Recover from an attack

Digital forensics investigation

After an attack, people will ask what happened: your board, your insurer, the ICO and your customers. A forensic investigation gives you answers based on evidence.

Before the investigation starts
  1. Don't wipe, rebuild or reinstall affected machines. If you have to get running again, set the originals aside.
  2. Leave machines powered on if you can, and disconnect them from the network instead.
  3. Don't run clean-up tools or delete suspicious files. They're evidence.
  4. Write down a timeline of what you saw and when, and who has touched what since.
The risk

Without an investigation, a business often can't say whether personal data was taken, and has to assume the worst when deciding who to tell.

Evidence doesn't last. Logs are overwritten, machines get rebuilt and some evidence is lost when a computer is switched off, so the sooner an investigation starts, the more it can find.

What it does
  • A timeline of the attack, from the first way in to the last thing the attacker did
  • Examines computers, servers, cloud services and email logs
  • Malware analysis, to work out what any malicious files were designed to do
  • Establishes what data was accessed or taken, to inform breach notifications
  • Collects and preserves evidence for your insurer, the police or your lawyers
  • A written report of the findings and what to fix

If the attack is still going on, start with emergency incident response: containing it comes first, and the investigation runs alongside.

Who it's for

Businesses that have had an incident and need to know what happened, including those that have already recovered but still need answers for their insurer, the regulator or their customers.

How we supply it

Investigations are carried out by Sophos's digital forensics and incident response team and arranged through us. Tell us what you need to find out, and we'll scope it with them.

What's under the hood

Sophos Incident Response Services — Sophos's digital forensics and incident response team, which gained NCSC-assured Cyber Incident Response (Level 2) status in 2024.

Questions
Forensics is part of incident response: responders use it to contain an attack while it is happening. A forensic investigation can also be done afterwards, to answer specific questions such as whether data was taken.
Often, yes, though less can be found once machines have been rebuilt. Logs in cloud services such as Microsoft 365 can still show what happened, for as long as they are kept.
It sets out what happened, what was affected and what was done about it, which is what insurers and the ICO usually ask for. If you expect legal proceedings, say so at the start so the evidence can be handled with that in mind.
It depends on what needs investigating, and the cost is agreed with you before work starts.

Not sure what you need?

Tell us a little about your business and we'll recommend the controls that matter most for it — no obligation, and no jargon.

Talk to us → or see every security area →