IT Forensics · Business
How can a company, even years later, have it assessed whether a past IT incident can be technically reconstructed?
Past incidents often only become relevant again as a result of legal proceedings, insurance claims or new information.
Why this question is important for a business
In cases involving significant damage and multiple parties, inaccurate technical statements can have considerable financial and legal consequences. It is therefore essential to make a clear distinction between what has actually been proven, what was merely technically possible, and which issues fall outside the scope of IT forensic evidence.
Technical investigative approach
We begin by carrying out an analysis of the evidence and retention policies: Which images, backups, logs, cloud exports, tickets and original files still exist, and what questions can they help answer?
Where the limits of what can be said lie
A lack of historical data can impose a permanent limitation on a reconstruction. This limitation is made clear before any extensive analysis is carried out.
Why LanCologne?
In the case of complex corporate incidents, it is not enough simply to collect as much technical data as possible or to rely on the report from a single product. What matters is which specific question of evidence needs to be answered and which primary data actually supports that conclusion.
LanCologne consistently distinguishes between technical feasibility, a proven event, cause, consequence and legal liability. This distinction helps to prevent hasty conclusions, particularly in the case of major claims, disputes with service providers and subsequent court or insurance proceedings.
We also examine alternative hypotheses. Where several technical causes are possible, these are not overlooked but are tested against one another on the basis of the available data. An incriminating finding is examined using the same criteria as an exonerating one.
Automated forensic reports, manufacturer specifications and security alerts are important tools, but they do not automatically constitute a source of evidence. Key findings are validated against primary artefacts and independent data sources wherever possible.
The results are documented in such a way that decision-makers can understand the main findings and a qualified IT forensic expert can follow and critically review the technical reasoning set out in the appendix.
How we work
Correlation does not imply causation
The mere fact that two events occur at the same time is not sufficient to establish a reliable causal link. We examine the technically possible mechanism of action, the chronological sequence, independent evidence and alternative causes. Where the data allow only a probability or a narrowing down of possibilities, no seemingly certain statement of causality is made on that basis.
Legal and procedural framework
With regard to matters of management, Section 43 of the German Limited Liability Companies Act (GmbHG) is relevant for a limited liability company (GmbH), amongst other provisions. According to this provision, managing directors must exercise the diligence of a prudent businessman in the company’s affairs; breaches of these obligations may give rise to claims for compensation by the company. IT forensics can document which technical information and system statuses were verifiably present at a specific point in time. Whether a management team has breached its legal duties, however, is a matter for legal assessment.
For particularly important and important organisations as defined by the current BSI Act, additional requirements may apply in relation to cyber security risk management and senior management. In the case of a specific company, it must first be assessed whether, and to what extent, it is covered by the current BSIG. Technical forensics can document the sequence of events, systems involved, impacts and measures taken; however, it does not replace a regulatory legal review.
Where personal data is processed or is affected by a security incident, particular attention must be paid to the GDPR principles, as well as to security requirements and, where applicable, reporting or notification obligations. In the case of external data processors, the specific roles and contractual arrangements are also relevant. A technical cause does not automatically imply an allocation of responsibility under data protection law.
The transparent preservation of electronic evidence may be important for subsequent civil proceedings. Section 371 of the Code of Civil Procedure (ZPO) covers evidence based on visual inspection and expressly refers to electronic documents; Sections 402 et seq. of the ZPO apply to expert evidence. However, a privately commissioned forensic report remains a party’s expert opinion or a qualified submission by a party and does not become a court expert’s report solely on the basis of its technical quality.
LanCologne does not assess contractual liability, directors’ and officers’ liability, the duty to provide cover or criminal liability. We provide the technical facts on which lawyers, insurers, regulatory authorities and courts can base their own assessments.
LanCologne for complex technical questions requiring proof
The greater the economic or legal significance of an incident, the more important it is to conduct an investigation that is not tailored to a desired outcome. LanCologne documents the technical facts, including contradictory findings and limitations of evidence, in such a way that they can be understood by senior management and legal advisers and subjected to a professional review by a qualified third party.
Frequently Asked Questions
How can a company, even years later, have it assessed whether a past IT incident can be technically reconstructed?
How is such a technical investigation carried out in practice?
Does the investigation always produce a clear-cut result, either for or against a person involved?
Is there a legal basis for this?
For particularly important and important organisations as defined by the current BSI Act, additional requirements may apply in relation to cyber security risk management and senior management. In the case of a specific company, it must first be assessed whether, and to what extent, it is covered by the current BSIG. Technical forensics can document the sequence of events, systems involved, impacts and measures taken; however, it does not replace a regulatory legal review.
Where personal data is processed or is affected by a security incident, particular attention must be paid to the GDPR principles, as well as to security requirements and, where applicable, reporting or notification obligations. In the case of external data processors, the specific roles and contractual arrangements are also relevant. A technical cause does not automatically imply an allocation of responsibility under data protection law.
The transparent preservation of electronic evidence may be important for subsequent civil proceedings. Section 371 of the Code of Civil Procedure (ZPO) covers evidence based on visual inspection and expressly refers to electronic documents; Sections 402 et seq. of the ZPO apply to expert evidence. However, a privately commissioned forensic report remains a party’s expert opinion or a qualified submission by a party and does not become a court expert’s report solely on the basis of its technical quality.
LanCologne does not assess contractual liability, directors’ and officers’ liability, the duty to provide cover or criminal liability. We provide the technical facts on which lawyers, insurers, regulatory authorities and courts can base their own assessments.
🔗 Related topics
LanCologne – IT Forensics for Businesses
Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.
Related to this topic
- Warum sollte ein Unternehmen bei wirtschaftlich oder rechtlich besonders bedeutsamen IT-Beweisfragen LanCologne als unabhängigen IT-Forensiker beauftragen?
- How should a company proceed with a forensic investigation when an internal IT incident is first suspected?
- Wie kann die Menge möglicherweise exfiltrierter Daten sachlich eingegrenzt werden?
- Wie kann ein Unternehmen einen forensisch nachvollziehbaren Rebuild nach einem Cyberangriff dokumentieren?