IT Forensics · Business

How can a company verify EDR or DLP alerts as evidence, rather than accepting them at face value?

A safety alert is a technical assessment of a product and does not yet constitute a definitive finding of fact.

Enquire without obligation

Why this question is important for a business

Internal investigations can have significant financial, personnel and legal consequences. This is precisely why it must first be clarified which specific technical fact is to be proven or disproved. The sheer volume of data is not an indicator of quality; what is crucial is that the investigation is appropriate, limited in scope and transparent.

Technical investigative approach

We examine the underlying raw events, rules, time references and contextual data, and look for independent corroboration or contradictory findings.

Where the limits of what can be said lie

An alert may be a false positive, incomplete or context-dependent. The reasoning must not be based solely on the product label.

Why LanCologne?

Internal investigations are particularly sensitive because they may simultaneously involve the company’s commercial interests, employees’ personal rights, data protection, employee participation in company decision-making, and potential future legal proceedings.

LanCologne therefore does not begin with the most comprehensive search of the IT systems possible. The starting point is a clearly formulated technical question of evidence. From this, the necessary data sources, time periods and investigative steps are derived. Technical feasibility and legal admissibility are deliberately kept separate.

The investigation remains open-ended. A suspicion is not confirmed simply because it sounds plausible. Incriminating, exculpatory and contradictory evidence is examined according to the same professional standards. Where several technical explanations are possible, these are identified and, as far as possible, tested against one another.

Automated reports, EDR alerts, DLP hits or output from forensic software are not accepted as evidence without verification. Key findings are, as far as possible, validated against primary data and correlated with independent artefacts.

To facilitate a subsequent technical review, we document not only the result but also the reasoning behind it. The main body of the report, written in clear language, is aimed at senior management and the legal department; a technical appendix enables a qualified external forensic expert to verify the key findings.

How we work

1Determine the grounds for the investigation and the specific issue to be established.
2Clarify in advance the responsibilities, legal basis and, where applicable, rights of participation.
3Limit the scope of users, systems, accounts, time and data to what is strictly necessary.
4Preserve volatile data or data at risk of loss at an early stage.
5Take confidentiality and the ‘need-to-know’ principle into account from both an organisational and a technical perspective.
6Separate the original data from suitable backups of working copies.
7Document the integrity, origin and time of sealing in a way that allows for traceability.
8Validate product alerts and tool outputs against primary data.
9Do not confuse account, device, session and user mapping.
10Examine incriminating, exculpatory and alternative explanations on an equal footing.
11Distinguish between technical findings and legal conclusions.
12Ensure the main report is clear and the technical appendix is reproducible.

No prejudgement – even where suspicions have already been confirmed internally

A company may already have clear grounds for suspicion for organisational or legal reasons. However, the outcome of the technical investigation remains open. We also document any findings that contradict the suspicion and explicitly state when an alleged act cannot be proven on the basis of the data obtained.

Technical findings and legal assessment remain separate

IT forensics can, for example, establish that a particular account exported a file, that a device was connected at a specific time, or that a message was technically transmitted. This does not automatically reveal which individual was responsible, whether the action was authorised, or what the consequences might be under employment, civil or criminal law.

LanCologne as an independent technical support service for the legal department and senior management

LanCologne is not commissioned to technically confirm a desired outcome. We are commissioned to provide an objective answer to a specific question of evidence based on the available digital traces. The investigation must remain verifiable even if it is subsequently scrutinised by an opposing party, a court or another qualified IT forensic expert.

Legal framework

Section 26 of the Federal Data Protection Act (BDSG) is a key legal reference point for employees’ data. Section 26(1) of the BDSG permits the processing of personal data relating to employees for the purposes of the employment relationship, subject to the conditions set out therein. With regard to the detection of criminal offences, the provision requires, in particular, that there be documented factual indications, as well as that the processing be necessary and proportionate; the employee’s legitimate interest must not take precedence. Section 26(6) of the BDSG leaves the participation rights of employee representative bodies unaffected.

In addition, the principles of the GDPR apply, in particular lawfulness, purpose limitation and data minimisation under Article 5, as well as the requirement for a valid legal basis under Article 6. In the case of special categories of personal data, Article 9 of the GDPR and, where applicable, Section 26(3) of the BDSG must also be observed.

In the case of technical equipment intended to monitor the behaviour or performance of employees, Section 87(1)(6) of the Works Constitution Act (BetrVG) provides for a right of co-determination for the works council, insofar as there are no statutory or collective agreement provisions in place. For MDM, EDR, DLP, logging and similar systems, the specific design of each must therefore be taken into account.

