WhatsApp
← Blog·Cyber·16/12/2025
Editorial infographic: a legal document with wax seal linked by a dotted evidence-chain to a server rack and a regulator shield, with paragraph marks and callouts for notification and chain of custody.

Why cyber forensics has become critical for UK legal and corporate work.

A cyber incident used to be an IT problem with a legal aftermath. It is now a legal event with an IT component from the moment it is discovered. The 72-hour notification clock under UK GDPR starts running before the incident is fully understood, insurers refuse to indemnify without a documented investigative trail, and any subsequent civil claim or regulatory enforcement will be decided on the strength of the evidence the organisation was able to preserve. Forensic evidence work is no longer an optional overlay on incident response — it is the substrate that determines whether an organisation can defend itself.

Ten years ago, a serious intrusion was largely a matter for the IT director and, eventually, an insurance claim. The legal consequences arrived slowly, if at all, and the evidence was rarely examined by anyone whose report would be tested in court. That model no longer survives contact with UK GDPR, the ICO's enforcement posture, the standard exclusions in modern cyber insurance policies, or the volume of data-subject litigation that now follows publicised breaches.

The organisations that come through an incident with reputation, insurance cover and legal position intact are, almost without exception, the ones that treated the first 24 hours as an evidence-preservation problem rather than a service-restoration problem. That reordering of priorities is the single most important shift in this discipline over the last five years.

The obligations that make forensics unavoidable

ObligationTriggerWhat forensics is expected to supply
UK GDPR Art. 33Personal data breach affecting rights and freedomsNature of the breach, categories and approximate numbers of data subjects and records affected
UK GDPR Art. 34High risk to affected data subjectsA factual basis for the notification and the mitigation described to those data subjects
Cyber insurance policyAny claim for indemnityIndependent investigation, root-cause analysis, evidence of remediation
Civil claim / group actionPost-breach litigation by data subjectsContemporaneous evidence of scope, mitigation and organisational response
NIS Regulations / DORA (financial)Significant incident affecting operators or financial entitiesIncident timeline, impact assessment, formal report to competent authority

What changes when forensics is done properly from hour one

  • Notification to the ICO can be made accurately, on time, and without the qualifying language that invites follow-up enforcement.
  • Insurance recovery is materially more likely; the carrier's panel forensic firm will accept preserved evidence rather than restart the investigation.
  • Data-subject notifications can be tailored to what was actually affected, rather than issued to a broader population out of caution.
  • Litigation risk falls, because the organisation can show what happened, when it acted, and what it did about it.
  • Any subsequent prosecution — whether of an insider or of an external actor identified during response — has evidence a court can rely on.

What goes wrong when it is not

The typical failure pattern is fast remediation and no preservation. Endpoints are re-imaged, servers are rebuilt from clean backups, cloud tenants are re-tenanted, logs age out of their default retention windows, and by the time a lawyer is instructed there is nothing left to examine. The organisation is then in the position of having to negotiate with the ICO, its insurers and its claimants without a defensible account of what happened — and every one of those counterparties knows it.

The single most expensive decision in a cyber incident is almost always taken in the first three hours, by someone who did not know they were making it: the decision to rebuild before imaging.

Where the legal team should sit in the response

  1. 01
    Instruct external counsel immediately. This establishes legal professional privilege over the investigative work product, provided the forensic examiner is instructed by counsel and not by the client directly.
  2. 02
    Retain the forensic examiner through counsel. This is not a formality — it is the mechanism by which the investigation report is protected from disclosure to opposing parties in any later civil claim.
  3. 03
    Agree the notification timetable in writing. The 72-hour clock is a legal decision, not a technical one; the examiner's role is to supply the facts, not to draft the notification.
  4. 04
    Preserve first, remediate second. Live images of affected systems, cloud audit logs exported to the examiner, endpoint memory captures where feasible — all before rebuilds begin.
  5. 05
    Document every decision. A contemporaneous decision log is the single most useful document in any post-incident review, ICO investigation or civil claim.

Why an independent examiner matters

The internal IT team, however competent, is a witness to the incident, not an investigator of it. Their emails, their configuration decisions and their access logs are part of what will be examined. Instructing an independent examiner — through counsel, on a defined scope — separates the investigation from the incident and produces a report the organisation can rely on in front of any tribunal, regulator or insurer that later asks the question.

Frequently asked questions

When does legal professional privilege attach to forensic work?

When the examiner is instructed by external counsel for the dominant purpose of advising on legal risk or contemplated litigation. Instructions issued directly by the client to the examiner do not generally attract litigation privilege over the resulting report.

Do we have to tell the ICO within 72 hours even if we don't know the scope?

Yes. Article 33 requires notification within 72 hours of becoming aware, in phases if necessary. The forensic evidence is what allows you to complete or correct the notification in later phases rather than retract it.

Will our insurer accept our chosen forensic firm?

Most cyber policies specify a panel of pre-approved responders. Using an off-panel firm without prior consent can void the indemnity. Confirm panel status before instructing.

Is a rebuild ever the right first step?

Only where preservation has already been achieved (memory capture, disk image, log export) and business continuity genuinely cannot wait. Rebuilding without preservation destroys the evidence you will later need to defend.

What does a defensible cyber forensics report look like?

It sets out the scope of the investigation, the evidence sources examined, the methodology applied, the factual findings (with references to specific artefacts), the limitations of what could be established, and a statement of truth from the named examiner who will attend to defend it.