IT Forensics · Courts
What impact does an incomplete chain of custody have on the technical validity of the findings?
Incomplete documentation of the chain of custody does not automatically render the evidence technically unusable. However, it may limit the extent to which it can be determined whether the current condition of the evidence can be traced back without interruption to a previous condition.
For the court, it is not a question of how many analysis programmes were used. What matters is which specific technical fact can be reliably established from the available data, how this finding is reached, and what its limitations are.
The specific question of evidence
We distinguish between documented facts and unsubstantiated handover or custody procedures, and examine which integrity characteristics can still be verified independently of these.
Why a single digital trail is rarely enough
Digital artefacts are generated in systems with their own storage, synchronisation and logging mechanisms. A single timestamp, log entry or database value is therefore not treated as conclusive evidence without context. Where the question of evidence requires it, several independent traces are correlated and technically plausible counter-hypotheses are examined.
Where the limits of what can be said lie
It is for the court to decide whether a gap in the documentation has any implications under procedural law. The IT expert describes its technical significance, not its legal implications.
How LanCologne tackles the question requiring proof
In LanCologne, the investigation begins with the legal question of evidence rather than with a specific analytical programme. The first step is to clarify which technical fact is to be established, which data sources are relevant to this, and which alternative hypotheses must be taken into account.
The evidence and source data are clearly documented. Where technically feasible, analysis is carried out on verified forensic backups or suitable working copies. Hits that are relevant to the decision are not accepted solely because they are flagged by software. We examine the origin, formation logic and context of the artefact and, where necessary, verify key findings against the underlying data or using a second, technically appropriate method.
In the expert report, the findings of fact, technical interpretation and conclusions are kept distinct from one another. The limits of what can be stated are described just as clearly: What can be proven? What is merely supported? What contrary findings exist? What remains unresolved? A lack of evidence is not reinterpreted as a seemingly certain statement.
The main body is written in such a way that a judge without specialist knowledge of IT forensics can understand the reasoning behind the findings. Technical verifiability is maintained. Data sources relevant to the audit, integrity information, artefacts and investigative steps are documented in such a way that an independent IT forensic expert can follow the key findings for a potential second opinion.
From a court order to a reliable statement
Positive results, negative results and no evidence found
An expert finding must be open-ended. If the data confirm the hypothesis under investigation, an explanation is provided as to what underpins it. If reliable evidence contradicts this hypothesis, this is also presented. If the data set is insufficient to reach a definitive conclusion, this is described as a lack of evidence or as an open technical question. It is precisely this distinction that prevents a data gap from giving rise to a seemingly definitive statement.
Understandable to the court – technically verifiable by a counter-expert
The core technical content is explained in clear, accessible language. Technical terms are used only where necessary and are subsequently defined. At the same time, the key technical fundamentals are retained: the data sources examined, relevant artefacts, integrity information, temporal references and methodological steps. An IT forensic expert unfamiliar with the procedure should be able to verify the reasoning without the main text becoming a collection of raw technical data for the court.
Methodological classification
There is no statutory list of prescribed analysis programmes for forensic IT investigations. From a technical perspective, the key factors are a controlled database, data integrity, documented investigative steps, verifiable conclusions and the possibility of independent verification.
The BSI Basic Protection Module DER.2.2, „Preparations for IT Forensics“, contains useful guiding principles on how to prepare for subsequent forensic investigations and on securing evidence in the event of IT security incidents. However, it is not a forensic standard for criminal proceedings; the actual forensic analysis is not the subject of this module. This distinction is expressly observed.
LanCologne as an independent IT expert
Where a court needs to have a specific issue relating to digital evidence clarified from a technical perspective, we examine the available data independently and without preconceptions. The aim is not to compile the most extensive collection of technical results possible, but to provide a technically sound answer: one that is comprehensible to the court, transparent in its reasoning and technically verifiable.
Legal framework
Sections 402 et seq. of the Code of Civil Procedure (ZPO) are particularly relevant to expert evidence in civil proceedings. Section 403 of the ZPO concerns the specification of the matters to be assessed. Under Section 404a of the ZPO, the court directs the expert’s work and may determine the nature and scope of their activities. Section 407a of the ZPO sets out the expert’s duties, including the obligation to assess their own field of expertise and to clarify any doubts regarding the content and scope of the mandate. Section 411 of the ZPO governs the written expert report, as well as its explanation and supplementation. The assessment of the expert report, together with the rest of the evidence, remains the responsibility of the court (Section 286 of the ZPO).
In the case of expert reports in criminal proceedings, Sections 72 et seq. of the Code of Criminal Procedure (StPO) apply to experts. Which provisions are relevant in a specific case depends on the terms of reference and the type of proceedings. An IT forensic report does not replace either the legal assessment or the court’s evaluation of the evidence.
Frequently Asked Questions
LanCologne – IT Forensics for the Courts
Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.
Related to this topic
- What happens if, during the IT forensic investigation, new facts come to light that are not covered by the court order?
- Where does the IT expert’s technical conclusion end, and where does the court’s assessment of the evidence begin?
- How are the independence and neutrality of an IT expert put into practice?
- Why does an IT report need to be understandable to non-forensic experts?