This overview brings together all the questions and answers relating to IT forensics for businesses at LanCologne – from cyberattacks and ransomware, through internal employee investigations and data breaches, to disputes with IT service providers, whistleblowing cases and legal proceedings. Click on a category to view the relevant questions.
Cyber attacks, ransomware and compromise
- How can a company reconstruct the actual point of initial access following a cyber attack?
- How can a company have the point of entry for a cyber attack forensically determined?
- How can you check whether stolen login details have been used in a cyberattack?
- How can a company have a suspected phishing incident investigated from a technical perspective?
- How can an exploited security vulnerability be identified as a potential initial access vector?
- How can a company determine whether a compromised account has actually been misused?
- How can a company arrange for an investigation into the compromise of a privileged administrator account?
- How can lateral movement within a corporate network be reconstructed?
- How can a company determine which systems have actually been compromised?
- How can an attacker’s persistence in an IT environment be demonstrated?
- How can a company determine whether security software has been disabled by an attacker?
- How can a complete chronology of the attack be compiled following a cyber incident?
- In the event of a ransomware attack, how can a company distinguish between the initial compromise and the encryption?
- How can the actual scope of a ransomware attack be determined?
- How can a company have a check carried out to determine whether data was exfiltrated prior to a ransomware attack?
- How can a company determine which personal data has been affected by a cyber attack?
- How can a company technically document a potential data breach following a cyber attack?
- How can a business email compromise be investigated within a company?
- How can you check whether forwarding or inbox rules have been set up by an attacker?
- How can a Microsoft 365 breach be forensically contained?
- How can a company have stolen sessions or tokens investigated following a cloud attack?
- How can a company investigate whether a cyber attack was carried out via an external service provider or remote maintenance access?
- How can a company balance the need to preserve evidence with the need for rapid containment in the event of a cyber attack?
- Why should a company commission LanCologne to carry out an independent forensic reconstruction following a serious cyber attack?
- How should a company coordinate the preservation of evidence and damage control immediately after discovering a cyber attack?
- How can a company carry out a robust root-cause analysis following a cyber attack?
- How can a company decide which systems should be isolated immediately following an attack?
- How can a company determine whether attackers still have access after the incident has been contained?
- How can a company assess whether a compromised system should be cleaned up or completely rebuilt?
- How can a company have its backups checked to see whether they have been tampered with or deleted as a result of a cyberattack?
- How can a company verify the actual recoverability of its backups following a cyber attack?
- How can a company determine which backup was still reliable prior to the breach?
- How can the technically necessary recovery time following a cyber attack be reconstructed in a verifiable manner?
- How can a company demonstrate which business processes were actually affected by a cyber attack from a technical point of view?
- How can contingency operations following a cyber attack be documented from a technical perspective?
- How can a company verify whether a system that was taken offline as a precautionary measure had in fact been compromised?
- How can a company systematically renew compromised passwords, tokens and privileged access credentials following an attack?
- How can a company determine, following an attack, whether compromised cloud sessions are still active?
- How can a company securely assess access by third-party providers and service providers following a cyber attack?
- How can a company decide, following a cyber attack, which logs and evidence should be retained in the long term?
- How can a company carry out a technical ‘lessons learnt’ analysis following a cyber attack without compromising the chain of evidence?
- How can a company, following a cyber attack, have a technically sound final report drawn up for the management, the insurance company and legal advisers?
- How can a company arrange for a potential supply chain attack to be investigated forensically?
Data leaks, trade secrets and data theft
- How can a company find out exactly which files have been copied onto a USB storage device?
- How can one check whether source code was copied or exported before a developer left the company?
- How can a company arrange for a forensic investigation into the possible misappropriation of customer lists?
- How can the possible unauthorised copying of price lists, cost calculations or quotation data be technically verified?
- How can a company arrange for an investigation into the unauthorised removal of design and development documents?
- How can a company check whether data has been sent via private email addresses?
- How can a company establish whether large volumes of data were archived shortly before a contract was terminated?
- How can one check whether company data has been sent via file-sharing or file-transfer services?
