Forensic Digital Analysis

When you have to prove what happened — to a court, to an insurer, to the data protection authority or to a client demanding answers — intuition is not enough. You need evidence collected under a documented chain of custody and a report that survives being challenged. That is what a computer forensics expert witness does: acquire the evidence without altering it, analyse it with a reproducible method, and state in writing, and later in court, what happened and what did not. We provide digital forensics and expert witness services for law firms, insurers and legal departments, and for companies that need to know what happened before deciding what to do about it.

When it is needed

After an incident: to establish how they got in, how long they were inside and what they took.
Data leakage or suspicion of exfiltration by an insider.
Litigation: expert report, counter-report or testimony in court.
Personal data breach: to be able to evidence the scope to the authority within the 72-hour deadline.
Misuse of resources or breach of internal policy, with the employment law safeguards that requires.

Legal framework: how the expert report is used in Spain

Expert evidence (arts. 335-352 Spanish Civil Procedure Act). A party-appointed computer forensics expert files the report with the claim or the defence. The expert can then be summoned to ratify it at the hearing and be cross-examined. The report is written for that moment, not for the moment it is delivered.
Party expert and court-appointed expert. We act as a party-appointed expert witness instructed directly by the client or by their law firm, and we accept court appointment when the court requires it. In both cases the commitment is to the method, not to the conclusion somebody would like to read.
Admissibility (art. 11.1 Spanish Judiciary Act). Evidence obtained in breach of fundamental rights has no effect. Before acquiring anything we define in writing what may be examined and under what authority: device ownership, consent, acceptable use policy, collective agreement or court order. Flawless analysis of improperly obtained evidence is worth nothing.
Chain of custody. Every item is identified, its hash value is computed before and after each handling step, and we record who held it, when and for what purpose. It is the first thing the opposing party attacks and the first thing we close.
Alternative hypotheses. We write assuming another forensic expert will review the report. The limits of the analysis, the data that could not be recovered and what the evidence does not allow us to state are set out explicitly.

Technical scope

Forensic acquisition of disks, system images and memory dumps, with integrity verification.
RAM analysis: processes, connections and artefacts that vanish when the machine is powered off.
Windows system analysis: registry, execution artefacts, persistence and traces of deletion.
Server and log analysis to reconstruct the full timeline.
Mobile devices and Android application analysis.
Cloud environments: access logs, identity activity and configuration changes.

Methodology and standards

ISO/IEC 27037. Identification, collection, acquisition and preservation of digital evidence. It governs the critical phase: what is done badly in the first hour cannot be fixed later.
ISO/IEC 27041, 27042 and 27043. Assurance of the suitability of the method used, analysis and interpretation of evidence, and incident investigation principles. They let us justify why one technique was chosen over another.
UNE 71506. The Spanish national standard for the forensic analysis of electronic evidence. Spanish courts refer to it when the procedure itself is disputed, so we follow it in every engagement heading for a Spanish court.
UNE 71505. Electronic evidence management system. It sets the traceability and life cycle of the evidence from creation to disposal.
Reproducibility. We always work on hash-verified copies, never on the original. We document the version of every tool and every relevant command, so that a third party with the same media can repeat the procedure and reach the same result. If it is not reproducible, it is not evidence.

How we work

1
Preservation
First, before it is lost: acquisition with documented chain of custody from minute one. Powering a machine down badly destroys half the evidence.
2
Analysis
Reconstruction of the incident: entry vector, movement, escalation, persistence and a timeline with cross-checked timestamps.
3
Scope determination
Which data was affected and which was not. That is the difference between reporting a breach and being able to evidence there was none.
4
Expert report
Written to be understood by a non-technical reader and to withstand a counter-report. Methodology, evidence and conclusions kept separate.
5
Testimony
If the matter reaches court, we defend the report.

What you get

Acquisition records and a complete chain of custody.
Expert report with methodology, evidence, analysis and conclusions.
Incident timeline, reconstructed and cross-checked.
Scope determination of the data affected.
Recommendations to prevent recurrence, where the engagement includes them.
Availability for court testimony.

