You may have 365 days of firewall logs…
…but only 30 days of DHCP history.
Result
Older IP activity may no longer be attributable to a specific endpoint.
Cyber Evidence Assurance
If you discovered a breach today that started 90, 180 or 365 days ago, could you reliably reconstruct what happened?
Forensic Horizon measures whether your identity, endpoint, network, cloud, SaaS, backup and security telemetry still contains the evidence investigators would need to reconstruct what happened.
On-prem deployment. Evidence metadata stays inside your environment.
Immediately queryable by responders
Exists and is realistically restorable
Complete, attributable and trustworthy
Current defensible horizon
73 days
Target
180 days
LimiterHistorical endpoint telemetry
Interactive
A browser arcade game about incident response, retention windows and the evidence that disappears before anyone asks for it.
No signup. 3 minutes. Best played with sound on.
The problem
You may have 365 days of firewall logs…
…but only 30 days of DHCP history.
Result
Older IP activity may no longer be attributable to a specific endpoint.
You may archive SIEM data for two years…
…but never have tested restoring it.
Result
The evidence may exist, but its recoverability and investigative usability remain unproven.
You may have EDR on 95% of endpoints…
…while several privileged servers are missing coverage.
Result
The missing 5% may matter more than the covered 95%.
Definition
Cyber Evidence Assurance is the practice of verifying that the evidence needed to reconstruct a cyber incident exists, remains accessible and trustworthy, and can be correlated for the period under investigation.
The four horizons
How far back can investigators immediately query evidence?
How far back does evidence still exist and remain realistically restorable?
How far back is the evidence sufficiently complete, attributable, accessible and trustworthy to support a defensible investigation?
How far back can a specific attack actually be reconstructed using all of the evidence it requires?
365 days of archived logs does not automatically equal a 365-day defensible forensic horizon.
The 180-day test
Try answering these questions.
If the answer changes depending on how old the incident is, you already have a forensic horizon.
Measure ItEvidence, not just logging
Evidence sources evaluated
What Forensic Horizon measures
Are the systems that matter actually producing evidence?
How long does searchable and recoverable evidence remain available?
Are the fields required for an investigation present and reliable?
Can activity be tied to identities, endpoints, sessions and historical IP ownership?
Can evidence from different systems be joined into a coherent timeline?
Could evidence have been altered or deleted?
Can incident responders access and export the evidence when needed?
Has historical evidence actually been queried and tested?
Attack scenarios
Illustrative figures. Actual horizons are measured per environment.
| Scenario | Example reconstruction horizon | Primary dependency |
|---|---|---|
| Ransomware | 180 days | Endpoint execution, backup integrity |
| Privileged Account Compromise | 88 days | Identity, PAM session records |
| Microsoft 365 / SaaS Compromise | 365 days | Unified audit, mailbox audit |
| Data Exfiltration | 93 days | Proxy, DNS, endpoint file activity |
| Persistent / Long-Dwell Compromise | 60 days | Historical endpoint telemetry |
| Insider Threat | 120 days | SaaS content access, data-layer logs |
| Cloud Control Plane Compromise | 365 days | Cloud audit trails, role changes |
| Lateral Movement | 45 days | DHCP history, authentication records |
| Business Email Compromise | 365 days | Mailbox audit, sign-in logs |
| Destructive Attack | 70 days | Endpoint telemetry, backup catalogues |
| Backup Compromise | 150 days | Backup system logs, PAM |
Horizon limiters
Limits historical IP-to-device attribution.
Affected scenarios
Lateral movement, ransomware, data exfiltration.
Limits historical execution reconstruction.
Affected scenarios
Malware, credential theft, ransomware, persistent compromise.
Limits historical content-access reconstruction.
Affected scenarios
Insider threat, account compromise, data exfiltration.
Improvement simulation
Current defensible horizon
73 days
Proposed improvements
Projected defensible horizon
180 days
How the assessment works
Define critical systems, identities, cloud environments and target forensic horizon.
Identify evidence across identity, endpoint, network, cloud, SaaS, email, PAM, backup and SIEM.
Assess retention, coverage, quality, attribution, integrity and accessibility.
Distinguish configured retention from evidence that can actually be retrieved.
Calculate scenario-specific reconstruction horizons.
Identify the changes that extend forensic capability the most.
What you receive
Who it is for
Understand whether existing security investments provide actual reconstruction capability.
Know which evidence will still exist when a serious incident is discovered.
Design telemetry and retention around investigation requirements.
Obtain measurable evidence about forensic readiness rather than assertions that logging is enabled.
Assess whether evidence will survive long enough to investigate persistent or destructive attacks.
Deployment
Cyber Evidence Assurance
Traceable. Verifiable. Defendable.
On-prem deployment. Evidence metadata stays inside your environment.
Category differentiation
| SIEM | EDR | GRC | Forensic Horizon | |
|---|---|---|---|---|
| Collects security telemetry | Yes | Endpoint | Usually no | No (evaluates it) |
| Detects attacks | Yes | Yes | No | Not its purpose |
| Tracks controls | Limited | No | Yes | Evidence-specific |
| Measures organization-wide reconstruction horizon | No | No | Usually no | Yes |
| Measures cross-source forensic dependencies | Limited | No | Usually no | Yes |
| Calculates scenario-specific reconstruction horizon | No | No | No | Yes |
Forensic Horizon evaluates whether the evidence produced by the tools you already own can support an investigation.
Checklist
A practical checklist for determining whether you could reconstruct an incident discovered three months late.
Email us and the checklist is sent back to you directly.
You already have a forensic horizon. The question is whether you know where it ends.