What Is Digital Forensics? A Practical Guide to Digital Evidence

ORIGINALLY PUBLISHED 29 March 2022   SUBSTANTIALLY REVISED 17 September 2026

By Navid Sobbi, Founder and CEO, NSI Global

What Digital Forensics Means

Digital forensics is the disciplined process of identifying, preserving, collecting, examining and explaining information from digital sources. Its purpose is to establish what the available data can support while maintaining a reliable record of where that data came from, how it was handled and how conclusions were reached.

The source may be a computer, mobile phone, server, email account, cloud platform, collaboration service, removable drive, application log, social-media account or connected device. The work may support litigation, an internal investigation, a regulatory response, an insurance matter, a cyber incident or a suspected misuse of information.

Digital forensics is broader than recovering deleted files. Recovery can be one part of an examination, but the investigator must also assess context, timestamps, user activity, system records, relationships between artefacts and the limitations of the evidence. A technically retrievable file does not automatically answer who created it, whether it was opened, how it moved or what it proves.

What a Digital Forensic Investigator Does

A digital forensic investigator begins with the question that needs to be answered and the lawful authority for examining the relevant sources. The investigator then selects an acquisition method that is proportionate to the matter and appropriate for the technology involved. Depending on the source, this may involve a bit-stream image, file-system or logical acquisition, targeted collection, live capture, remote collection or provider-assisted export.

The examination should preserve provenance, record important handling decisions and distinguish observations from interpretation. Cryptographic hashes can help verify that a collected data set has not changed after acquisition, but hashing alone does not establish authenticity, authorship, relevance or admissibility. Those questions depend on the wider evidence and, where litigation is involved, the applicable legal and procedural rules.

Typical investigative tasks include:

  • Reconstructing activity across accounts, devices and systems
  • Examining email, documents, messages, browser history, application data and system logs
  • Recovering available deleted or damaged data where the source conditions permit
  • Testing whether files were copied, altered, shared, concealed or accessed
  • Developing timelines and links between people, events, devices and records
  • Identifying malware, persistence, unauthorised access or data-exfiltration indicators
  • Producing clear findings, limitations and supporting material for decision-makers

How Digital Forensics Differs from Related Services

Several services use overlapping tools and skills, but they answer different questions. Defining the objective early prevents an engagement from being scoped around a tool or device when the real issue spans people, systems, accounts and business processes.

Discipline Primary question Typical focus
Digital forensics What occurred and what does the available digital evidence support? Evidence identification, acquisition, examination, interpretation and reporting
Digital forensic data recovery What data can be retrieved from this source? Deleted, damaged, corrupted, inaccessible or partially available data
DFIR How did the cyber incident occur, what is affected and how should it be contained? Incident investigation, containment support, scoping, eradication and recovery evidence
Electronic discovery What electronically stored information must be preserved, reviewed and produced? Legally directed preservation, processing, review and production
Cybersecurity How can systems and information be protected? Preventive, detective and responsive controls across people, process and technology

 

For deeper treatment of recovery, see What Is Digital Forensic Data Recovery. For incident-response capabilities, see 7 DFIR Capabilities for Cyber Incident Investigations.

When Digital Forensics is Used

Digital evidence can become important whenever conduct leaves a trace in a device, account or service. The investigation should be tied to a defined business or legal question rather than an unrestricted search for anything unusual.

Matter Examples of questions or evidence
Cyber incidents Business email compromise, ransomware, unauthorised access, insider activity, data loss and suspected persistence
Workplace matters Misuse of systems, policy breaches, harassment allegations, confidential-information leakage and disputed conduct
Commercial disputes Intellectual-property theft, contract disputes, fraud, ownership questions and contested communications
Litigation and regulation Preservation, expert analysis, disclosure support, defensible reporting and evidence explanation
Mobile and cloud matters Messages, account activity, application artefacts, synchronised data and provider records
Data recovery Deleted, damaged, encrypted, corrupted or inaccessible information where recovery is technically possible

 

A single matter may require several disciplines. A suspected intellectual-property theft, for example, could involve endpoint forensics, cloud-account examination, access-control review, document analysis and eDiscovery. A compromised executive mailbox may require both DFIR and financial-fraud investigation. The scope should follow the risk and the questions, not the label initially applied to the incident.

How a Defensible Matter Progresses

NSI Global structures digital evidence work through its nine-stage Digital Forensic Incident Response and Electronic Discovery Methodology. The stages create a common framework; the depth, order and techniques used still depend on the matter, authority, source systems and urgency.

Stage Activity Purpose
1 Legal Notices and Authority Confirm the purpose, authority, restrictions, stakeholders and applicable notices before collection begins.
2 Chain of Custody Create a documented record of evidence possession, transfers, access and handling decisions.
3 Preservation Protect potentially relevant data against avoidable loss, alteration, deletion or routine system processes.
4 Collection Acquire relevant information using a source-appropriate and proportionate forensic method.
5 Processing Prepare collected material for examination while retaining links to the source and acquisition record.
6 Analysis Test hypotheses, correlate artefacts, develop timelines and identify findings and limitations.
7 Review Assess relevance, privilege, privacy, sensitivity and legal or investigative requirements.
8 Production Provide approved material in an agreed format with necessary controls and documentation.
9 Reporting Explain the methods, results, limitations and significance of the evidence in clear language.

