ServingNew York, New Jersey, and Connecticut
24/7 incident response1-800-868-8189Contact GDF

Global Digital Forensics | New York, New Jersey, Connecticut

Digital forensics, expert witness, cybersecurity, and OT security

GDF preserves and examines computers, mobile devices, email, cloud data, and operational systems. The team provides expert reports and testimony, 24/7 cyber incident response, human-led penetration testing, and OT, ICS, and SCADA assessments across the tri-state region.

Manhattan skyline viewed from the Empire State Building in 2018
Photograph by Carol M. Highsmith, Library of Congress.
  • Since 1992
  • Court-tested experts
  • 24/7 incident response
  • Sixteen U.S. offices

Start with the problem

What does your team need to do next?

A device needs to be preserved. An expert opinion is due. A cyber event is active. An OT change must be tested within safety and uptime limits. Start there. GDF brings in adjacent disciplines when the evidence crosses systems.

Counsel, litigants, and legal departments

Digital evidence and expert testimony

Computer forensics may involve laptops, workstations, servers, virtual machines, and removable media. Related evidence can sit on phones, email, cloud platforms, databases, and media. GDF documents custody and method, tests competing explanations, and states where the artifacts support or limit a conclusion.

When retained as an expert, the same work can support reports, rebuttal, deposition, hearings, arbitration, and trial. Counsel controls legal strategy, disclosure, and admissibility arguments.

CISOs, IT leaders, counsel, and risk owners

Cyber response and security testing

Contain active events, correlate identity and system activity, and test the paths that can reach important data or services. Human-led work supplements scanning where business logic, chained weaknesses, and compensating controls change the answer.

Each finding identifies the affected system, observed consequence, recommended correction, responsible owner, and retest result. Reports state the point-in-time scope and any paths that were not tested.

Operators, engineers, asset owners, and safety teams

Operational technology, ICS, and SCADA security

Map assets and data flows, validate segmentation and remote access, prepare for cyber events, and review technical audit evidence under operator-defined limits. Passive observation and engineering records establish context before any active validation is proposed.

Life safety, environmental protection, and stable operation take priority. The designated operator controls active methods, maintenance windows, stop conditions, and recovery support.

Method maps

Four systems. Four different records.

Digital evidence, discovery data, enterprise networks, and operational systems do not share one generic method. These maps show the decisions that change the work.

Technical map connecting a computer, mobile device, cloud account, verified evidence set, and documented timeline

Digital forensics

From source device to defensible finding

The technical record connects the original source, acquisition method, integrity checks, custody events, examination notes, and the limits on any conclusion.

Review the method
eDiscovery record flow from source mapping and preservation through collection, review, and production

eDiscovery

Preservation before review

Custodians, cloud services, retention controls, local caches, collection scope, and production requirements are mapped before records move into review.

Review the method
Cybersecurity attack-path map connecting identity, cloud, endpoint, application, business consequence, and remediation

Cybersecurity

Attack paths tied to operational consequence

Identity, endpoint, cloud, network, and application weaknesses are tested as connected routes, then assigned for correction and point-in-time retesting.

Review the method
OT and SCADA security architecture showing enterprise, operations, control, process, and safety boundaries

OT, ICS, and SCADA

Security boundaries built around the process

Asset purpose, zones, conduits, vendor access, safety functions, and recovery dependencies establish where passive and active methods are appropriate.

Review the method
Marble lobby of the Thurgood Marshall United States Courthouse in Manhattan
Photograph by Carol M. Highsmith, Library of Congress.

Expert reports, rebuttal, and testimony

Show the path from the evidence to the opinion.

GDF begins with the disputed issue and the best available source material. The workpapers identify what was preserved, how it was acquired, which methods were used, what assumptions affected the analysis, and where the evidence stops.

Examiners test ordinary and competing explanations before stating a conclusion. Reports separate direct observation from inference and information supplied by others. Rebuttal work focuses on differences that could affect the opinion.

Counsel controls legal strategy, disclosure, and admissibility arguments. GDF supplies the technical work for reports, declarations, demonstratives, deposition, hearings, arbitration, and trial.

STATENew York Frye preparation
FEDERALDaubert and Rule 702 preparation
DELIVERABLESReport, rebuttal, deposition, trial
Path from disputed technical fact to expert testimony
The workpapers connect the disputed fact to preserved material, an explainable method, tested alternatives, and a stated opinion.

How an engagement proceeds

What happens after the first call

The method changes with the source and operating conditions. Every assignment still needs clear authority, a defined scope, documented handling, technical review, and a useful deliverable.

  1. 01

    Confirm authority, urgency, and scope

    The first call identifies the parties, the question to be answered, who may authorize the work, the next deadline, and any immediate preservation or safety concern. An engagement begins only after conflicts and scope are resolved.

  2. 02

    Map and preserve the sources

    Examiners identify the relevant devices, accounts, cloud services, logs, applications, backups, custodians, and control-system assets. The acquisition record identifies the method, operator, date and time, source condition, and available verification details.

