HOME / SERVICES / DIGITAL FORENSICS
DIGITAL FORENSICS
Court-admissible digital forensic investigation for organisations that need to prove what happened, who did it, and what was taken. NEWORDER has conducted forensic search and seizure since 2000 and has given expert testimony accepted in a court of law. We serve clients across Africa, Europe, and the Middle East.
EVIDENCE THAT HOLDS. INSIGHT THAT MOVES.
Most organisations discover the limits of their logging on the worst day of their year. By the time the question becomes legal rather than technical, the evidence has already been overwritten, the endpoint has already been reimaged, and the answer that would have settled the matter is gone.
Digital forensics is the discipline of recovering, preserving, and interpreting digital evidence so that it survives challenge. Not just technical challenge from your own team, but legal challenge from opposing counsel, regulatory challenge from the Information Regulator, and commercial challenge from an insurer deciding whether to pay a claim.
NEWORDER approaches forensics from the offensive side. Our investigators spend the rest of their time breaking into the same systems they are now asked to reconstruct. That perspective changes what they look for, where they look first, and how quickly they get to the answer that matters.
Every engagement produces two things: a defensible evidentiary record and a plain language account of what happened, written so that a board, a regulator, and a court can each take what they need from it.
CORE CAPABILITIES
- Forensic Acquisition and Preservation — Bit-level imaging of endpoints, servers, mobile devices, and volatile memory under documented chain of custody, executed so the evidence is admissible before anyone asks whether it is.
- Intrusion Reconstruction and Timeline Analysis — Correlating logs, artefacts, and telemetry into a defensible sequence of events: initial access, dwell, lateral movement, privilege escalation, and exfiltration.
- Malware Analysis and Reverse Engineering — Static and dynamic analysis of recovered samples to establish capability, command and control infrastructure, persistence mechanisms, and attribution indicators.
- Data Breach Scoping and Impact Assessment — Establishing exactly which records were accessed or removed, which is the question that determines your POPIA and GDPR notification obligations and the size of your exposure.
- Cloud and SaaS Forensics — Investigation across Microsoft 365, Google Workspace, AWS, and Azure, where the evidence lives in tenant audit logs with retention windows that expire while organisations are still deciding whether to call someone.
- Expert Reporting and Litigation Support — Forensic reports written to survive cross-examination, with expert witness testimony accepted in a court of law.
- Insider Threat and Employee Misconduct Investigation — Discreet investigation of data theft, policy breach, and misuse, handled to a standard that supports disciplinary action or civil recovery.
Chain of Custody From the First Minute
Evidentiary integrity is decided at acquisition, not at report writing. Every NEWORDER engagement runs documented custody, hashing, and handling from the moment we touch the first device, so the evidence is still usable months later when the matter turns legal.
Investigated by Operators Who Attack
Our forensic investigators also run penetration tests and red team operations. They know what an attacker cleans up, what an attacker forgets, and which artefact survives. Adversary Path Engineering applied in reverse.
Speed to Insight
Cloud audit logs expire. Endpoints get reimaged by well-meaning IT teams. NEWORDER prioritises the evidence with the shortest shelf life first, so the record is preserved before the investigation is fully scoped.
Human Validation at Scale
Forensic tooling produces enormous volumes of artefacts and a great many false leads. Every finding in a NEWORDER report has been validated by an investigator, not lifted from a tool summary.
Built to Hand Off to First Response
Investigation and containment are different disciplines with different urgency. Where a live incident is running, forensics and First Response operate together so that containment does not destroy the evidence you will need later.
Reporting Insurers and Regulators Accept
Insurers require documented engagement records and preservation protocols before validating a claim. Regulators require defensible scoping. Our reporting is built for both, alongside the plain language executive account your board needs.
OTHER SERVICES
FREQUENTLY ASKED QUESTIONS
FAQ
When should we call a forensic investigator rather than handle it internally?
Whenever the answer might end up in front of a regulator, an insurer, a court, or a disciplinary hearing. Internal teams are usually capable of establishing what happened. What they rarely have is the documented chain of custody that makes the finding stand up when someone disputes it. If in doubt, call before you touch the device.
What should we do in the first hour, before you arrive?
Do not reimage, do not power cycle, and do not let anyone log in to the affected system. Isolate it from the network if you can do so without shutting it down, since volatile memory disappears the moment power is lost. Preserve logs and extend any retention setting that is about to expire. Then call us.
Can your findings be used in a South African court?
Yes. NEWORDER has conducted digital forensic search and seizure since 2000 and has provided expert testimony accepted in a court of law. Reports are prepared to evidentiary standard, with chain of custody documentation, methodology disclosure, and defensible conclusions.
How long does a forensic investigation take?
Preservation happens immediately, usually within hours of engagement. Initial findings on scope and impact typically follow within days. Full reconstruction and formal reporting depends on the size of the environment and the volume of evidence, and NEWORDER provides a timeline after the preservation phase, once the actual scope is visible rather than assumed.
Do you handle cloud environments as well as on-premises?
Yes. A significant proportion of modern investigations run entirely in Microsoft 365, Google Workspace, AWS, or Azure. The constraint in cloud forensics is retention: tenant audit logs expire on a schedule, and evidence that existed on day one is often gone by day ninety. Cloud incidents are time critical for that reason alone.
How does forensics relate to our POPIA notification obligations?
POPIA requires notification where personal information has been accessed or acquired by an unauthorised person. Establishing whether that actually happened, and to which records, is a forensic question. Notifying without scoping risks both over-reporting and under-reporting, each of which carries its own consequence with the Information Regulator.
Can you investigate an employee without alerting them?
Yes, subject to the applicable legal basis and your internal policy framework. Insider investigations are handled discreetly, and NEWORDER will advise where the proposed collection requires authorisation before it proceeds. We will not conduct collection without a proper authorisation basis.
Do you offer forensic readiness work before an incident happens?
Yes, and it is the single highest-value forensic engagement available. Most investigations are constrained by evidence that was never collected in the first place. Forensic readiness review examines logging coverage, retention periods, and preservation capability so that when something does happen, the evidence exists.
TAKE ACTION
WHEN THE EVIDENCE HAS TO HOLD UP
Contact NEWORDER for a confidential discussion about your digital forensic requirements, whether that is an active investigation, litigation support, an insider matter, or forensic readiness before anything goes wrong. If you have a live incident right now, call +27 12 880 5830.