IT Forensics · Business

How can a company have the technical cause of a complex, large-scale IT incident independently investigated?

In the event of major IT incidents, conflicting explanations can quickly emerge from the in-house IT department, manufacturers, service providers and insurers.

Enquire without obligation

Why this question is important for a business

In cases involving significant damage and multiple parties, inaccurate technical statements can have considerable financial and legal consequences. It is therefore essential to make a clear distinction between what has actually been proven, what was merely technically possible, and which issues fall outside the scope of IT forensic evidence.

Technical investigative approach

We break down the damage into specific technical questions of evidence and, using the available primary data, reconstruct the cause, the sequence of events, the systems affected and the verifiable consequences.

Where the limits of what can be said lie

The fact that an event and damage occur in close temporal proximity does not in itself prove technical causality.

Why LanCologne?

In the case of complex corporate incidents, it is not enough simply to collect as much technical data as possible or to rely on the report from a single product. What matters is which specific question of evidence needs to be answered and which primary data actually supports that conclusion.

LanCologne consistently distinguishes between technical feasibility, a proven event, cause, consequence and legal liability. This distinction helps to prevent hasty conclusions, particularly in the case of major claims, disputes with service providers and subsequent court or insurance proceedings.

We also examine alternative hypotheses. Where several technical causes are possible, these are not overlooked but are tested against one another on the basis of the available data. An incriminating finding is examined using the same criteria as an exonerating one.

Automated forensic reports, manufacturer specifications and security alerts are important tools, but they do not automatically constitute a source of evidence. Key findings are validated against primary artefacts and independent data sources wherever possible.

The results are documented in such a way that decision-makers can understand the main findings and a qualified IT forensic expert can follow and critically review the technical reasoning set out in the appendix.

How we work

1Define the specific technical question to be proven.
2Identify the parties, systems, data sources and relevant time periods.
3Prioritise the preservation of volatile data or data at risk of loss.
4Document the origin, audit trail and integrity.
5Normalise timestamps relative to their sources and take their semantics into account.
6Do not confuse correlation with causation.
7Distinguish between what is technically possible and what has actually been proven to have taken place.
8Prioritise primary data over mere interpretations of tools.
9Examine counter-hypotheses and standard alternative explanations.
10Identify data gaps and their impact on the conclusion.
11Distinguish technical facts from issues of liability and legal matters.
12Produce a clear main report and a reproducible technical appendix.

Correlation does not imply causation

The mere fact that two events occur at the same time is not sufficient to establish a reliable causal link. We examine the technically possible mechanism of action, the chronological sequence, independent evidence and alternative causes. Where the data allow only a probability or a narrowing down of possibilities, no seemingly certain statement of causality is made on that basis.

Legal and procedural framework

With regard to matters of management, Section 43 of the German Limited Liability Companies Act (GmbHG) is relevant for a limited liability company (GmbH), amongst other provisions. According to this provision, managing directors must exercise the diligence of a prudent businessman in the company’s affairs; breaches of these obligations may give rise to claims for compensation by the company. IT forensics can document which technical information and system statuses were verifiably present at a specific point in time. Whether a management team has breached its legal duties, however, is a matter for legal assessment.

For particularly important and important organisations as defined by the current BSI Act, additional requirements may apply in relation to cyber security risk management and senior management. In the case of a specific company, it must first be assessed whether, and to what extent, it is covered by the current BSIG. Technical forensics can document the sequence of events, systems involved, impacts and measures taken; however, it does not replace a regulatory legal review.

Where personal data is processed or is affected by a security incident, particular attention must be paid to the GDPR principles, as well as to security requirements and, where applicable, reporting or notification obligations. In the case of external data processors, the specific roles and contractual arrangements are also relevant. A technical cause does not automatically imply an allocation of responsibility under data protection law.

The transparent preservation of electronic evidence may be important for subsequent civil proceedings. Section 371 of the Code of Civil Procedure (ZPO) covers evidence based on visual inspection and expressly refers to electronic documents; Sections 402 et seq. of the ZPO apply to expert evidence. However, a privately commissioned forensic report remains a party’s expert opinion or a qualified submission by a party and does not become a court expert’s report solely on the basis of its technical quality.

LanCologne does not assess contractual liability, directors’ and officers’ liability, the duty to provide cover or criminal liability. We provide the technical facts on which lawyers, insurers, regulatory authorities and courts can base their own assessments.

LanCologne for complex technical questions requiring proof

The greater the economic or legal significance of an incident, the more important it is to conduct an investigation that is not tailored to a desired outcome. LanCologne documents the technical facts, including contradictory findings and limitations of evidence, in such a way that they can be understood by senior management and legal advisers and subjected to a professional review by a qualified third party.

Frequently Asked Questions

How can a company have the technical cause of a complex, large-scale IT incident independently investigated?+
In cases involving significant damage and multiple parties, inaccurate technical statements can have considerable financial and legal consequences. It is therefore essential to make a clear distinction between what has actually been proven, what was merely technically possible, and which issues fall outside the scope of IT forensic evidence.
How is such a technical investigation carried out in practice?+
We break down the damage into specific technical questions of evidence and, using the available primary data, reconstruct the cause, the sequence of events, the systems affected and the verifiable consequences.
Does the investigation always produce a clear-cut result, either for or against a person involved?+
The fact that an event and damage occur in close temporal proximity does not in itself prove technical causality.
Is there a legal basis for this?+
With regard to matters of management, Section 43 of the German Limited Liability Companies Act (GmbHG) is relevant to a limited liability company (GmbH), amongst other provisions. According to this provision, managing directors must exercise the due care of a prudent businessman in the company’s affairs; breaches of these obligations may give rise to claims for compensation by the company. IT forensics can document which technical information and system statuses were verifiable at a specific point in time. Whether a management team has breached its legal obligations, however, is a matter for legal assessment. For particularly important and important organisations under the current BSI Act, additional requirements regarding cyber security risk management and management may apply. In the case of a specific company, it must first be assessed whether, and to what extent, it is covered by the current BSI Act. Technical forensics can document the sequence of events, systems, impacts and measures taken in this regard, but it does not replace a regulatory legal assessment. If personal data is processed or is affected by a security incident, particular attention must be paid to the GDPR principles as well as requirements regarding security and, where applicable, reporting or notification. In the case of external data processors, the specific roles and contractual arrangements are also relevant. A technical cause does not automatically imply an allocation of responsibility under data protection law. The traceable preservation of electronic evidence may be important for subsequent civil proceedings. Section 371 of the German Code of Civil Procedure (ZPO) covers evidence by inspection and expressly includes electronic documents; Sections 402 et seq. ZPO apply to expert evidence. However, a privately commissioned forensic report remains a party’s expert opinion or a qualified submission by a party and does not become a court-appointed expert report solely on the basis of its technical quality. LanCologne does not assess contractual liability, directors’ and officers’ liability, the duty to provide cover or criminal liability. We provide the technical factual basis on which lawyers, insurers, authorities and courts can make their own respective assessments.

LanCologne – IT Forensics for Businesses

Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.

Get in touch now