When you have to prove what happened — to a court, to an insurer, to a data protection authority or to a client demanding answers — intuition is not enough. You need evidence collected under chain of custody and a report that survives being challenged.
When it is needed
After an incident: to establish how they got in, how long they were inside and what they took.
Data leakage or suspicion of exfiltration by an insider.
Litigation: expert report, counter-report or testimony in court.
Personal data breach: to be able to evidence the scope to the authority within the 72-hour deadline.
Misuse of resources or breach of internal policy, with the employment law safeguards that requires.
Technical scope
Forensic acquisition of disks, system images and memory dumps, with integrity verification.
RAM analysis: processes, connections and artefacts that vanish when the machine is powered off.
Windows system analysis: registry, execution artefacts, persistence and traces of deletion.
Server and log analysis to reconstruct the full timeline.
Mobile devices and Android application analysis.
Cloud environments: access logs, identity activity and configuration changes.
How we work
1
Preservation
First, before it is lost: acquisition with documented chain of custody from minute one. Powering a machine down badly destroys half the evidence.
2
Analysis
Reconstruction of the incident: entry vector, movement, escalation, persistence and a timeline with cross-checked timestamps.
3
Scope determination
Which data was affected and which was not. That is the difference between reporting a breach and being able to evidence there was none.
4
Expert report
Written to be understood by a non-technical reader and to withstand a counter-report. Methodology, evidence and conclusions kept separate.
5
Testimony
If the matter reaches court, we defend the report.
What you get
Acquisition records and a complete chain of custody.
Expert report with methodology, evidence, analysis and conclusions.
Incident timeline, reconstructed and cross-checked.
Scope determination of the data affected.
Recommendations to prevent recurrence, where the engagement includes them.
Availability for court testimony.
Who does the work. The same team that audits, not an account manager. Governance, risk and compliance: CISSP, CISM, ISO 27001 Lead Auditor, ENS and Risk Analysis (CCN), certified DPO, CCSP and CDPP (ISMS Forum) and PMP (PMI). On the technical side: OSCP, CRTO II and eWPTX, ranked in the top 1% of the CCN-CERT Atenea platform. We have run compliance projects for crypto exchanges, universities and public administrations.
Questions we get asked
Something has happened. What do I do right now?
Do not power off the affected machines and do not rebuild them. Isolate them from the network and call us. The rush to get back into production is what destroys the most evidence, and after that it is no longer possible to establish what happened.
Will the report stand up in court?
That is what it is written for. Reproducible methodology, documented chain of custody and a clear separation between facts, analysis and conclusions. And we testify if required.
Can you analyse an employee’s laptop?
Yes, with the right legal framing: a prior acceptable use policy, notice to the employee, proportionality and, depending on the case, the presence of workers’ representatives. We tell you what is and is not permissible before touching the device.
What if we have already rebuilt?
Work can still proceed from logs, backups, telemetry and perimeter systems, though with narrower scope. It is not ideal, but you rarely start completely empty-handed.
If something has happened, do not power anything off
Call us before touching the systems: +34 686 250 244. Every hour that passes destroys evidence.
Phone: +34 686 250 244 (Mon-Fri, 9:00 to 18:00 CET) · Email: info@jaymonsecurity.com
We reply within 2 working hours.

