IT Forensics · Insurance
How can the evidential value of an individual digital artefact be objectively assessed in the context of an insurance claim?
A single log entry, timestamp or registry, database or cloud finding may be important, but it always has a specific technical meaning.
Why this question is important for an insurance company
In the case of disputed or financially significant insurance claims, it is not enough for a technical explanation to simply sound plausible. The decisive factor is whether the factual assertion relevant to the settlement can be substantiated in a verifiable manner on the basis of the available digital data.
Technical investigative approach
We will determine what causes the artefact, when it is updated, what alternative explanations exist, and whether independent sources support the claim.
Where the limits of what can be said lie
An artefact only proves what its technical origins actually reflect.
Why LanCologne?
Insurance companies must make decisions – particularly in the case of high-value or disputed claims – which can have significant financial implications. A digital forensics investigation is only helpful if it is not tailored to a desired settlement outcome.
LanCologne therefore begins by addressing the specific technical question of evidence. What facts need to be clarified? Which digital sources are actually capable of providing reliable evidence in this regard? What data is lawfully available? Only then is the scope of the investigation defined.
Key findings are validated at the level of the raw data where necessary. Automated analyses, reports and specialised forensic software are tools; they do not replace the expert examination of the underlying artefacts. If different tools or parsers produce differing results, the cause of the discrepancy is investigated rather than relying on a result solely on the basis of the product used.
We place particular emphasis on counter-hypotheses. A finding is not only examined to see whether it supports the most obvious explanation, but also to determine whether standard system processes, synchronisation, recovery, administration or other technical procedures might have produced the same pattern.
The result must meet two requirements simultaneously: the claims department and the legal representatives must be able to understand the key findings without specialist knowledge; and another qualified IT forensic expert must be able to verify the technical reasoning on the basis of the documented data and investigation steps.
How we work
Independence also means confirming an existing result
A cross-check is not a search for a counter-argument. If the re-examination reveals that an existing finding has been technically soundly derived and is reproducible, this is documented just as clearly as an actual methodological or factual contradiction. This openness regarding the outcome is particularly essential in cases involving high levels of damage.
A clear and comprehensible main body and a verifiable technical appendix
The main body answers the question of evidence in clear language and distinguishes between established findings, interpretations and outstanding issues. The technical section documents the key data sources, identifiers, integrity information, time references, artefact locations and validation steps. This ensures that the investigation remains verifiable for any subsequent expert review.
LanCologne for complex and contentious insurance claims
Where high claims values, conflicting expert reports or the prospect of legal proceedings require a particularly robust technical basis, LanCologne provides support in the form of an unbiased and transparent IT forensic investigation. What matters is not the expected outcome, but the conclusion actually supported by the digital evidence.
Legal framework
Section 31 of the Insurance Contract Act (VVG) is particularly relevant to the out-of-court assessment of claims. This provision concerns the information required to establish the occurrence of an insured event or the extent of the insurer’s obligation to pay benefits following the occurrence of such an event, as well as supporting documents where the statutory conditions are met. This does not imply a blanket right to an unlimited forensic search of all devices, accounts or communication data.
Depending on the circumstances, contractual obligations and Section 28 of the German Insurance Contract Act (VVG), as well as Section 82 of the VVG in relation to the prevention and mitigation of loss, may also be relevant. Whether the statutory requirements are met and what legal consequences ensue is a matter for legal assessment. In this regard, IT forensics should establish the underlying technical facts, rather than itself declaring exemption from liability, a reduction in cover or the existence of cover.
When processing personal data, particular attention must be paid to the principles set out in Article 5 of the GDPR and to ensuring a sound legal basis in accordance with Article 6 of the GDPR. The principles of necessity, purpose limitation and data minimisation also place restrictions on technically feasible investigations.
Should civil proceedings arise, Section 286 of the Code of Civil Procedure (ZPO) is central to the court’s assessment of evidence. Section 287 of the ZPO may be relevant to the determination of damage and its extent. A private expert report commissioned by an insurance company does not replace the court’s taking of evidence or assessment of evidence. However, its professional quality is enhanced if the data basis, methodology, findings and limitations of the report are documented in a transparent and verifiable manner.
Where a court-appointed expert is involved, the procedural rules of the ZPO governing expert evidence apply. A clear distinction must be drawn between this and the role of a privately commissioned expert acting on behalf of a party.
Frequently Asked Questions
LanCologne – IT Forensics for Insurance Companies
Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.
Related to this topic
- How can an insurance company have a technical causal link between an event and a loss investigated?
- How can an insurance company verify whether several reported claims are in fact attributable to the same IT incident?
- How can an IT forensic report present uncertainties in such a way that an insurance company can assess them correctly?
- How can an insurance company prepare a counter-report without simply looking for errors made by the other expert?