- How can a company investigate remote desktop or remote maintenance access in the event of a suspected data breach?
- How can you check whether files have been shared via messaging apps or collaboration platforms?
- How can a company find out whether data has been photographed or transferred via a private smartphone?
- How can a company find out whether confidential documents have been printed on a large scale?
- How can you check whether files have been renamed, compressed or obfuscated before being copied?
- How can a company have deleted data investigated following a suspected data breach?
- How can a company have an investigation carried out to determine whether log files have been deliberately deleted or tampered with?
- When does a company file actually constitute a trade secret within the meaning of the Trade Secrets Act (GeschGehG)?
- What technical safeguards might be relevant when a trade secret is subsequently classified?
- How can a company carry out a technical investigation into unauthorised access to or copying of electronic files containing trade secrets?
- How can a company preserve evidence whilst civil claims relating to a breach of trade secrets are being investigated?
- How can a company clearly distinguish between whistleblowing and disclosure of confidential information in the event of a suspected data leak?
- Why should a company engage LanCologne at an early stage if it suspects data theft or a breach of trade secrets?
Disputes involving IT service providers, liability and the cause of damage
- How can a company have the technical cause of a complex, large-scale IT incident independently investigated?
- How can a company distinguish between a breach of technical obligations and the actual cause of the damage?
- How can senior management document the technical basis for the decisions they took at the time following a serious IT incident?
- How can a company arrange for an investigation to determine whether an external IT service provider has caused damage through technical means?
- How can a company establish the technical facts in the event of a dispute with a managed service provider?
- How can a company determine whether a software Update was in fact the source of a security incident?
- In the event of a cloud or SaaS outage, how can a company determine where the technical line of responsibility lies?
- How can a company create a shared timeline of events when several service providers are involved?
- How can a company ensure that conflicting log data from different systems is assessed objectively?
- How can a company have it assessed whether a security measure would actually have prevented a specific loss?
- How can a company carry out a technical investigation into a dispute concerning patch management or an alleged failure to install an update?
- How can an organisation retrospectively determine the effectiveness of existing security controls at the time of an incident?
- How can a company secure technical evidence in the event of a dispute over backup or recovery services?
- How can a company technically quantify an alleged data loss without resorting to speculation?
- How can a company provide clear documentation of the technical cause of a loss in the event of an insurance claim?
- How can a company allocate technical costs and measures following a cyber incident in a way that is traceable for a subsequent audit?
In-house staff surveys and equipment
- How can a company secure digital evidence before an employee’s device is used further or reassigned?
- How can a company investigate a specific suspicion against an employee without carrying out unlawful blanket surveillance?
- How can an internal IT forensic investigation be carried out in a way that remains open-ended?
- How can a company sensibly limit the scope of an internal investigation?
- How can a company arrange for a forensic examination of an employee’s work computer?
- How can a company have a work smartphone or tablet subjected to a forensic examination?
- What role can MDM play in an internal IT forensic investigation?
- How can a company make use of MDM reports without overestimating their significance?
- How can a company use endpoint and EDR telemetry in an internal investigation?
- How can a company properly examine an employee’s email data as part of an internal investigation?
- How can a company use Microsoft 365 or Google Workspace data in an internal investigation?
- How can a company technically analyse an employee’s login and account activity?
- How can a company find out whether an employee has copied files onto a USB stick?
- How can a company check whether files have been transferred to a private cloud storage service?
- How can a company investigate the use of private webmail services where there is a specific suspicion of a data breach?
- How can a company have an employee’s browser and download history analysed in relation to a specific issue requiring evidence?
- How can a company check print, export or PDF creation logs if it suspects a data leak?
- How can a company determine whether large numbers of relevant files were opened or copied before an employee left the company?
- How can a company carry out an internal investigation if the private use of company IT was permitted?
- What role does the works council play in relation to technically feasible employee monitoring and internal investigations?
- How can a company document the chain of custody in a way that is traceable during an internal investigation?
- How can a company prevent an internal investigation from altering even important digital evidence?
