IT Forensics · Solicitors & Criminal Defence Lawyers
How can a comprehensive IT forensic case timeline support the defence across multiple courts?
In proceedings that drag on for many years, safeguards, expert reports, cross-checks and new data sets are produced at different points in time. Without a clear chronology, technical statements from different stages of the proceedings can become intermingled.
Why this question is important for a criminal defence
Following a judgement or in proceedings before a higher court, a technical examination must not be conflated with the legal review of the appeal. However, it may be crucial for the defence to know precisely whether a digital statement is supported by the available primary data and whether a subsequent finding actually substantiates something new.
Technical investigative approach
We document evidence, the dates of evidence collection, extracts, the status of expert reports, new findings, changes and technical conclusions in a consistent chronological order.
Where the limits of what can be said lie
The chronology of events serves as a technical working document and does not constitute a legal assessment of the course of the proceedings.
Why LanCologne?
Following the conclusion of the first trial, the role of a defence-led IT forensic investigation changes once again. It is now essential to draw a clear distinction between the technical establishment of facts and the legal assessment of appeals or applications for a retrial.
LanCologne therefore does not examine any issue with the aim of retrospectively constructing a legal error. We examine solely whether digital statements are technically supported by the available data, whether different data sets have been confused with one another, whether the attribution to a specific individual extends beyond the technical facts on which it is based, or whether a finding discovered at a later date is in fact new and authentic.
The same standards apply here as in any other forensic investigation: primary data takes precedence over mere representations; automated outputs are validated in the case of decisive findings; incriminating and exculpatory findings are treated equally; and questions that cannot be resolved are expressly left open.
This restraint is particularly important when it comes to appeals or applications for a retrial. It is the criminal defence lawyer or the competent court – not the IT forensic expert – who assesses whether a technical finding constitutes a legal error, a valid ground for appeal or a ground for a retrial.
How we work
Incriminating, exculpatory and inconclusive findings
Even following a conviction or in the event of a possible appeal, the investigation remains open-ended. A previous incriminating finding is confirmed if the primary data supports it. A new counter-finding is only designated as such if its origin, integrity and technical significance are verifiably documented. Questions that cannot be resolved are not replaced by assumptions.
Understandable to the defence lawyer – technically verifiable
The main section explains the core technical message without using unnecessary specialist terminology. The technical section documents data states, backup times, identifiers, integrity values, artefact locations, time references and validation steps. This ensures that the investigation remains verifiable for another qualified IT forensic expert.
LanCologne as an independent source of technical support for the defence
Whether it is a preliminary investigation, interim proceedings, a trial or a subsequent technical examination: LanCologne answers the specific question regarding digital evidence objectively, without prejudging the outcome, and in a transparent manner. The benchmark is not the desired outcome, but solely what can or cannot be technically substantiated on the basis of the available data.
Legal framework
Once the main hearing has concluded, the court shall, in accordance with section 261 of the Code of Criminal Procedure, decide on the outcome of the taking of evidence in accordance with its free assessment, based on the substance of the proceedings. Section 267 of the Code of Criminal Procedure governs the content of the grounds for the judgement. A subsequent IT forensic examination can compare technical statements in the written grounds for the judgement with the available data and findings; however, it does not involve a legal review of the judgement.
Under section 312 of the Code of Criminal Procedure (StPO), an appeal may be lodged against judgements handed down by the criminal court and the lay judges’ court. The time limit for lodging an appeal is set out in section 314 of the Code of Criminal Procedure (StPO). The criminal defence lawyer assesses whether an appeal is permissible, admissible or advisable in the specific case. IT forensics can structure digital evidence in a professional manner to facilitate a fresh examination of the facts.
An appeal on points of law is governed by sections 333 et seq. of the Code of Criminal Procedure. Under section 337(1) of the Code of Criminal Procedure, it may only be based on the ground that the judgement is founded on a breach of the law. Section 344 of the Code of Criminal Procedure governs the grounds for an appeal on points of law and imposes specific requirements, in particular, on procedural objections. LanCologne does not formulate grounds for appeal and does not assess whether a technical circumstance constitutes a legal error that is subject to appeal. We merely document the technical factual basis for the defence counsel.
Sections 359 et seq. of the Code of Criminal Procedure (StPO) apply to the reopening of proceedings that have been concluded by a final and binding judgment in favour of the convicted person. Section 359 of the StPO sets out the statutory grounds for reopening proceedings. Whether a newly discovered digital data record, a device decrypted at a later date or new technical findings fulfil these conditions is a question of law. However, a digital forensics examination can determine whether the finding in question is authentic, technically new, relevant in terms of timing and compatible or incompatible with earlier findings.
This clear division of roles is essential: LanCologne provides technical facts, documents how they were arrived at and identifies the limits of their validity. The choice of legal remedies, time limits, requirements for raising objections, legal relevance and the submission of procedural applications remain entirely the responsibility of the defence.
Frequently Asked Questions
LanCologne – IT Forensics for Lawyers & Criminal Defence Solicitors
Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.
Related to this topic
- How much weight does an IP address carry from a criminal defence perspective?
- Can the use of a VPN or proxy alter the attribution of internet activity?
- How can a screenshot be independently verified as incriminating evidence?
- From a criminal defence perspective, how can the authenticity of an audio recording be verified using technical methods?