IT Forensics · Business

Wie kann ein Business-E-Mail-Compromise in einem Unternehmen rekonstruiert werden?

BEC kann kompromittierte Postfächer, Sessiondiebstahl, Weiterleitungsregeln oder manipulierte Zahlungsprozesse umfassen.

Enquire without obligation

Why this question is important for a business

Following a cyberattack, technical, economic, data protection and regulatory decisions may all depend on the same set of facts. A robust reconstruction must therefore clearly distinguish between proven activity, technical feasibility and mere conjecture.

Technical investigative approach

Wir untersuchen Login-, Session-, Mailbox-, Regel-, Audit- und Kommunikationsereignisse und erstellen eine chronologische Rekonstruktion.

Where the limits of what can be said lie

Der sichtbare Absender einer E-Mail beweist weder Kontokompromittierung noch Urheberschaft.

Why LanCologne?

Following a cyber attack, a company’s immediate priority is to ensure security and business continuity. However, for subsequent decisions, it is not enough simply to know that ‚an attack has taken place‘. Senior management, data protection officers, legal advisers, insurers and, where applicable, the authorities require reliable answers to specific factual questions.

LanCologne therefore distinguishes between discovery, initial access, compromise, persistence, lateral movement, data access, potential exfiltration and actual damage. These phases may be separated by significant time intervals and must not be equated with one another.

Where possible, key findings are cross-referenced against several independent data sources. Endpoint, network, identity, cloud and system data each have their own limitations in terms of what they can reveal. For us, an automated alert or a product report is not the source of evidence in itself, but rather a starting point for verifying the underlying primary data.

Counter-hypotheses are also part of the investigation. An unusual login, for example, may be explained by legitimate administration, VPN infrastructure, automated services or compromised login credentials. Only by correlating further evidence can a reliable conclusion be reached.

If crucial data is missing, this gap is not filled with speculation. Particularly in the case of cyber incidents, the statement ‚cannot be determined with certainty on the basis of the data received‘ is of greater technical value than an apparently clear account of the attack that cannot be substantiated in a way that can be reproduced.

How we work

1Coordinate business-critical containment measures and the preservation of forensic evidence.
2Define specific technical questions of evidence.
3Prioritise data sources and retention risks.
4Document the origin, integrity and time of security.
5Normalise timestamps and time zones on a per-source basis.
6Reconstruct the initial attack and subsequent attacker activity separately.
7Distinguish between account, device, session and user assignments.
8Do not equate compromise, access, exfiltration and damage.
9Correlate cloud, endpoint, network and identity data.
10Also consider other plausible technical explanations.
11Identify data gaps and their impact on each key message.
12Present the results in a clear and understandable manner and document them in the technical appendix in such a way that they can be reproduced.

Incident response and forensics have different but complementary objectives

The primary aim of containing an ongoing attack is to protect the organisation. Forensic reconstruction then clarifies – either subsequently or in parallel – what actually happened. Necessary security measures are therefore not withheld simply to preserve an ideal state of evidence; unavoidable changes are documented as far as possible.

Why LanCologne following a cyberattack?

LanCologne does not base its investigation on a hypothetical sequence of events. What matters is what technical conclusions can actually be drawn from the primary data obtained. Findings that are incriminating, exonerating or inconclusive are documented in a transparent manner so that the management and legal advisers can make decisions based on verifiable facts.

Legal framework

Article 32 of the GDPR requires data controllers and data processors to ensure a level of protection appropriate to the risk. Among other things, it refers to confidentiality, integrity, availability and resilience, as well as the ability to restore availability and access promptly following a technical or physical incident.

If a cyber incident has resulted in a personal data breach, Article 33 of the GDPR may apply. According to this provision, a breach subject to notification must, in principle, be reported to the competent supervisory authority without undue delay and, where possible, within 72 hours of it coming to light, provided that it is not likely to result in a risk to the rights and freedoms of natural persons. Article 33(5) also requires the breach, its effects and the remedial measures taken to be documented. Where a high risk is likely, Article 34 of the GDPR may additionally require the data subjects to be notified. Whether these conditions are met is a matter for assessment under data protection law; IT forensics provides the technical facts for this purpose.

Since 6 December 2025, the revised BSI Act, which implements the NIS 2 requirements, has applied to certain private companies. Whether a company is classified as a particularly important or important organisation must be assessed on a case-by-case basis in accordance with the current BSI Act, taking into account the sectors, types of organisation and size criteria. For covered organisations, the BSIG sets out, amongst other things, obligations regarding cybersecurity risk management and security incidents; Section 38 of the BSIG assigns obligations to the management of particularly important and important organisations to implement and monitor risk management measures.

Statutory reporting and documentation obligations may be time-sensitive. However, LanCologne does not make any definitive legal determinations regarding reporting obligations, responsibility or liability. We provide the technically verifiable factual basis on which management, data protection officers and legal advisers can make decisions.

Frequently Asked Questions

Wie kann ein Business-E-Mail-Compromise in einem Unternehmen rekonstruiert werden?
Following a cyberattack, technical, economic, data protection and regulatory decisions may all depend on the same set of facts. A robust reconstruction must therefore clearly distinguish between proven activity, technical feasibility and mere conjecture.
How is such a technical investigation carried out in practice?
Wir untersuchen Login-, Session-, Mailbox-, Regel-, Audit- und Kommunikationsereignisse und erstellen eine chronologische Rekonstruktion.
Does the investigation always produce a clear-cut result, either for or against a person involved?
Der sichtbare Absender einer E-Mail beweist weder Kontokompromittierung noch Urheberschaft.
Is there a legal basis for this?
Article 32 of the GDPR requires data controllers and data processors to ensure a level of protection appropriate to the risk. Among other things, it refers to confidentiality, integrity, availability and resilience, as well as the ability to restore availability and access promptly following a technical or physical incident.
If a cyber incident has resulted in a personal data breach, Article 33 of the GDPR may apply. According to this provision, a breach subject to notification must, in principle, be reported to the competent supervisory authority without undue delay and, where possible, within 72 hours of it coming to light, provided that it is not likely to result in a risk to the rights and freedoms of natural persons. Article 33(5) also requires the breach, its effects and the remedial measures taken to be documented. Where a high risk is likely, Article 34 of the GDPR may additionally require the data subjects to be notified. Whether these conditions are met is a matter for assessment under data protection law; IT forensics provides the technical facts for this purpose.
Since 6 December 2025, the revised BSI Act, which implements the NIS 2 requirements, has applied to certain private companies. Whether a company is classified as a particularly important or important organisation must be assessed on a case-by-case basis in accordance with the current BSI Act, taking into account the sectors, types of organisation and size criteria. For covered organisations, the BSIG sets out, amongst other things, obligations regarding cybersecurity risk management and security incidents; Section 38 of the BSIG assigns obligations to the management of particularly important and important organisations to implement and monitor risk management measures.
Statutory reporting and documentation obligations may be time-sensitive. However, LanCologne does not make any definitive legal determinations regarding reporting obligations, responsibility or liability. We provide the technically verifiable factual basis on which management, data protection officers and legal advisers can make decisions.

🔗 Related topics

LanCologne – IT Forensics for Businesses

Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.

Get in touch now