IT Forensics · Solicitors & Criminal Defence Lawyers

How can the defence provide a technical explanation for a negative digital finding during the trial?

The absence of an expected artefact may be significant if, given the claimed sequence of events, its formation and preservation would have been reliably expected.

Enquire without obligation

Why this question is important for a criminal defence

In the main hearing, it is not the volume of technical data that is decisive, but the reliability of the evidence that has actually been presented and assessed. The defence must therefore be able to recognise what information a digital artefact conveys, what conditions apply to it, and where interpretation begins.

Technical investigative approach

We document the basis for expectations, data completeness, retention, possible deletion or rotation mechanisms, and comparable cases within the system under investigation.

Where the limits of what can be said lie

The absence of an artefact should not automatically lead to the conclusion that an event did not take place.

Why LanCologne?

During the main hearing, digital evidence must not only be technically accurate, but its actual scope must also be made clear. This is precisely where the role of independent IT forensic support for the defence comes in.

LanCologne does not carry out its assessments with the aim of refuting a court-appointed or regulatory expert. The key consideration is whether the data set, methodology and conclusion are consistent. If a finding is substantiated, it is confirmed. Where technical limitations, contradictory primary data or plausible alternative explanations exist, these are also clearly documented.

Particular attention is paid to the distinction between automated parser representations and raw data, between devices, accounts, sessions and natural persons, and between technical possibilities and events that have actually been verified.

The findings are presented in two stages: in a way that is clear to the defence and the court, whilst also providing sufficient technical detail to enable another qualified IT forensic expert to verify the key findings.

How we work

1Identify key digital findings relevant to the main hearing.
2Clearly link expert reports, reports and primary data to one another.
3Record the evidence, method, findings and conclusion separately.
4Where necessary, validate key parser findings against the raw data.
5Check the allocation of time, devices, accounts, sessions and users separately.
6Test technically specific alternative explanations against expected evidence.
7Distinguish between dependent and independent sources of evidence.
8Compare expert opinions and new findings with the database.
9Explicitly document the limits of the statements and the questions that cannot be resolved.
10Prepare technical queries and explanations in a way that the defence can understand.

Incriminating, exculpatory and inconclusive findings

Technical support is not geared towards a desired outcome of the proceedings. A finding that is technically incriminating is stated just as clearly as a finding that is exculpatory. If a question cannot be resolved on the basis of the available data, this fact is specifically documented. Such an open-minded approach to findings is a prerequisite for credible forensic work.

Understandable to the defence and the court – technically reproducible

Key points are explained without unnecessary technical jargon. The technical section documents data sources, identifiers, time references, integrity information, artefact locations and validation steps. This ensures that the reasoning behind the findings can be technically verified by another qualified IT forensic expert.

LanCologne as an independent technical support service during the main hearing

Where digital evidence, IT forensic reports or expert witness statements need to be professionally prepared or reviewed for the main hearing, LanCologne supports the defence with a transparent and unbiased technical analysis. What matters is what the data actually proves – and what cannot be reliably deduced from it.

Legal framework

Section 244 of the Code of Criminal Procedure (StPO) is of particular importance for the taking of evidence at the main hearing. Under Section 244(2), the court must, of its own motion, extend the taking of evidence to all facts and evidence relevant to the decision. The legal requirements for applications for evidence and their rejection are set out, in particular, in Section 244(3) et seq. of the Code of Criminal Procedure. The legal formulation and submission of an application for evidence is the responsibility of the defence lawyer, not of a privately commissioned IT forensic expert.

Sections 72 et seq. of the Code of Criminal Procedure (StPO) apply to expert evidence. An IT forensic expert privately commissioned by the defence does not, by virtue of that commission alone, become an expert formally appointed by the court. These roles must be strictly separated.

Section 244(4) of the Code of Criminal Procedure (StPO) sets out specific rules governing the rejection of a motion to call an expert witness. Under the conditions laid down by law, the hearing of a further expert witness may, in particular, be relevant. In addition, Section 83 of the Code of Criminal Procedure (StPO) provides for the possibility of a new expert report in the circumstances specified therein. Whether these conditions are met in the specific case is a matter of criminal procedure to be determined by the defence and the court.

Section 245 of the Code of Criminal Procedure contains specific rules on the taking of evidence in relation to evidence produced and persons summoned or appearing in court. Whether the provision applies to a specific piece of digital evidence or a specific procedural situation must be assessed on a case-by-case basis.

The defence counsel retains the right to inspect the case file in accordance with Section 147 of the Code of Criminal Procedure. LanCologne does not acquire any procedural powers of its own through a private commission. Our role is to carry out a technical examination of digital evidence, prepare technical matters and clearly set out the limitations of any testimony.

Frequently Asked Questions

Can LanCologne provide technical advice to the defence during the trial?+
In principle, expert support may be arranged or provided within the permissible organisational framework. The defence lawyer will coordinate the specific involvement and procedural application of such support in light of the proceedings.
Does this mean that a privately commissioned IT forensic expert thereby becomes a court-appointed expert?+
No. Acting as a private adviser to the defence and serving as a formal expert witness under sections 72 et seq. of the Code of Criminal Procedure are different roles.
Can LanCologne draft or submit a motion for evidence?+
We can clarify the technical issues of evidence, suitable data sources and specialist investigative approaches. The criminal defence lawyer is responsible for the legal wording and the submission of the application.
Does a cross-examination have to refute the court-appointed expert’s evidence?+
No. A thorough independent review may confirm, qualify or, on technical grounds, refute the findings. The only decisive factor is the available technical data.

LanCologne – IT Forensics for Lawyers & Criminal Defence Solicitors

Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.

Get in touch now