Independent technical practice

Independent digital forensics since 1992

Global Digital Forensics was founded to answer one kind of question: what actually happened, and can you prove it.

Boardroom table prepared for a technical briefing.

The firm

What we are, and what we are not

For over three decades we have been retained by law firms, corporations, utilities, insurers, government agencies and boards to examine digital evidence and explain it under scrutiny. Our examiners have testified in civil and criminal matters, supported regulators, and been engaged on investigations across the United States and internationally.

Our technical opinions are not tied to a remediation sale. Any GDF software used or discussed is identified separately from the scope, methods and conclusions of the engagement. Findings are documented for decision-makers and for the technical reviewers who may test them.

Today the firm operates from 16 regional offices with a 24/7 hotline, and covers digital forensics and expert witness work, biometrics and identity sciences, critical infrastructure and OT security, cyber due diligence, executive cyber risk advisory, and AI and deepfake analysis.

Standards

Credentials & certifications

  • Court-qualified expert witnesses

    Examiners who have been accepted by courts, deposed and cross-examined, in civil and criminal matters.

  • Certified forensic examiners

    Practitioners holding recognized digital forensic examiner certifications and vendor tool certifications for the platforms used in acquisition and analysis.

  • Biometrics and identity science

    Latent print and identity examination performed by qualified scientists rather than subcontracted out.

  • Documented methodology

    Written acquisition, hashing, chain-of-custody and reporting procedures applied to every engagement and produced on request.

  • Standards alignment

    Analysis and reporting aligned to accepted forensic practice and to the framework the matter or regulator requires.

  • Confidentiality by default

    Engagements run under confidentiality; clients are never named and never appear on this site.

The engagement record identifies the examiner, methodology and credentials relevant to the matter. Supporting credential evidence is available during scoping and expert qualification.

People

Team

Certified examiners, court-tested expert witnesses and infrastructure specialists who remain independent in every engagement.

Specialist-led by scope

Each matter is staffed around the evidence, forum and operational constraints involved. Clients receive the qualifications of the assigned examiners before work begins, while public profiles remain limited to protect personnel and confidential engagements.

Coverage

Locations

Sixteen listed locations and one 24/7 hotline: 1-800-868-8189 · International +1.727.287.6000. Ask about response coverage for the location and systems involved.

Working with us

Partnership Program

We work as the forensics, deepfake and critical infrastructure capability behind law firms, insurers, breach coaches, managed service providers and consultancies. They work under their engagement while keeping their client relationship intact.

Discuss partnership program

Knowledge transfer

Training

We deliver practitioner and executive training on digital evidence handling, incident readiness and operational technology security, from courtroom-facing evidence workshops for counsel to tabletop exercises for utility and board audiences.

Discuss training

Firm background

Practice, training and partnerships

Background on how the practice developed and how related work is organized.

How the practice was built

The firm was founded in 1992 around cyber security: preventing breaches and limiting the damage when they happened. Forensics followed from that work: investigating an incident leads to identifying who caused it, and identifying who caused it only matters if the finding holds up in court. Engagements since have spanned finance and banking, government, defense manufacturing, healthcare and insurance, with response delivered across the United States, Europe and Asia.

Training that is vendor neutral

The computer forensics and electronic discovery curriculum teaches examination by hand before tooling: the history behind current procedure, disk and file system storage including FAT and NTFS structures, recovery from slack and unallocated space, and the accepted principles that keep an examination defensible. The course is deliberately not built around one vendor's product, because an investigator who can only run a tool cannot explain a result.

Partnership program

Qualified forensic and security practitioners can deliver work locally under the firm's engagement, methodology and management, with no quotas and no participation fees. Because partners are trusted with confidential client matters, final applicants are background checked.

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.