What is digital forensics and what gets decided in the first hour?
Digital forensics is the discipline that acquires, preserves and documents digital data so that it holds up as evidence.
Digital forensics, known in Italian as informatica forense, is the discipline that identifies, acquires, preserves and documents digital data so that it remains usable as evidence before a court, a supervisory authority or an insurer. What separates it from ordinary technical analysis is not the tooling but the method: work happens on a bit-for-bit copy of the medium, a cryptographic fingerprint (hash) is computed before and after the copy to show nothing changed, and a chain of custody is kept, meaning the record of who held that data, where and at what moment. If you run a company, the practical point is a single one: digital evidence is fragile and it is almost always destroyed in the first few hours, in good faith, by the very people who are honestly trying to get the systems running again.
What Italian law requires of whoever acquires
The reference is law n. 48 of 18 March 2008, which ratified the Budapest Convention on cybercrime and rewrote several articles of the Italian code of criminal procedure. Article 244(2) allows the judicial authority to carry out any technical operation on computer or telematic systems, but only by adopting technical measures aimed at preserving the original data and preventing its alteration. The same law inserted article 254-bis on the seizure of data held by providers of computer, telematic and telecommunications services, which permits acquisition by copying onto a suitable medium through a procedure ensuring the copy matches the originals and cannot be modified, while ordering the provider to retain and protect the originals. These duties fall on the judicial authority, not on the company: a badly made private copy is not thereby unusable, it is simply open to challenge, and the court weighs it freely along with everything that produced it. The distinction does not remove the practical incentive to work to the same standard: the other side still attacks how the copy was made, and the evidence loses weight exactly when it is needed. On how that is done in practice the statute is silent, and standards fill the gap: ISO/IEC 27037:2012 on the identification, collection, acquisition and preservation of digital evidence, and NIST SP 800-86, which since 2006 has tied forensic technique to incident response.
A concrete example
A design practice of sixty people finds its project files encrypted on a Monday morning. The trusted technician does what looks sensible: powers the servers down, reinstalls the operating system and restores from the previous week's backup. By evening people are working again, and the evidence is gone. Volatile memory, which held the attacker's running processes and the open outbound connections, went with the shutdown; the traces of exfiltration were on the disk that has been overwritten; the timestamp of the first unlawful login sat in records nobody had moved elsewhere. Three weeks later all three are needed: by the insurer to establish how the claim arose, by the Garante, the Italian data protection authority, to state which data left, by the lawyer to work out whether entry came through the remote support supplier.
What the person in charge decides in the first hour
Three instinctive moves destroy the evidence: powering the machines off, restoring from backup over the affected systems, and letting the trusted technician have a look around with administrator credentials. Each has an opposite: isolate without powering off, unless the spread is already under way, restore onto fresh hardware leaving the originals untouched, and freeze privileged accounts until someone who can acquire properly arrives.
Cloud systems add a fourth, and it is the most common one: resetting the password and deleting the forwarding rule the attacker created, which is often the only trace left. There nobody destroys the evidence, it expires: audit records have short retention windows, so export them at once and keep them outside the platform.
In parallel, record the timestamps and secure the event records, which are the material precondition of any evidence and have to be arranged beforehand, as explained under log management. Who to call, and under which contractual terms, belongs instead to the incident response plan, which also explains why the first number to dial is the insurer's rather than the examiner's. This holds for ransomware as much as for the suspicion that a departing employee walked off with an archive: the evidence is lost just as easily. Once the hypothesis becomes concrete, the work goes to a technical consultant who works to ISO/IEC 27037 and documents every step, coordinated with legal counsel, because it is that documentation that has to survive cross-examination.
This entry is informational and does not constitute legal advice: for the acquisition of digital evidence and its consequences in proceedings, involve a forensic examiner and your legal counsel.
Frequently asked questions
Related terms
- Incident response · The set of roles, decisions and procedures by which a company detects, contains and closes a security incident.
- Log management · Log management is the practice of collecting, centralizing and retaining the event records produced by company systems.
- Ransomware · Malware that encrypts company data and demands a ransom for the decryption key, often with double extortion.
- Data breach · An incident that exposes confidential data through an external attack or an internal error, with direct and reputational cost.
- Data breach notification · The controller's GDPR duty to alert the supervisory authority within 72 hours of a breach risking people's rights.
A term that hits close to home? Let's talk.
CONTACT ME