Resources

Technical notes on cyber evidence assurance

Practitioner-oriented material on evidence coverage, retention, scenario reconstruction and investigative capability. Articles are published as they are completed.

Index

Articles

  • 01

    365 Days of Logs Does Not Mean 365 Days of Investigative Capability

    Why aggregate retention figures overstate what an investigation can establish, and how the shortest load-bearing source sets the limit.

    Evidence retentionIn preparation
  • 02

    What Is a Forensic Horizon?

    Definition, calculation method, and why the measurement is scenario-specific rather than a single organizational number.

    MethodologyAvailable
  • 03

    The 50 Questions Your SOC Must Be Able to Answer During Ransomware

    A structured question set covering initial access, execution, credential access, lateral movement, exfiltration and impact.

    Incident responseIn preparation
  • 04

    Why EDR Coverage Is Not the Same as Forensic Readiness

    Agent deployment percentages, retained process detail and field fidelity are three different measurements with three different consequences.

    EndpointIn preparation
  • 05

    From Log Collection to Cyber Evidence Assurance

    Moving from a collection-oriented programme to one that validates whether required evidence is available, accessible and usable.

    ProgrammeIn preparation

Articles marked “in preparation” are not yet published. No publication dates are shown until an article is available.

Prefer a measurement over a reading list?

A Forensic Horizon Assessment applies this methodology directly to your environment.