Incident Response Solutions provides computer forensics services to clients throughout New Zealand. We collect, preserve, examine and report on electronic evidence to a standard that will withstand scrutiny in court.
Computer forensics is the disciplined recovery and interpretation of data held on computers, phones, servers and cloud services, carried out in a way that keeps that data intact and defensible as evidence. It is used whenever what happened on a device matters – in employment investigations, intellectual property and data theft disputes, fraud inquiries, litigation and regulatory matters, and after a cyber attack or privacy breach.
Our background includes law enforcement with the New Zealand Police and Big 4 professional services. We have significant experience preparing expert witness reports and giving expert testimony at trial.
Call 0800 WITNESS (0800 948 637) or email support@incidentresponse.co.nz.
When you may need a computer forensic examination
- A departing employee is suspected of taking client lists, pricing, designs or other confidential information to a competitor.
- Company computers or phones may have been misused, and the conduct needs to be established properly before a disciplinary process begins.
- The authenticity, authorship or timing of a document, email or message is disputed.
- Files have been deleted and need to be recovered and interpreted.
- Litigation or a regulatory request requires electronic evidence to be preserved before it is lost or overwritten.
- A cyber attack or data breach has occurred and you need to establish what happened, how, and which data was affected.
- Devices need to be secured urgently, before staff depart, hardware is reissued or systems are rebuilt.
If a device may hold evidence, the most useful thing you can do is stop using it and seek advice before anyone attempts to look through it. Ordinary use overwrites deleted data and changes timestamps. In-house IT staff searching a laptop, however well intentioned, frequently destroys the record of what was on it.
What we examine
- Laptops and desktop computers, Windows and macOS
- Servers, network storage and backups
- Mobile devices, including phones and tablets
- Cloud services and hosted email
- External hard drives, USB storage and memory cards
We are often asked to work across several of these at once, for example correlating activity on a work laptop with the USB devices attached to it and the files later found in a personal cloud account.
Our approach
Scoping
Every matter begins with understanding the question you actually need answered, the timeframe involved, and where relevant evidence is likely to sit. This keeps the work proportionate. A focused examination of the right sources is usually more useful, and less expensive, than imaging everything in the building.
Preservation and forensic imaging
We create a forensic image: a verified, bit-for-bit copy of the source media. All examination is carried out on that copy, leaving the original untouched. Chain of custody is documented from the moment we take receipt of a device, so the handling of the evidence can be accounted for if it is later challenged.
Examination and analysis
We apply established investigative and analytical techniques to recover and interpret the evidence. Depending on the matter this can include recovering deleted files, establishing which files and folders were accessed and when, tracing external devices connected to a machine, reconstructing program execution and browser activity, and building a reliable timeline of user activity. Timestamps are interpreted carefully. Dates and times on a computer are more nuanced than they first appear, and misreading them is one of the more common failings in digital evidence.
Reporting
You receive a written report setting out what was examined, what was found, and what can and cannot reasonably be concluded from it. Reports are written to be understood by lawyers, HR teams and boards rather than only by technical specialists, and they state the limitations of the findings as clearly as the findings themselves.
Expert witness testimony
Where a matter proceeds, we prepare expert witness reports and give evidence at trial.
Expert witness and court admissibility
Evidence is only as good as the process that produced it. A finding that cannot be explained, reproduced or defended under cross-examination is of limited use, however compelling it first appears. We work to global forensic standards throughout, document our methodology, and are prepared to have that methodology tested.
Campbell McKenzie has significant experience providing expert witness reports and delivering expert witness testimony at trial, with a background in the New Zealand Police and Big 4 professional services.
Professional standards
We are members of the Australia New Zealand Forensic Science Society and abide by the ANZFSS Code of Professional Practice.
Who we work with
We are engaged by law firms and barristers, in-house counsel, HR and people teams, boards and executives, insurers and government agencies, as well as by private individuals in employment and civil matters. Work is frequently carried out at the instruction of your lawyers.
Related services: eDiscovery and document review, online investigations, data breach response and incident response.
Common questions
Can deleted files be recovered?
Often, yes, though it depends on the device, the file system, how long ago the deletion occurred and how heavily the device has been used since. Even where the contents of a file cannot be recovered, evidence that the file existed, when it was accessed and what became of it frequently survives.
Do you need the original device?
We need access to it in order to create a forensic image, but that is usually a short engagement and the device can often be returned quickly. In some circumstances we can image remotely or collect from cloud sources instead.
How long does an examination take?
It depends on the number of devices, the volume of data and the questions being asked. We scope each matter up front and give you an estimate of time and cost before work begins.
Can you examine phones as well as computers?
Yes. Mobile devices are examined on the same principles and to the same evidential standard as a computer. In most matters they are best treated as complementary to the wider examination rather than as a source in isolation, since activity on a phone is usually understood properly only alongside what is found on the associated computers, servers and cloud accounts.
What should I do before calling you?
Stop using the device, secure it somewhere it cannot be accessed, and avoid switching it on or searching it. Note who has had access to it and when. Then call us.
For more detailed technical information on the forensic artefacts examined during an investigation, see our microsite forensictech.co.nz.
Talk to us
Call 0800 WITNESS (0800 948 637), phone 021 779 310, or email support@incidentresponse.co.nz. If evidence may be at risk, call first and leave the device alone.
