WhatsApp
← Blog·Cyber·08/01/2026
Editorial infographic: client and forensic investigator shaking hands over an engagement agreement listing scope, legal basis, evidence handling, deliverables and confidentiality.

Engaging a computer hacking investigator: what to expect.

Clients often expect a hacking investigation to look like the movies — a lone operator, a black terminal, a moment of triumph. In practice it looks like disciplined evidence work, with the same rhythm as any other forensic instruction: intake, preservation, analysis, attribution, report. Understanding what the engagement actually looks like — and what deliverables to expect at each stage — is the single largest determinant of whether the investigation produces something you can act on.

The engagement, stage by stage

  1. 01
    Intake call (Day 0). Understanding what happened, what the client fears, what needs to be protected first, and — crucially — what the client wants the investigation to produce: a report to management, evidence for an insurance claim, material for civil proceedings, or a criminal referral. The deliverable shapes the methodology.
  2. 02
    Engagement letter (Day 0–1). Scope of investigation, legal basis, evidence handling standards (ACPO / NPCC / ISO 17025), reporting format, fee structure and confidentiality. Signed before any evidence changes hands.
  3. 03
    Preservation (Day 1–3). Forensic images of affected devices, exports of account audit logs, isolation of compromised accounts. Every acquisition hashed and logged; nothing is examined until the copies are complete.
  4. 04
    Analysis (Week 1–2). Vector identification, timeline reconstruction, dwell-time analysis, exfiltration assessment, persistence enumeration. Every conclusion tied to a specific artefact.
  5. 05
    Attribution (Week 2, if in scope). Linking activity to accounts, infrastructure or — where the evidence permits — identifiable individuals. Attribution is treated conservatively; "consistent with" and "cannot be excluded" carry more weight in court than "proves".
  6. 06
    Report (Week 2–3). Written report suitable for the deliverable agreed at intake: internal action, insurance claim, civil proceedings or criminal referral. Draft shared with instructing party for factual accuracy check before finalisation.

What the engagement letter should actually cover

  • Scope — the systems, accounts and time window in the investigation, and — equally important — what is outside scope.
  • Legal basis — who is authorised to consent to examination of each device and account (owner, employer, court order).
  • Evidence handling — ACPO / NPCC principles, ISO 17025 accreditation, chain-of-custody standards.
  • Reporting format — CPR Part 35 for civil use; NPCC / ACPO for criminal use; management-facing summary for internal use.
  • Confidentiality — NDA covering both parties, retention period for the forensic images and reports, destruction protocol.
  • Fees — hourly, daily or fixed; expenses (travel, disclosure fees, court attendance); payment terms.
  • Communication protocol — single point of contact on each side; secure channel; agreed cadence for updates.

What the report will — and will not — tell you

A good report says three things clearly: what is known, what is likely, and what cannot be determined from the available evidence. The temptation to overclaim attribution — naming an individual, or a nation-state actor, on evidence that only supports "consistent with" — is where most cyber reports fall over on cross-examination. A defensible report distinguishes between technical findings (facts) and analytical conclusions (opinions), and it says so on the page.

What the report containsWhat that means
Executive summaryTwo to three pages a non-technical reader can act on
Timeline of eventsEvery artefact-supported event, with source and timestamp (UTC and local)
Initial access vectorHow the intruder got in, with evidence — or an honest "not determined"
Dwell time and activityWhat happened between initial access and detection
Data accessed / exfiltratedWhat the evidence supports about what was seen or removed
Persistence mechanismsEverything the intruder left behind to maintain access
AttributionOnly what the evidence supports; conservative language throughout
RecommendationsImmediate remediation, medium-term hardening, monitoring
AppendicesFull artefact list; hash values; tool versions; examiner statement of truth

Red flags when selecting an investigator

Any investigator who guarantees an outcome — guaranteed unlock, guaranteed attribution, guaranteed decryption — before seeing the evidence is either overselling or misunderstanding the discipline. Reputable practitioners quote on process, not on outcomes.

  • No engagement letter, or an engagement letter without scope, evidence-handling standards or fee structure.
  • No accreditation — ISO 17025, NPCC-listed CSPs, or comparable standards.
  • No willingness to name the examiner who will sign the report, or their credentials.
  • Refusal to attend court to defend the report — if the case may go contested, the report is only as useful as the person prepared to stand behind it.
  • Payment demanded up front in cryptocurrency, or through unusual routes; a hallmark of low-quality "recovery" services aimed at breach victims.

How the client can make the engagement work

  • Nominate a single point of contact with authority to sign the engagement letter and to authorise access to systems.
  • Provide the network diagram, asset list and any prior security assessments on Day 1; do not make the examiner reverse-engineer the environment.
  • Stop remediating. Freeze the environment in its current state until the examiner confirms preservation is complete.
  • Preserve rather than delete. Every log, every mailbox, every device, until scope is agreed and preservation is done.
  • Trust the process. The first week produces evidence collection, not conclusions; useful analysis follows from complete evidence, not from rushed guesses.

Frequently asked questions

How much does a hacking investigation cost?

A focused incident with one affected system and one cloud tenant typically runs £8,000–£20,000 for full forensic response and report. Complex incidents involving multiple systems, extensive dwell time, or litigation-grade reporting can run into six figures. Preliminary scoping is usually free or fixed-fee.

Will you notify the ICO for me?

No — the notification obligation sits with the data controller, and the wording of the notification is a legal decision, not a technical one. We provide the technical facts your data protection lawyer needs to draft the notification.

Do you work with insurers?

Yes. Most cyber insurance policies include a panel of pre-approved incident response firms. Where we are on the panel we work under that arrangement; where we are not, we can be added or work under a separate engagement subject to insurer approval.

Will you attend court?

Yes. The named examiner who signs the report attends to defend it under cross-examination. Reports produced by staff who will not stand behind them in court are worth less to a contested case.

What is the difference between a hacking investigator and a penetration tester?

A penetration tester attacks a system to find weaknesses before real attackers do. A hacking investigator examines a system that has already been attacked, to determine what happened. Different disciplines, different tool sets, different accreditations — do not confuse them.