Who signs the report

The team. The same team that audits, not an account manager. Governance, risk and compliance: CISSP, CISM, ISO 27001 Lead Auditor, ENS and Risk Analysis (CCN), certified DPO, CCSP and CDPP (ISMS Forum) and PMP (PMI). On the technical side: OSCP, CRTO II and eWPTX, ranked in the top 1% of the CCN-CERT Atenea platform. We have run compliance projects for crypto exchanges, universities and public administrations.
Verifiable technical standing. Top 1% on the Spanish National Cryptologic Centre (CCN-CERT) Atenea platform, and first place in the Web Hacking challenge at the CCN-CERT STIC Conference 2025. Not a decorative credential: it measures the ability to reconstruct what an attacker actually did.
Research and disclosure. Speakers at Navaja Negra 2025, one of the reference offensive security conferences in Spain.
Teaching. We run a 150-hour digital forensics course with a verifiable certificate, aimed at professionals who will sign reports themselves. Teaching the method forces us to keep it written down and defensible.
Independence. We do not resell licences, hardware or third-party services. There is no sale behind the report conditioning its conclusion.

Fees and timelines

Fixed price, by phase. First a bounded acquisition and triage phase. What that turns up is what the full analysis is quoted against. Nobody pays for an exploratory analysis before knowing whether there is anything to analyse.
Retainer. Expert witness engagements start with a retainer and are settled on delivery of the report.
Court attendance quoted separately. Appearance in court and ratification of the report are quoted separately, because they depend on the court listing and not on the volume of analysis.
Timelines. An urgent on-site acquisition is resolved in hours. The timeline for the report depends on the number of devices, their size and the type of analysis; it is fixed in writing in the engagement before work starts and does not move unless new material appears.
Rebuttal reports. Critical review of an opposing expert report is quoted as an engagement in its own right, because it means reviewing their methodology and redoing their checks against the available evidence.

Where we work

Coverage. Based in Madrid, working throughout Spain. Acquiring evidence requires being there in person — a disk is not imaged over a video call — so we travel to wherever the equipment is, with acquisition kit and write blockers. The subsequent analysis, the meetings with the firm handling the matter and the preparation for ratification are done remotely. Cross-border matters. We work in English and Spanish. If your company, your insurer or your parent entity is outside Spain and the incident, the devices or the proceedings are in Spain, we act as your forensic expert on the ground: we acquire the evidence here, report in English, and appear before the Spanish court in Spanish. Where evidence sits in another jurisdiction we coordinate with local examiners.

Questions we get asked

Something has happened. What do I do right now?
Do not power off the affected machines and do not rebuild them. Isolate them from the network and call us. The rush to get back into production is what destroys the most evidence, and after that it is no longer possible to establish what happened.
Will the report stand up in court?
That is what it is written for. Reproducible methodology, documented chain of custody and a clear separation between facts, analysis and conclusions. And we testify if required.
Can you analyse an employee’s laptop?
Yes, with the right legal framing: a prior acceptable use policy, notice to the employee, proportionality and, depending on the case, the presence of workers’ representatives. We tell you what is and is not permissible before touching the device.
What if we have already rebuilt?
Work can still proceed from logs, backups, telemetry and perimeter systems, though with narrower scope. It is not ideal, but you rarely start completely empty-handed.
What is the difference between a party-appointed expert and a court-appointed expert in Spain?
A party expert is instructed by you or your lawyer and the report is filed with your pleading. A court-appointed expert is designated by the court, normally by drawing from professional association lists. The working method and the duty of objectivity are the same; what changes is who instructs and who pays.
How much does a digital forensics engagement cost?
It depends on the number of devices, the volume of data and whether court attendance is needed. We work to a fixed price by phase: a bounded acquisition and triage phase first, then a fixed figure for the analysis. On the first call, at no cost, we give you a range you can plan against.
Is a screenshot of a WhatsApp chat or an email admissible?
On its own, weak. A screenshot can be manipulated in a minute and the opposing party will say so. What holds the evidence up is acquisition of the device or the mailbox with a documented chain of custody, a full extraction of the application database and hash verification. If only the screenshot survives, it can sometimes be corroborated against provider records, but it is a far weaker position.
We are a foreign company with an incident in Spain. Can you work with our counsel?
Yes. We acquire and analyse the evidence in Spain, deliver the report in English for your legal and executive teams, and produce the version that is filed and ratified before the Spanish court. We work directly with your Spanish counsel or with your in-house team.
If something has happened, do not power anything off
Call us before touching the systems: +34 686 250 244. Every hour that passes destroys evidence.

Book 30 min with an expert

Phone: +34 686 250 244 (Mon-Fri, 9:00 to 18:00 CET)  ·  Email: info@jaymonsecurity.com
We reply within 2 working hours.
ENES