Independent technical practice
Forensics and assessment for public agencies
Independent examiners for agencies, authorities and public bodies, where the record must withstand oversight as well as litigation.
Exposure
Why public systems are exposed
Public agencies run some of the oldest and most interconnected estates in operation: legacy applications, records systems with decades of retained data, and operational technology in water, transit, courts and public safety. Replacement cycles are set by budget cycles, so risk has to be managed around systems that will not be modernized soon.
Agencies also hold some of the most sensitive categories of data: criminal justice information, benefits and tax records, health data and biometric records. That data crosses jurisdictions and is shared with contractors and neighboring authorities, multiplying both access paths and notification consequences.
Municipalities and special districts face the same threats as federal agencies with a fraction of the staff. Ransomware against local government has shown that disruption to courts, utilities, emergency dispatch and permitting falls on residents, not an IT department.
Scoping
Questions the engagement must answer
- What handling, classification and access constraints apply to the evidence?
- Which findings must be reproducible by an internal team after the engagement ends?
- How will the work support an inspector general, oversight or prosecutorial process?
- What are the interoperability and records-retention requirements for deliverables?
- Which limitations must be documented for a public or oversight audience?
Services
How we help
-
Digital Forensics & Expert Witness
Investigation, evidence handling and testimony for administrative, civil and criminal proceedings.
-
Critical Infrastructure & OT Security
Assessment of water, transit, public safety and facility control systems in live operating conditions.
-
Biometrics & Identity Sciences
Independent examination of fingerprint, facial and identity evidence by qualified scientists.
-
Incident Response & Retainer Programs
Pre-contracted response so procurement is not the first task after an incident is declared.
Context
Regulatory context
- CJIS
- Agencies handling criminal justice information work to federally defined security policy covering access control, auditing, encryption and personnel screening, including for contractors.
- FISMA and NIST frameworks
- Federal systems and many federally funded programs are assessed against NIST-based control catalogs, with continuous monitoring and documented authorization expected.
- State and local mandates
- State information security offices, election authorities and public utility commissions each impose their own assessment and reporting requirements on covered bodies.
- Public records and retention
- Investigations touch records governed by retention schedules and disclosure law, so preservation is planned with those obligations in view.
Requirements vary by agency, funding source and jurisdiction; scope is set against the frameworks that apply to you.
Related case study
Drug Diversion Investigation
Investigation into diversion of controlled substances using system and access records.
Digital Forensics
Talk with an examiner
Discuss the matter and the next step.
Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.
24/7 hotline: 1-800-868-8189