Digital forensics is the structured collection and analysis of electronic evidence — from workstations and servers to email, Microsoft 365, and mobile devices. It answers the questions that matter after a breach: what was accessed, how did the attacker get in, and what must you report?
South African businesses call AOLC after ransomware, account takeovers, insider data theft, fraud investigations, and POPIA breach notifications. A skilled forensic partner helps you make the best of a bad situation — preserving evidence before it is destroyed, building a defensible timeline, and producing reports your legal team, insurer, and the Information Regulator can rely on.
AOLC's forensic engagements are delivered by certified Tier 3 and Tier 4 consultants with experience across SME, financial, legal, education, and government environments. See our Trust & Security posture for how we handle sensitive data during investigations.
Request a Forensic Consultation
Structured analysis across your entire digital estate.
Disk imaging, memory capture, registry and event log analysis. Identify malware persistence, lateral movement, and data exfiltration from Windows and Linux systems.
Account takeover investigation, mailbox rule analysis, SharePoint and OneDrive access review, and Unified Audit Log correlation across your Microsoft 365 tenant.
Firewall, DNS, and proxy log analysis. Trace command-and-control traffic, identify compromised accounts, and map the attack path across your network.
Analysis of company phones and tablets involved in data misuse, phishing compromise, or insider threat investigations.
Investigate unauthorised access, bulk downloads, policy violations, and departing employee data theft with audit-ready evidence.
Executive summaries, technical timelines, and IOC lists formatted for cyber insurers, legal counsel, and regulatory submissions.
Five phases — from first call to final report.
Scope the incident, identify systems of interest, and agree investigation objectives with your leadership or legal team.
Forensic imaging with documented chain of custody. Do not wipe or reinstall affected systems before this step — you may destroy the only copy of critical evidence.
Deep-dive examination of artefacts, logs, and memory. Build a defensible timeline of attacker activity and data impact.
Deliver executive summary, technical findings, indicators of compromise, and remediation recommendations.
Brief your team, insurer, or legal counsel. Support POPIA notification and post-incident hardening. See Ransomware Remediation if recovery is also required.
Plain-language briefing for directors and non-technical stakeholders.
Minute-by-minute reconstruction of attacker activity with supporting evidence.
Scope of personal information affected — ready for Information Regulator notification.
Formatted for cyber insurance claims and loss adjuster review.
Forensic investigations move faster when you have a pre-signed Incident Response Retainer. Reserved hours, a named case manager, and a guaranteed SLA mean we start preserving evidence within hours — not days.
AOLC offers Basic (10 hours/year) and Standard (20 hours/year) retainer tiers with digital forensics, containment, and insurance-ready breach reporting included.
View IR Retainer OptionsIf encryption is in progress right now, you need containment and recovery — not just investigation. See our dedicated Ransomware Remediation service or call +27 87 55 00 555 immediately.
Direct answers to the questions that come up most often. Encoded as FAQPage structured data so AI search engines can quote them accurately.
Digital forensics is the structured collection and analysis of electronic evidence from computers, servers, email, cloud services, and mobile devices. South African businesses typically need it after a data breach, ransomware attack, insider threat, fraud investigation, or when preparing a POPIA breach notification or cyber insurance claim.
AOLC works to minimise disruption. Live systems can often be imaged after hours or from snapshots. Where a device must be taken offline for imaging, we coordinate timing with your team and provide a clear schedule before work begins.
Yes. Our forensic reports document what data was accessed or exfiltrated, when the incident occurred, and how it happened — the evidence the Information Regulator expects when you report a breach under POPIA section 22.
Yes. AOLC produces insurer-ready documentation including a technical timeline, indicators of compromise, scope of impact, and remediation steps taken. We work directly with your broker or loss adjuster when required.
Do not wipe, reformat, or reinstall affected systems. Isolate compromised devices from the network but leave them powered on where safe. Preserve logs from firewalls, email, and cloud services. Document who discovered the incident and when. Then call AOLC on +27 87 55 00 555.
A preliminary scope and containment assessment typically happens within one business day. Full analysis depends on the number of systems involved — a single-endpoint investigation may take 3–5 business days; multi-site engagements take longer. We provide a timeline estimate at engagement.
Yes. We regularly coordinate with external legal counsel, forensic accountants, and cyber insurers. Reports can be prepared for privileged review, and we can attend insurer or regulator briefings on your behalf.
Tell us about the incident and we'll scope the right forensic engagement.