IT Forensics · Business
How can a company determine, following an attack, whether compromised cloud sessions are still active?
Cloud access may continue via sessions and tokens even after passwords have been changed.
Why this question is important for a business
During the recovery phase following a cyber incident, technical decisions are made that can simultaneously affect operational capability, the preservation of evidence, data protection and the ability to provide evidence at a later date. Thorough documentation therefore not only protects the IT systems, but also establishes a robust factual basis for management and legal advice.
Technical investigative approach
We review the available sign-in, session, token, device and audit information, as well as the effectiveness of any revocation measures taken.
Where the limits of what can be said lie
The specific level of visibility depends on the platform, licensing, retention and available telemetry.
Why LanCologne?
Following a serious cyber incident, the task does not end with stopping the attack. The organisation must bring its systems back online in a controlled manner, assess data and backups, secure identities, analyse the impact of service disruptions and, at the same time, preserve evidence for any subsequent legal, insurance-related or regulatory matters.
LanCologne therefore distinguishes between operational incident response and forensic reconstruction, without artificially isolating the two from one another. Containment and recovery protect the organisation; forensics documents what happened and the technical facts that underpinned the measures taken.
We do not operate on the principle of backing up as many systems as possible in their entirety. The decisive factors are the specific evidential issue at hand, the ephemeral nature of a data source, the role of the system in the attack, and the principle of proportionality. Primary data that is particularly informative is given priority.
When it comes to recovery, we distinguish between technical availability, system functionality, business usability and full normal operation. Similarly, the existence of backups, backup integrity and actual recoverability are not considered to be one and the same.
The documentation leaves the conclusion open. If a precautionary shutdown was technically justifiable, even though no compromise could subsequently be proven, both conclusions may be correct at the same time. It is precisely such distinctions that make a subsequent assessment robust.
How we work
Restoration must not distort the historical evidence retrospectively
A system that has been properly restored following the incident does not automatically reveal what the system’s state was before or during the attack. We therefore document historical findings and subsequent remedial measures separately. This prevents the improved state following the incident from being treated retrospectively as evidence of earlier circumstances.
Legal and regulatory framework
When processing personal data, the principles set out in Article 5 of the GDPR continue to apply, in particular, as does the requirement for a sound legal basis under Article 6 of the GDPR. Article 32 of the GDPR requires appropriate technical and organisational measures to be taken, taking into account the risk, and specifies, amongst other things, confidentiality, integrity, availability, resilience, and the ability to restore availability and access promptly following an incident.
In the event of a personal data breach, Articles 33 and 34 of the GDPR may apply. Article 33 provides that, subject to certain conditions, a breach must generally be reported to the supervisory authority without undue delay and, where possible, within 72 hours of it coming to light; paragraph 5 requires documentation of the breach, its effects and the remedial measures taken. Where the risk is likely to be high, Article 34 may additionally require that data subjects be notified. Whether the relevant conditions are met is assessed under data protection law; forensic analysis provides the technical facts.
For organisations falling within the scope of the revised BSI Act, which comes into force in December 2025, additional obligations may apply to particularly important and important organisations. Depending on their classification, these include requirements relating to cyber security risk management and the handling or reporting of significant security incidents. The obligations of senior management are explicitly set out in the current BSI Act. Whether a specific company is covered and which deadlines or obligations apply in each individual case must be assessed on the basis of the current legal classification.
In the case of employee data, Section 26 of the Federal Data Protection Act (BDSG) and workplace co-determination rights may also be relevant. Even during a cyber incident, the mere technical possibility of access does not confer an unlimited scope of investigation.
LanCologne provides technical findings and documents the reasoning behind them. Decisions regarding reporting obligations, liability, measures under employment law or other legal consequences remain the prerogative of the relevant corporate bodies, data protection officers and legal advisers.
LanCologne for forensic analysis and controlled recovery
LanCologne combines technical depth with a presentation that is accessible to decision-makers. We document not only which measures were carried out, but also the technical facts on which they were based and the limitations of the findings. This ensures transparency for management, legal advisers, insurers and any potential subsequent technical review.
Frequently Asked Questions
How can a company determine, following an attack, whether compromised cloud sessions are still active?
How is such a technical investigation carried out in practice?
Does the investigation always produce a clear-cut result, either for or against a person involved?
Is there a legal basis for this?
In the event of a personal data breach, Articles 33 and 34 of the GDPR may apply. Article 33 provides that, subject to certain conditions, a breach must generally be reported to the supervisory authority without undue delay and, where possible, within 72 hours of it coming to light; paragraph 5 requires documentation of the breach, its effects and the remedial measures taken. Where the risk is likely to be high, Article 34 may additionally require that data subjects be notified. Whether the relevant conditions are met is assessed under data protection law; forensic analysis provides the technical facts.
For organisations falling within the scope of the revised BSI Act, which comes into force in December 2025, additional obligations may apply to particularly important and important organisations. Depending on their classification, these include requirements relating to cyber security risk management and the handling or reporting of significant security incidents. The obligations of senior management are explicitly set out in the current BSI Act. Whether a specific company is covered and which deadlines or obligations apply in each individual case must be assessed on the basis of the current legal classification.
In the case of employee data, Section 26 of the Federal Data Protection Act (BDSG) and workplace co-determination rights may also be relevant. Even during a cyber incident, the mere technical possibility of access does not confer an unlimited scope of investigation.
LanCologne provides technical findings and documents the reasoning behind them. Decisions regarding reporting obligations, liability, measures under employment law or other legal consequences remain the prerogative of the relevant corporate bodies, data protection officers and legal advisers.
🔗 Related topics
LanCologne – IT Forensics for Businesses
Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.
Related to this topic
- Wie kann ein Unternehmen nach einem Cyberangriff Drittanbieter- und Dienstleisterzugänge sicher bewerten?
- Wie kann ein Unternehmen nach einem Cyberangriff entscheiden, welche Logs und Beweisdaten langfristig aufbewahrt werden sollten?
- Wie kann ein Unternehmen nach einem Cyberangriff eine technische Lessons-Learned-Analyse durchführen, ohne die Beweisführung zu verfälschen?
- Wie kann ein Unternehmen nach einem Cyberangriff einen technisch belastbaren Abschlussbericht für Geschäftsführung, Versicherung und Rechtsberatung erstellen lassen?