The critical importance of digital evidence

Digital evidence is any information that is stored or transmitted in binary form that may need to be presented in a judicial proceeding.

All organisations collect and store confidential data, from Personally Identifiable Information (PII), such as ID numbers and contact details, to banking information. Considering how these details can be used to defraud customers, it is essential that PII is always kept private and secured. Around the world, privacy acts and data protection laws for consumers have been enacted. In South Africa, the Protection of Personal Information Act (POPIA) protects personal data and holds businesses and individuals within those businesses responsible for ensuring the safety and integrity of any data the business collects, stores or uses.

Unfortunately, enacting a law alone does not secure data. Given the value of personal data and what businesses will do to protect data, cybercrime has become one of the most lucrative criminal industries in the world. Think about it – a cybercriminal can cash in if they steal PII, and even more so if they combine it with a ransomware attack. Given the business interruption and reputational damage businesses face if data is stolen or leaked – as well as possible legal consequences and hefty fines associated with data breaches – businesses will pay millions to get to their data back.

This is why digital forensic investigations during an Incident Response are so important.

Under POPIA, your business must disclose if any data was compromised during a cyberattack. Additionally, digital forensics will trace the cyberattack path and scrutinise every move the attacker made on your network.

Following the digital evidence

A comprehensive digital forensics audit and investigation provides a report of any data that was copied or removed from a network. It also reveals if your network is still compromised, where your vulnerabilities lie and how your network can be secured. The Information Regulator requires your business to notify it – POPIA’s legislation states that all data subjects must be notified if their data was leaked in a breach (and what that data is) and, in many cases, insurance companies will only pay out ransomware claims after a full digital forensic audit has been conducted as well.

In other words, digital evidence is at the centre of any cyber-related incident. Let’s take a closer look at each of these critical areas.

  1. Is the network still compromised?

If your organisation fails to perform an effective threat hunting and digital forensics investigation, you risk the possibility that the attacker is still on your network. Resolving a cyberattack does not guarantee the safety or security of your networks and data moving forward. Most attackers leave a backdoor so that they will have access to your systems in the future.

Digital forensics experts can determine if there is still suspicious activity on your network and, by tracing the digital footprints of an attacker, they can determine what steps need to be taken to mitigate potential future cyberthreats.

  1. Was data removed from the network?

In a ransomware attack, networks are locked down and data is encrypted (so that you cannot access the data your business needs to function), or data is ‘exfiltrated’ or removed and held for ‘ransom’ until an agreed-upon amount is paid, usually in an untraceable cybercurrency.

Here’s the challenge – consider how much data your company stores. How much is duplicated? Where does it all live? How will you know what has been accessed, copied or removed? Only digital evidence can reveal the answers to these questions. Additionally, a digital forensics team will be able to estimate the likelihood that your data was leaked by utilising threat intelligence from previous cases.

  1. Will a digital forensics investigation help prevent a future cyberattack?

You can’t safeguard your data in the future if you can’t pinpoint your vulnerabilities. A threat assessment performed by a security team leveraging the digital evidence of previous attacks will be able to find and solve any gaps that need to be filled in a security infrastructure.

These audits will also provide an opportunity to identify additional security vulnerabilities that can be proactively addressed.

Armed with vital intelligence from a digital forensics expert, you will be able to determine the next logical steps to take to ensure your cyber security. Whether or not you choose cyber security services from a team of experts, improving your cyber security after an attack is crucial.

Actively patching the cybersecurity vulnerabilities of your organisation can:

  • Reduce risks of malware entering your network.
  • Keep your sensitive data safe.
  • Reduce the potential of experiencing costly cyberattacks in the future.

Act fast

When a cyberbreach occurs, time is of the essence. Cybercriminals will focus on removing any trace of digital evidence that they may leave behind. Digital forensic experts must access compromised systems quickly to be able to detect and gather the required digital evidence.

At Cyanre, our team deal with cyberbreaches on a daily basis. We know exactly what to look for and how to collect and preserve the digital evidence that your business will need to adhere to POPIA and to close any vulnerabilities.