THREAT BRIEFING · 09.10.2026 DEENFRES

Strategy & Governance

Cyber Forensics for Non-Technicians: What Happens After a Security Incident

By Tobias Massow · July 21, 2022 · 4 min read

After a cyberattack, forensics begins – and for most CEOs, things quickly become overwhelming. Exactly what do forensic investigators do? How long does it take? What can you touch – and what must you leave untouched? And what do the findings mean for liability, insurance claims, and mandatory reporting obligations? A guide for decision-makers.

TL;DR

The Golden Hour: Evidence Preservation Before Recovery

The natural instinct after an attack is to immediately rebuild systems and restore operations. Doing exactly that destroys the most valuable evidence. RAM contents, active network connections, running processes, and temporary files vanish irretrievably upon reboot.

Forensic investigators first create forensic images: bit-for-bit copies of hard drives and RAM dumps. These copies form the foundation of the entire investigation – and are often a prerequisite for insurance payouts and criminal prosecution.

Timeline Analysis: What Happened – and When?

The core task of forensics: reconstructing a complete, chronological timeline of the attack. When did the initial access occur? How did the attacker move laterally across the network? When were data exfiltrated? When was ransomware deployed?

This timeline emerges from correlating hundreds of data sources: Windows Event Logs, firewall logs, Active Directory changes, email logs, cloud audit trails, and endpoint telemetry. The more data sources available, the more complete the picture.

What the Findings Mean for Decision-Makers

Forensic results answer four critical questions: What happened (attack vector and progression)? Which data were compromised (scope of compromise)? Is the attacker still inside the network (containment status)? And how can recurrence be prevented (remediation steps)?

These insights feed directly into regulatory reporting obligations (GDPR: 72-hour deadline; NIS2: 24-hour deadline), insurance claims (the forensic report serves as official damage documentation), and communications strategy (what do we tell customers, partners, and the public?).

Preparation: What Companies Can Do Before an Incident

Forensics is far more effective when prepared in advance. Three essential measures: First, centralized log aggregation (SIEM or at least a Syslog server) – without logs, forensics is impossible. Second, define log retention periods (minimum 90 days; ideally 365). Third, secure an Incident Response (IR) retainer agreement with a qualified forensic service provider.

The most common post-incident realization: “If only we’d had those logs, we’d have detected the attack weeks earlier.” Log management isn’t optional – it’s the foundational requirement for any forensic investigation.

Key Facts

Forensics duration: 2-8 weeks, depending on scope and complexity

Log gap: In 40% of cases, critical logs are missing – preventing full reconstruction (Mandiant)

Costs: €50,000-€250,000 for a comprehensive forensic investigation in mid-sized enterprises

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

Do I need to involve law enforcement?

Strongly recommended in cases of ransomware and data theft. Each German federal state has a Central Office for Cybercrime (ZAC) serving as the primary contact. Some cyber insurance policies explicitly require filing a criminal complaint as a condition for coverage.

Can I keep working during the forensic investigation?

Generally, yes – on systems confirmed not to be compromised. Forensic efforts focus exclusively on affected systems. Crucially: coordinate closely with the forensic team to confirm which systems may be used – and which must remain untouched.

How do I find a qualified forensic service provider?

Look for: BSI (Federal Office for Information Security) certification as an APT response provider, GIAC-certified analysts (e.g., GCFA, GCFE), proven experience in your industry sector, and 24/7 availability. Ideally, secure an IR retainer before an incident occurs.

Related Articles

More from the MBF Media Network

cloudmagazinCloud MagazinMyBusinessFutureMyBusinessFutureDigital ChiefsDigital Chiefs

Translated from the German original using artificial intelligence. The German version is authoritative.

Further reading

A magazine by Evernine Media GmbH