
Protect the response before investigating
Computer forensics uses documented methods to examine digital information and explain what it supports. For a small business facing a suspicious event, the first useful task is usually to preserve observations, establish who may investigate, and get the right responder involved.
Record what you directly observed: the time and time zone, the device or account, the visible message and the person who saw it. Separate those observations from your interpretation. “The account exported a file at 09:12” and “a particular employee stole it” are very different claims.
When an incident is active, follow the designated response lead’s containment instructions. Avoid independently wiping devices, running cleanup tools, opening suspicious files or connecting backup media. Power and network decisions can affect both damage and evidence; they need context. CISA’s ransomware response guide discusses prompt isolation and the loss of volatile evidence that can follow a shutdown.
This is an organizational preparation guide. Authority to access a device, collect employee information or request provider records must be established for the situation. Involve management, the information owner, counsel and a qualified examiner as appropriate, including before an employment dispute becomes an improvised device search.
Understand the stages and their outputs
NIST SP 800-86, published in 2006, explains forensic techniques from an IT incident-response perspective. Its collection, examination, analysis and reporting framework remains useful for asking structured questions; its older tool and platform examples require current specialist judgment. NIST SP 800-61 Revision 3, published in 2025, provides the broader current incident-response framework.
| Stage | Purpose | Useful output |
|---|---|---|
| Collection | Acquire relevant data under established authority and preserve its integrity | Identified sources, acquisition records and protected originals or preserved copies. |
| Examination | Extract and organize information from the collected material | Documented artifacts and the method used to obtain them. |
| Analysis | Relate artifacts to the actual investigation question | A supported timeline, competing explanations and stated gaps. |
| Reporting | Explain methods, findings and limitations to the decision-maker | A clear report tied to evidence references and reviewable reasoning. |
File recovery seeks usable data. Forensic work also needs a defensible account of where the data came from and what happened to it. A recovered filename by itself rarely answers who performed an action or whether the file’s contents were ever read.
Make a useful evidence handoff
Give the responder a narrow question, such as “Was this external share accessed during the contractor’s final week?” Identify the service, accounts, approximate period and business impact. That helps the responder prioritize sources before short-lived logs expire.
- Device context: private inventory reference, owner, current state and any actions already taken.
- Account context: tenant or service, relevant identities, authorized administrator and retention settings if known.
- Event context: original alerts, timestamps with time zones, ticket references and witness observations.
- Custody context: who collected, received or accessed an item; when; for what purpose; and where it is protected.
Keep originals and working material clearly distinguished. An examiner may use a forensic image, verified exports, write blockers or other tools appropriate to the source. Ordinary copying can change metadata or omit relevant data. Let the examiner select and validate acquisition methods.
A cryptographic hash can help show that a particular acquired file has not changed between checks. It establishes a relationship between those bytes and the recorded digest; it does not establish that the original story is true, that a person created the file, or that collection was lawful. Record the algorithm and the exact item hashed.
Use access-controlled storage and transfer methods approved for the evidence. Keep credentials out of the handoff sheet; provide necessary access through the responder’s approved process. Preserve retention obligations while the authorized owner decides what can eventually be deleted.
Ask what the evidence actually supports
When selecting an examiner, ask about experience with the specific operating system or cloud service, collection authority, methods, data handling, reporting and preservation of originals. Agree on scope, fees, communication and the decision points that require approval.
A useful final report states the question, data sources, collection period, methods, findings, time assumptions and remaining uncertainty. Ask whether another competent examiner could follow the evidence references. Legal admissibility depends on the case and applicable requirements; a software export or a completed worksheet cannot guarantee it.
After the investigation, route remediation through the incident lead, and record any logging or retention gap that prevented an answer. Keep that improvement work distinct from altering the evidence used to reach the finding.
Historical forensic and recovery coverage
These earlier Yenra articles document services, laboratories and equipment from their publication periods. Use current provider and agency information before making decisions.