Independent technical practice
Digital forensics and cybersecurity insights
Publications and case studies for counsel, boards, technical leaders, insurers and deal teams.
Insights archive
Every post, filtered by topic
Filter by topic to narrow the archive. 112 posts total.
Suspected Token Theft: What Evidence Should Your Business Preserve?
Business Email Compromise: Coordinate the First 24 Hours
Map Evidence Across Tenants, Providers and Acquired Businesses
Preservation Failures at Enterprise Handoffs
Scoping Digital Forensics Across an Organization
Prepare the Digital Expert's Technical File for Scrutiny
Validate a Mobile Location Timeline Before You Map It
SHIELD Act Response: Reconcile the Enterprise Data Record
Part 500: Test Shared Controls Across Business Entities
Validate OT Boundaries Across a Multi-Site Operation
Build an OT Inventory That Can Be Compared Across Plants
Reconcile Teams, Slack and Email Collections Before Review
AI Red Teaming With Findings That Can Be Reproduced
Authenticating Questioned Media: Provenance, Pixels and Context
Cyber Due Diligence Before Close: Questions That Can Affect Deal Terms
Digital Evidence That Can Withstand Cross-Examination
Preserving Evidence in the First Hours of Incident Response
Scoping OT Security Testing Around Operational Risk
Time is Running Out to Get Mandated Cybersecurity Compliance Testing Done Before Year’s End
How to Deal with Sextortion Scams
10 Steps to a More Secure Mobile Workforce
DFARS CMMC Draft has been released.
Digital Forensics-Security Info-graphic - Maryville University
From Cyber Risk Assessments through Emergency Response - GDF Offers Unified Solutions for 2018
Hollywood Hospital Victimized by Ransomware: “Locky” Spreading Fast
Cyber Risk Assessment through Emergency Incident Response - GDF Offers Unified Solutions for 2016
Hacked for the Holidays? Global Digital Forensics can Help
Small Businesses are Big Targets for Cyber Attacks
Want Affordable Cyber Insurance? Healthy Cyber Security Helps
Most Healthcare Organizations Lacking Against Phishing Attacks
SEC’s 2nd Push on Cyber Security Focuses on Risk Assessment
IT Security Beware: A Cyber Security Nightmare at Work Can Start at Home
Business Cyber Security: Come Out of the Summer with a Clean Slate
Digital Forensics Moving Closer to the Center of the Clinton Email Drama
Executives Failing Hard Regarding Employee Cyber Security Awareness
The Internet of Things Poised to be the Next Big Bang in Cyber Security and eDiscovery
Frenemy at the Gates - Hackers Excel at Leveraging Trust
Mobile Apps Are a Major Gateway for Hackers
Effective Response Plan Key to Surviving a Data Breach
Out of Sight, Out of Mind: Hackers Bank On It
New FTC Scam Alert Shows Latest Example of Social Engineering Dangers
Hackers Still Going Hard After Banks - But Employees Are Now Prized Targets
Corporate Cyber-Espionage Can Be a Major League Headache for Any Business
Mobile Forensics Often the Key to Finding Answers
Cyber Security Tips for a Safer and Happier Summer Vacation
IRS Attack Exemplifies the Compounding Dangers of Stolen Personal Data
One Headline Making Cyber Attack Sparks Discovery of Another
APTs Top the List of Scariest Cyber Threats
The Effectiveness of Spear Phishing Not Lost on Cyber Terrorists
Cyber Aftershocks from Nepal’s Earthquake Can Cripple Businesses Right Here at Home
An Outsider’s Perspective on Cyber Security Can Only Benefit CIOs
Cyber Attackers Continue to Fine Tune Deception and Stealth Tactics
Digital Evidence Best Chance for Answers in Germanwings Air Disaster
Businesses Dealing With PCI Falling Short On Regular Vulnerability Scans and Pen Testing
Boston Bombing Trial Sets Sights on Digital Evidence
Application Security Too Often Overlooked on the Cyber Front
