Before asking how many computers to collect, decide what the examination must establish. A suspected transfer of source code, a disputed approval and a ransomware event call for different sources. The useful starting point is a question, a deadline and a list of systems that could answer it.
Who can authorize access to each source?
Business ownership and technical access are not the same. A subsidiary may use a parent company's tenant; a service provider may control exports; a departing administrator may hold the only recovery information. Identify the authorized decision-maker and the person who can perform the collection for each source. Counsel addresses rights, restrictions and legal scope.
Do we need full-device acquisition or a targeted collection?
Choose the method against the disputed facts. A targeted export may efficiently preserve known business messages but omit deleted records, application databases or system artifacts needed to test another explanation. A larger acquisition can preserve more context while increasing processing and review obligations. Document the tradeoff before treating a narrow collection as a complete record.
Can operations continue during the work?
Often they can, but the answer depends on the source. A live server, a powered-on encrypted phone and a damaged drive present different risks. Record current condition and obtain source-specific handling instructions. Life safety and urgent containment take priority. Do not power down or isolate equipment reflexively when doing so may destroy accessible evidence or disrupt a critical process.
What should the estimate include?
Separate acquisition, processing, analysis and reporting. Identify source counts, access assumptions, encryption, data volume, collection windows and review responsibilities. Set decision points for expanding the work when the first findings reveal another system or custodian. Deleted-data recovery should be assessed, not promised; storage behavior, encryption, overwrite and retention can prevent it.
How will findings move into a report or testimony?
Agree on deliverables at intake. A chronology for a response team differs from an expert report that must explain methods, facts, alternatives and limitations. Retain the underlying acquisition records, tool settings and working notes so the conclusion can be tested. A chart without traceable source records is a presentation, not a complete technical file.
For a first discussion, prepare the technical question, deadlines, known systems, authorized contacts and actions already taken. Do not send passwords or sensitive evidence through an ordinary contact form. Start with computer forensics, eDiscovery or expert-witness services, according to the work required.
Source guidance
NIST's forensic incident-response guide and mobile-device forensics guide provide technical background. This checklist concerns engagement planning, not legal advice.