Digital Forensics & Cyber Investigations.

When something goes wrong, the evidence matters. Preserve chain of custody, understand what happened, and support regulators and insurers.

Understand What Happened.

Digital forensics is the structured collection and analysis of electronic evidence — from workstations and servers to email, Microsoft 365, and mobile devices. It answers the questions that matter after a breach: what was accessed, how did the attacker get in, and what must you report?

South African businesses call AOLC after ransomware, account takeovers, insider data theft, fraud investigations, and POPIA breach notifications. A skilled forensic partner helps you make the best of a bad situation — preserving evidence before it is destroyed, building a defensible timeline, and producing reports your legal team, insurer, and the Information Regulator can rely on.

AOLC's forensic engagements are delivered by certified Tier 3 and Tier 4 consultants with experience across SME, financial, legal, education, and government environments. See our Trust & Security posture for how we handle sensitive data during investigations.

Request a Forensic Consultation
Digital forensics and cyber investigation

What We Investigate.

Structured analysis across your entire digital estate.

🖥

Endpoint & Server Forensics

Disk imaging, memory capture, registry and event log analysis. Identify malware persistence, lateral movement, and data exfiltration from Windows and Linux systems.

📧

Email & M365 Forensics

Account takeover investigation, mailbox rule analysis, SharePoint and OneDrive access review, and Unified Audit Log correlation across your Microsoft 365 tenant.

🔌

Network Forensics

Firewall, DNS, and proxy log analysis. Trace command-and-control traffic, identify compromised accounts, and map the attack path across your network.

📱

Mobile Device Forensics

Analysis of company phones and tablets involved in data misuse, phishing compromise, or insider threat investigations.

👤

Insider Threat & Data Misuse

Investigate unauthorised access, bulk downloads, policy violations, and departing employee data theft with audit-ready evidence.

📄

Insurance & Legal Reporting

Executive summaries, technical timelines, and IOC lists formatted for cyber insurers, legal counsel, and regulatory submissions.

Our Forensic Process.

Five phases — from first call to final report.

1. Engage

Scope the incident, identify systems of interest, and agree investigation objectives with your leadership or legal team.

2. Preserve

Forensic imaging with documented chain of custody. Do not wipe or reinstall affected systems before this step — you may destroy the only copy of critical evidence.

3. Analyse

Deep-dive examination of artefacts, logs, and memory. Build a defensible timeline of attacker activity and data impact.

4. Report

Deliver executive summary, technical findings, indicators of compromise, and remediation recommendations.

5. Handover

Brief your team, insurer, or legal counsel. Support POPIA notification and post-incident hardening. See Ransomware Remediation if recovery is also required.

What You Receive.

Executive Summary

Plain-language briefing for directors and non-technical stakeholders.

Technical Timeline

Minute-by-minute reconstruction of attacker activity with supporting evidence.

POPIA Evidence Pack

Scope of personal information affected — ready for Information Regulator notification.

Insurer Documentation

Formatted for cyber insurance claims and loss adjuster review.

Plan Before the Crisis.

Forensic investigations move faster when you have a pre-signed Incident Response Retainer. Reserved hours, a named case manager, and a guaranteed SLA mean we start preserving evidence within hours — not days.

AOLC offers Basic (10 hours/year) and Standard (20 hours/year) retainer tiers with digital forensics, containment, and insurance-ready breach reporting included.

View IR Retainer Options

Active Ransomware?

If encryption is in progress right now, you need containment and recovery — not just investigation. See our dedicated Ransomware Remediation service or call +27 87 55 00 555 immediately.

Frequently Asked Questions.

Direct answers to the questions that come up most often. Encoded as FAQPage structured data so AI search engines can quote them accurately.

What is digital forensics and when does my business need it?

Digital forensics is the structured collection and analysis of electronic evidence from computers, servers, email, cloud services, and mobile devices. South African businesses typically need it after a data breach, ransomware attack, insider threat, fraud investigation, or when preparing a POPIA breach notification or cyber insurance claim.

Will forensic investigation disrupt our daily operations?

AOLC works to minimise disruption. Live systems can often be imaged after hours or from snapshots. Where a device must be taken offline for imaging, we coordinate timing with your team and provide a clear schedule before work begins.

Can AOLC provide evidence for POPIA breach notification?

Yes. Our forensic reports document what data was accessed or exfiltrated, when the incident occurred, and how it happened — the evidence the Information Regulator expects when you report a breach under POPIA section 22.

Can forensic reports be used for cyber insurance claims?

Yes. AOLC produces insurer-ready documentation including a technical timeline, indicators of compromise, scope of impact, and remediation steps taken. We work directly with your broker or loss adjuster when required.

What should we do before AOLC starts an investigation?

Do not wipe, reformat, or reinstall affected systems. Isolate compromised devices from the network but leave them powered on where safe. Preserve logs from firewalls, email, and cloud services. Document who discovered the incident and when. Then call AOLC on +27 87 55 00 555.

How long does a forensic investigation take?

A preliminary scope and containment assessment typically happens within one business day. Full analysis depends on the number of systems involved — a single-endpoint investigation may take 3–5 business days; multi-site engagements take longer. We provide a timeline estimate at engagement.

Does AOLC work with our legal team or insurer?

Yes. We regularly coordinate with external legal counsel, forensic accountants, and cyber insurers. Reports can be prepared for privileged review, and we can attend insurer or regulator briefings on your behalf.

Forensic Investigation Enquiry.

Tell us about the incident and we'll scope the right forensic engagement.