Investigation and evidence
Cyber Forensic Audit
When an organisation suspects that an ex-employee retained access, that data left the building, or that internal systems were used in ways they should not have been, the first requirement is evidence that will stand up — not a theory. This engagement examines on-premises and cloud infrastructure, preserves evidence to legal standards, attributes activity to identity and time, and ends with both corrective actions and long-term prevention.

- Delivery
- 25–35 working days
- Platform modules
- 9 modules on one data model
- Operated by
- Webworx Asia, under a managed model
The situation
What this exists to fix
- A departing employee may have retained access to systems, servers and email after exit.
- There is suspicion of data exfiltration but no proof either way.
- Logs exist but nobody has correlated them across authentication, file shares, mail and the network.
- Any evidence gathered informally is already at risk of being inadmissible.
- Off-boarding and access control gaps that allowed it are still open.
- Management needs to decide on disciplinary or legal action and has nothing defensible to decide on.
The platform
9 modules, one data model.
Each module is purpose-built, and all of them share one record, one user directory and one audit trail.
01
Data acquisition
Non-intrusive imaging and cloning of drives, preserving timestamps, metadata and audit trails under a zero-alteration policy so evidence remains admissible.
02
Network forensics
Packet captures, traffic anomaly mapping, and VPN and firewall access log analysis.
03
Disk forensics
Sector-level imaging, file integrity reconstruction, deleted file recovery, and exfiltration and deletion analysis.
04
Memory forensics
RAM captures where possible, malware artefact hunting and credential harvesting indicators.
05
Log analysis
Authentication logs, file-share access patterns, database and administrative activity, and syslog or SIEM correlation across directory, cloud and endpoints.
06
Email forensics
Suspicious forwarding rules, unauthorised mailbox access, egress patterns across attachments, downloads and auto-sync, and Exchange, Microsoft 365 or Google Workspace audit trails.
07
Attribution and reporting
Correlation of activity to user identity and time, a timeline of events, findings mapped to systems, observed cleanup or obfuscation, and legally defensible audit documentation.
08
Remediation
Patch and policy recommendations, access control restructuring, network segmentation and least-privilege enforcement, and a cybersecurity policy overhaul covering the off-boarding failure that allowed it.
09
Compliance review
Verification against applicable standards — GDPR for data privacy and retention, HIPAA where healthcare data is involved, PCI-DSS where payments are processed.
What you receive
Deliverables
- Comprehensive forensic audit report
- Incident chronology and impact assessment
- Evidence bundle, where permissible
- Legal-ready documentation suitable for disciplinary action or litigation
- Mitigation recommendations, both policy and technical
- Security hardening roadmap
- Optional post-remediation support plan
What changes
Outcomes
- A defensible answer on whether unauthorised access or exfiltration occurred
- Evidence preserved to a standard that supports disciplinary or legal action
- Activity attributed to identity and time rather than inferred
- The access control and off-boarding gaps closed
- A hardening roadmap that reduces the chance of a repeat
How it is delivered
25–35 working days
The plan we quote, with the gates where you sign off before the next stage starts.
01
2–3 days
Requirement collection and environment access
Scope, authorisation, credentials and physical access arranged.
02
5–7 days
Device and server imaging
Forensic acquisition under a zero-alteration policy.
03
10–15 days
Forensic investigation, log and network audit
Disk, memory, log, network and email analysis.
04
5–7 days
Correlation and threat attribution
Activity mapped to identity and time.
05
3–5 days
Final report, remediation roadmap and briefing
Findings presented to management with corrective and preventive actions.
Integrate, don't rebuild
Built on services that already work
We build and own the application, the workflows and the operations. For infrastructure we integrate proven managed services rather than untested in-house equivalents — lower deployment risk, faster launch, and infrastructure billed at real usage.
- Active Directory
- Microsoft 365
- Google Workspace
- SIEM platforms
- Firewall and VPN logs
- Cloud consoles
Questions
Asked before every engagement
No engagement can promise that, and you should distrust one that does. Across aggregated industry studies, properly conducted forensic audits detect unauthorised activity in roughly 62–71% of suspected cases, and evidence recovery averages 70–85% depending on log retention policy, whether files were deleted, and how devices were handled before they were secured. We use industry frameworks to maximise actionable findings, and we report honestly on what could not be established.
Encrypted drives may require key recovery. High log and storage volumes lengthen analysis. Data jurisdiction and privacy law must be respected. Insider activity frequently involves deliberate stealth. And we need access — credentials, physical presence and the implicated devices themselves. We work with your IT team to minimise disruption while maximising retrieval accuracy.
Direct access to on-premise servers, networking racks and restricted rooms; handover of the relevant devices; administrative access to servers, directory, cloud consoles, workstations, mail and collaboration systems, logs, SIEM, firewall and API endpoints; and an onsite escort for infrastructure access. Travel and accommodation for the team where the engagement is onsite.
No. A penetration test asks whether someone could get in. A forensic audit asks whether someone already did, what they took, and whether it can be proven. If you want the first, that is a separate engagement.
More platforms
Other solutions
Unified content and video
OTT & Video Streaming Platform
End-to-end OTT: ingest, transcoding, live, VOD, DRM, CDN delivery, subscriptions, pay-per-view and advertising on one governed platform.
Custody, lifecycle and audit
Asset Management System
Barcode and QR asset tracking with a controlled asset master, custody history, maintenance records, audit trail and management reporting.
Field data to decisions
MIS Dashboard & Field Inspection App
Centralised management information system with Android and iOS apps for field data capture, real-time insights and large-scale inspection programmes.
Storefront, CRM and automation
Premium Website & AI Commerce Suite
Premium brand site through to a full commerce platform — inventory, orders, GST invoicing, CRM, marketing automation and AI assistants.
Start with the problem, not the product
Tell us what is breaking. We will scope it honestly — including telling you when Cyber Forensic Audit is more platform than you need.