Technical services

Digital forensics, cybersecurity and OT security

GDF examines digital evidence, validates adversarial attack paths and assesses operational systems. Each engagement is scoped to the decision, records its sources and methods, and produces work another qualified practitioner can test.

Isolated test laptop connected to a network appliance.

Field capability

  • Legalevidence and testimony
  • Cybercontrol validation
  • OTsafety and resilience

Engagement paths

Technical scope by audience

The forum, operating environment and decision determine the method. Each path below identifies the technical record GDF is retained to produce.

CISOs and IT managers

Validated attack paths and remediation evidence

Human-led penetration testing traces adversarial attack paths through internet-facing services, internal networks, identity systems, cloud control planes, applications and APIs. A practitioner reproduces each material finding before it enters the report.

Findings are ranked for material risk reduction rather than scanner severity alone. Vulnerability remediation guidance identifies the affected asset, exploit preconditions, business consequence, control owner, recommended fix and retest evidence. Incident readiness planning covers authority, escalation, preservation, communications and technical decision points.

SCADA and OT operators

Control-system evidence tied to operating consequence

Passive-first asset discovery establishes device, protocol, firmware, zone and communication context before any active step. Network segmentation validation checks whether documented IT/OT boundaries, remote-access paths and vendor connections behave as designed.

ICS security architecture review ties findings to safety, availability, recovery and process constraints. Operational consequence ranking puts credible process impact ahead of generic severity. NERC CIP compliance audit evidence is organized around the applicable requirement, source record, observed control, exception and remediation proof.

Professional boundary: GDF documents technical controls and audit evidence. GDF does not provide legal or regulatory advice or determine compliance status.

Service map

Select the technical workstream

Each service page defines the questions, evidence sources, methods, deliverables and limits. Scope expands only when the record or operating environment requires additional disciplines.

01

Digital Evidence & Litigation Support

Preserve source material, maintain a defensible chain of custody and explain the technical record for litigation, arbitration, regulatory proceedings or internal review. The work is organized for independent reproduction and expert challenge.

02

Cybersecurity & Adversarial Testing

Measure how realistic adversarial attack paths cross network, identity, cloud and application controls. Findings are validated by a practitioner, ranked for material risk reduction and paired with remediation and retest evidence.

03

OT, ICS & SCADA

Map assets and trust paths with a passive-first method, validate segmentation within operator-approved limits and rank findings by operational consequence. Safety, availability and recoverability remain part of the technical scope.

04

AI, Identity & Media

Examine whether a person, recording or digital artifact is consistent with its claimed source and history. Conclusions draw on provenance, metadata, signal characteristics and corroborating records, with confidence and limits stated in writing.

05

Incident Response & Resilience

Preserve volatile evidence while containment and recovery move forward. The response record documents entry, persistence, affected systems, potential data access, material decisions and the facts that remain unresolved.

Engagement standards

A record that survives review.

Scope, source material, methods and limitations are written down so another qualified examiner can test the work.

  • Scope

    We agree on the question, the available evidence, authority to act and the conditions that would require a change in plan.

  • Examine

    Collection and testing follow the approved scope. Material observations are tied to their source, and open questions stay open until the evidence resolves them.

  • Report

    The final record separates observed facts from expert interpretation and states what the available material cannot establish.

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.