{"id":8460,"date":"2022-07-21T10:00:00","date_gmt":"2022-07-21T10:00:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/02\/post_id-5093\/"},"modified":"2026-07-06T15:16:21","modified_gmt":"2026-07-06T15:16:21","slug":"cyber-forensics-for-non-technicians-what-happens-after-a-security-incident","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2022\/07\/21\/cyber-forensics-for-non-technicians-what-happens-after-a-security-incident\/","title":{"rendered":"Cyber Forensics for Non-Technicians: What Happens After a Security Incident"},"content":{"rendered":"<p><strong>After a cyberattack, forensics begins  &#8211;  and for most CEOs, things quickly become overwhelming. Exactly what do forensic investigators do? How long does it take? What can you touch  &#8211;  and what must you leave untouched? And what do the findings mean for liability, insurance claims, and mandatory reporting obligations? A guide for decision-makers.<\/strong><\/p>\n<h2>TL;DR<\/h2>\n<ul>\n<li>Forensics starts with preserving volatile evidence (RAM contents, network logs, active sessions)<\/li>\n<li>Rule #1: Do <em>not<\/em> shut down affected systems  &#8211;  critical evidence will be lost forever<\/li>\n<li>Chain of Custody: Complete, unbroken documentation required for law enforcement and insurance purposes<\/li>\n<li>Forensics timeline: 2-8 weeks, depending on complexity and scope<\/li>\n<\/ul>\n<h2>The Golden Hour: Evidence Preservation Before Recovery<\/h2>\n<p>The natural instinct after an attack is to immediately rebuild systems and restore operations. Doing exactly that destroys the most valuable evidence. RAM contents, active network connections, running processes, and temporary files vanish irretrievably upon reboot.<\/p>\n<p>Forensic investigators first create forensic images: bit-for-bit copies of hard drives and RAM dumps. These copies form the foundation of the entire investigation  &#8211;  and are often a prerequisite for insurance payouts and criminal prosecution.<\/p>\n<h2>Timeline Analysis: What Happened  &#8211;  and When?<\/h2>\n<p>The core task of forensics: reconstructing a complete, chronological timeline of the attack. When did the initial access occur? How did the attacker move laterally across the network? When were data exfiltrated? When was ransomware deployed?<\/p>\n<p>This timeline emerges from correlating hundreds of data sources: Windows Event Logs, firewall logs, Active Directory changes, email logs, cloud audit trails, and endpoint telemetry. The more data sources available, the more complete the picture.<\/p>\n<h2>What the Findings Mean for Decision-Makers<\/h2>\n<p>Forensic results answer four critical questions: What happened (attack vector and progression)? Which data were compromised (scope of compromise)? Is the attacker still inside the network (containment status)? And how can recurrence be prevented (remediation steps)?<\/p>\n<p>These insights feed directly into regulatory reporting obligations (GDPR: 72-hour deadline; NIS2: 24-hour deadline), insurance claims (the forensic report serves as official damage documentation), and communications strategy (what do we tell customers, partners, and the public?).<\/p>\n<h2>Preparation: What Companies Can Do <em>Before<\/em> an Incident<\/h2>\n<p>Forensics is far more effective when prepared in advance. Three essential measures: First, centralized log aggregation (SIEM or at least a Syslog server)  &#8211;  without logs, forensics is impossible. Second, define log retention periods (minimum 90 days; ideally 365). Third, secure an Incident Response (IR) retainer agreement with a qualified forensic service provider.<\/p>\n<p>The most common post-incident realization: <em>\u201cIf only we\u2019d had those logs, we\u2019d have detected the attack weeks earlier.\u201d<\/em> Log management isn\u2019t optional  &#8211;  it\u2019s the foundational requirement for any forensic investigation.<\/p>\n<h2>Key Facts<\/h2>\n<p><strong>Forensics duration:<\/strong> 2-8 weeks, depending on scope and complexity<\/p>\n<p><strong>Log gap:<\/strong> In 40% of cases, critical logs are missing  &#8211;  preventing full reconstruction (Mandiant)<\/p>\n<p><strong>Costs:<\/strong> \u20ac50,000-\u20ac250,000 for a comprehensive forensic investigation in mid-sized enterprises<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>Do I need to involve law enforcement?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Strongly recommended in cases of ransomware and data theft. Each German federal state has a Central Office for Cybercrime (ZAC) serving as the primary contact. Some cyber insurance policies explicitly require filing a criminal complaint as a condition for coverage.<\/p>\n<\/details>\n<details>\n<summary><strong>Can I keep working during the forensic investigation?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Generally, yes  &#8211;  on systems confirmed <em>not<\/em> to be compromised. Forensic efforts focus exclusively on affected systems. Crucially: coordinate closely with the forensic team to confirm which systems may be used  &#8211;  and which must remain untouched.<\/p>\n<\/details>\n<details>\n<summary><strong>How do I find a qualified forensic service provider?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Look for: BSI (Federal Office for Information Security) certification as an APT response provider, GIAC-certified analysts (e.g., GCFA, GCFE), proven experience in your industry sector, and 24\/7 availability. Ideally, secure an IR retainer <em>before<\/em> an incident occurs.<\/p>\n<\/details>\n<h2>Related Articles<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/06\/post_id-3837\/\">Cybersecurity Trends 2026: The 7 Developments Every Security Leader Must Know<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/?p=3282\">The MOVEit Hack: Anatomy of a Supply-Chain Attack That Hit Thousands<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2022\/12\/15\/post_id-5038\/\">Incident Response Retainers: Why Companies Need an IR Contract <em>Before<\/em> the Crisis Hits<\/a><\/li>\n<\/ul>\n<p style=\"font-weight:700;color:#e6e3da;font-size:1.05em;margin:48px 0 16px;\">More from the MBF Media Network<\/p>\n<div style=\"display:flex;flex-direction:column;gap:14px;margin-bottom:40px;\"><a href=\"https:\/\/www.cloudmagazin.com\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#0bb7fd;\">cloudmagazin<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">Cloud Magazin<\/span><\/a><a href=\"https:\/\/www.mybusinessfuture.com\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#aa8ac2;\">MyBusinessFuture<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">MyBusinessFuture<\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#d65663;\">Digital Chiefs<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">Digital Chiefs<\/span><\/a><\/div>\n","protected":false},"excerpt":{"rendered":"After a cyberattack, forensics begins &#8211; and for most CEOs, things quickly become overwhelming. Exactly what do forensic investigators do? How long does it take? What can you touch &#8211; and what must you leave untouched? And what do the findings mean for liability, insurance claims, and mandatory reporting obligations? A guide for decision-makers. TL;DR [&hellip;]","protected":false},"author":55,"featured_media":5092,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"cyber forensics","_yoast_wpseo_title":"Cyber Forensics for Non-Technicians: What Happens After a Security Incident","_yoast_wpseo_metadesc":"Cyber forensics for non-technicians: understand the investigation process, protect your data, and respond confidently after an attack. Learn what to do next.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_pin_until":0,"evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":["post_id-5093"],"footnotes":""},"categories":[259],"tags":[245,233],"class_list":["post-8460","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-strategie-governance-en","tag-compliance","tag-ransomware"],"evm_reading_time_minutes":4,"wpml_language":"en","wpml_translation_of":5093,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8460","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=8460"}],"version-history":[{"count":7,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8460\/revisions"}],"predecessor-version":[{"id":19835,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8460\/revisions\/19835"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/5092"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=8460"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=8460"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=8460"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}