Case Study — Forensics
A crashed hard drive, deleted emails, and the evidence a court needed.
Two real forensic cases from our lab — a business dispute that hinged on old emails, and a misuse investigation on a work PC. Every case starts with a read-only image of the original drive; nothing is ever touched directly.
What came through the lab
Two disputes, one forensic standard.
Different circumstances, the same requirement: evidence that would hold up once it reached a solicitor or a courtroom.
The first case involved a business customer whose computer had crashed years earlier and been replaced. It had sat untouched in an attic ever since — until a dispute with a former business partner meant he suddenly needed something from that old machine: the emails proving what had actually been agreed between them.
The second case came from an employer who suspected an employee of misusing their work PC. The employer needed proof, and needed every piece of data the employee had put on that machine recovered.
Both jobs were, at their core, data recovery jobs — a faulty hard drive and files that needed rebuilding. But because the outcome of each was likely to end up in court, the work had to be done to a forensic standard from the first step, not just a data-recovery one.
Case one
An old computer, an attic, and a corrupted Outlook file.
The computer itself had failed years before and been replaced, then stored away and forgotten — until the customer found himself in dispute with a former business partner and needed to prove what had actually been agreed. The evidence he needed lived in old emails, sitting on a hard drive that had also developed a fault of its own.
Because the drive was faulty, this was first a data recovery job: cloning the disk before any other work was carried out, so nothing further was ever done on the original. From that clone, we repaired the corrupted Outlook database and recovered its contents in full — including emails the customer had deleted.
All the data on that drive was recovered, and the damage to the corrupted Outlook file repaired. Years-old data the customer assumed was gone turned out to be exactly what his case needed.
Case two
Proving what was on a work PC.
An employer suspected an employee of misusing their work computer and needed evidence: everything the employee had put on that PC, recovered and accounted for.
As with the first case, the drive was imaged before any analysis began. Recovery covered the full range of what the machine held — emails, files, pictures and browser history among them.
The process
Why both cases were handled the same way.
- 01
Image first, always
Every hard drive is imaged using dedicated hardware tools set to read-only before any recovery or analysis takes place. The original device is never worked on directly.
- 02
No risk of accidental loss
Because the imaging hardware is read-only, there is no possibility of data being altered or deleted from the original drive during the process.
- 03
Full documentation
Each forensic job is supplied with detailed documentation describing exactly what was done — suitable for use in court proceedings.
- 04
Original preserved for the other side
Because the original drive is never touched, it can be handed to the opposing party for their own independent investigation if required.
Deleted emails, deleted files or browsing history — recovered from a read-only image and documented to a standard that holds up in court.