Taking instructions now — the first conversation is freeExhibits posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
FDRForensic Data Recovery 0800 6890668 Price my job
FDR / What is digital forensics

Digital forensics · computer forensics · data forensics · imaging · artefacts · evidence · the law

What is digital forensics? The examination of digital devices in a way that can be relied on as evidence, explained without the jargon.

Digital forensics is the recovery, examination and presentation of data from digital devices, computers, drives, memory cards, recorders, phones, in a way that can be relied on as evidence. The word forensic means fit for the court, and that is the whole difference from ordinary data recovery: the original is never altered, an exact copy is proved identical and examined instead, every step is recorded so another examiner could repeat it, and the findings are reported as fact with their limits stated. Computer forensics is the branch that deals with computers and storage; data forensics is the same thing seen from the data's side; mobile forensics, network forensics and cloud forensics are the other branches. This page explains what a forensic examination is, what a computer actually records, who uses forensics and why, the law around it in the UK, and where the limits lie. It is written for anyone who needs to understand it, whether you are instructing an examination, studying the field, or on the receiving end of one.

Rather talk it through? An engineer answers the bench line
0800 6890668

What makes an examination forensic.

Four things, and they are the same whether the device is a laptop in an employment dispute or an exhibit in a criminal trial. The original is not altered: the drive is connected through a write blocker, hardware that allows reading but physically prevents writing, so the act of examining cannot change the evidence. A copy is proved identical: the drive is imaged bit for bit, and a hash, a mathematical fingerprint, is computed for both; matching values prove the copy is exact, and recomputing the hash later proves nothing has changed. Every step is recorded: who held the exhibit, what was done, with which tools and versions, so that an independent examiner could repeat the work and reach the same result. The findings are reported as fact: what the device shows, under which user account, at what time, with a clear statement of what it does not show.

In the United Kingdom these principles were set out for the police in the ACPO Good Practice Guide for Digital Evidence and are followed across the field. Criminal forensic work in England and Wales is also governed by the Forensic Science Regulator's statutory Code of Practice; Northern Ireland has no statutory equivalent, though its courts look for the same discipline. The legal framework page sets this out.

What a computer actually records.

Most people are surprised by how much. A Windows computer keeps a permanent record of every USB storage device ever connected, with its make, serial number and the dates; it records which files were opened from a removable drive; it logs when programs were installed and run, including cleaning and wiping tools; it keeps a change journal that timestamps every file deleted; it holds browser history, cloud-sync client logs, email archives and the metadata inside every document; and it keeps earlier versions of files in shadow copies. Deleting a file removes the index entry, not the data, which stays on a hard drive until overwritten. The evidence pages explain each category, and the sample reports show how they come together.

Two limits are always stated. First, these records show what happened under a user account and when; they do not, on their own, show who was physically at the keyboard. Second, solid-state drives erase deleted data quickly through a feature called TRIM, so deleted-file recovery from an SSD is far more limited than from a hard drive; strong encryption without the key cannot be broken; and overwritten data is gone.

Who uses digital forensics, and for what.

Employers, when an employee is suspected of taking data on the way out, or of misconduct on a company device; solicitors, in civil litigation, employment and family matters, where what a device shows bears on the case; insurers, for damaged devices and disputed data loss; executors, for a deceased person's computer; individuals, for evidence on their own devices, such as harassing messages received; and the police and the courts, through prosecution and defence examinations. The services pages take each situation in turn.

Who may examine a device is governed by law. Accessing a computer without authority is an offence under the Computer Misuse Act 1990, intercepting communications without lawful authority is an offence under the Investigatory Powers Act 2016, and personal data on a device is protected by UK GDPR. A legitimate examination therefore begins with proof of ownership or documented authority, which is why this service refuses covert work on anyone else's device.

Two kinds of report, and the difference from data recovery.

An examination produces either a factual report, which records what the device shows and is used by employers, solicitors and insurers to decide what to do, or an expert report for a court, which adds the examiner's opinion within the rules that govern expert evidence, with declarations and a duty to the court above the instructing party. The comparison page explains which is needed when.

The difference from ordinary data recovery is discipline rather than skill. A data recovery lab gets the files back, and may repair, mount or write to the drive to do it. A forensic examination gets them back without altering the original, proves the copy, records every step and reports the findings with their limits, which is what lets them stand up when challenged. This service does both: a recovery lab that works to forensic standards, including on drives that have physically failed.

The questions that come up first.

What does a digital forensic examiner do?

Preserves a device, images it behind a write blocker, verifies the image with hashes, examines the copy for the artefacts the question turns on, confirms key findings in a second tool, and reports the findings as fact with their limits. For a court, an expert also gives an opinion within the rules governing expert evidence.

Can digital forensics prove who did something?

It can prove what was done, under which account, and when. Proving who was at the keyboard usually needs corroboration from outside the device, and an honest report says so.

How is digital forensics different from data recovery?

Data recovery gets the files back; digital forensics gets them back in a way that can be repeated and relied on, and examines what the device records about how they were used. The method, not the tools, is the difference.

Is digital forensics a career?

Yes, a growing one, in police units, forensic providers, large organisations and consultancies, usually entered through a computing or forensic degree or a professional background in IT or law enforcement, with vendor and professional certifications on top. This page explains the field; the rest of the site explains the service.

What does an examination cost here?

The standard forensic report for a one-disk system is £800 + VAT; expert reports for court are quoted. The first conversation is free.

Now the service makes sense.

If you need a device examined, tell us the situation and who owns it; the first conversation is free and tells you what an examination can show.

0800 6890668