Digital Forensics FAQ

Clear answers to common questions before you send an enquiry.

Common questions

Should I turn off a compromised computer?

If an incident is active, disconnecting from the network may help contain risk, but powering off can sometimes lose volatile evidence. If safe, preserve photos and notes first, then ask for advice.

Should I delete a phishing email?

Not immediately. Keep the original message, sender details, links and attachments so the incident can be assessed. You can move it to a safe folder if needed.

Can you guarantee recovery after ransomware?

No responsible specialist should guarantee recovery without reviewing backups, systems and the attack path. The aim is to preserve evidence, contain risk and build the safest recovery pathway.

What if money was redirected?

Contact your bank immediately using official channels. Then preserve emails, invoices, phone notes and payment records. Business email compromise and invoice fraud can be very time-sensitive.

What if I suspect spyware?

Use a separate trusted device if safety may be involved. Avoid confronting the suspected person or changing settings in a way that may increase risk until you have safe advice.

Do you publish an email address?

No. Public contact is through the enquiry form so each matter arrives with the key facts and is easier to triage.

Start an enquiry

Related help

Evidence checklist

A practical list of what to preserve before logs, screenshots or account records disappear.

Need clear next steps?

Speak with a digital forensic specialist before evidence is lost.

Tell us what happened, what devices or accounts are involved, and how urgent it is. We will help you frame the right response.

Request a consultation