  3. 03

    Examine or test under agreed limits

    The method is selected for the device or system and the question. Related artifacts are compared, competing explanations are tested, and active cyber or OT techniques remain inside approved rules and stop conditions.

  4. 04

    Review the findings and workpapers

    A second review checks whether the findings follow from the preserved material and recorded method. The client receives the agreed deliverable, which may be a chronology, collection log, report, data production, remediation plan, or audit package.

  5. 05

    Support testimony, remediation, or retesting

    Counsel may use the work for expert disclosure, rebuttal, deposition, or trial. Security and operations teams receive prioritized corrections and a retest method. Open questions and residual scope remain visible.

Evidence and security questions

Common requirements across regional matters

Every assignment is narrowed to the available sources, authority to act, disputed facts, operating risk, deadline, and limits in the technical record.

Commercial disputes and trade secrets

Corporate laptops, Microsoft 365, cloud drives, USB history, source repositories, file metadata, and access logs can address copying, deletion, authorship, timing, and the movement of confidential material. Activity is compared with ordinary work patterns before any conclusion is stated.

Email, cloud, and payment events

A forwarded message rarely answers an authenticity or account-compromise question. Native email, transport headers, mailbox rules, identity events, OAuth grants, tenant audit logs, endpoints, and transaction records are correlated to establish what the systems record and where attribution remains limited.

Mobile, location, and questioned media

Phones combine messages, application databases, photographs, backups, cloud synchronization, and location-related artifacts. Acquisition type, operating-system version, device state, platform processing, and source quality determine which conclusions can be supported.

Cyber events, insurance, and recovery

Ransomware, unauthorized access, business email compromise, insider activity, and destructive events require containment and evidence preservation at the same time. GDF develops the chronology, affected scope, access facts, likely initial-access path and contributing conditions where the evidence supports a conclusion, recovery dependencies, and the retest record.

Financial services and regulated systems

Banks, insurers, investment firms, fintech companies, and service providers need evidence tied to privileged access, cloud controls, payment processes, sensitive data, third parties, resilience, and remediation. GDF can test controls and organize technical evidence while management and counsel retain compliance decisions.

Critical infrastructure and cyber-physical operations

Building systems, manufacturing, power, water, transportation, logistics, and healthcare facilities require security work that respects process safety and uptime. Asset purpose, network path, vendor access, segmentation, backup, spares, and recovery ownership are evaluated together.

Evidence sources and technical environments

Evidence sources GDF examines

A reliable chronology often depends on several systems. GDF maps the records that can corroborate, contradict, date, qualify, or explain one another before deciding what must be preserved.

Computers and storage

Windows, macOS, Linux, virtual machines, servers, RAID, removable media, file systems, backups, and damaged devices.

Mobile and communications

Supported iPhone, iPad, Android, text, chat, application data, photos, video, audio, and location-related records.

Cloud and identity

Microsoft 365, Entra ID, Google Workspace, AWS, Azure, email, collaboration services, object storage, and SaaS audit data.

Business systems and databases

ERP, CRM, financial, access-control, application, transaction, source-code, and operational data with query and transformation records.

Networks and security telemetry

Firewall, VPN, DNS, proxy, packet, endpoint, authentication, remote-access, alert, and vulnerability records.

OT and cyber-physical systems

PLCs, HMIs, historians, engineering workstations, industrial protocols, gateways, safety systems, building controls, and vendor paths.

Service areas

New York, New Jersey, and Connecticut

Remote, on-site, and laboratory methods are selected according to source condition, access, data volume, custody requirements, and operating risk. Intake confirms current logistics before work begins.

Questions at intake

What to do before evidence changes or disappears

The first call can identify expiring logs, unsafe handling, unsupported assumptions, and the source most likely to answer the technical question.

When should GDF be called?

Call before a device is reissued, an account is disabled, a retention period expires, a cloud tenant is remediated, or an OT change alters the available record. For an active cyber or operational event, use the 24/7 telephone line rather than waiting for the website form.

Can the work begin remotely?

Many interviews, cloud collections, log acquisitions, reviews, and planning tasks can begin remotely. Device condition, data volume, source access, legal protocol, network design, or operational risk may require on-site work or laboratory handling. The first scope identifies the appropriate method.

Does a forensic tool make evidence court-admissible?

No. A tool is one part of the method. Source identification, authorization, preservation, chain of custody, validation, repeatability, interpretation, disclosure, and the applicable legal framework all affect how evidence is used. GDF addresses the technical foundation; counsel addresses admissibility and law.

Can OT security testing be performed without disrupting production?

The plan begins with passive observation, engineering records, operator interviews, and configuration review. Any active validation is separately approved with defined targets, windows, communications, stop conditions, and recovery support. Some fragile assets should not be actively tested in production.

What should be sent through the contact form?

Send the general source type, deadline, forum or operating environment, and the decision your team needs to make. Do not upload evidence or include passwords, protected health information, payment data, government identification, or other sensitive records. The form delivers your message by email; the website does not store a separate copy.

Talk with a GDF technical lead

Tell us what happened, which source or system is involved, and your next deadline. Do not send evidence through the public form.

Contact GDF