What Is Cyber Forensics? How Digital Investigations Work
Cyber forensics is the practice of identifying, preserving, analyzing and presenting digital evidence in a way that holds up under legal or investigative scrutiny, following strict methodology to ensure that evidence remains genuinely trustworthy. If you have wondered whether this is the same thing as eDiscovery, the honest answer is no, and the distinction matters directly if you ever need either one.
What Is Cyber Forensics?
Cyber forensics, also called digital forensics, is the practice of identifying, collecting, preserving and analyzing digital evidence in a scientifically sound, legally defensible way, whether for a criminal investigation, civil litigation, or an internal security incident requiring a genuine understanding of exactly what happened.
The defining feature separating cyber forensics from general IT investigation is methodology specifically. A forensic investigator follows strict, documented procedures at every step precisely because the resulting evidence may eventually need to withstand challenge in court, meaning shortcuts that would be entirely reasonable during routine troubleshooting can genuinely undermine or invalidate evidence gathered without proper forensic discipline.
Cyber Forensics vs eDiscovery: Genuinely Different Jobs, Often Confused
| Criteria | Cyber Forensics | eDiscovery |
| Core question | What technically happened? | What relevant information exists? |
| Depth | Deep technical investigation | Broad information identification and production |
| Typical context | Criminal cases, security incidents | Civil litigation, regulatory requests |
Cyber forensics asks a genuinely technical question: what actually happened on this system, in what sequence, and how can that be proven with technical rigor. eDiscovery asks a broader, more legal question: what relevant electronically stored information exists across an organization’s systems that needs identifying, collecting and producing for litigation or regulatory purposes.
These roles genuinely overlap but are not interchangeable. eDiscovery often involves searching broadly across emails, documents and communications for anything relevant to a legal matter, without necessarily requiring the deep technical reconstruction cyber forensics demands. A cyber forensics investigation might determine precisely how an attacker moved through a network step by step. An eDiscovery process might simply need to locate and produce every email mentioning a specific contract, without any need to reconstruct technical events at all. Confusing the two leads organizations to either over-invest in forensic-grade technical investigation for a straightforward document production request, or under-invest genuine forensic rigor into a matter that will eventually require technically defensible, court-ready evidence.
Chain of Custody: The Record That Decides Whether Evidence Stands Up in Court
Chain of custody is the documented, unbroken record of who handled a piece of digital evidence, when, and what specifically was done to it, from the moment it was first collected through to its eventual presentation in court or a formal proceeding. This record exists specifically to prove the evidence presented is genuinely the same evidence originally collected, unaltered and untampered with at every step along the way.
A single, undocumented gap in this chain, evidence handled by someone not recorded, a device left unsecured even briefly, a missing timestamp on when a copy was made, can give opposing counsel genuine grounds to challenge the evidence’s authenticity entirely, regardless of how technically sound the underlying forensic analysis actually was. This is precisely why forensic investigators document every single interaction with evidence meticulously, since the strength of a forensic conclusion depends entirely on the documented integrity of the chain that produced it, not simply on the accuracy of the final technical finding alone.
The Six Branches of Digital Forensics
Digital forensics spans six generally recognized branches, each addressing a genuinely distinct type of digital evidence. Computer forensics examines desktop and laptop systems specifically, recovering files, analyzing system logs and reconstructing user activity. Network forensics analyzes network traffic and logs to reconstruct how data moved and where an attacker’s activity actually traveled across an environment.
Mobile device forensics addresses smartphones and tablets specifically, given their genuinely distinct storage architecture and operating systems compared to traditional computers. Database forensics examines database systems directly, reconstructing transactions and identifying unauthorized data access or modification. Cloud forensics addresses the genuinely distinct challenges of investigating data and activity within cloud environments, where an investigator often lacks the same direct physical access traditional forensics assumes. Memory forensics examines a system’s volatile memory specifically, capturing evidence, running processes, encryption keys, active network connections, that would otherwise disappear entirely the moment a device powers down. Each branch connects directly back to the broader forensic principles covered throughout this guide, chain of custody, documented methodology, evidence integrity, applied specifically to that particular evidence type’s own unique technical characteristics.
DFIR: When Containing a Threat and Preserving Evidence Pull in Opposite Directions
DFIR, Digital Forensics and Incident Response, combines two disciplines that share obvious overlap but genuinely pull in opposite directions during an active incident, a tension worth naming directly rather than glossing over as if the two always align smoothly.
Incident response’s immediate priority is containing an active threat, isolating a compromised device, cutting off an attacker’s access, stopping further damage as quickly as possible. Forensic preservation’s priority is the opposite: capturing evidence in its original, unaltered state before anything changes it, since even a well-intentioned containment action, disconnecting a device from the network, rebooting a system to clear malware, can destroy exactly the volatile evidence, active memory contents, running processes, an investigator would otherwise need to reconstruct what happened.
This is a genuine, practical dilemma every DFIR team faces, not a theoretical concern. Isolating a compromised device from the network is usually the right immediate containment step, and it can typically be done without powering the device down, preserving memory-resident evidence while still cutting off the attacker’s active access. Rebooting or fully shutting down a system, by contrast, genuinely destroys volatile evidence, memory contents, active network state, that forensic investigators specifically rely on to understand an attack’s full scope. The practical resolution most mature DFIR programs adopt involves capturing forensic images and memory dumps specifically before taking any action that would alter system state, even under genuine time pressure, since evidence lost in the first few minutes of a rushed containment response often cannot be recovered afterward, potentially leaving both the technical investigation and any later legal action with a genuine, permanent gap.
What Is a PST File, and Why Does It Matter in Email Forensics?