- How can a company check whether a departing employee has taken company data with them?
- How can you check whether an employee has uploaded company files to a private cloud account?
- How can a company find out whether an employee has accessed the company’s systems after being made redundant?
- How can one check whether a former employee has subsequently used company data at a competitor’s firm?
- How can a company correctly interpret MDM data in an investigation relating to employment law?
- How can a company verify EDR or DLP alerts as evidence, rather than accepting them at face value?
- How can a company properly prepare for an internal investigation in consultation with the works council?
- How can a company carry out internal investigations if a works agreement governs the use of IT?
- How can a company restrict the scope of an internal investigation where the use of private email or the internet is permitted?
- How can a company protect special categories of personal data during an internal investigation?
- Why should a company’s legal department involve LanCologne at an early stage in a technically oriented internal investigation?
Whistleblowing and Compliance
- How can a company carry out an IT forensic investigation into a suspected breach of compliance without prejudging the outcome?
- How can an internal investigation technically protect the confidentiality of a whistleblower?
- How can a company ensure that an IT forensic investigation does not itself become a form of reprisal against a whistleblower?
- How can a company investigate a potentially false internal report without prematurely dismissing the whistleblower’s protection?
- How can a company protect the identity of accused individuals and others mentioned during internal investigations?
- How can a company analyse email and chat data in a targeted manner, rather than across the board, as part of a compliance investigation?
- How can a company arrange for a technical investigation into conflicts of interest or unauthorised secondary employment?
- How can a company conduct an objective investigation into possible unauthorised disclosures to competitors?
Manipulation of business data and misuse of services
- How can a company carry out a forensic investigation into possible manipulation of business data by employees?
- How can a company investigate suspicions that business-related data has been deleted or destroyed?
- How can a company carry out a technical investigation into suspected manipulation of working hours or performance without introducing unauthorised continuous monitoring?
Legal proceedings, the works council and the preservation of evidence
- How can a company document the results of technical investigations in such a way that senior management and the legal department can understand them?
- Why should a company call in an independent IT forensic expert at an early stage when there is a suspected internal incident?
- How should a company preserve digital evidence following receipt of an internal report?
- How can a company technically integrate legal hold and forensic evidence preservation?
- How can a company prepare digital evidence for a potential employment tribunal case in a way that is transparent?
- How can a company technically prepare digital evidence for a potential civil lawsuit?
- How can a company compile technical evidence for a potential criminal complaint without prejudging the criminal law assessment?
- How can a company ensure that a private IT forensic report is drawn up in such a way that it can be examined by a court-appointed expert at a later date?
- How can a company deal with conflicting findings from its internal IT department, external service providers and forensic experts?
Other questions
- How should a company proceed with a forensic investigation when an internal IT incident is first suspected?
- How can the volume of data that may have been exfiltrated be objectively estimated?
- How can a company document a forensically traceable system rebuild following a cyber attack?
- How can a company have the actual duration of an IT-related business interruption determined by technical means?
- How can a company verify the integrity of restored systems following a cyber attack?
- How can a company carry out a forensic audit of the restoration of an Active Directory or central identity system?
- How can a company document the decisions taken by senior management during a cyber incident in a way that is technically verifiable?
- What role can independent IT forensics play in cyber incidents relevant to NIS 2 or the BSIG?
- Why should a company commission LanCologne to carry out forensic analysis even after the acute incident response phase has ended?
- How can a company arrange for an independent second review of an existing IT forensic report?
- How can a company commission a technical counter-assessment that is objective and does not predetermine the outcome?
- Given the variety of forensic tools available, how can a company determine which findings are technically correct?
- How can a company preserve digital evidence if several parties might later request access to it or carry out a cross-check?
- How can a company structure an IT forensic report in such a way that it is both comprehensible to lawyers and technically sound?
- How can a company prepare technical evidence for a future court case without pre-empting the court’s role?
- How can a company, even years later, have it assessed whether a past IT incident can be technically reconstructed?
- Why should a company engage LanCologne as an independent IT forensic expert when dealing with IT evidence issues of particular economic or legal significance?