DIGITAL FORENSICS. EXPERT TESTIMONY. SECURITY TESTING.
Digital forensics that finds facts. Security testing that measures risk.
Global Digital Forensics preserves and explains digital evidence, supports expert testimony, and tests systems for weaknesses that create real exposure. Our work extends into SCADA and OT environments, media authentication, cyber risk, and incident response.
Independent work, documented so another expert can check it.
- Since 1992
- 24/7 incident response
- Court-tested experts
- National and global reach
Technical practice areas
Digital evidence, security testing and operational risk.
Preserve digital evidence, test security controls or put an independent technical opinion on the record. GDF supports counsel, security leaders and operators across digital forensics, expert testimony, penetration testing, OT security, media authentication and executive cyber risk.
-
Digital evidence
Computer & Digital Forensics
Preserve and reconstruct activity across computers, email, cloud systems and connected evidence sources.
Learn more -
Expert testimony
Expert Witness Testimony
Independent examination, clear reporting, deposition support and testimony prepared to withstand technical challenge.
Learn more -
Offensive security
Penetration Testing
Test realistic attack paths under written rules of engagement, validate consequence and retest the fixes that matter.
Learn more -
Risk validation
Vulnerability Assessments
Identify exposed systems and control gaps, validate material findings and prioritize remediation by practical risk.
Learn more -
Operational technology
SCADA & OT Security Assessments
Assess segmentation, remote access, asset exposure and response readiness without treating a live plant like an office network.
Learn more -
Media authentication
Media Forensics & Deepfake Analysis
Examine questioned audio, video and images through provenance, metadata, signal analysis and analyst-led interpretation.
Learn more -
AI assurance
AI Security Consulting
Govern AI risk, test models and AI-enabled applications, and secure implementation from data flow through production monitoring.
Learn more -
Executive risk
Cyber Risk Assessment
Translate technical exposure, control gaps and unresolved evidence into decisions counsel, executives and boards can act on.
Learn more
What is at stake
Technical facts have to work in the real world.
An incident is rarely only a technical event. The facts may need to survive a courtroom, keep an operation running and make sense to the people responsible for the next decision.
-
01 · For counsel
- Preservation and legal hold guidance before routine activity overwrites the record.
- Collection and analysis documented for repeatability by an opposing examiner.
- Expert reporting and testimony support, with limitations stated in writing.
-
02 · For operators
- Containment sequencing that accounts for safety and process constraints.
- OT and IT context, so a control network is not treated like an office network.
- Remediation priorities ordered by consequence rather than by finding count.
-
03 · For executives
- A plain-language account of what is known, what is inferred, and what is unresolved.
- Material risk framing for disclosure, regulatory and transaction decisions.
- Board-ready briefings that separate fact from interpretation.
Selected outcomes
-
$228 million jury judgment
GDF’s expert database and computer-forensics analysis was key to plaintiffs’ trial proof and helped counsel secure the landmark BNSF jury judgment; the case later settled for $75 million.
Read the public-record case study -
200+ instances of fraud
Rebuilt transaction records exposed more than $10 million in previously unidentified securities-fraud damages.
Read the case study -
Convictions and cross-border investigations
Digital evidence supported convictions in the United States and investigations in five other countries.
Read the case study -
Federal court credibility finding
A federal court described GDF expert testimony as reasonable, logical, and ultimately highly credible.
Read the public-record case study
GDF software
Software built around the work.
GDF is preparing seven products for forensic collection, media analysis, privacy, case operations, source-code security and large-scale data movement. Explore what each product is designed to do and confirm current release status with our team.
-
Cloud acquisition
eCloud Discovery
Collect cloud evidence, reduce it to a workable review set and deliver it in the format the matter requires.
Explore the capability -
Remote collection
CompleteDiscovery
Collect supported devices remotely without asking every custodian to become a forensic examiner.
Explore the capability -
Media authentication
Forensic Media Analyzer
Examine questioned images, video and audio with several technical methods while the analyst retains the final judgment.
Explore the capability -
Personal privacy
DeSpy Privacy Software
Look for hidden tracking and monitoring signals without turning the privacy scan into another source of exposure.
Explore the capability -
Case operations
Bitstream SuperHighway
Run case operations, client communication and large evidence transfers from one working environment.
Explore the capability -
Cloud migration
DataTube
Move large data sets between cloud providers with continuous verification and a record of what moved.
Explore the capability -
Code security
SourceScan
Analyze source code, keep expert review in the workflow and track findings through remediation.
Explore the capability
Products are approaching release. Features, integrations, provider support and availability can change by version, so confirm the current scope before relying on a product for a live matter.
Industries
Where the work happens
Sectors where the consequence of a wrong answer is measured in verdicts, outages, valuations or licenses.
-
01
Legal
Preservation, examination and expert reporting for matters that will be tested.
-
02
Utilities & Critical Infrastructure
OT and ICS work in environments where availability and safety come first.
-
03
Financial Services
Insider activity, account compromise and transaction records, examined independently.
-
04
Insurance
Factual basis for claimed loss, response timelines and control representations.
-
05
Private Equity & M&A
What cyber risk is being acquired, and what it costs to fix after close.
-
06
Government
Reproducible technical findings for oversight, procurement and prosecutorial use.
-
07
Healthcare
Evidence and security work planned around care delivery, ePHI and connected systems.
Insights
What we are seeing
Analysis for counsel, boards, utility executives and deal teams. All insights
-
Biometrics
Biometrics in the Courtroom
What judges actually ask when identity evidence is challenged.
-
Due Diligence
Cyber Due Diligence During M&A
The five findings that most often change a purchase price.
-
AI & Deepfake
The Rise of Deepfake Evidence
How synthetic media is tested, and where authentication fails.
Talk with an examiner
Discuss the matter and the next step.
Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.
24/7 hotline: 1-800-868-8189