Skip to content
All projects
Confidential enterprise groupEnterpriseSaudi Arabia2025

Digital forensics and incident response across a 1,100-employee enterprise

A defensible account of what happened, how far it reached, and what to change — evidence handled to a standard that holds up outside the IT department.

The challenge

When something goes wrong on a network of this size, the first casualty is certainty. Logs disagree, people remember events differently, and the pressure to restore service immediately competes directly with the need to preserve what actually happened.

Scope is the hard question. Establishing whether an incident touched one machine or four hundred, and whether anything left the organisation, cannot be answered by inspecting the obvious endpoint — it requires sweeping an estate of over 1,100 employees for the same indicators.

And the findings had to survive scrutiny. An internal summary is not sufficient where legal, regulatory or HR consequences may follow; the evidence has to be acquired and handled so that its integrity can be demonstrated later.

Our approach
01

Preserve before anything else

Forensically sound acquisition of the affected systems with documented chain of custody, taken before remediation begins. Restoring a machine first destroys the answer to what happened on it.

02

Reconstruct the timeline

Disk and memory artefacts correlated against authentication, endpoint and network logs to build a single defensible sequence of events, rather than a set of disagreeing partial accounts.

03

Scope across the estate

Indicators recovered from the initial systems were swept across the wider environment covering all 1,100+ employees, to establish the true blast radius instead of assuming the first system found was the only one affected.

04

Report for the audience that matters

Findings delivered in two registers — a technical account with the supporting evidence, and an executive summary stating what happened, what was affected, and what to do — suitable for legal, regulatory and HR use.

How it works

Evidence is acquired under chain of custody, analysed across disk, memory and log sources, correlated into a single timeline, then converted into indicators that are swept across the wider estate to establish scope before remediation and reporting.

Forensic acquisition
Chain of custody
Disk / memory analysis
Log correlation
Timeline reconstruction
Estate-wide IOC sweep
Root cause & remediation
Expert report
What we built

The system, in specifics.

Forensically sound acquisition and documented chain of custody across affected systems.

Disk, memory and mobile device forensic analysis.

Log correlation and full timeline reconstruction of the incident.

Malware and artefact analysis to establish mechanism and persistence.

Estate-wide indicator sweep across an organisation of 1,100+ employees to determine scope.

Root cause analysis with a prioritised remediation roadmap.

Expert reporting prepared to withstand legal and regulatory scrutiny.

Outcome

What changed.

1,100+
Employees in scope
Estate-wide indicator sweep

A single defensible timeline replacing conflicting partial accounts

True scope established across 1,100+ employees rather than assumed

Evidence handled so its integrity can be demonstrated later

Root cause identified with a prioritised remediation roadmap

Findings usable in legal, regulatory and HR proceedings

Next

Related work.

SCORA — Security posture assessment without the consultant invoice

SCORA

SCORAEnterpriseGlobal

Security posture assessment without the consultant invoice

A security, compliance and risk assessment platform that scores an organisation against NIST CSF 2.0, ISO 27001:2022 and an SME health check, then returns a prioritised action plan.

Next.jsTypeScriptPostgreSQL
Read case studySee SCORA live
Sharebius Messenger — End-to-end encrypted messenger with integrated payments

Sharebius Messenger

SharebiusCommunicationsGlobal

End-to-end encrypted messenger with integrated payments

Privacy-first messaging with self-destructing messages, encrypted calls and built-in cryptocurrency payments.

JavaKotlinSwift
Read case study
SwingSmith — AI golf swing analyser with a 10-position engine and in-app coach
Flagship

SwingSmith

SwingSmithSports TechGlobal

AI golf swing analyser with a 10-position engine and in-app coach

Upload one swing from a phone and get a 10-position breakdown, 50+ metrics, and the single fix worth practising next.

Computer VisionPose EstimationAI/ML
Read case studySee SwingSmith live