SERVICES

Cybersecurity & Data Protection

We help teams identify and preserve incident records, work out which systems and data may be affected, and prepare a factual record for the incident, privacy and legal decision-makers. The same work often shows where forensic readiness is weak.

Services

  • Cyber Incident Evidence

    Identification and preservation of the logs, account activity, endpoint traces and communications needed to understand an event.

  • Data Breach Support

    Technical scoping, sensitive-data analysis, review workflows and documented evidence for the decisions the client, DPO and legal counsel have to make.

  • Data Subject Access Request (DSAR) Support

    Source mapping, defining the data population, preparing the review, handling exceptions and preparing the final response set for complex data-subject access requests.

Focus areas

  • Forensic readiness and post-incident improvement

    A practical check of whether logging, evidence handling and ownership would hold up in the next incident.

When this work is useful

  • A compromised account or suspicious activity may indicate a cyber incident.
  • The affected systems, people or accounts are not yet clear.
  • A potential personal-data breach needs a documented technical basis.
  • A complex DSAR spans fragmented systems and data sources.
  • Logging, retention or evidence handling is not ready for an incident.
  • A post-incident review needs improvements someone actually owns.

Typical work product

  • Incident source and evidence inventories
  • Event and account-activity timelines
  • Affected-system and affected-data matrices
  • Sensitive-data review packages
  • DSAR source, review and exception maps
  • Technical findings and limitations
  • Forensic-readiness assessments
  • Remediation priorities and action registers

How the work is structured

  1. Clarify

    Agree the event, systems, people and decisions that need support.

  2. Preserve

    Secure the relevant technical records and establish the handling route.

  3. Analyse

    Assess events, accounts, systems and affected data, with the evidence gaps stated.

  4. Respond and improve

    Deliver the technical findings and prioritise practical readiness improvements.

Contact

Start with the matter.

Describe what the matter is about, the timing, the jurisdiction and the decision, deadline or work product you need support with. We agree the next step before any sensitive information is exchanged.