In the case of reports made under the Whistleblower Protection Act, Section 8 of the HinSchG is particularly relevant. The duty of confidentiality protects not only the identity of the whistleblower, but also the persons who are the subject of a report and any other persons named in the report. Section 9 of the HinSchG sets out statutory exceptions to the duty of confidentiality. Section 36 of the HinSchG prohibits reprisals and, subject to the conditions set out therein, contains a rule on the burden of proof.

In the case of trade secrets, an internal investigation must not automatically treat a report as a breach of confidentiality. Section 5 of the Trade Secrets Act (GeschGehG) sets out exceptions to the prohibitions in Section 4, including, amongst other things, under certain conditions for the detection of unlawful acts or professional or other misconduct, as well as for necessary disclosures to employee representatives.

Should civil proceedings arise at a later stage, the Code of Civil Procedure (ZPO) provides, amongst other things, for evidence by inspection; Section 371(1) ZPO expressly governs the case where an electronic document forms the subject matter of the evidence. Sections 402 et seq. ZPO apply to expert evidence. In criminal proceedings, the court determines the scope of the taking of evidence in accordance with the Code of Criminal Procedure (StPO); in particular, Section 244 of the StPO governs the principle of investigation and applications for evidence. However, these procedural provisions do not automatically transform a privately commissioned IT forensic report into a court expert report.

LanCologne provides technical expert services and does not offer legal advice. The specific admissibility of an investigative measure, the consequences under employment law, procedural strategy and criminal law assessment remain the responsibility of the relevant legal advisers, authorities and courts.

Frequently Asked Questions

How can a company verify EDR or DLP alerts as evidence, rather than accepting them at face value?
Internal investigations can have significant financial, personnel and legal consequences. This is precisely why it must first be clarified which specific technical fact is to be proven or disproved. The sheer volume of data is not an indicator of quality; what is crucial is that the investigation is appropriate, limited in scope and transparent.
How is such a technical investigation carried out in practice?
We examine the underlying raw events, rules, time references and contextual data, and look for independent corroboration or contradictory findings.
Does the investigation always produce a clear-cut result, either for or against a person involved?
An alert may be a false positive, incomplete or context-dependent. The reasoning must not be based solely on the product label.
Is there a legal basis for this?
Section 26 of the Federal Data Protection Act (BDSG) is a key legal reference point for employees’ data. Section 26(1) of the BDSG permits the processing of personal data relating to employees for the purposes of the employment relationship, subject to the conditions set out therein. With regard to the detection of criminal offences, the provision requires, in particular, that there be documented factual indications, as well as that the processing be necessary and proportionate; the employee’s legitimate interest must not take precedence. Section 26(6) of the BDSG leaves the participation rights of employee representative bodies unaffected.
In addition, the principles of the GDPR apply, in particular lawfulness, purpose limitation and data minimisation under Article 5, as well as the requirement for a valid legal basis under Article 6. In the case of special categories of personal data, Article 9 of the GDPR and, where applicable, Section 26(3) of the BDSG must also be observed.
In the case of technical equipment intended to monitor the behaviour or performance of employees, Section 87(1)(6) of the Works Constitution Act (BetrVG) provides for a right of co-determination for the works council, insofar as there are no statutory or collective agreement provisions in place. For MDM, EDR, DLP, logging and similar systems, the specific design of each must therefore be taken into account.
In the case of reports made under the Whistleblower Protection Act, Section 8 of the HinSchG is particularly relevant. The duty of confidentiality protects not only the identity of the whistleblower, but also the persons who are the subject of a report and any other persons named in the report. Section 9 of the HinSchG sets out statutory exceptions to the duty of confidentiality. Section 36 of the HinSchG prohibits reprisals and, subject to the conditions set out therein, contains a rule on the burden of proof.
In the case of trade secrets, an internal investigation must not automatically treat a report as a breach of confidentiality. Section 5 of the Trade Secrets Act (GeschGehG) sets out exceptions to the prohibitions in Section 4, including, amongst other things, under certain conditions for the detection of unlawful acts or professional or other misconduct, as well as for necessary disclosures to employee representatives.
Should civil proceedings arise at a later stage, the Code of Civil Procedure (ZPO) provides, amongst other things, for evidence by inspection; Section 371(1) ZPO expressly governs the case where an electronic document forms the subject matter of the evidence. Sections 402 et seq. ZPO apply to expert evidence. In criminal proceedings, the court determines the scope of the taking of evidence in accordance with the Code of Criminal Procedure (StPO); in particular, Section 244 of the StPO governs the principle of investigation and applications for evidence. However, these procedural provisions do not automatically transform a privately commissioned IT forensic report into a court expert report.
LanCologne provides technical expert services and does not offer legal advice. The specific admissibility of an investigative measure, the consequences under employment law, procedural strategy and criminal law assessment remain the responsibility of the relevant legal advisers, authorities and courts.

🔗 Related topics

LanCologne – IT Forensics for Businesses

Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.

Get in touch now