DIGITAL FORENSICS. EXPERT TESTIMONY. SECURITY TESTING.

Digital forensics that finds facts. Security testing that measures risk.

Global Digital Forensics preserves and explains digital evidence, supports expert testimony, and tests systems for weaknesses that create real exposure. Our work extends into SCADA and OT environments, media authentication, cyber risk, and incident response.

Independent work, documented so another expert can check it.

Evidence drives connected to a forensic write blocker.

Technical practice areas

Digital evidence, security testing and operational risk.

Preserve digital evidence, test security controls or put an independent technical opinion on the record. GDF supports counsel, security leaders and operators across digital forensics, expert testimony, penetration testing, OT security, media authentication and executive cyber risk.

Browse every service and focused capability

  • Bagged hard drive beside a forensic write blocker.

    Digital evidence

    Computer & Digital Forensics

    Preserve and reconstruct activity across computers, email, cloud systems and connected evidence sources.

    Learn more
  • Fingerprint reference cards beside a livescan platen.

    Expert testimony

    Expert Witness Testimony

    Independent examination, clear reporting, deposition support and testimony prepared to withstand technical challenge.

    Learn more
  • Isolated test laptop connected to a network appliance.

    Offensive security

    Penetration Testing

    Test realistic attack paths under written rules of engagement, validate consequence and retest the fixes that matter.

    Learn more
  • Incident response plan beside a hotline handset.

    Risk validation

    Vulnerability Assessments

    Identify exposed systems and control gaps, validate material findings and prioritize remediation by practical risk.

    Learn more
  • Water treatment and electrical utility infrastructure.

    Operational technology

    SCADA & OT Security Assessments

    Assess segmentation, remote access, asset exposure and response readiness without treating a live plant like an office network.

    Learn more
  • Audio waveform and video frames under forensic review.

    Media authentication

    Media Forensics & Deepfake Analysis

    Examine questioned audio, video and images through provenance, metadata, signal analysis and analyst-led interpretation.

    Learn more
  • Evidence drives connected to a forensic write blocker.

    AI assurance

    AI Security Consulting

    Govern AI risk, test models and AI-enabled applications, and secure implementation from data flow through production monitoring.

    Learn more
  • Boardroom table prepared for a technical briefing.

    Executive risk

    Cyber Risk Assessment

    Translate technical exposure, control gaps and unresolved evidence into decisions counsel, executives and boards can act on.

    Learn more

What is at stake

Technical facts have to work in the real world.

An incident is rarely only a technical event. The facts may need to survive a courtroom, keep an operation running and make sense to the people responsible for the next decision.

  • 01 · For counsel

    • Preservation and legal hold guidance before routine activity overwrites the record.
    • Collection and analysis documented for repeatability by an opposing examiner.
    • Expert reporting and testimony support, with limitations stated in writing.
  • 02 · For operators

    • Containment sequencing that accounts for safety and process constraints.
    • OT and IT context, so a control network is not treated like an office network.
    • Remediation priorities ordered by consequence rather than by finding count.
  • 03 · For executives

    • A plain-language account of what is known, what is inferred, and what is unresolved.
    • Material risk framing for disclosure, regulatory and transaction decisions.
    • Board-ready briefings that separate fact from interpretation.

Selected outcomes

  • $228 million jury judgment

    GDF’s expert database and computer-forensics analysis was key to plaintiffs’ trial proof and helped counsel secure the landmark BNSF jury judgment; the case later settled for $75 million.

    Read the public-record case study
  • 200+ instances of fraud

    Rebuilt transaction records exposed more than $10 million in previously unidentified securities-fraud damages.

    Read the case study
  • Convictions and cross-border investigations

    Digital evidence supported convictions in the United States and investigations in five other countries.

    Read the case study
  • Federal court credibility finding

    A federal court described GDF expert testimony as reasonable, logical, and ultimately highly credible.

    Read the public-record case study

GDF software

Software built around the work.

GDF is preparing seven products for forensic collection, media analysis, privacy, case operations, source-code security and large-scale data movement. Explore what each product is designed to do and confirm current release status with our team.

  • Cloud acquisition

    eCloud Discovery

    Collect cloud evidence, reduce it to a workable review set and deliver it in the format the matter requires.

    Explore the capability
  • Remote collection

    CompleteDiscovery

    Collect supported devices remotely without asking every custodian to become a forensic examiner.

    Explore the capability
  • Media authentication

    Forensic Media Analyzer

    Examine questioned images, video and audio with several technical methods while the analyst retains the final judgment.

    Explore the capability
  • Personal privacy

    DeSpy Privacy Software

    Look for hidden tracking and monitoring signals without turning the privacy scan into another source of exposure.

    Explore the capability
  • Case operations

    Bitstream SuperHighway

    Run case operations, client communication and large evidence transfers from one working environment.

    Explore the capability
  • Cloud migration

    DataTube

    Move large data sets between cloud providers with continuous verification and a record of what moved.

    Explore the capability
  • Code security

    SourceScan

    Analyze source code, keep expert review in the workflow and track findings through remediation.

    Explore the capability

Products are approaching release. Features, integrations, provider support and availability can change by version, so confirm the current scope before relying on a product for a live matter.

Seventh pillar

Incident Response & Retainer Programs

When an incident starts, the contract should already be signed. The responders should know your environment, your safety constraints and who can authorize each action.

See retainer tiers
Incident response plan beside a hotline handset.

Industries

Where the work happens

Sectors where the consequence of a wrong answer is measured in verdicts, outages, valuations or licenses.

  • 01

    Legal

    Preservation, examination and expert reporting for matters that will be tested.

  • 02

    Utilities & Critical Infrastructure

    OT and ICS work in environments where availability and safety come first.

  • 03

    Financial Services

    Insider activity, account compromise and transaction records, examined independently.

  • 04

    Insurance

    Factual basis for claimed loss, response timelines and control representations.

  • 05

    Private Equity & M&A

    What cyber risk is being acquired, and what it costs to fix after close.

  • 06

    Government

    Reproducible technical findings for oversight, procurement and prosecutorial use.

  • 07

    Healthcare

    Evidence and security work planned around care delivery, ePHI and connected systems.

Working with us

The work is meant to be checked.

An independent examiner should expect questions. We write for the person who will challenge the method or disagree with the conclusion.

  • Before

    Retainers, preservation protocols, response plans and tabletop exercises are agreed while there is time to argue about them. Scope, rates and contacts are settled in advance.

  • During

    Evidence is preserved first and analyzed second. Observed facts, expert interpretation and open questions are kept separate in every status update, including the uncomfortable ones.

  • After

    You receive a written record that another qualified examiner could follow: methodology, evidence handling, findings, stated limitations, exhibits, and testimony support where the matter calls for it.

Insights

What we are seeing

Analysis for counsel, boards, utility executives and deal teams. All insights

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.