Managing Cyber Risks a High Priority for Healthcare and Insurers
DIY Phishing and Malware Kits Make it Easy to Compromise Businesses
Hackers Use Patience, Persistence and Patsies to Fleece Banks
Healthcare Providers and Insurers Can Expect Increased Cyber Security Scrutiny in Their Future
RansomWeb Kicks the Problem of Ransomware Into a Whole New Gear
FBI Cyber Scam Warning: BEC Scams
Report Shows Targeting Users a Steam-Gathering Trend for Hackers
Accident Attorneys Should Leave No Phone Unturned in 2015
Insider Cyber Threats are an Escalating Danger for Businesses
Better Cyber Security Should Be High on the Resolution List for Businesses in 2015
Sony Pictures Hack Perfect Example of the Reach a Single Cyber Attack Can Have
It’s No Secret - This is the Trifecta Most Cyber Attackers Rely on to Hit it Big
Holiday Phishing Can Pose Real Threat To Business Networks
Nothing Builds a Timeline for Attorneys on a Case like Digital Evidence
Cyber Espionage Room Service - DarkHotel Hackers Target High Ranking Executives and Officials
Targeted Cyber Attacks Expected to Rise in 2015
Third Party Hacks Can Pose Significant Threat to Businesses
Another FBI Cyber Attack Warning for US Businesses
Cybercrime Insurance Industry Poised to Explode, But Danger Lurks
Disgruntled Employees Can Be Insider Cyber Threats Waiting to Happen Warns FBI
Survey Shows Cyber Emergency Response Plans Need to be Regularly Flexed to Stay Effective
Don’t Let Data Breach Fatigue Cause Dangerous Cyber Security Complacency
Hacking Retail Whales Can Start With Just One Little Phish
Are the Dominoes Starting to Fall After Historic Bounty of User Credentials Stolen?
Safe Harbor Notice
Big Name Bank Hacks Highlight the Importance of Regular Testing and Effective Emergency Response
Prominent Hospital Group Falls Prey to Hackers Believed to be Based in China
SANS Survey Shows Most Businesses Lacking Effective Cyber Emergency Repsonse Plans
Russian Hackers Steal over a Billion Credentials
Black Hat USA 2014 Will Again Stress Need for Security Basics
Businesses the New Target for Nigeria’s 419 Cyber-Scammers
Cyber Security and eDiscovery Complicated in the Cloud
Mobile Device Forensics Guidelines Play Key Role in Supreme Court’s Smartphone Evidence Warrant Decision
Financial Trojan EMOTET Uses Network Sniffing
Hackers Target Critical Infrastructure SCADA Systems with Havex Trojan
Litigation-Forensic Readiness Can Play a Crucial Role
The Covert Devaluation of US Businesses: Hackers Stealing IP
The Scary Hacking Power of Big Botnets
eBay Hacked
Iranian Hackers Use Facebook and Others For Cyber Attack
Are Your Cyber Security Measures Doomed to Failure?
Social Engineering Awareness Crucial to Survive Today’s Cyber Threats
Cyber Attacks Can Take a Heavy Toll
Cyber Security Tips for Safer Travels
Law Firm Used as Watering Hole in Energy Sector Attack
Lawyers and Law Firms Prime Targets for Hackers
Beware of Hackers Using Watering Hole Attacks
POS Systems-Malware-XP-2014-Threat-Trifecta-for-Retailers
Smart Appliances and Other SPPDs Hacked
Hack Gives Snapchat a Black Eye on Privacy
Holiday Cyber Security
Top Holiday Cyber Scams
7 Simple Tips to Prevent Malware Infections
Could badBIOS Change Cyber Security?
Kids, there are some things you CAN try at home. Do-it-yourself (DIY) e-discovery in 2012
Electronic Discovery 2012: Coming Back to Earth, by way of the “Cloud”
Insights
Publications and case studies
Publications explain the technical and decision issues. Case studies show how evidence was used in real matters while protecting client confidentiality.
Current publications
Guidance for evidence and risk decisions
Original analysis grounded in public standards, with practical limits stated alongside the method.