A PST file, Personal Storage Table, is the file format Microsoft Outlook uses to store email messages, contacts, calendar entries and other mailbox data locally on a device or exported from an Exchange server. In email forensics and eDiscovery specifically, PST files often represent one of the richest, most complete sources of communication evidence available, since a single file can contain an entire mailbox’s history in one place.
This matters directly for investigations because PST files preserve considerably more than just message content: metadata including exact timestamps, sender and recipient details, and message headers all remain intact within the file structure, information often essential for reconstructing a precise timeline of communication during an investigation. Handling PST files forensically requires the same chain of custody discipline applied to any other evidence, since a PST file extracted or exported improperly can alter metadata in ways that undermine its evidentiary value entirely, precisely the kind of technical detail separating a forensically sound email investigation from a simple, informal mailbox export.
The UK’s Own Standard: ACPO’s Four Principles, and a Genuinely Current Tension
The UK’s own foundational digital evidence doctrine, originally published by the Association of Chief Police Officers and still widely referenced today, sets out four core principles. No action taken by investigators should change data that may later be relied upon in court. Where accessing original data directly is genuinely necessary, the person doing so must be competent and able to explain the relevance and implications of their actions. An audit trail or record of every process applied to digital evidence must be created and preserved, allowing an independent third party to examine those processes and achieve the same result. The person in overall charge of an investigation carries ultimate responsibility for ensuring the law and these principles are properly followed throughout.
Here is a genuinely current, unresolved tension worth understanding directly, since it connects these established principles to a live, active UK legal debate. Separate from ACPO’s own investigator-focused principles, UK law has long contained a distinct legal presumption specifically about computer evidence in court: that a computer is presumed to have been operating correctly at the material time, unless specific evidence proves otherwise. Introduced in 1999, this presumption replaced an earlier rule under the Police and Criminal Evidence Act that had actually placed the burden of proving reliability on the prosecution, reversing that burden onto whoever wished to challenge the computer evidence instead. This presumption has come under formal government review specifically because of its central role in one of the most serious miscarriages of justice in recent UK legal history, developed fully in the next section. As of the most recent government position, the Ministry of Justice launched a formal call for evidence specifically examining this presumption and remains actively considering the responses received, meaning this remains a genuinely open, unresolved question in UK law right now, not a settled matter forensic investigators and legal teams can treat as fixed doctrine.
Why UK Courts Have Grown Sceptical of Software-Generated Evidence
The Post Office Horizon scandal is the direct, well-documented reason this scepticism developed, and understanding the actual legal mechanism involved matters for anyone working with digital evidence in the UK specifically. From 1999 onward, the Post Office prosecuted hundreds of subpostmasters for theft, fraud and false accounting, based on evidence from its Horizon accounting software, supplied by Fujitsu, which showed unexplained shortfalls in branch accounts. Those shortfalls were, in a significant share of cases, actually caused by errors within the Horizon system itself, not genuine theft or fraud by the people prosecuted.
This became possible specifically because of the legal presumption covered in the previous section, that courts should treat computer-generated evidence as reliable unless proven otherwise. Notably, the Post Office itself had supported introducing this presumption back in 1999, at the time describing the alternative, having to actively prove a computer’s reliability, as burdensome from a prosecution standpoint. Challenging this presumption in individual cases proved, in practice, extremely difficult, particularly for individuals facing a large, well-resourced institution, until a 2018 High Court case involving 555 former subpostmasters directly examined Horizon’s actual reliability and exposed the scale of the underlying software failures. This is widely regarded as one of the most serious miscarriages of justice in modern UK legal history, and it directly explains why UK courts, legal professionals and forensic investigators now treat software-generated evidence with considerably more caution than the historical presumption alone would suggest is warranted. Cyber Security Solutions Ltd applies exactly this heightened scrutiny in its own forensic work, since the Horizon case demonstrated concretely that a computer system producing consistent, seemingly authoritative output is not, on its own, proof that the underlying system was actually functioning correctly.
Conclusion
Cyber forensics depends entirely on methodology and documented integrity, and the Post Office Horizon scandal remains the clearest, most consequential proof of what happens when software-generated evidence gets trusted without that same rigorous scrutiny. Start by confirming your own organization’s incident response process actually preserves evidence properly before containment actions risk destroying it. To get help building a forensically sound incident response process, visit cybersecuritysolutionsltd.com for expert support from Cyber Security Solutions Ltd.
FAQs
Cyber forensics is the practice of identifying, preserving, analyzing and presenting digital evidence in a scientifically sound, legally defensible way, following strict documented methodology so the resulting evidence can withstand challenge in court or a formal investigation.
Cyber forensics asks what technically happened, requiring deep technical reconstruction. eDiscovery asks what relevant information exists, focusing on broadly identifying, collecting and producing electronically stored information for litigation, without necessarily requiring the same technical depth as forensics.
Chain of custody is the documented record proving evidence remained unaltered from collection through presentation. A single undocumented gap can give opposing counsel grounds to challenge the evidence’s authenticity entirely, regardless of how sound the underlying technical analysis was.
Incident response prioritizes containing an active threat quickly, while forensic preservation prioritizes capturing evidence in its original state. Actions like rebooting a system can destroy volatile evidence, memory contents, active connections, that investigators need to reconstruct what actually happened.
Four core UK principles: investigator actions should not change data relied upon in court, only competent individuals should access original data when necessary, a full audit trail of all processes must be preserved, and the lead investigator holds ultimate responsibility for compliance.
Hundreds of subpostmasters were wrongly prosecuted based on faulty Horizon software evidence, enabled by a legal presumption that computers operate correctly unless proven otherwise. This exposed how difficult that presumption made it to challenge flawed computer evidence, prompting an ongoing government review.