 

Not every engagement requires a full device image or every form of examination. Modern mobile devices, live systems and cloud platforms may demand targeted or logical techniques, and some evidence may exist only through a provider or enterprise log source. A defensible process explains what was collected, what was not, why the method was chosen and how those choices affect the conclusions.

Protecting Digital Evidence Before Examination

Well-intentioned actions can change or destroy evidence. Opening files can alter metadata; installing recovery software can overwrite deleted material; a reset can remove artefacts; cloud-retention cycles can delete logs; and an attacker may still have access to a compromised account. Early advice is therefore part of evidence preservation, not an administrative step after the incident.

If a device, account or system may require forensic examination:

  • Do not reset, update, wipe, repair or install recovery or security software unless a qualified responder directs the action
  • Avoid searching through files or messages to investigate the issue yourself
  • Record what was observed, when it occurred, who had access and any steps already taken
  • Preserve relevant emails, alerts, invoices, screenshots and provider notices in their original form where possible
  • Use a separate trusted device and a communication channel outside the suspected environment when seeking help
  • Obtain source-specific advice before powering down, isolating or disconnecting a device

There is no universal instruction to switch every device off. Powering down may protect some sources, but it can also remove volatile information or lock access to an encrypted system or mobile device. Containment actions must balance continuing harm against evidence loss. Where there is an immediate threat to personal safety, contact emergency services first and preserve evidence only when it is safe to do so.

What the Evidence Can and Cannot Establish

A forensic examination can identify artefacts and patterns that support or contradict an account of events. It may show that an account authenticated, a file existed, a message was stored, a USB device was connected or a transfer occurred. Whether that proves a particular person acted, knew something or intended a result is a separate question that may require identity evidence, access records, witness accounts and surrounding circumstances.

Good reporting makes these boundaries visible. It distinguishes facts observed in the data from technical interpretation and from assumptions supplied by others. It also identifies missing sources, retention gaps, inaccessible content, encryption, unreliable timestamps and alternative explanations where they materially affect the result.

No competent examiner should guarantee recovery, attribution, admissibility or a preferred outcome. Data may have been overwritten, a provider may no longer hold records, a device may be damaged beyond practical recovery, or the available artefacts may support more than one explanation. Courts and other decision-makers determine the weight and admissibility of evidence in context.

What Clients Should Expect From a Specialist

Before work starts, the client should understand the purpose, scope, authority, priority sources, likely limitations, reporting format, security arrangements and decision points for extending the examination. A broad matter does not require indiscriminate collection, but a narrow device-only instruction can miss the accounts, logs or third parties that contain the decisive evidence.

Useful questions to ask include:

  • What legal or organisational authority supports access to each source?
  • Which evidence could disappear first because of retention limits, synchronisation or continued activity?
  • Does the scope cover the relevant devices, cloud services, email, collaboration platforms and system logs?
  • Which acquisition method is appropriate for each source, and what will that method not capture?
  • How will chain of custody, hashing, examiner actions and source limitations be documented?
  • Will the report separate technical findings from inference and explain alternative interpretations?
  • Can the examiner communicate the findings to legal, executive and technical audiences if required?

Relevant qualifications and tool capability matter, but they do not replace method, judgment and communication. The examiner must be able to explain why a process was appropriate, reproduce important steps where feasible and withstand scrutiny of both the evidence and its limitations.

Digital Forensics at NSI Global

NSI Global provides digital forensic services for corporate, legal, government, insurance and investigative matters. The available capabilities include computer and hard-drive forensics, social-media and cloud forensics, digital forensic data recovery, advanced electronic discovery and expert witness support.

The engagement should begin early enough to preserve time-sensitive material and define the risk properly. NSI Global can help determine which sources matter, what should be preserved and whether the issue requires digital forensics, DFIR, eDiscovery, data recovery or a coordinated investigation.

For a confidential consultation, contact NSI Global or call 1300 000 NSI (674).

Frequently Asked Questions

Is digital forensics only used after a cyberattack?

No. It is used in cyber incidents, litigation, workplace investigations, fraud matters, intellectual-property disputes, regulatory responses, insurance claims and other matters involving electronic evidence.

Can a forensic examiner recover deleted data?

Sometimes. Recovery depends on the device, storage technology, encryption, subsequent use, damage, application behaviour and available backups or cloud records. Recovery should never be guaranteed before assessment.

Does a hash make digital evidence admissible?

No. A hash can help demonstrate that a collected data set has remained unchanged, but admissibility and weight depend on the jurisdiction, authority, relevance, handling process and the wider evidence.

Should a suspected device be switched off?

Not automatically. Powering down can preserve some sources but may destroy volatile information or prevent access to an encrypted system. Obtain source-specific advice promptly.

What should be included in the scope?

The scope should reflect the risk and questions. It may need to cover devices, accounts, cloud services, email, collaboration platforms, logs, backups and third-party records, while remaining lawful and proportionate.

How soon should a specialist be engaged?

As early as practical. Log retention, remote access, account changes, synchronisation and continued device use can alter or remove relevant evidence.

Sources and Further Reading

  1. ISO/IEC 27037 Digital evidence identification collection acquisition and preservation
  2. NIST SP 800-86 Guide to Integrating Forensic Techniques into Incident Response
  3. SWGDE published digital evidence guidance
  4. NSI Global Digital Forensics
  5. NSI Global What Is Digital Forensic Data Recovery
  6. NSI Global 7 DFIR Capabilities for Cyber Incident Investigations

Important  General information only; not legal advice. Recovery, attribution, admissibility and investigative outcomes are case-specific.

Secure your peace of mind