Digital evidence and security
Boston Computer Forensics
Computer forensics, expert witness support and security testing for Greater Boston businesses, research teams and counsel.
Plan collection around your people and equipment
Were research files shared outside the approved project team, and which account shared them?
Research records may sit in a project account, an individual mailbox and a locally synchronized folder. We can coordinate remote email collection while the account remains in use, then discuss the computer or phone sources needed to connect the messages with the project files.
Preserve project and research records around a departure
For a Greater Boston research or technology matter, start with the specific project, source repository or shared research folder involved. Identify the email accounts, collaborators and record owners alongside the departing person's computer. GDF can plan the collection around those connected sources.
A project history may be distributed between collaboration tools, versioned files and messages. Give counsel and the forensic team the relevant project dates, account administrators and record identifiers. This helps the examination connect document access, email communication and the movement of proprietary information.
Employee email theft and company-file transfers in Boston
Explore flat-rate employee exit Core Analysis or a broader trade-secret forensic examination for your matter.
For an executive departure or partner separation, discuss the business records, account authority and decisions the examination should support.
Can a Boston employee departure review include research documents?
Yes. We can scope authorized project records, email, cloud storage and related computer activity. The collection plan identifies the systems holding the research material and the records needed to trace access or transfer.
Plan the service around your Boston team
Explore the evidence sources, security assessment methods and expert deliverables for the engagement you need.
- Outlook, Microsoft 365, OneDrive and SharePoint evidence
- Gmail, Google Workspace and Drive collection
- Cloud file sharing and account activity
- AI security assessment and deployment review
- OT, ICS and SCADA security assessments
- AI expert reports and testimony
- Answers about collection, costs and forensic reports
Start with the question the evidence needs to answer
Research and commercial disputes often depend on more than a document's visible contents. Revision history, repository access, laboratory records and messages may explain when a file existed, who could access it and how it moved. GDF helps Boston-area clients identify those sources before retention settings or routine device reuse alter the record.
A useful scope connects the business question to specific evidence. It also identifies what cannot be established from the available material. Recoverability depends on the device, encryption, provider access and retention history; no examiner can promise that every deleted item will be available.
Evidence priorities in Greater Boston
MassBio's industry reporting documents Massachusetts' life-sciences sector. For a Greater Boston research or technology matter, laboratory systems and collaboration platforms may be as important as conventional computers and email. Their record formats, permissions and audit settings need individual review.
Scope the work to the matter
Research data and intellectual property
Preserve the relevant project versions, source repositories, electronic notebooks and access records. Separate authorship, possession and transfer questions: a file on a device does not by itself establish who created it or whether a trade secret was used. Compare independent records and explain limits in the resulting timeline.
Cloud and distributed custodians
A Boston team may use email, shared storage and messaging platforms administered by different organizations. Identify the correct tenant and account, the available export method and whether a preservation hold has actually been applied. Keep collection logs and reconcile expected sources against what was delivered.
Applications and sensitive workflows
Security testing for a research or software organization should describe the application, user roles, data boundaries and connected services. Agree on test accounts, permitted techniques and handling of sensitive records. Findings should include reproducible evidence, a practical remediation owner and a way to verify the correction.
Services available through GDF
Use the technical service pages for methods, evidence sources and deliverables.
- Computer and hard drive forensics
- Mobile device forensics
- Email and cloud evidence
- Expert witness support
- Penetration testing
- Vulnerability assessments
- Application penetration testing
- Incident response
- eDiscovery collections
- Departing employee analysis
- Evidence-aware data recovery
- OT and SCADA security
- AI security consulting
Arrange an evidence or security consultation
For Greater Boston work, describe the project or event, the organizations that administer the records and any device or account scheduled for reuse. If a matter involves counsel, coordinate the scope and communication channel before collecting privileged or confidential material.
Text-message evidence for Massachusetts matters
A disputed message raises several different questions: whether the displayed conversation is complete, whether a record was changed, and what connects the account or device to the person alleged to have sent it. GDF helps Boston counsel examine those questions using authorized phone, backup and account evidence.
The Massachusetts Guide to Evidence discusses authentication through witness knowledge and surrounding circumstances. A forensic extraction is not the only possible foundation, and a screenshot is not automatically inadmissible. Counsel determines the legal foundation and the court decides admissibility. Our work documents the available technical evidence and its limitations.
- Preserve context: Identify the application, participants, relevant dates, attachments and connected accounts. Retain the original screenshots as well as any available underlying messages.
- Compare sources: Where authorized and available, compare device records, backups and the other participant's messages. Account names and contact labels alone do not establish who typed a message.
- Explain the timeline: Record source timestamps, time-zone conversions and gaps. Export order, delivery time and the time displayed on a phone may differ.
- Document limits: Encryption, application versions, retention and device condition affect access. Deleted messages, edit history and read receipts are not recoverable in every collection.
Before changing settings, resetting a device or running recovery software, discuss its current state with the examiner. Agree on authorized access, collection scope, custody records and the required report or exhibits. A hash identifies the collected data set; it does not independently prove authorship.
Read the Massachusetts authentication guidance and digital-evidence guidance. For acquisition methods and litigation deliverables, see mobile device forensics and expert witness services.
OT monitoring evidence for New England operators
A utility or industrial operator needs to know which control-system communications are visible, which are not, and who will act on an alert. For a Greater Boston or New England engagement, bring operations, engineering, IT and the compliance lead into the scope discussion before connecting a sensor or changing network configuration.
GDF can review network architecture, passive visibility, remote-access paths and incident evidence. Start with the approved asset inventory and network diagrams, then identify safe observation points and known blind spots. A monitoring product alone does not establish complete coverage or regulatory compliance.
- Observation: Document the network segments and protocols visible at each collection point, along with packet loss, encrypted traffic and unmonitored links.
- Operating context: Compare observed communications with engineering expectations and approved maintenance activity. Confirm safety constraints and change-control requirements.
- Response: Assign alert review, escalation and evidence-preservation responsibilities. Exercise the handoff between the security team and plant or control-room personnel.
- Work product: Request a coverage map, identified gaps, supporting records and a prioritized remediation plan with owners and retest criteria.
For NERC CIP planning, the responsible compliance team must confirm the applicable standard version, system classification and implementation schedule. Do not assume that one date applies to every New England utility, water system or manufacturer. Use NERC's current standards and implementation plans for the governing requirements.
See OT network assessment methods, ICS and SCADA security assessments and OT incident response. These national pages describe the technical scope; the Boston team can help plan source access, operating windows and local coordination.
Frequently asked
Questions about Boston engagements
Can an examination include electronic laboratory records?
It can, subject to authorized access and the system's export capabilities. Discuss version history, audit trails, attachments, record identifiers and vendor limitations. A PDF export may not contain the metadata needed to answer the question.
Can you review another examiner's findings?
An independent review can examine the available acquisition records, methods, artifacts and reasoning. The scope depends on access to the underlying evidence; reviewing a report alone is not the same as repeating the examination.
Before collecting evidence
For an active incident, call 1-800-868-8189.
Talk with an examiner
Talk with the local team
Tell us where the people, devices or retaining team are located and the matter you need help with.
Since 1992 · 24/7 dispatch · Court-tested experts
Talk with an examiner
Discuss the matter and the next step.
Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.
24/7 hotline: 1-800-868-8189