YOU DO NOT COPY PROFESSIONALISM. YOU ALIGN WITH IT.
HOME / SERVICES / DIGITAL FORENSICS

DIGITAL FORENSICS

Court-admissible digital forensic investigation for organisations that need to prove what happened, who did it, and what was taken. NEWORDER has conducted forensic search and seizure since 2000 and has given expert testimony accepted in a court of law. We serve clients across Africa, Europe, and the Middle East.

EVIDENCE THAT HOLDS. INSIGHT THAT MOVES.

Most organisations discover the limits of their logging on the worst day of their year. By the time the question becomes legal rather than technical, the evidence has already been overwritten, the endpoint has already been reimaged, and the answer that would have settled the matter is gone.

Digital forensics is the discipline of recovering, preserving, and interpreting digital evidence so that it survives challenge. Not just technical challenge from your own team, but legal challenge from opposing counsel, regulatory challenge from the Information Regulator, and commercial challenge from an insurer deciding whether to pay a claim.

NEWORDER approaches forensics from the offensive side. Our investigators spend the rest of their time breaking into the same systems they are now asked to reconstruct. That perspective changes what they look for, where they look first, and how quickly they get to the answer that matters.

Every engagement produces two things: a defensible evidentiary record and a plain language account of what happened, written so that a board, a regulator, and a court can each take what they need from it.

CORE CAPABILITIES

Chain of Custody From the First Minute

Evidentiary integrity is decided at acquisition, not at report writing. Every NEWORDER engagement runs documented custody, hashing, and handling from the moment we touch the first device, so the evidence is still usable months later when the matter turns legal.

Investigated by Operators Who Attack

Our forensic investigators also run penetration tests and red team operations. They know what an attacker cleans up, what an attacker forgets, and which artefact survives. Adversary Path Engineering applied in reverse.

Speed to Insight

Cloud audit logs expire. Endpoints get reimaged by well-meaning IT teams. NEWORDER prioritises the evidence with the shortest shelf life first, so the record is preserved before the investigation is fully scoped.

Human Validation at Scale

Forensic tooling produces enormous volumes of artefacts and a great many false leads. Every finding in a NEWORDER report has been validated by an investigator, not lifted from a tool summary.

Built to Hand Off to First Response

Investigation and containment are different disciplines with different urgency. Where a live incident is running, forensics and First Response operate together so that containment does not destroy the evidence you will need later.

Reporting Insurers and Regulators Accept

Insurers require documented engagement records and preservation protocols before validating a claim. Regulators require defensible scoping. Our reporting is built for both, alongside the plain language executive account your board needs.

OTHER SERVICES

FREQUENTLY ASKED QUESTIONS

FAQ

Whenever the answer might end up in front of a regulator, an insurer, a court, or a disciplinary hearing. Internal teams are usually capable of establishing what happened. What they rarely have is the documented chain of custody that makes the finding stand up when someone disputes it. If in doubt, call before you touch the device.

Do not reimage, do not power cycle, and do not let anyone log in to the affected system. Isolate it from the network if you can do so without shutting it down, since volatile memory disappears the moment power is lost. Preserve logs and extend any retention setting that is about to expire. Then call us.

Yes. NEWORDER has conducted digital forensic search and seizure since 2000 and has provided expert testimony accepted in a court of law. Reports are prepared to evidentiary standard, with chain of custody documentation, methodology disclosure, and defensible conclusions.

Preservation happens immediately, usually within hours of engagement. Initial findings on scope and impact typically follow within days. Full reconstruction and formal reporting depends on the size of the environment and the volume of evidence, and NEWORDER provides a timeline after the preservation phase, once the actual scope is visible rather than assumed.

Yes. A significant proportion of modern investigations run entirely in Microsoft 365, Google Workspace, AWS, or Azure. The constraint in cloud forensics is retention: tenant audit logs expire on a schedule, and evidence that existed on day one is often gone by day ninety. Cloud incidents are time critical for that reason alone.

POPIA requires notification where personal information has been accessed or acquired by an unauthorised person. Establishing whether that actually happened, and to which records, is a forensic question. Notifying without scoping risks both over-reporting and under-reporting, each of which carries its own consequence with the Information Regulator.

Yes, subject to the applicable legal basis and your internal policy framework. Insider investigations are handled discreetly, and NEWORDER will advise where the proposed collection requires authorisation before it proceeds. We will not conduct collection without a proper authorisation basis.

Yes, and it is the single highest-value forensic engagement available. Most investigations are constrained by evidence that was never collected in the first place. Forensic readiness review examines logging coverage, retention periods, and preservation capability so that when something does happen, the evidence exists.

TAKE ACTION

WHEN THE EVIDENCE HAS TO HOLD UP

Contact NEWORDER for a confidential discussion about your digital forensic requirements, whether that is an active investigation, litigation support, an insider matter, or forensic readiness before anything goes wrong. If you have a live incident right now, call +27 12 880 5830.