Cyber Evidence Assurance

How far back can you actually investigate?

If you discovered a breach today that started 90, 180 or 365 days ago, could you reliably reconstruct what happened?

Forensic Horizon measures whether your identity, endpoint, network, cloud, SaaS, backup and security telemetry still contains the evidence investigators would need to reconstruct what happened.

On-prem deployment. Evidence metadata stays inside your environment.

Example horizon profileToday
Searchable41d

Immediately queryable by responders

Recoverable210d

Exists and is realistically restorable

Defensible73d

Complete, attributable and trustworthy

Current defensible horizon

73 days

Target

180 days

LimiterHistorical endpoint telemetry

Interactive

Evidence Run

A browser arcade game about incident response, retention windows and the evidence that disappears before anyone asks for it.

Play Evidence Run

No signup. 3 minutes. Best played with sound on.

The problem

Your SIEM retention is not your forensic horizon.

Security teams usually know how long data is configured to be retained. That does not tell you how far back an incident can actually be reconstructed.

You may have 365 days of firewall logs…

…but only 30 days of DHCP history.

Result

Older IP activity may no longer be attributable to a specific endpoint.

You may archive SIEM data for two years…

…but never have tested restoring it.

Result

The evidence may exist, but its recoverability and investigative usability remain unproven.

You may have EDR on 95% of endpoints…

…while several privileged servers are missing coverage.

Result

The missing 5% may matter more than the covered 95%.

Definition

Cyber Evidence Assurance is the practice of verifying that the evidence needed to reconstruct a cyber incident exists, remains accessible and trustworthy, and can be correlated for the period under investigation.

The four horizons

One retention number is not enough.

01

Searchable Horizon

How far back can investigators immediately query evidence?

02

Recoverable Horizon

How far back does evidence still exist and remain realistically restorable?

03

Defensible Horizon

How far back is the evidence sufficiently complete, attributable, accessible and trustworthy to support a defensible investigation?

04

Scenario Reconstruction Horizon

How far back can a specific attack actually be reconstructed using all of the evidence it requires?

365 days of archived logs does not automatically equal a 365-day defensible forensic horizon.

The 180-day test

Could you investigate an attack that started 180 days ago?

Try answering these questions.

  1. 01Could you identify the first compromised account?
  2. 02Could you identify the endpoint used by that account?
  3. 03Could you reconstruct lateral movement?
  4. 04Could you attribute historical IP addresses to actual systems?
  5. 05Could you determine what cloud or SaaS data was accessed?
  6. 06Could you prove whether backups were tampered with?

If the answer changes depending on how old the incident is, you already have a forensic horizon.

Measure It

Evidence, not just logging

Forensic investigations depend on evidence chains.

A single investigative question normally crosses several systems at once. If one critical link no longer holds usable evidence for the period in question, reconstruction may become incomplete, unattributable or materially less defensible.
  1. Identity
  2. Endpoint
  3. Network
  4. Cloud / SaaS
  5. Data
  6. Backup

Evidence sources evaluated

  • Identity providers
  • Active Directory
  • EDR / XDR
  • Endpoint logs
  • DNS
  • DHCP / IPAM
  • Firewalls
  • VPN / ZTNA
  • Proxy / SWG
  • Email
  • Microsoft 365
  • SaaS platforms
  • AWS / Azure / GCP
  • PAM
  • Databases
  • Backup systems
  • SIEM / data lakes
  • Asset inventory
  • Vulnerability history
  • DevOps / CI-CD
  • OT / IoT where applicable

What Forensic Horizon measures

Eight properties decide whether evidence is usable.

Coverage

Are the systems that matter actually producing evidence?

Retention

How long does searchable and recoverable evidence remain available?

Quality

Are the fields required for an investigation present and reliable?

Attribution

Can activity be tied to identities, endpoints, sessions and historical IP ownership?

Correlation

Can evidence from different systems be joined into a coherent timeline?

Integrity

Could evidence have been altered or deleted?

Accessibility

Can incident responders access and export the evidence when needed?

Validation

Has historical evidence actually been queried and tested?

Attack scenarios

Your forensic horizon changes with the incident.

A ransomware investigation does not depend on the same evidence as a business email compromise or an insider case. Each scenario depends on a different combination of evidence, and reaches a different point where reliable reconstruction stops.

Illustrative figures. Actual horizons are measured per environment.

