Evidence and readiness

Forensic Readiness Assessment

Prepare evidence sources, retention, escalation and collection procedures before an incident or eDiscovery request creates a deadline.

Incident response plan beside a hotline handset.

Global Digital Forensics | Updated September 9, 2026

Prepare before an incident or discovery request

Forensic readiness means knowing where relevant information resides, who can preserve it and how to collect it when a matter arises. A readiness assessment examines those practical steps before an incident, employee departure or discovery request creates an urgent deadline.

Global Digital Forensics reviews the evidence sources, access arrangements and response procedures that support your environment. The result is a documented set of gaps and actions, with owners and priorities. It supports technical preparation; it does not guarantee a particular litigation outcome or prevent every incident.

Inventory data stores and responsible people

Map user roles to the systems they use: endpoints, email, messaging, cloud storage, business applications, mobile devices and shared repositories. Identify administrators, service providers and escalation contacts. Include remote work, third-party systems and backups rather than limiting the inventory to the corporate network.

For each source, record retention settings, available logs, export options, time-zone behavior and access requirements. Check whether the people expected to preserve evidence actually have the necessary permissions. Document sources that cannot be collected with current tools or agreements.

Align retention and preservation procedures

Review how normal retention operates and how an authorized preservation instruction changes that process. A backup schedule is not necessarily a legal hold, and a legal hold does not by itself confirm that every relevant source is preserved. Test the technical steps that suspend deletion or retain required records.

Identify who approves exceptions, how instructions reach custodians and administrators, and how completion is recorded. Counsel defines legal obligations and scope. Technical procedures should make those directions executable and show where platform limitations require an alternative.

Discuss the sources and deadline

Tell us what you need to establish and which systems are available.

Talk with a forensic expert

Define escalation and first response

Build an escalation matrix around incident type, affected systems, data sensitivity and business impact. Identify decision makers for containment, preservation, external support and communications. Include a fallback contact when the primary person is unavailable.

First-response guidance should explain what to document and which actions require specialist advice. Routine remediation, account resets or device handling can change evidence. The plan should coordinate preservation with containment and operational needs rather than requiring staff to improvise under pressure.

Test collection and delivery

Exercise a representative collection from the systems most likely to matter. Check that permissions work, exports complete, metadata remains usable and the receiving team can open the result. Record the acquisition method, integrity checks and custody handoff.

Agree on search and production protocols for recurring eDiscovery needs. A procedure should identify relevant sources, preserve an original copy and record filters or transformations. If a restore from backup is part of the plan, test the restore and document the environment required to interpret it.

Turn the assessment into an operating plan

  • A source and custodian matrix with access owners and retention risks.
  • A prioritized gap list with concrete remediation tasks.
  • Preservation and collection procedures for selected systems.
  • An escalation matrix and technical handoff checklist.
  • Exercise findings, unresolved limitations and a retest plan.

Train the people expected to use the plan, then repeat exercises after significant system or staffing changes. Keep contacts and platform instructions current. For a scoping conversation, share the main platforms, existing response plan and the events you most need to prepare for.

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.