IT Forensics · Business

How can a company, even years later, have it assessed whether a past IT incident can be technically reconstructed?

Past incidents often only become relevant again as a result of legal proceedings, insurance claims or new information.

Enquire without obligation

Why this question is important for a business

In cases involving significant damage and multiple parties, inaccurate technical statements can have considerable financial and legal consequences. It is therefore essential to make a clear distinction between what has actually been proven, what was merely technically possible, and which issues fall outside the scope of IT forensic evidence.

Technical investigative approach

We begin by carrying out an analysis of the evidence and retention policies: Which images, backups, logs, cloud exports, tickets and original files still exist, and what questions can they help answer?

Where the limits of what can be said lie

A lack of historical data can impose a permanent limitation on a reconstruction. This limitation is made clear before any extensive analysis is carried out.

Why LanCologne?

In the case of complex corporate incidents, it is not enough simply to collect as much technical data as possible or to rely on the report from a single product. What matters is which specific question of evidence needs to be answered and which primary data actually supports that conclusion.

LanCologne consistently distinguishes between technical feasibility, a proven event, cause, consequence and legal liability. This distinction helps to prevent hasty conclusions, particularly in the case of major claims, disputes with service providers and subsequent court or insurance proceedings.

We also examine alternative hypotheses. Where several technical causes are possible, these are not overlooked but are tested against one another on the basis of the available data. An incriminating finding is examined using the same criteria as an exonerating one.

Automated forensic reports, manufacturer specifications and security alerts are important tools, but they do not automatically constitute a source of evidence. Key findings are validated against primary artefacts and independent data sources wherever possible.

The results are documented in such a way that decision-makers can understand the main findings and a qualified IT forensic expert can follow and critically review the technical reasoning set out in the appendix.

How we work

1Define the specific technical question to be proven.
2Identify the parties, systems, data sources and relevant time periods.
3Prioritise the preservation of volatile data or data at risk of loss.
4Document the origin, audit trail and integrity.
5Normalise timestamps relative to their sources and take their semantics into account.
6Do not confuse correlation with causation.
7Distinguish between what is technically possible and what has actually been proven to have taken place.
8Prioritise primary data over mere interpretations of tools.
9Examine counter-hypotheses and standard alternative explanations.
10Identify data gaps and their impact on the conclusion.
11Distinguish technical facts from issues of liability and legal matters.
12Produce a clear main report and a reproducible technical appendix.

Correlation does not imply causation

The mere fact that two events occur at the same time is not sufficient to establish a reliable causal link. We examine the technically possible mechanism of action, the chronological sequence, independent evidence and alternative causes. Where the data allow only a probability or a narrowing down of possibilities, no seemingly certain statement of causality is made on that basis.

Legal and procedural framework

With regard to matters of management, Section 43 of the German Limited Liability Companies Act (GmbHG) is relevant for a limited liability company (GmbH), amongst other provisions. According to this provision, managing directors must exercise the diligence of a prudent businessman in the company’s affairs; breaches of these obligations may give rise to claims for compensation by the company. IT forensics can document which technical information and system statuses were verifiably present at a specific point in time. Whether a management team has breached its legal duties, however, is a matter for legal assessment.

For particularly important and important organisations as defined by the current BSI Act, additional requirements may apply in relation to cyber security risk management and senior management. In the case of a specific company, it must first be assessed whether, and to what extent, it is covered by the current BSIG. Technical forensics can document the sequence of events, systems involved, impacts and measures taken; however, it does not replace a regulatory legal review.

Where personal data is processed or is affected by a security incident, particular attention must be paid to the GDPR principles, as well as to security requirements and, where applicable, reporting or notification obligations. In the case of external data processors, the specific roles and contractual arrangements are also relevant. A technical cause does not automatically imply an allocation of responsibility under data protection law.

The transparent preservation of electronic evidence may be important for subsequent civil proceedings. Section 371 of the Code of Civil Procedure (ZPO) covers evidence based on visual inspection and expressly refers to electronic documents; Sections 402 et seq. of the ZPO apply to expert evidence. However, a privately commissioned forensic report remains a party’s expert opinion or a qualified submission by a party and does not become a court expert’s report solely on the basis of its technical quality.

LanCologne does not assess contractual liability, directors’ and officers’ liability, the duty to provide cover or criminal liability. We provide the technical facts on which lawyers, insurers, regulatory authorities and courts can base their own assessments.

LanCologne for complex technical questions requiring proof

The greater the economic or legal significance of an incident, the more important it is to conduct an investigation that is not tailored to a desired outcome. LanCologne documents the technical facts, including contradictory findings and limitations of evidence, in such a way that they can be understood by senior management and legal advisers and subjected to a professional review by a qualified third party.

Frequently Asked Questions

How can a company, even years later, have it assessed whether a past IT incident can be technically reconstructed?
In cases involving significant damage and multiple parties, inaccurate technical statements can have considerable financial and legal consequences. It is therefore essential to make a clear distinction between what has actually been proven, what was merely technically possible, and which issues fall outside the scope of IT forensic evidence.
How is such a technical investigation carried out in practice?
We begin by carrying out an analysis of the evidence and retention policies: Which images, backups, logs, cloud exports, tickets and original files still exist, and what questions can they help answer?
Does the investigation always produce a clear-cut result, either for or against a person involved?
A lack of historical data can impose a permanent limitation on a reconstruction. This limitation is made clear before any extensive analysis is carried out.
Is there a legal basis for this?
With regard to matters of management, Section 43 of the German Limited Liability Companies Act (GmbHG) is relevant for a limited liability company (GmbH), amongst other provisions. According to this provision, managing directors must exercise the diligence of a prudent businessman in the company’s affairs; breaches of these obligations may give rise to claims for compensation by the company. IT forensics can document which technical information and system statuses were verifiably present at a specific point in time. Whether a management team has breached its legal duties, however, is a matter for legal assessment.
For particularly important and important organisations as defined by the current BSI Act, additional requirements may apply in relation to cyber security risk management and senior management. In the case of a specific company, it must first be assessed whether, and to what extent, it is covered by the current BSIG. Technical forensics can document the sequence of events, systems involved, impacts and measures taken; however, it does not replace a regulatory legal review.
Where personal data is processed or is affected by a security incident, particular attention must be paid to the GDPR principles, as well as to security requirements and, where applicable, reporting or notification obligations. In the case of external data processors, the specific roles and contractual arrangements are also relevant. A technical cause does not automatically imply an allocation of responsibility under data protection law.
The transparent preservation of electronic evidence may be important for subsequent civil proceedings. Section 371 of the Code of Civil Procedure (ZPO) covers evidence based on visual inspection and expressly refers to electronic documents; Sections 402 et seq. of the ZPO apply to expert evidence. However, a privately commissioned forensic report remains a party’s expert opinion or a qualified submission by a party and does not become a court expert’s report solely on the basis of its technical quality.
LanCologne does not assess contractual liability, directors’ and officers’ liability, the duty to provide cover or criminal liability. We provide the technical facts on which lawyers, insurers, regulatory authorities and courts can base their own assessments.

🔗 Related topics

LanCologne – IT Forensics for Businesses

Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.

Get in touch now