ScenarioExample reconstruction horizonPrimary dependency
Ransomware180 daysEndpoint execution, backup integrity
Privileged Account Compromise88 daysIdentity, PAM session records
Microsoft 365 / SaaS Compromise365 daysUnified audit, mailbox audit
Data Exfiltration93 daysProxy, DNS, endpoint file activity
Persistent / Long-Dwell Compromise60 daysHistorical endpoint telemetry
Insider Threat120 daysSaaS content access, data-layer logs
Cloud Control Plane Compromise365 daysCloud audit trails, role changes
Lateral Movement45 daysDHCP history, authentication records
Business Email Compromise365 daysMailbox audit, sign-in logs
Destructive Attack70 daysEndpoint telemetry, backup catalogues
Backup Compromise150 daysBackup system logs, PAM

Horizon limiters

Find what actually limits your investigations.

Forensic Horizon does not stop at a score. It identifies the evidence source or capability that prevents reliable reconstruction from going further back.

DHCP history

30 days

Limits historical IP-to-device attribution.

Affected scenarios

Lateral movement, ransomware, data exfiltration.

Endpoint telemetry

90 days

Limits historical execution reconstruction.

Affected scenarios

Malware, credential theft, ransomware, persistent compromise.

SaaS audit

180 days

Limits historical content-access reconstruction.

Affected scenarios

Insider threat, account compromise, data exfiltration.

Improvement simulation

Know which investment extends reconstruction capability the most.

Before extending retention, buying more storage or adding another security product, Forensic Horizon shows which change would materially extend reconstruction capability.

Current defensible horizon

73 days

Proposed improvements

  • Extend DHCP history
  • Increase EDR retention
  • Validate SIEM archive retrieval

Projected defensible horizon

180 days

How the assessment works

From telemetry inventory to defensible answer.

01

Profile the environment

Define critical systems, identities, cloud environments and target forensic horizon.

02

Map evidence sources

Identify evidence across identity, endpoint, network, cloud, SaaS, email, PAM, backup and SIEM.

03

Verify the evidence

Assess retention, coverage, quality, attribution, integrity and accessibility.

04

Test historical availability

Distinguish configured retention from evidence that can actually be retrieved.

05

Reconstruct attack scenarios

Calculate scenario-specific reconstruction horizons.

06

Prioritize improvements

Identify the changes that extend forensic capability the most.

What you receive

A measurable forensic readiness baseline.

  • Searchable Horizon
  • Recoverable Horizon
  • Defensible Horizon
  • Scenario Reconstruction Horizons
  • Evidence Assurance scores
  • Missing evidence sources
  • Collection gaps
  • Attribution gaps
  • Integrity weaknesses
  • Archive validation status
  • Horizon limiters
  • Prioritized remediation roadmap
  • Executive-ready report

Who it is for

Built for the people who are asked what happened.

CISO / Security Leadership

Understand whether existing security investments provide actual reconstruction capability.

SOC / Incident Response

Know which evidence will still exist when a serious incident is discovered.

Security Architecture

Design telemetry and retention around investigation requirements.

Internal Audit / Risk

Obtain measurable evidence about forensic readiness rather than assertions that logging is enabled.

Critical Infrastructure

Assess whether evidence will survive long enough to investigate persistent or destructive attacks.

Deployment

Designed for environments where sensitive security evidence and assessment data must remain under organizational control.

Forensic Horizon is designed as an on-prem platform. Assessment metadata remains within the customer's environment, and the product can be used as an ongoing forensic evidence assurance workspace rather than a one-time questionnaire.

Cyber Evidence Assurance

Traceable. Verifiable. Defendable.

On-prem deployment. Evidence metadata stays inside your environment.

Category differentiation

Forensic Horizon is not a SIEM, an EDR or a GRC platform.

SIEMEDRGRCForensic Horizon
Collects security telemetryYesEndpointUsually noNo (evaluates it)
Detects attacksYesYesNoNot its purpose
Tracks controlsLimitedNoYesEvidence-specific
Measures organization-wide reconstruction horizonNoNoUsually noYes
Measures cross-source forensic dependenciesLimitedNoUsually noYes
Calculates scenario-specific reconstruction horizonNoNoNoYes

Forensic Horizon evaluates whether the evidence produced by the tools you already own can support an investigation.

Checklist

The Forensic Horizon 90-Day Test

A practical checklist for determining whether you could reconstruct an incident discovered three months late.

Request the 90-Day Test

Email us and the checklist is sent back to you directly.

How far back could you prove what happened?

You already have a forensic horizon. The question is whether you know where it ends.