Digital forensics
for evidence that holds up
Disputes involving information technology demand specialized tools and expertise so digital evidence stays intact, and admissible when it reaches a court.
Evidence at risk? Call:(450) 681-1681 ext. 277Time is of the essence: logs roll off, cloud retention windows close, devices get wiped. Call now.
Since 2010
delivering digital forensics engagements
100+ mandates
plus the forensic work inside incident response
Expertise for gathering volatile evidence
Digital evidence is complex and volatile, so it demands the highest level of security when collected, handled and analyzed. Specialized digital forensics expertise is essential to identify the strongest evidence and ensure it is recognized before the courts.
Forensics is the downstream counterpart to prevention: where offensive security works to keep an attacker out, forensics reconstructs what happened once one got in. Most incident response engagements include forensic work: establishing the root cause and the attacker’s modus operandi, documented to a standard that holds up with an insurer, a regulator or a court. It also stands on its own: a seizure order to execute, a labour investigation to settle, an intellectual property dispute where the proof sits on a device.
From acquisition to the witness stand
Every engagement protects confidentiality, integrity, chain of custody and admissibility, at each stage of the evidence lifecycle.
Acquire
Evidence is obtained under documented procedure, in access-controlled premises, with specialized tooling and secure transport.
Preserve
A forensic duplicate is created so the original stays untouched, the foundation of an unbroken chain of custody.
Analyze
Certified experts examine the copy: recovering deleted data, correlating traces and countering anti-forensic techniques.
Report & testify
Findings are documented in an expert report, with trial testimony and counter-expertise when the matter reaches court.
What we do to recover and prove
From seizure and imaging to encrypted data and deleted files: the work that turns a device into defensible evidence.
- Preliminary analysis
- Data and computer seizures
- Analysis of evidence and data integrity
- Data retrieval and restoration of deleted files
- Malware investigation
- Attempts at cracking encryption
- Analysis of litigious emails
- Identification and correlation of traces
- Smartphones and devices analysis
- Counter-expertise and anti-forensic techniques
- eDiscovery and evidence review
- Strategic coaching
Examples of cases we handled
OKIOK has supported clients in a wide range of sensitive, complex and high-stakes matters, including:
Criminal & fraud
- Criminal cases (fraud, extortion, etc.)
- Falsification of data
- Computer hacking and incident response
Civil & commercial
- Anton Piller and Norwich orders
- Intellectual property and industrial espionage
- Corporate investigations and internal audits
Workplace & privacy
- Work and labour investigations
- Privacy and data breaches
- Defamation and cyber-harassment
Certified experts, specialized tools, secure premises
Supported by their experience, training and specialized tools, OKIOK's certified experts handle evidence according to best industry practices to guarantee its integrity throughout the process.
The same experts who probe systems offensively bring that insight to the forensic bench, and to the witness stand.
A controlled environment
- Access-controlled secure premises
- Safes for evidence storage
- Highly secure transport equipment
Tools
- OSForensics
- KAPE
- Duplication hardware

Questions about digital forensics?
How forensics differs from incident response, and which one an active breach calls for.
Evidence on the line? Let’s talk
Tell us about your situation: what happened, what is at stake, and what you need to prove. Our experts will work through the evidence involved and the options open to you.
Evidence at risk? Call:(450) 681-1681 ext. 277

