forumNew topic

Insurer asked for 'digital forensic evidence' after a breach — what is this, and who collects it?

PPınar Ç***Expert
Job title
Call center representative
Sector
Livestock
Organization type
40-person manufacturing company
Joined
Jan 2022
Message
189
#1

We are a London-based wholesale trading platform with 20 employees. Two weeks ago, our accounting manager's email account was compromised, and a 42,000 GBP payment intended for a supplier was diverted to a fraudulent bank account. As soon as we realized what happened, we notified the bank and the broker that handles our cyber risk insurance.

The insurance company opened a claim file, but yesterday they sent us a formal letter asking for a 'digital forensic report collected by an accredited digital forensics expert in compliance with chain of custody rules.' Our in-house IT staff took screenshots of the servers and email admin consoles and dumped the mail queue logs into a text file, but the insurer says this does not qualify as valid evidence.

What exactly does this digital forensic evidence cover? Why can't we collect it ourselves, where do we find this expert, and how much will it cost us? We're terrified of mishandling the process and blowing our claim.

NNazlı T***New member
Job title
Accounting clerk
Sector
Seafood
Organization type
40-person manufacturing company
Joined
May 2026
Message
32
Most Helpful#2

Short answer: Digital forensic evidence is technical data that proves, by digital forensics standards, how the attack happened, which systems were impacted, and that the data has not been tampered with. Screenshots or copy-pasted logs gathered by your internal staff are deemed inadmissible in court or by insurers because they are vulnerable to manipulation.

When investigating a computer or server, simply opening a random file alters the last accessed timestamps and contaminates the evidence. Accredited experts capture a live memory dump (RAM dump) of the endpoint, take a bit-stream image (an exact, bit-by-bit clone of the drive), and generate a cryptographic checksum (SHA-256 hash) for every image. A chain of custody form records who acquired the disk, when, using what hardware, and where it is stored under lock and key.

Do not let your in-house IT team handle this under any circumstances. Most cyber insurance policies have a 'panel of approved vendors.' Contact your insurer and ask them to assign a firm directly from their approved DFIR panel.

If your policy covers expert investigation costs, the specialist fees will either be deducted from your policy limit or applied against your deductible. If you have to retain an independent expert out of pocket, expect to budget anywhere between 4,000 and 9,000 GBP per incident.

ZZuhalMember
Job title
Store Manager
Organization type
chain store
Joined
Jul 2024
Message
82
#3

The first thing you need to do right now is NOT shut down those computers and never reboot them. Just disconnect them from the network by unplugging the ethernet cable or turning off Wi-Fi. If you power them off, any attacker traces in volatile memory (RAM) get wiped, destroying the evidence.

KKoray B***ExpertCommunity member
Joined
Jan 2023
Message
235
#4

We went through a similar fake invoice incident and lost 36,000 GBP. A digital forensics firm on the insurer's panel pulled the images within two days. The reporting came out to 6,500 GBP; we covered our 2,500 GBP policy excess, and the insurer reimbursed both the rest of the report fee and the full stolen amount.

HHakan U***Member
Job title
Regional Manager
Sector
Sports and fitness
Organization type
40-person manufacturing company
Joined
Aug 2022
Message
13

Doki · Server maintenance contract · 2025

#5

Review the 'Proof of Loss and Burden of Proof' clause in your policy's terms and conditions carefully. Reports prepared by third-party experts not pre-approved by the insurer can be procedurally dismissed by the claims committee.

HHilal B***Veteran
Job title
Graphic Designer
Sector
Electrical-electronics
Organization type
regional distributor
Joined
Dec 2023
Message
17
#6

Screenshots don't cut it as evidence because local logs, source IPs, user session tokens, and inbox rules all need to be audited. The attacker might have set up a hidden forwarding rule in the accountant's mailbox; a forensics expert will uncover that from audit logs and attach it to the report with hash verification.

