IT Forensics · Insurance
How can an insurance company arrange for an investigation to determine whether a damaged data storage device was already showing signs of failure before the damage occurred?
In the case of hard disk drives and SSDs, it may be relevant whether any faults had already been recorded prior to the reported incident.
Why this question is important for an insurance company
In the case of technically complex claims, a decision must be based on verifiable facts. Digital evidence can confirm the reported sequence of events, narrow down the timeframe, refute specific points, or show that a reliable reconstruction is no longer possible. Each of these outcomes is valuable for claims handling, provided that the reasoning behind them remains transparent.
Technical investigative approach
We examine existing SMART data, controller logs, operating system events, file system errors and, where applicable, previous diagnostic reports.
Where the limits of what can be said lie
SMART values are diagnostic indicators and do not constitute a complete event log. Their absence should not be taken as definitive proof that the system is fault-free.
Why LanCologne?
In the event of a technically complex claim, an insurance company does not require as much data as possible, but rather a reliable answer to a specific factual question. This is precisely what LanCologne uses to determine the scope of its investigation.
We therefore do not start from the assumption that a claim must be either correct or incorrect. First of all, we clarify which technical facts are actually relevant to the claims assessment: When did the incident occur? Which systems were affected? What data was actually lost? What were the conditions before and after the incident? Are there any independent records that confirm or contradict the sequence of events described?
Key findings are verified at the level of primary data where necessary. Automated reports or software outputs serve as aids, but are not equated with the source of evidence without verification. Findings that are incriminating or exonerating, or that confirm the claim, are treated according to the same standard.
Equally important is the scope of the assignment. A claim investigation does not justify the unwarranted comprehensive analysis of private devices or communications content. We limit the investigation to the data that is lawfully available and necessary for the specific issue at hand.
The findings are documented in such a way that a claims adjuster or lawyer can understand the key message without specialist IT knowledge, whilst another qualified IT forensic expert can follow the technical reasoning based on the documented sources.
How we work
Confirmatory, contradictory and inconclusive findings
An independent loss assessment must not be geared towards a desired settlement outcome. If the technical data corroborate the policyholder’s statements, this is documented just as clearly as any verifiable contradiction. If the available data are insufficient to reach a sound decision, no assumption is made in place of a finding.
Comprehensible to claims adjusters and legal professionals – technically reproducible
The main finding is explained in clear language. In the technical section, we document the relevant data sources, identifiers, backup times, integrity values, time references, artefact locations and validation steps. This enables another qualified IT forensic expert to verify the key findings from a technical perspective.
LanCologne as an independent technical support service for claims assessment
Where an insurance claim depends on digital evidence, LanCologne provides support in the form of an objective, unbiased and transparent IT forensic investigation. The decisive factor is not whether a finding is favourable to the insurer or the policyholder, but solely what the lawfully available data actually reveals.
Legal framework
Under Section 30 of the Insurance Contract Act (VVG), an insured event must, as a general rule, be reported without delay once it has come to the policyholder’s attention. Section 31 of the VVG is of particular significance for the technical assessment of claims: Once an insured event has occurred, the insurer may require the policyholder to provide the information necessary to determine the insured event or the extent of the insurer’s obligation to pay benefits. Pursuant to Section 31(1) of the VVG, the insurer may request supporting documents to the extent that the policyholder can reasonably be expected to obtain them.
This does not imply that the insurer has a general right to carry out a full forensic analysis of all private smartphones, computers, cloud accounts or communication content. A sound legal basis under data protection law is required for any processing of personal data. Article 5 of the GDPR requires, in particular, purpose limitation and data minimisation; personal data must be limited to what is necessary for the specific purpose. The lawfulness of the processing is governed, in particular, by Article 6 of the GDPR.
Section 28 of the Insurance Contract Act (VVG) governs the consequences of a breach of contractual obligations. Whether the provision applies in a particular case depends, amongst other things, on the specific obligation agreed, the degree of fault, the statutory rules on causation and other conditions. An IT forensic report must therefore not itself establish the legal consequence of ‚exemption from liability‘. It can only answer the underlying technical question of fact.
Where personal data is to be further processed for another purpose, in the case of non-public bodies, the conditions set out in Section 24 of the Federal Data Protection Act (BDSG) may apply, in particular where the assertion, exercise or defence of civil law claims is involved. This provision, too, does not apply without restriction; the conflicting interests of the data subject must be taken into account.
Should civil proceedings arise, the court shall, pursuant to Section 286 of the Code of Civil Procedure (ZPO), decide on the truth of factual allegations according to its free conviction, taking into account the entirety of the proceedings and the outcome of the taking of evidence. Section 287 of the German Code of Civil Procedure (ZPO) contains specific rules regarding whether damage has been incurred and the extent of such damage or the interest to be compensated. A privately commissioned IT forensic report does not replace this judicial assessment of the evidence.
Frequently Asked Questions
LanCologne – IT Forensics for Insurance Companies
Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.
Related to this topic
- How can the circumstances surrounding the loss or theft of a smartphone be digitally verified?
- How can it be verified whether a reported device is in fact the one affected by the damage?
- How can an insurance company determine the last verifiable time a damaged device was in use?
- How can an insurance company objectively verify the policyholder’s digital details against the data in its existing systems?