The engagement, stage by stage
- 01Intake call (Day 0). Understanding what happened, what the client fears, what needs to be protected first, and — crucially — what the client wants the investigation to produce: a report to management, evidence for an insurance claim, material for civil proceedings, or a criminal referral. The deliverable shapes the methodology.
- 02Engagement letter (Day 0–1). Scope of investigation, legal basis, evidence handling standards (ACPO / NPCC / ISO 17025), reporting format, fee structure and confidentiality. Signed before any evidence changes hands.
- 03Preservation (Day 1–3). Forensic images of affected devices, exports of account audit logs, isolation of compromised accounts. Every acquisition hashed and logged; nothing is examined until the copies are complete.
- 04Analysis (Week 1–2). Vector identification, timeline reconstruction, dwell-time analysis, exfiltration assessment, persistence enumeration. Every conclusion tied to a specific artefact.
- 05Attribution (Week 2, if in scope). Linking activity to accounts, infrastructure or — where the evidence permits — identifiable individuals. Attribution is treated conservatively; "consistent with" and "cannot be excluded" carry more weight in court than "proves".
- 06Report (Week 2–3). Written report suitable for the deliverable agreed at intake: internal action, insurance claim, civil proceedings or criminal referral. Draft shared with instructing party for factual accuracy check before finalisation.
What the engagement letter should actually cover
- Scope — the systems, accounts and time window in the investigation, and — equally important — what is outside scope.
- Legal basis — who is authorised to consent to examination of each device and account (owner, employer, court order).
- Evidence handling — ACPO / NPCC principles, ISO 17025 accreditation, chain-of-custody standards.
- Reporting format — CPR Part 35 for civil use; NPCC / ACPO for criminal use; management-facing summary for internal use.
- Confidentiality — NDA covering both parties, retention period for the forensic images and reports, destruction protocol.
- Fees — hourly, daily or fixed; expenses (travel, disclosure fees, court attendance); payment terms.
- Communication protocol — single point of contact on each side; secure channel; agreed cadence for updates.
What the report will — and will not — tell you
A good report says three things clearly: what is known, what is likely, and what cannot be determined from the available evidence. The temptation to overclaim attribution — naming an individual, or a nation-state actor, on evidence that only supports "consistent with" — is where most cyber reports fall over on cross-examination. A defensible report distinguishes between technical findings (facts) and analytical conclusions (opinions), and it says so on the page.
| What the report contains | What that means |
|---|---|
| Executive summary | Two to three pages a non-technical reader can act on |
| Timeline of events | Every artefact-supported event, with source and timestamp (UTC and local) |
| Initial access vector | How the intruder got in, with evidence — or an honest "not determined" |
| Dwell time and activity | What happened between initial access and detection |
| Data accessed / exfiltrated | What the evidence supports about what was seen or removed |
| Persistence mechanisms | Everything the intruder left behind to maintain access |
| Attribution | Only what the evidence supports; conservative language throughout |
| Recommendations | Immediate remediation, medium-term hardening, monitoring |
| Appendices | Full artefact list; hash values; tool versions; examiner statement of truth |
Red flags when selecting an investigator
Any investigator who guarantees an outcome — guaranteed unlock, guaranteed attribution, guaranteed decryption — before seeing the evidence is either overselling or misunderstanding the discipline. Reputable practitioners quote on process, not on outcomes.
- No engagement letter, or an engagement letter without scope, evidence-handling standards or fee structure.
- No accreditation — ISO 17025, NPCC-listed CSPs, or comparable standards.
- No willingness to name the examiner who will sign the report, or their credentials.
- Refusal to attend court to defend the report — if the case may go contested, the report is only as useful as the person prepared to stand behind it.
- Payment demanded up front in cryptocurrency, or through unusual routes; a hallmark of low-quality "recovery" services aimed at breach victims.
How the client can make the engagement work
- Nominate a single point of contact with authority to sign the engagement letter and to authorise access to systems.
- Provide the network diagram, asset list and any prior security assessments on Day 1; do not make the examiner reverse-engineer the environment.
- Stop remediating. Freeze the environment in its current state until the examiner confirms preservation is complete.
- Preserve rather than delete. Every log, every mailbox, every device, until scope is agreed and preservation is done.
- Trust the process. The first week produces evidence collection, not conclusions; useful analysis follows from complete evidence, not from rushed guesses.
Frequently asked questions
A focused incident with one affected system and one cloud tenant typically runs £8,000–£20,000 for full forensic response and report. Complex incidents involving multiple systems, extensive dwell time, or litigation-grade reporting can run into six figures. Preliminary scoping is usually free or fixed-fee.
No — the notification obligation sits with the data controller, and the wording of the notification is a legal decision, not a technical one. We provide the technical facts your data protection lawyer needs to draft the notification.
Yes. Most cyber insurance policies include a panel of pre-approved incident response firms. Where we are on the panel we work under that arrangement; where we are not, we can be added or work under a separate engagement subject to insurer approval.
Yes. The named examiner who signs the report attends to defend it under cross-examination. Reports produced by staff who will not stand behind them in court are worth less to a contested case.
A penetration tester attacks a system to find weaknesses before real attackers do. A hacking investigator examines a system that has already been attacked, to determine what happened. Different disciplines, different tool sets, different accreditations — do not confuse them.
