Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Proven Legal Technologies Reveals 10 Worst e-Disclosure Searches
News & Analysis

Proven Legal Technologies Reveals 10 Worst e-Disclosure Searches

ISBuzz TeamBy ISBuzz TeamOctober 15, 2014Updated:July 3, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
computer_forensics
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Proven Legal Technologies, the corporate forensic investigation and e-disclosure firm, has revealed 10 of the worst searches made by businesses during e-disclosure investigations.

Phil Beckett, Partner, Proven Legal Technologies, comments:

“In cases where an e-disclosure investigation is necessary, it is essential that the procedure is highly efficient and provides clear and concise results. However, our experience has shown that firms are still making crucial errors in the process, such as agreeing to search for ineffective words and phrases.”

Featured Download: CISO Data Breach Guide

Beckett’s top 10 worst e-disclosure searches include:

1)      Words likely to appear in email footers

Terms that appear in standard email footers will do little to narrow down the search process. Examples include: “deletion”, “company”, “legal”, “confidential”, and any alternative forms of the words.

2)      Names

Searching an individual’s or custodian’s name is impractical, for they often if not always appear in email signatures. In addition, there are numerous alternative spellings and abbreviations that would require separate searches.

3)      System-related words

Using words that are common place within computer or system terminology often brings up a vast number of false-positive results, including “network”, ”windows” or even “data”.

4)       Standard terminology

Using standard terminology, be it relating to the specifics of a business (for example, products, or customers) or relating to business in general (invoices or sales), can create a large number of results. These results will generally need to be combined with other terms to be effective.

5)      “Fraud”

Fraudsters would rarely use this word within emails or other methods of communication, not least because they do not believe that they are doing anything wrong, hence searching for this term is fruitless.

6)      Misunderstood syntax

The same sentences can have numerous implications and meanings depending on its grammatical characters and structure. It is therefore essential to ensure that the search accounts for this possibility or eliminates any incorrect interpretations.

7)      Initialisms

Many custodians use abbreviations or initialisation to references names or act as signatures. However, searching individual letters, particularly “A” and “I,” will prove futile due to their high frequency.

8)      Proximity searching

When a phrase is searched, frequent words such as “a” and “of” are treated as “noise” or “stop” words, meaning that a phrase containing noise words will not be searched as intended. A more appropriate method is to use the “X within two words of Y” operator, where for example, “bill of sale” would become bill w/2 sale.

9)      Searches in which one expects obvious fraud

In most cases, perpetrators of suspected wrongdoing will be aware of the illegitimacy of their actions and will endeavour to conceal them, thus searching material that blatantly betrays the fraudsters is unlikely to be successful.

10)   Keywords

It is sometimes inappropriate to use keywords at all. One example of this is when actions are being deliberately concealed. Another is when dealing with hard-copy material that has had Optical Character Recognition (OCR) to make it searchable. No matter how good the software is, it will be dependent on the quality of the paper, text and scan. Words can be incorrectly identified on a regular basis, which would not be responsive to a keyword search.

Beckett concludes:

“Search processes within e-disclosure investigations should be cyclical and progressive, building on the findings of previous searches in order to narrow down results. Firms should also consider whether keyword searches are suitable to the nature of the investigation, or whether alternative methods would be more suitable.

“In order to establish an effective method and specific list of search terms for an investigation, businesses should seek expert advice and consultation. Specialist keyword analytics tools and experience eliminates wasted time and significantly increases the likelihood of producing crucial results and a conclusive investigation.”

By Phil Beckett, managing director at Proven Legal Technologies

Phil Beckett (Proven Legal Technologies - Good Governance Group) (Portra...Phil Beckett is a Managing Director at Proven Legal Technologies and joined the team after spending seven years leading Navigant Consulting Inc’s European Forensic Technology practice.

Throughout his career Phil has provided advice to lawyers, regulators, corporate entities, not-for-profit organisations and other stakeholders in relation to forensic investigations and e-disclosure projects in both the public and private sectors in the UK and also internationally. He specialises in advising clients concerning the preservation and investigation of digital evidence, the interrogation of complex data sets and the disclosure of electronic documents. He is also a qualified fraud examiner and has been a recognised court expert in relation to various aspects of digital evidence, producing numerous expert reports.

 

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Understanding Cloud Access Security Brokers (CASB)

March 28, 202410 Mins Read

Decoding Cloud Security Posture Management (CSPM)

March 28, 202411 Mins Read

Master Cloud Compliance Tools: Achieve Regulatory Success

March 28, 202411 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}