-
Evidence practice
Digital Evidence That Can Withstand Cross-Examination
A practical framework for collecting, documenting and explaining digital evidence when the method and conclusion may be challenged.
-
Incident response
Preserving Evidence in the First Hours of Incident Response
A first-hours incident response checklist for containing harm while protecting volatile evidence, timelines and later investigative options.
-
Operational technology
Scoping OT Security Testing Around Operational Risk
How to scope OT and ICS security testing around safety, reliability, engineering authority and evidence that decision-makers can use.
-
Transactions
Cyber Due Diligence Before Close: Questions That Can Affect Deal Terms
A pre-close cyber due diligence framework for testing identity, exposure, incident history, integration risk and the cost of remediation.
-
Media authentication
Authenticating Questioned Media: Provenance, Pixels and Context
A practical method for examining questioned images, audio and video without treating provenance metadata or AI detection as a truth machine.
-
AI security
AI Red Teaming With Findings That Can Be Reproduced
How to turn AI red teaming from an alarming demo into a reproducible finding with scope, evidence, impact and a retest path.
Current publications
Technical field notes
Practical records, checks and decision points for evidence collection, incident response and operational security.
-
Enterprise incident response
Business Email Compromise: Coordinate the First 24 Hours
Coordinate finance, identity and evidence teams after business email compromise. Track payment changes, cloud records and containment across units.
-
Evidence preservation
Preservation Failures at Enterprise Handoffs
Prevent evidence loss during employee departures, device replacements and cloud changes. Define preservation gates and document exceptions across teams.
-
Planning the engagement
Scoping Digital Forensics Across an Organization
Questions for counsel and technical owners planning digital forensics across devices, cloud tenants and business units, from access to reporting scope.
-
Expert methodology
Prepare the Digital Expert's Technical File for Scrutiny
Build an opinion-to-source record for digital expert evidence. Document validation, alternative explanations and limitations before a Rule 702 challenge.
-
Mobile evidence analysis
Validate a Mobile Location Timeline Before You Map It
Reconcile device, application and account location records. Preserve time conversions, uncertainty and attribution limits in a defensible mobile timeline.
-
Enterprise breach evidence
SHIELD Act Response: Reconcile the Enterprise Data Record
Reconcile repositories, record populations and evidence gaps after a breach involving New York data. Technical support for multi-state businesses.
-
Financial-services control evidence
Part 500: Test Shared Controls Across Business Entities
Map shared identity, infrastructure and testing evidence to the entities they serve. Document Part 500 coverage, exceptions and remediation retests.
-
Operational technology boundaries
Validate OT Boundaries Across a Multi-Site Operation
Validate OT architecture against plant connections, vendor access and approved process flows. Record site exceptions and safe retest conditions.
-
OT asset coverage
Build an OT Inventory That Can Be Compared Across Plants
Build an OT inventory across plants using passive observations, engineering records and explicit coverage limits. Test what each sensor can actually see.
-
Collaboration evidence
Reconcile Teams, Slack and Email Collections Before Review
Reconcile messages, channel membership, attachments and export gaps across Teams, Slack and email before handing enterprise collections to a review team.
-
Cloud collection planning
Map Evidence Across Tenants, Providers and Acquired Businesses
Map cloud evidence across tenants and acquired businesses. Record ownership, access, retention, export limits and validation before collection begins.
Archive
Explore the archive
94 historical articles published on the original site, preserved with their original URLs and dates.
-
Archive
Time is Running Out to Get Mandated Cybersecurity Compliance Testing Done Before Year’s End
October 17, 2019
-
Archive
How to Deal with Sextortion Scams
October 2, 2019
-
Archive
10 Steps to a More Secure Mobile Workforce
September 24, 2019
-
Archive
DFARS CMMC Draft has been released.
September 12, 2019
-
Archive
Digital Forensics-Security Info-graphic - Maryville University
February 27, 2017
-
Archive
From Cyber Risk Assessments through Emergency Response - GDF Offers Unified Solutions for 2018
January 19, 2017
Talk with an examiner
Discuss the matter and the next step.
Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.
24/7 hotline: 1-800-868-8189