Skip to content

Digital forensics
for evidence that holds up

Disputes involving information technology demand specialized tools and expertise so digital evidence stays intact, and admissible when it reaches a court.

Evidence at risk? Call:(450) 681-1681 ext. 277

Time is of the essence: logs roll off, cloud retention windows close, devices get wiped. Call now.

Since 2010

delivering digital forensics engagements

100+ mandates

plus the forensic work inside incident response

Expertise for gathering volatile evidence

Digital evidence is complex and volatile, so it demands the highest level of security when collected, handled and analyzed. Specialized digital forensics expertise is essential to identify the strongest evidence and ensure it is recognized before the courts.

Forensics is the downstream counterpart to prevention: where offensive security works to keep an attacker out, forensics reconstructs what happened once one got in. Most incident response engagements include forensic work: establishing the root cause and the attacker’s modus operandi, documented to a standard that holds up with an insurer, a regulator or a court. It also stands on its own: a seizure order to execute, a labour investigation to settle, an intellectual property dispute where the proof sits on a device.

From acquisition to the witness stand

Every engagement protects confidentiality, integrity, chain of custody and admissibility, at each stage of the evidence lifecycle.

Acquire

Evidence is obtained under documented procedure, in access-controlled premises, with specialized tooling and secure transport.

Preserve

A forensic duplicate is created so the original stays untouched, the foundation of an unbroken chain of custody.

Analyze

Certified experts examine the copy: recovering deleted data, correlating traces and countering anti-forensic techniques.

Report & testify

Findings are documented in an expert report, with trial testimony and counter-expertise when the matter reaches court.

What we do to recover and prove

From seizure and imaging to encrypted data and deleted files: the work that turns a device into defensible evidence.

  • Preliminary analysis
  • Data and computer seizures
  • Analysis of evidence and data integrity
  • Data retrieval and restoration of deleted files
  • Malware investigation
  • Attempts at cracking encryption
  • Analysis of litigious emails
  • Identification and correlation of traces
  • Smartphones and devices analysis
  • Counter-expertise and anti-forensic techniques
  • eDiscovery and evidence review
  • Strategic coaching

Examples of cases we handled

OKIOK has supported clients in a wide range of sensitive, complex and high-stakes matters, including:

Criminal & fraud

  • Criminal cases (fraud, extortion, etc.)
  • Falsification of data
  • Computer hacking and incident response

Civil & commercial

  • Anton Piller and Norwich orders
  • Intellectual property and industrial espionage
  • Corporate investigations and internal audits

Workplace & privacy

  • Work and labour investigations
  • Privacy and data breaches
  • Defamation and cyber-harassment

Certified experts, specialized tools, secure premises

Supported by their experience, training and specialized tools, OKIOK's certified experts handle evidence according to best industry practices to guarantee its integrity throughout the process.

The same experts who probe systems offensively bring that insight to the forensic bench, and to the witness stand.

A controlled environment

  • Access-controlled secure premises
  • Safes for evidence storage
  • Highly secure transport equipment

Tools

  • OSForensics
  • KAPE
  • Duplication hardware
Three OKIOK specialists, with a certification seal, a graduation cap and crossed tools above them
  • GCFA, GIAC Certified Forensic Analyst
  • CHFI, Computer Hacking Forensic Investigator (EC-Council)

Questions about digital forensics?

How forensics differs from incident response, and which one an active breach calls for.

Evidence on the line? Let’s talk

Tell us about your situation: what happened, what is at stake, and what you need to prove. Our experts will work through the evidence involved and the options open to you.

Evidence at risk? Call:(450) 681-1681 ext. 277

Send us a message

Only your email is required. Pick a subject, add a note, and send.

Incident in progress? Call the 24/7 line instead of waiting for a reply: +1 450 681-1681, extension 277