ServingNew York, New Jersey, and Connecticut
24/7 incident response1-800-868-8189Contact GDF

New York City / five-borough coordination

New York City digital forensics, expert witness, and cyber response

Preservation and technical analysis for disputes, urgent cyber events, security testing, and operational systems in Manhattan, Brooklyn, Queens, the Bronx, and Staten Island.

Courthouses in the Civic Center district of Lower Manhattan
Photograph by Angelo Rizzuto, Library of Congress.

A New York City assignment rarely stays inside one office. A disputed record may touch a company laptop in Midtown, a personal phone in Queens, a Microsoft 365 tenant, a vendor in New Jersey, and counsel working toward a federal or state court deadline. GDF maps those sources before collection, assigns one technical lead, and selects remote, on-site, or laboratory methods according to source condition, access, volume, custody, and operating risk.

Expert work begins with the question the record must answer

A useful technical opinion starts with a disputed fact. Counsel may need to determine whether a person used a device, whether an email is authentic, when files moved, how a database produced a result, whether media was altered, or why two examiners reached different conclusions. GDF identifies the systems capable of answering that question before deciding which tools or acquisition methods belong in the scope.

Court-admissible digital forensics is not achieved by adding a label to a report. It depends on source identification, defensible chain of custody, repeatable methods, validation, and a clear account of exceptions and limits. Workpapers record the source, acquisition method, hash values where applicable, tool versions, relevant settings, testing, and the basis for each conclusion.

Frye/Daubert challenge readiness is developed while the work is performed. The examiner tests competing explanations, separates direct observation from inference, and states where the available evidence cannot support a conclusion. Counsel determines the governing standard, disclosure strategy, and admissibility position. GDF provides technical analysis and expert witness testimony, not legal advice.

  • Early technical assessment and evidence-source mapping
  • Affirmative and rebuttal expert reports, declarations, and demonstratives
  • Deposition, hearing, arbitration, and trial testimony
  • Independent review of another examiner's methods, assumptions, and conclusions

Preserve computer, cloud, and collaboration records early

Computer forensics can establish activity recorded on laptops, workstations, servers, virtual machines, and removable media. Email, collaboration platforms, cloud storage, mobile applications, and business systems add records that may change under retention settings, synchronization, licensing, administrative action, or ordinary user activity. GDF documents the source, provider, tenant, administrators, custodians, time range, retention state, and fields needed for later analysis before collection begins.

eDiscovery data preservation may require more than a mailbox export. Message headers, transport records, identity events, audit logs, file versions, sharing records, mobile artifacts, and endpoint data can answer different parts of the same question. GDF records collection status, exceptions, transfers, processing decisions, and the handoff to review. Counsel controls legal holds, privilege, responsiveness, and production decisions.

Build the incident record while containment moves

GDF provides 24/7 incident response for events involving identity systems, endpoints, email, cloud platforms, applications, networks, and operational environments. The first response plan identifies the systems still at risk, evidence likely to change, current business impact, available telemetry, and the people authorized to contain or restore affected services.

The technical record develops alongside containment. GDF reconstructs access and activity, tests the likely entry and movement path, identifies affected systems and accounts, and documents recovery and validation. Management and counsel decide whether a notice, filing, or regulatory response is required. GDF supplies the chronology, affected-system analysis, evidence gaps, and technical findings needed for those decisions.

Test the path an attacker would actually use

A scanner result does not show whether a weakness can be reached, combined with another condition, or used to affect a material system. Human-led penetration testing follows authorized adversarial attack paths across identity, cloud, network, application, and endpoint controls. Written rules define approved targets, test windows, communications, stop conditions, and evidence handling.

Findings connect the demonstrated path to business consequence and material risk reduction. Vulnerability remediation guidance identifies the affected asset, accountable owner, required correction, and validation method. Retesting checks the original route and relevant adjacent exposure without representing untested systems as secure.

Treat operational technology as an operating environment

Building controls, transportation support systems, healthcare facilities, utility interfaces, campus systems, access controls, and other connected operations cannot be assessed as ordinary office IT. GDF begins with engineering records, operator interviews, passive-first asset discovery, and existing network data. The resulting inventory records operational purpose, communications, ownership, dependencies, and consequence, not only an address and device name.

Work can include ICS security architecture, network segmentation validation, remote-access review, operational consequence ranking, recovery planning, and incident readiness planning. Active validation requires separate operator approval, named targets, communications, stop conditions, and recovery support. For entities to which NERC CIP applies, GDF can help assemble NERC CIP compliance audit evidence that traces technical records to the applicable control. The client retains safety, production, and compliance authority.

Coordinate five boroughs and outside sources under one record

A city matter may require collection in Manhattan, Brooklyn, Queens, the Bronx, or Staten Island while cloud administrators, vendors, witnesses, or other custodians work elsewhere. One technical lead can maintain the source map, custody history, collection status, exception log, and reporting method across those locations.

The first call should identify the general source location, device or system type, current custodian, deadline, and any reason the source cannot be moved or interrupted. GDF then confirms whether the work should proceed remotely, on site, or in the laboratory. Evidence and sensitive records should not be sent through the public contact form.

Primary and public sources

Discuss a New York City requirement

Include the region, system or evidence type, deadline, and any reason the source cannot be moved or the process interrupted.

Contact GDF