What this service helps clarify
This page is for matters involving mailbox rules, cloud sharing, login activity, account recovery settings and app permissions. The goal is to organise the facts, preserve useful evidence and decide the right pathway before important information is lost or the issue becomes more expensive.
Good digital forensic work starts with the question that needs answering. Was an account accessed? Did data leave the business? Was a message genuine? Was a device used? Was the problem a mistake, malware, fraud, insider activity or system failure?
Evidence that may matter
- Mailbox rules, forwarding settings and delegated access.
- Sign-in logs, MFA prompts and unfamiliar devices.
- Cloud folder sharing links and file access history.
- Admin changes, OAuth apps and recovery details.
Useful questions before a consultation
- Are logs still available?
- Was an account accessed or only impersonated?
- Which users, folders or messages may have been exposed?
How a specialist consultation helps
A specialist can help separate assumptions from evidence, identify time-sensitive logs, explain what should be preserved and recommend whether the matter needs forensic imaging, cyber containment, privacy review, legal support, insurance notice, bank action or platform reporting.
The safest first step is often to document the situation before changing too much. Avoid deleting accounts, wiping devices or reinstalling systems until the evidence value is considered.
Request specialist consultation
Related help
Threat types
Understand the common threat categories and how incidents overlap.
Evidence checklist
Prepare a short, useful brief before contacting a specialist.
Start an enquiry
Use the form to share key facts without exposing public email addresses.