What this service helps clarify
This page is for matters involving alerts, suspicious logins, malware, unauthorised access and system disruption. The goal is to organise the facts, preserve useful evidence and decide the right pathway before important information is lost or the issue becomes more expensive.
Good digital forensic work starts with the question that needs answering. Was an account accessed? Did data leave the business? Was a message genuine? Was a device used? Was the problem a mistake, malware, fraud, insider activity or system failure?
Evidence that may matter
- Security alerts and endpoint detections.
- Firewall, VPN, email and identity provider logs.
- Affected user accounts, admin accounts and shared systems.
- Actions already taken by IT or external providers.
Useful questions before a consultation
- Is the incident still active?
- What systems are business critical?
- Has personal or confidential information been exposed?
How a specialist consultation helps
A specialist can help separate assumptions from evidence, identify time-sensitive logs, explain what should be preserved and recommend whether the matter needs forensic imaging, cyber containment, privacy review, legal support, insurance notice, bank action or platform reporting.
The safest first step is often to document the situation before changing too much. Avoid deleting accounts, wiping devices or reinstalling systems until the evidence value is considered.
Request specialist consultation
Related help
Threat types
Understand the common threat categories and how incidents overlap.
Evidence checklist
Prepare a short, useful brief before contacting a specialist.
Start an enquiry
Use the form to share key facts without exposing public email addresses.