{"id":3844,"date":"2024-05-31T15:39:10","date_gmt":"2024-05-31T20:39:10","guid":{"rendered":"https:\/\/www.darkreading.com\/endpoint-security\/lawyers-forensics-investigators-help-outside-cybersecurity"},"modified":"2024-05-31T15:39:10","modified_gmt":"2024-05-31T20:39:10","slug":"lawyers-ask-forensics-investigators-for-help-outside-cybersecurity","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/31\/lawyers-ask-forensics-investigators-for-help-outside-cybersecurity\/","title":{"rendered":"Lawyers Ask Forensics Investigators for Help Outside Cybersecurity"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt48d7165fd2b96987\/64f15ac8b39c03b358f55d5a\/magnifyingglass_Brain_light_Alamy_Stock_Photo.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/lawyers-ask-forensics-investigators-for-help-outside-cybersecurity.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/lawyers-ask-forensics-investigators-for-help-outside-cybersecurity.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Digital forensics investigators are meticulous sleuths, and their skills are increasingly being sought after outside of cybersecurity to help corporate and outside counsels with tasks such as document authentication. With the growing number of data breaches and intellectual property thefts, cybersecurity experts <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.jdsupra.com\/legalnews\/the-increasing-role-of-cybersecurity-7339443\/\" rel=\"noopener\">getting involved in legal disputes such as eDiscovery and fraud cases<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> is not as unusual as it used to be.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Attorneys and traditional investigators may not be as skilled in understanding risk and personally identifiable information, says Aravind Swaminathan, a partner at Orrick, Herrington &amp; Sutcliffe LLP. It is the the ability to see things as being something other than how they appear that sets apart a cybersecurity investigator from traditional private investigators.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For example, a simple eDiscovery analysis turned into something far more when a lawyer questioned the authenticity of a document, says J-Michael Roberts, a forensics expert for Law and Forensics, a legal engineering firm. In that instance, the data on the document seemed off, and a deep dive into the document metadata and a full analysis of the computer on which it was created revealed the document had been doctored. Artifacts uncovered in a forensic search of the system proved the document and much of its content was added at different times and brought together to make the composite document.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;[It] went from a simple contract dispute, essentially into a very large and significant matter where one side was actively working to defraud the other,&#8221; Roberts says.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Bringing A Different Perspective\">Bringing A Different Perspective<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">According to Steven Hailey, an instructor on digital forensics at Edmonds College in Lynnwood, Wash., forensics investigators can uncover evidence that turn simple cases into serious crimes. A dispute over a family business following the death of the patriarch and owner centered on the authenticity of contemporaneous notes of discussions about the future of the business. The resulting forensics investigation discovered that the documents were not created at the time they appeared to have been made and artifacts in the documents and computers showed the documents had been manipulated.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;To the average person, it would it look foolproof&nbsp; \u2013 all these documents in chronological order,&#8221; Hailey says. &#8220;We have an expert understanding of the evidence left behind when data is created, manipulated, stored, and moved throughout an organization. This expertise often uncovers important but disparate data sets in an investigation that would have otherwise gone unnoticed or considered unimportant to the matter at hand.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Helping Boards Understand Incidents\">Helping Boards Understand Incidents<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Unlike a major incident, such as an airplane crash, where the event occurs and is then done, cyberattacks are ongoing and it takes a while to even pinpoint what the event actually is. Even after the defenders manage to remove the adversaries, there is still the possibility of a follow-up attack, or that the attackers were not completely removed in the first place. Forensics experts must make decisions on imperfect information, which is why CISOs run tabletop exercises to prepare boards for incident responses.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Boards fail to understand that organizations are judged on their response to a breach, not the breach itself. Having the right team in place for incident response, including the forensic teams working with the attorneys, is crucial to responding appropriately.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">\u201cThe notion that there&#8217;s answers, that we will find out what happened, and we&#8217;ll find out quickly, is a challenge that boards have, because sometimes there are no answers, and we sometimes don&#8217;t find out quickly,\u201d says Swaminathan.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/endpoint-security\/lawyers-forensics-investigators-help-outside-cybersecurity\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Digital forensics investigators are meticulous sleuths, and their skills are<\/p>\n","protected":false},"author":12,"featured_media":3845,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3844","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/lawyers-ask-forensics-investigators-for-help-outside-cybersecurity-scaled.jpg?fit=2560%2C1862&ssl=1",2560,1862,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/lawyers-ask-forensics-investigators-for-help-outside-cybersecurity-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/lawyers-ask-forensics-investigators-for-help-outside-cybersecurity-scaled.jpg?fit=300%2C218&ssl=1",300,218,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/lawyers-ask-forensics-investigators-for-help-outside-cybersecurity-scaled.jpg?fit=640%2C466&ssl=1",640,466,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/lawyers-ask-forensics-investigators-for-help-outside-cybersecurity-scaled.jpg?fit=640%2C466&ssl=1",640,466,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/lawyers-ask-forensics-investigators-for-help-outside-cybersecurity-scaled.jpg?fit=1536%2C1117&ssl=1",1536,1117,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/lawyers-ask-forensics-investigators-for-help-outside-cybersecurity-scaled.jpg?fit=2048%2C1490&ssl=1",2048,1490,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/lawyers-ask-forensics-investigators-for-help-outside-cybersecurity-scaled.jpg?fit=1024%2C745&ssl=1",1024,745,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/lawyers-ask-forensics-investigators-for-help-outside-cybersecurity-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/lawyers-ask-forensics-investigators-for-help-outside-cybersecurity-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/lawyers-ask-forensics-investigators-for-help-outside-cybersecurity-scaled.jpg?fit=2560%2C1862&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3844","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3844"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3844\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3845"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3844"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3844"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3844"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}