What this service helps clarify
This page is for matters involving emails, devices, logs, screenshots, cloud records and timelines. The goal is to organise the facts, preserve useful evidence and decide the right pathway before important information is lost or the issue becomes more expensive.
Good digital forensic work starts with the question that needs answering. Was an account accessed? Did data leave the business? Was a message genuine? Was a device used? Was the problem a mistake, malware, fraud, insider activity or system failure?
Evidence that may matter
- Original emails and message headers where possible.
- Screenshots with visible dates, URLs and sender details.
- Device details, account names and affected users.
- A written timeline of discovery, actions and changes.
Useful questions before a consultation
- What should not be changed yet?
- Which logs are time-sensitive?
- Who will need to rely on the evidence later?
How a specialist consultation helps
A specialist can help separate assumptions from evidence, identify time-sensitive logs, explain what should be preserved and recommend whether the matter needs forensic imaging, cyber containment, privacy review, legal support, insurance notice, bank action or platform reporting.
The safest first step is often to document the situation before changing too much. Avoid deleting accounts, wiping devices or reinstalling systems until the evidence value is considered.
Request specialist consultation
Related help
Threat types
Understand the common threat categories and how incidents overlap.
Evidence checklist
Prepare a short, useful brief before contacting a specialist.
Start an enquiry
Use the form to share key facts without exposing public email addresses.