Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Five Key Steps For Digital Forensics and Incident Response
Articles

Five Key Steps For Digital Forensics and Incident Response

ISBuzz TeamBy ISBuzz TeamOctober 28, 20165 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Dr Bernard Parsons, CEO at Becrypt, looks closer into how every organisation can prepare, prevent and even learn cyber threats using Digital Forensics.

The significance of activities such as Incident Response planning and Digital Forensics may for many seem only relevant for organisations that work in the most security conscious sectors. However, I believe that a rounded appreciation of good cybersecurity practices is valuable, if not critical, for all organisations. It is important that, in any size or type of organisation, if a security incident should occur, those charged with responding and investigating are prepared to follow a structured, effective and informed process.

Spending a small amount of time thinking through how well an IT environment’s configuration and security controls may support a forensics exercise, in the event that an organisation suffers a breach, can have a significant impact on the cost and disruption experienced when one actually does occur. Being prepared could be the deciding factor for the subsequent longevity of an organisation or individuals within it.

Both physical and digital forensics have the same fundamental goal; to prove exactly what happened during a given event period, and to attribute actions to a specific individual, allowing effective and appropriate response. They both rely on the acquisition and analysis of data in a timely fashion, and in a manner that allows the provenance of the data to be confirmed.

There are many proposed methodologies for digital forensics, but generally, they can be condensed into the same five steps:

 Gather human intelligence

Clarify the time and date boundaries

A modern network generates thousands of events every minute, which means that, before undertaking any investigative action, it is important to narrow down where to look.

Find out who is involved

The crux of any investigation, this requires detailed questioning of those who reported the event. Questions such as: ‘When did you first spot it; how long was it a problem/did it go on for; is it still happening; who is involved?’

Ascertain which machines are affected

You can identify from the users which machines have been affected. However, this may not represent the only area that needs investigation; remain open minded.

Identify what actions have been taken since the discovery

In any digital forensic investigation, once you interact with the environment it automatically changes and the evidence is altered. It is important to understand what actions people have taken (or tried to take) and work from that point.

Be prepared to eliminate ‘false positives’. Disproving facts with evidence is equally as useful as proving a theory during an investigation.

 Plan your approach

Prioritise your targets

In a digital environment events happen very quickly. Identify and prioritise the areas where you can get valuable evidence; working from the most volatile environment, to the most stable.

Keep it legal

Ensure that legal guidelines are followed. If you don’t follow procedure, evidence may be inadmissible in a court of law, should the need arise.

Allocate resources and skillsets

Ascertain whether you have the right people to conduct the investigation. You will need experts for your hardware and software configurations to ensure that valuable evidence is not inadvertently compromised. External agents could provide an unbiased alternative.

Balance value against cost

There is a cost associated with any work, and so a sanity check is vital. Balancing the proportional effort, cost and risk to the business is essential.

 Obtain evidence

Document and sign your evidence

Everything that is captured must be documented exactly, dated and signed because as evidence is touched, it is immediately changed. This ensures that a clear audit path is kept.

Capturing the data

Any work carried out on data should be on copies only, always preserving the integrity of the original data. Keeping a strong chain of custody ensures that the master copy is kept intact and remains the ultimate reference point.

Use cryptographically verifiable data

When data is captured and recorded it will always have a ‘hash’; its unique identification number. Any copies taken will also have the same hash reference.

 Analyse the evidence

Make a timeline of events

Data from multiple sources may have different time stamps, by compiling the data together you can build a complete picture. Matching the evidence over the time period also helps to identify corroborating evidence.

Analyse the data

From the timeline of events it is important to work systematically, hypothesising and running tests to prove/disprove any theories. Additional corroborating evidence may be required.

 Report on your findings

At the end of the investigation your report needs to be understandable and contain only defensible data. The report will need to explain findings that make sense to non-technical people. The report must be factual, presenting data, dates and events that have happened, and it must be impartial.

As well as the summary report, it is also important that all relevant data is compiled in an additional appendix. For serious cases, investigative experts will need to review the data to corroborate the facts that you have presented.

By following these five steps your digital forensic investigation and subsequent report is more likely to meet the stringent requirements of courts and industrial tribunals, and provide valuable information to the business and people affected.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Understanding Cloud Access Security Brokers (CASB)

March 28, 202410 Mins Read

Decoding Cloud Security Posture Management (CSPM)

March 28, 202411 Mins Read

Master Cloud Compliance Tools: Achieve Regulatory Success

March 28, 202411 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}