ZZehra D***Expert
Job title
IT manager
Sector
Food wholesale
Organization type
120-person company
Joined
Feb 2025
Message
44

Doki · Server maintenance contract · 2024

#7

Insurers often use evidence requirements as an excuse to avoid paying out or to drag the process on for months. If you don't follow the procedure down to the letter, they'll claim you contaminated your own evidence and close the file right then and there. Be extremely careful.

EElif D***MemberCommunity member
Joined
Oct 2024
Message
98
#8

Did your cyber policy include 'Incident Response and Forensic Investigation Coverage' when you bought it? If you have that rider, the insurer is required to dispatch the forensics team themselves; they can't push the burden of sourcing a vendor onto you.

note: I wrote this based on my own experience, it might not apply to everyone.

BBurak A***Member
Job title
IT manager
Sector
E-commerce
Organization type
early-stage startup
Joined
May 2023
Message
126
#9

don't even think about deleting the outlook profile on the accountant's pc. every single deleted file raises red flags leave it as is and wait for the expert to arrive.

NNurayMember
Job title
Publisher
Organization type
two-branch business
Joined
Oct 2023
Message
92
#10

My question might sound amateurish, sorry about that. Security isn't absolute; it's about making attacks not worth the effort.

That's all, sorry if I went on too long.

YYavuz P***Veteran
Job title
Project manager
Sector
Freight
Organization type
sole proprietorship
Joined
Oct 2024
Message
35

Doki · Log management setup · 2023

#11

My questions are cleared up, thanks.

OOsman K***Member
Job title
Logistics planning
Sector
Energy
Organization type
a company within a holding
Joined
Sep 2025
Message
125
#12

If I understood correctly, you're saying: If permission and scope aren't in writing, don't start that test.

If you get three different answers on a topic, the question was asked wrong. This is my opinion, I'm not claiming it's absolute truth.

NNeslihan B***Expert
Job title
Project manager
Sector
Cosmetics
Organization type
regional distributor
Joined
Jun 2025
Message
129
#13

The discussion got scattered let me summarize. I mean security isn't absolute; it's about making attacks not worth the effort.

This is my opinion I'm not claiming it's absolute truth.

GGökhan Y***MemberCommunity member
Joined
Sep 2023
Message
223
#14

To get into the details: Having backups accessible on the same network and with the same identity makes them part of the target.

Most time waste accumulates in tasks waiting for approval. Correct me if I'm wrong.

BBurcu V***Member
Job title
Field sales representative
Sector
Automotive aftermarket
Organization type
120-person company
Joined
May 2023
Message
2
#15

I'm curious too. Security isn't absolute; it's about making attacks not worth the effort.

If you post the result here, it will help others too.

NNecati B***Member
Job title
Content Editor
Sector
Tourism
Organization type
a company within a holding
Joined
May 2023
Message
249

Doki · SEO consulting · 2026

#16

don't miss this: If you scold false alarms nobody will report again.

that's all srry if I went on too long.

MMehmet K***MemberCommunity member
Joined
Jan 2025
Message
237
#17

The opposite happened to me that's why I'm writing. When we decide without measuring, we always end up in the same place.

The biggest time-waster for us was not knowing who had the final say. I'm also curious if anyone does it differently.

MMustafa M***Member
Job title
Quality control inspector
Sector
Food wholesale
Organization type
regional distributor
Joined
Feb 2024
Message
106
#18

There's a trap here, let me mention it. Payment information changes are never verified through the channel they came from.

I'm also curious if anyone does it differently.

BBora A***MemberCommunity member
Joined
Sep 2025
Message
118
#19

I felt relieved reading this answer, so it's not just me. Hasty decisions become decisions you have to fix six months later.

The real issue isn't the number, but what it's based on. That's all, sorry if I went on too long.

DDilekNew member
Job title
Pastry Shop
Organization type
a company within a holding
Joined
Nov 2024
Message
19
#20

absolutely then if I were to add anything: Start with a small trial; dont commit to everything at once.

taking measures without an inventory leaves doors you haven't seen open.

Reply