When to Call a Digital Forensics Firm

Call a digital forensics firm when you suspect a breach, when an employee may have taken data, when a matter is heading for litigation or when an insurer or regulator requires an investigation. The common thread is that electronic evidence exists and it is degrading. The sooner an examiner preserves it, the more you can prove. This guide covers the triggers, the cost of waiting and what the first call looks like.

The short answer: Call a digital forensics firm the moment you have a credible reason to believe electronic evidence matters and may be at risk: a suspected breach, an insider taking data, a litigation hold or an insurer requirement. Evidence degrades and logs expire, so the value of the call falls with every day you wait.

The Question Behind the Question

Most organizations ask how to choose a forensics firm before they have settled the more basic question of whether they need one at all and when. Getting the timing right matters as much as getting the firm right, because the single biggest factor in what a forensic investigation can recover is how quickly it starts. This guide is the companion to our guide on how to choose a digital forensics firm: this one covers when to make the call, that one covers who to call.

The unifying principle is simple. Digital evidence is perishable. Logs roll off, systems get reimaged, devices get reused and memory is lost at the next reboot. A forensic examiner can only analyze what still exists when they arrive, so the decision to call is really a decision about how much of the evidence you get to keep.

Sign One: A Suspected or Confirmed Breach

The clearest trigger is a suspected intrusion: unusual account activity, ransomware, data appearing where it should not, an alert you cannot explain or a tip from a third party that your data is for sale. In these moments the instinct is to clean up and restore service, but cleaning up first can destroy the evidence of how the attacker got in and what they took.

Calling an examiner early lets the investigation and the recovery run together, so you restore service without erasing the record. That record is what lets you scope the incident accurately, close the actual entry point rather than a guessed one and meet notification duties with facts instead of assumptions.

Sign Two: An Insider Taking Data

A departing employee, a disgruntled contractor or a suspected policy violation is a forensic matter, not just an HR one. When someone may have taken customer lists, source code or trade secrets to a competitor, the evidence lives in email logs, file-access records, USB history and cloud-sync activity and much of it is time-limited.

Acting quickly preserves that evidence before the account is deprovisioned and the device is wiped and reissued. A forensic examiner can establish what was accessed, copied or exfiltrated and document it to a standard that supports a legal or employment action. Wait too long and the laptop is already running as someone else workstation with the original evidence gone.

Sign Three: A Litigation Hold or Dispute

When litigation is reasonably anticipated, the duty to preserve relevant evidence attaches and failing to preserve it can lead to spoliation findings that damage your position regardless of the underlying merits. Contract disputes, employment claims, fraud allegations and intellectual-property matters all commonly turn on electronic evidence.

A forensics firm helps you meet the preservation duty properly: identifying the relevant devices and accounts, imaging them in a defensible way and holding them under a documented chain of custody. Doing this early and correctly is far cheaper than explaining to a court why the evidence was altered or lost.

Sign Four: An Insurer or Regulator Requires It

A cyber-insurance policy will often require a forensic investigation as a condition of paying a breach claim and a regulator may require one to establish the scope of an incident. In both cases the investigation has to meet a standard set by someone other than you and a qualified forensics firm is what produces documentation those parties will accept.

If you carry cyber insurance, know the requirement before an incident, because the policy may specify how quickly you must engage a forensic provider and even which providers are approved. Our guide on the forensic evidence a cyber insurer requires to pay a claim covers what those parties expect.

The Cost of Waiting

Every day between an incident and the forensic response is a day of evidence loss and, usually, added cost. Industry research consistently finds that the longer a breach goes undetected and uncontained, the more it costs and IBM annual Cost of a Data Breach study has reported for years that faster identification and containment lower the total. Forensic readiness and a prompt call are two of the levers that shorten that window.

There is also a scoping cost to waiting. When the evidence of initial access is gone, an organization often has to assume the worst for notification purposes because it cannot prove the narrower reality. That turns a contained incident into a broad, expensive disclosure. Our analysis of the real cost of a breach for a mid-market company breaks that dynamic down.

What Evidence Degrades and How Fast

Different evidence has different shelf lives. Volatile memory is gone at the next reboot. Cloud and mailbox audit logs may retain for only a short window unless retention was extended in advance. Endpoint logs roll over as new activity overwrites old. Deleted files survive only until the space is reused. A device that is reimaged or reissued takes its evidence with it.

This is why the call is time-sensitive even when the situation feels ambiguous. Preserving evidence does not commit you to a full investigation, but it keeps the option open. Reversing the order, deciding to investigate after the evidence is gone, is the one path that cannot be recovered.

The Risk of Doing It Yourself First

A well-meaning internal responder can do real damage in the first hours: logging into the suspect account and generating new activity, restoring from backup over the evidence, running tools that alter timestamps or wiping and reissuing a device. Each of these can spoil evidence in ways that are hard to explain later. The safest first move once you suspect a serious matter is to preserve and isolate, not to remediate.

If you are unsure, a short call to a forensics firm to decide whether the situation warrants preservation costs little and can save the case. A good firm will tell you plainly whether you need them, which is a far better outcome than discovering after the fact that a routine cleanup erased the answer.

What the First Call Looks Like

The first contact with a forensics firm is a triage conversation, not a commitment to a large engagement. The examiner asks what happened, what systems and data are involved and what has been done so far, then advises on immediate preservation steps and scopes the work. In an urgent matter that advice may be to isolate a device or extend a log retention setting before anything else changes.

From there the engagement is defined in writing and the investigation begins. Once you know you need help, the next question is who to trust with it, which our guide on how to choose a digital forensics firm answers. Sherlock Forensics handles this triage through its incident response service, so the first call reaches an examiner rather than a sales queue.

Preserve First: The First Hour

If you suspect a serious matter and cannot reach a forensics firm immediately, a few preservation steps protect the evidence without requiring expertise. Avoid powering down a running system unless you must, because shutting down destroys volatile memory and can trigger disk changes; isolating it from the network is usually safer. Avoid logging into the suspect account, restoring over the affected system or running cleanup tools, because each generates new activity that overwrites the record you need.

Where you can, extend the retention on cloud and mailbox logs immediately, since those often expire on a short default and cannot be recreated once gone. Write down what you observed and when, including any actions already taken, because that contemporaneous note becomes part of the timeline. Then wait for the examiner rather than investigating further yourself.

These steps keep options open. They do not commit you to a full investigation and they do not require you to diagnose the incident. They simply prevent the routine, well-intentioned actions that most often destroy evidence in the first hour, so the decision about how far to take the matter can be made on intact evidence rather than fragments. Sherlock Forensics walks callers through exactly these steps at the start of an incident response engagement.

One more habit helps: keep the number of people touching the situation small and log who did what. Every additional person acting on a live system is another set of changes an examiner has to account for later and a tight circle with a written record turns a chaotic first hour into a preservable one.