Long Island work often begins with a local device or facility and expands into cloud accounts, home offices, metropolitan counsel, national vendors, and custodians in other states. A laptop in Nassau County, a mobile device in Suffolk County, and a business tenant administered from Manhattan may all contain different parts of the same record. GDF establishes one source map, preservation plan, custody history, and reporting method for the assignment.
Preserve evidence spread across Nassau and Suffolk
Computer forensics may cover employer-owned laptops, workstations, servers, virtual machines, and removable media. Related evidence may sit on personal phones, home networks, Microsoft 365 or Google Workspace, accounting systems, collaboration platforms, security cameras, and line-of-business applications. GDF identifies ownership, control, retention, encryption, synchronization, and current condition before a source is collected or altered.
eDiscovery collections are designed around the fields needed for later use. A simple export may omit deletion state, version history, administrative activity, message routing, access events, or application context. The collection record identifies custodians, sources, date ranges, methods, exceptions, transfers, and the handoff to processing or review. Counsel decides preservation obligations, privilege, and production scope.
- Computer, storage-media, mobile, email, cloud, database, and media preservation
- Remote, on-site, and laboratory acquisition based on source condition and authority
- Traceable status and exception records for distributed collections
Trace every expert conclusion back to its source
An expert assignment may concern file access, device use, disputed communications, deletion, data movement, media authenticity, database output, or the reliability of another examiner's opinion. GDF narrows the work to the systems that can answer the disputed question and records the method used to reach each conclusion.
Reports distinguish observed facts, technical inferences, information supplied by others, and unresolved limits. Custody records, acquisition details, validation, relevant tool settings, and workpapers provide the path from source to opinion. Support can include an early technical assessment, collection protocol, affirmative or rebuttal report, declaration, demonstrative, deposition, hearing, arbitration, or trial testimony.
The Eastern District of New York maintains a courthouse in Central Islip, and the New York Commercial Division lists Nassau and Suffolk among its jurisdictions. The forum alone does not determine the technical method. Counsel controls venue, procedure, disclosure, and the governing legal standard. GDF does not provide legal advice.
Respond to cyber events without losing the first record
A business email compromise, ransomware event, stolen account, vendor intrusion, or unauthorized cloud change can produce evidence across identity, endpoint, email, network, application, and financial systems. GDF can begin 24/7 triage by telephone and work with the client team to balance containment, business continuity, and preservation.
The response record identifies known changes, likely access, affected accounts and systems, persistence, data exposure indicators, and recovery actions. It also states which records were unavailable or had aged out. GDF provides the technical facts needed by management, insurers, and counsel without deciding whether an event triggers a legal notice.
Incident readiness planning reduces avoidable delay before an event. Work can address logging, time synchronization, administrator access, contact paths, evidence retention, backup validation, communication roles, and tabletop exercises.
Turn security testing into an accountable repair plan
Human-led penetration testing examines how an authorized tester can move from an exposed service, compromised identity, application flaw, or configuration weakness toward a meaningful business asset. The scope defines approved systems, credentials, test windows, communications, prohibited techniques, stop conditions, and reporting expectations.
Each material finding records the demonstrated path, observed consequence, affected asset, and evidence supporting the result. Vulnerability remediation guidance assigns a practical correction and a validation step. This gives engineers a usable work queue and gives leadership a clearer basis for deciding which exposure warrants attention first.
Plan OT security around uptime, safety, and process ownership
Manufacturing, water and wastewater, utilities, healthcare facilities, building systems, transportation, and other connected operations require methods that account for production and safety. GDF starts with operator interviews, engineering records, passive traffic, existing inventory data, and vendor-access information. Passive-first asset discovery identifies operational purpose and relationships before any active request is considered.
Assignments can include ICS security architecture, network segmentation validation, vendor and remote-access review, operational consequence ranking, backup and recovery review, and OT incident readiness. Active testing is separately authorized with named targets, a maintenance window, communications, stop conditions, and recovery support. The operator retains control of process safety and production.
Set the handling route before a device or system changes
GDF coordinates work from western Nassau through Suffolk County and the East End. Geography is only one part of the handling decision. Encryption, physical damage, data volume, contested custody, plant restrictions, and the need to preserve volatile information may determine whether the source can be handled remotely, on site, or in the laboratory.
Do not restart a suspect endpoint or factory-reset a phone solely to make transport easier. Call first so the plan can account for volatile state, encryption, synchronization, authority, and operating risk. The initial call confirms current availability and logistics without implying a staffed office in every community.
