By Quinn Varcoe, Founder & CEO, SleuthX
Why the first hour matters more than the next week
Most of what a business loses in an incident is lost before anyone calls an examiner. Not to the attacker. To ordinary, well-meant cleanup.
A device in use is a device that is changing. Every hour a suspect laptop stays in service, deleted files get overwritten by normal disk activity, access timestamps advance, and scheduled maintenance quietly discards the logs that would have shown what happened. Reimaging the machine, which is the reflex of almost every IT team, destroys the evidence completely and irreversibly.
So the useful instruction is short. Stop using the device. Do not shut it down if it is running and you can isolate it from the network instead, because memory holds things the disk does not. Do not let anyone log in to look around. Write down who has touched it and when. Then decide, unhurried, whether you need an examination at all.
What an examination actually involves
The work has a shape, and it is the same shape whether the question is theft, intrusion, or a dispute between two employees about what was said.
Acquisition
An examiner takes a bit-for-bit copy of the storage, not a copy of the files. The difference matters: a file-level copy takes what the operating system currently admits exists, while an image takes the whole volume including space the system considers free, which is where deleted material lives until it is overwritten. The original is then set aside and the analysis runs against the copy, so the evidence is never worked on directly.
Verification and chain of custody
The image is hashed, and that hash is what makes the copy defensible. Re-running it later proves the data has not changed since acquisition. Alongside it runs the chain of custody: a record of who held the device, when, and what they did with it. Chain of custody is not paperwork for its own sake. It is the thing that answers the only question an opposing expert really needs to win, which is whether anyone could have altered this between the incident and the report.
Analysis
This is where the question you asked shapes everything. An examiner reconstructs activity from artifacts the operating system creates as a side effect of normal use: records of which files were opened, which devices were attached, which accounts authenticated, what was searched for, what was deleted and when. Cloud and account logs are pulled alongside the device, because most modern activity leaves as much trace in a service provider as on the hardware.
The report
A good report states findings, the basis for each finding, and the limits of what the evidence supports. It is written to be read by someone non-technical and to survive being challenged by someone technical. Where a conclusion is probable rather than certain, it says so in those words.
What an examination cannot do
This is the part most worth reading, because it is the part that gets oversold.
- It cannot recover what has been overwritten. Deleted is recoverable until the space is reused. After that it is gone, and no tool changes that.
- It cannot put a person at a keyboard by itself. Devices record accounts and sessions. Tying those to a human needs corroboration from outside the device.
- It cannot see what was never recorded. If logging was off, or the retention window has passed, the answer is that the evidence does not exist, not that the event did not happen.
- It cannot promise an outcome. An examination establishes what the evidence shows. What that is worth to a case, a claim, or an insurer is a separate judgment.
How this fits an incident response
Forensic examination and incident response are related but not the same. Response is about containing an active problem. Examination is about establishing what happened, and it is what makes the answer defensible afterwards. The two overlap badly under pressure, which is why the preservation step is so often skipped.
The public frameworks are worth knowing even if you never run them yourself. NIST SP 800-86 covers integrating forensic technique into incident handling, and SP 800-61r3 is the current incident-handling guidance, having superseded the widely-cited r2 in 2025. The FTC data-breach response guide is the plainest summary of the obligations side.
When it is not worth it
Sometimes the honest answer is that an examination will not change anything. If you already know what happened, nobody disputes it, no obligation turns on the detail, and the device has been in use for weeks, then paying to confirm what you know is not a good use of money. We would rather tell you that than take the engagement.
Common questions from business owners
How long does an examination take?
Can you tell me who did it?
Will using the device destroy the evidence?
Does this have to go to court to be worth doing?
What do you need from us to start?
What this means for you
- Written scope before any work. You see a written scope covering deliverables, timeline, and price, and you approve it before we begin. You are never billed for work you did not authorize.
- We commit to findings, not outcomes. We tell you up front what the evidence can and cannot establish. Recovery, attribution, and prosecution are decided by banks, platforms, insurers, and courts. We produce the record they act on, and we put that distinction in writing.
- Every case is investigated, not just scanned. A credentialed examiner reviews every case before findings leave the practice. You get a documented investigation to court-admissible standards, not a single automated scan and a one-line answer.
- We will tell you if you do not need us. If a free or simpler step would resolve your situation, whether a police report, an IC3 filing, or a platform's own recovery flow, we point you there first.















