IT Forensics · Business
How can a company arrange for an investigation to determine whether an external IT service provider has caused damage through technical means?
Following outages or security incidents, there may be grounds for suspecting that changes, maintenance work or misconfigurations by a service provider were the cause.
Why this question is important for a business
In cases involving significant damage and multiple parties, inaccurate technical statements can have considerable financial and legal consequences. It is therefore essential to make a clear distinction between what has actually been proven, what was merely technically possible, and which issues fall outside the scope of IT forensic evidence.
Technical investigative approach
We correlate change, ticket, remote, system, configuration and time data, and also investigate alternative technical causes.
Where the limits of what can be said lie
Documented access by a service provider does not prove either a fault or that it was the cause of the damage.
Why LanCologne?
In the case of complex corporate incidents, it is not enough simply to collect as much technical data as possible or to rely on the report from a single product. What matters is which specific question of evidence needs to be answered and which primary data actually supports that conclusion.
LanCologne consistently distinguishes between technical feasibility, a proven event, cause, consequence and legal liability. This distinction helps to prevent hasty conclusions, particularly in the case of major claims, disputes with service providers and subsequent court or insurance proceedings.
We also examine alternative hypotheses. Where several technical causes are possible, these are not overlooked but are tested against one another on the basis of the available data. An incriminating finding is examined using the same criteria as an exonerating one.
Automated forensic reports, manufacturer specifications and security alerts are important tools, but they do not automatically constitute a source of evidence. Key findings are validated against primary artefacts and independent data sources wherever possible.
The results are documented in such a way that decision-makers can understand the main findings and a qualified IT forensic expert can follow and critically review the technical reasoning set out in the appendix.
How we work
Correlation does not imply causation
The mere fact that two events occur at the same time is not sufficient to establish a reliable causal link. We examine the technically possible mechanism of action, the chronological sequence, independent evidence and alternative causes. Where the data allow only a probability or a narrowing down of possibilities, no seemingly certain statement of causality is made on that basis.
Legal and procedural framework
With regard to matters of management, Section 43 of the German Limited Liability Companies Act (GmbHG) is relevant for a limited liability company (GmbH), amongst other provisions. According to this provision, managing directors must exercise the diligence of a prudent businessman in the company’s affairs; breaches of these obligations may give rise to claims for compensation by the company. IT forensics can document which technical information and system statuses were verifiably present at a specific point in time. Whether a management team has breached its legal duties, however, is a matter for legal assessment.
For particularly important and important organisations as defined by the current BSI Act, additional requirements may apply in relation to cyber security risk management and senior management. In the case of a specific company, it must first be assessed whether, and to what extent, it is covered by the current BSIG. Technical forensics can document the sequence of events, systems involved, impacts and measures taken; however, it does not replace a regulatory legal review.
Where personal data is processed or is affected by a security incident, particular attention must be paid to the GDPR principles, as well as to security requirements and, where applicable, reporting or notification obligations. In the case of external data processors, the specific roles and contractual arrangements are also relevant. A technical cause does not automatically imply an allocation of responsibility under data protection law.
The transparent preservation of electronic evidence may be important for subsequent civil proceedings. Section 371 of the Code of Civil Procedure (ZPO) covers evidence based on visual inspection and expressly refers to electronic documents; Sections 402 et seq. of the ZPO apply to expert evidence. However, a privately commissioned forensic report remains a party’s expert opinion or a qualified submission by a party and does not become a court expert’s report solely on the basis of its technical quality.
LanCologne does not assess contractual liability, directors’ and officers’ liability, the duty to provide cover or criminal liability. We provide the technical facts on which lawyers, insurers, regulatory authorities and courts can base their own assessments.
LanCologne for complex technical questions requiring proof
The greater the economic or legal significance of an incident, the more important it is to conduct an investigation that is not tailored to a desired outcome. LanCologne documents the technical facts, including contradictory findings and limitations of evidence, in such a way that they can be understood by senior management and legal advisers and subjected to a professional review by a qualified third party.
Frequently Asked Questions
How can a company arrange for an investigation to determine whether an external IT service provider has caused damage through technical means?
How is such a technical investigation carried out in practice?
Does the investigation always produce a clear-cut result, either for or against a person involved?
Is there a legal basis for this?
For particularly important and important organisations as defined by the current BSI Act, additional requirements may apply in relation to cyber security risk management and senior management. In the case of a specific company, it must first be assessed whether, and to what extent, it is covered by the current BSIG. Technical forensics can document the sequence of events, systems involved, impacts and measures taken; however, it does not replace a regulatory legal review.
Where personal data is processed or is affected by a security incident, particular attention must be paid to the GDPR principles, as well as to security requirements and, where applicable, reporting or notification obligations. In the case of external data processors, the specific roles and contractual arrangements are also relevant. A technical cause does not automatically imply an allocation of responsibility under data protection law.
The transparent preservation of electronic evidence may be important for subsequent civil proceedings. Section 371 of the Code of Civil Procedure (ZPO) covers evidence based on visual inspection and expressly refers to electronic documents; Sections 402 et seq. of the ZPO apply to expert evidence. However, a privately commissioned forensic report remains a party’s expert opinion or a qualified submission by a party and does not become a court expert’s report solely on the basis of its technical quality.
LanCologne does not assess contractual liability, directors’ and officers’ liability, the duty to provide cover or criminal liability. We provide the technical facts on which lawyers, insurers, regulatory authorities and courts can base their own assessments.
🔗 Related topics
LanCologne – IT Forensics for Businesses
Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.
Related to this topic
- Wie kann ein Unternehmen bei einem Streit mit einem Managed Service Provider die technischen Tatsachen sichern?
- Wie kann ein Unternehmen feststellen, ob ein Software-Update tatsächlich Ausgangspunkt eines Sicherheitsvorfalls war?
- Wie kann ein Unternehmen bei einem Cloud- oder SaaS-Ausfall die technische Verantwortungsgrenze nachvollziehen?
- Wie kann ein Unternehmen bei mehreren beteiligten Dienstleistern eine gemeinsame Ereigniszeitlinie erstellen?