropriate and what documents or evidence will be required for this.