Services
Digital forensics, expert witness, cybersecurity, and OT services
Preserve and explain digital evidence, prepare an expert opinion, respond to a cyber event, test a reachable attack path, or assess an OT environment within safety and uptime limits.
Choose the evidence source, security exposure, or operating constraint that defines the assignment.
A useful scope begins with the question, the available devices and systems, the deadline, and the limits on collection or testing. GDF defines what will be preserved or tested, who is authorized to act, and what the client will receive. Counsel retains legal strategy. Security and operations leaders retain business and safety authority. GDF documents the examination, findings, assumptions, and limits they rely on.
For counsel and litigants
GDF can join at preservation, protocol design, early case assessment, expert reporting, rebuttal, deposition, hearing, or trial. Workpapers identify the device or system examined, acquisition method, queries, assumptions, contrary facts, validation, and limits behind each opinion. This supports a defensible chain of custody, eDiscovery data preservation, expert witness testimony, and Frye/Daubert challenge readiness without promising that any court will admit a particular item or opinion.
The phrase court-admissible digital forensics describes a legal objective, not an outcome a practitioner can guarantee. Courts determine admissibility. GDF supplies the documented methods and technical foundation; counsel controls legal theory, disclosure, and argument.
- Computer, mobile, email, cloud, database, and media examination
- Affirmative and rebuttal reports with assumptions and limits stated
- Declarations, demonstratives, deposition, hearing, and trial support
For CISOs and IT teams
GDF handles active response, human-led penetration testing, vulnerability assessment, application review, and incident readiness planning. Analysts test how identities, configurations, networks, applications, and business processes combine into adversarial attack paths. Findings connect the affected system to an observed consequence, a responsible owner, vulnerability remediation guidance, and a defined retest.
Retesting checks whether the original demonstrated route remains reproducible after the change. The report identifies the test date, approved scope, result, residual exposure, and paths that were not tested. Leadership uses that evidence with business context to judge material risk reduction. Engineers receive the same chronology and decision record at the depth needed to plan corrective work.
- 24/7 incident response, scoping, containment, and recovery support
- Network, cloud, identity, application, API, wireless, and source-code testing
- Prioritized corrections with evidence for remediation and retesting
For OT operators and engineers
OT work begins with the process, not a generic IT test plan. Passive-first asset discovery, operator interviews, engineering records, and traffic analysis establish what the assets do and which changes require a controlled window. ICS security architecture and network segmentation validation are assessed against real data flows, vendor access, recovery dependencies, and safety constraints.
Operational consequence ranking separates findings that could affect control, visibility, availability, or safety from ordinary hygiene work. Incident readiness planning and NERC CIP compliance audit evidence remain tied to actual configurations, access records, change history, and test results. Management and counsel retain compliance decisions; GDF provides the technical examination and supporting evidence.
- Asset inventory and engineering-record reconciliation
- Zones, conduits, remote access, jump hosts, and IT/OT boundary testing
- OT response plans, tabletop exercises, recovery dependencies, and audit support
Specialist expert witnesses
Independent analysis, reports, rebuttal, and testimony matched to the technology and disputed technical proposition.
Computer forensics expert witness
Computer forensics expert witness analysis for endpoint imaging, mobile and cloud evidence, timelines, rebuttal, reports, and testimony in New York.
Review service02 / Expert witnessBiometrics expert witness
Biometrics expert witness analysis for facial recognition, fingerprints, voice, identity matching, reports, rebuttal, and testimony in New York.
Review service03 / Expert witnessDatabase expert witness
Database expert witness analysis for transactions, queries, schemas, data lineage, calculations, rebuttal, reports, and testimony in New York.
Review service04 / Expert witnessSource-code expert witness
Source code expert witness analysis of repositories, behavior, development history, similarity, security, and technical claims for New York matters.
Review service05 / Expert witnessWireless technology expert witness
Wireless technology expert witness analysis for Wi-Fi, cellular, Bluetooth, RF coverage, interference, device records, rebuttal, and testimony.
Review service06 / Expert witnessCloud and SaaS expert witness
Cloud and SaaS expert witness analysis of tenant records, audit logs, architecture, exports, APIs, retention, and system behavior in New York matters.
Review service07 / Expert witnessTechnology expert witness
Technology expert witness analysis of systems, architecture, software, hardware, databases, networks, and disputed performance in New York matters.
Review service08 / Expert witnessAI expert witness
AI expert witness analysis of models, prompts, retrieval, outputs, evaluations, provenance, human review, and technical reliability for New York matters.
Review serviceDigital forensics and evidence
Preservation, examination, recovery, and production methods tied to the source, question, and required use.
Digital forensics and analysis
Digital forensics, documented chain of custody, evidence preservation, technical analysis, and expert reporting for New York counsel and organizations.
Review service02 / Digital evidenceComputer and storage-media forensics
Forensic imaging and examination of Windows, macOS, Linux, servers, removable media, and damaged drives for New York legal and business matters.
Review service03 / Digital evidenceMobile device forensics
Preservation and analysis of iPhone, iPad, Android, messaging, application, photo, and location records for New York matters.
Review service04 / Digital evidenceEmail and Microsoft 365 forensics
Email, Microsoft 365, Exchange, Google Workspace, header, mailbox, audit-log, and business email compromise analysis for New York organizations.
Review service05 / Digital evidenceCloud and SaaS forensics
Cloud and SaaS forensic analysis for Microsoft 365, Google Workspace, AWS, Azure, identity, collaboration, audit, and content records in New York matters.
Review service06 / Digital evidenceeDiscovery preservation and collection
Defensible eDiscovery data preservation, custodian collection, cloud export, processing coordination, and production support for New York counsel.
Review service07 / Digital evidenceDeparting-employee evidence preservation
Preserve and examine corporate laptops, cloud accounts, USB activity, email, file transfers, and access records after an employee departure.
Review service08 / Digital evidenceAudio, video, and image authentication
Technical authentication of photos, video, audio, metadata, edits, compression, provenance, and suspected AI-generated media.
Review service09 / Digital evidenceEvidence-aware data recovery
Data recovery triage, forensic preservation, damaged-media imaging, deleted-file reconstruction, backup comparison, and documented recovery results in New York.
Review serviceCybersecurity
Human testing, 24/7 response, application review, and technical evidence tied to material risk reduction.
Cybersecurity assessment and response
Material risk reduction through penetration testing, vulnerability assessment, incident readiness, response, application security, and security architecture.
Review service02 / Cybersecurity24/7 cyber incident response
24/7 cyber incident response, containment, evidence preservation, scoping, analysis of likely entry paths, recovery support, and readiness planning.
Review service03 / CybersecurityHuman-led penetration testing
Human-led penetration testing across networks, cloud, identity, applications, wireless, and adversarial attack paths, with remediation and retesting.
Review service04 / CybersecurityVulnerability assessment and remediation
Asset-informed vulnerability assessment, exposure validation, operational consequence ranking, remediation guidance, and scoped retesting.
Review service05 / CybersecurityApplication and source-code security
Application, API, source-code, architecture, authentication, authorization, and secure-development review with reproducible findings.
Review service06 / CybersecurityNYDFS technical evidence support
Technical testing and evidence support for NYDFS cybersecurity programs, control validation, incident records, vulnerability management, and audit readiness.
Review serviceOT, ICS, and SCADA
Passive-first discovery, architecture, segmentation, incident readiness, and audit evidence under operator control.
OT, ICS, and SCADA security
Passive-first asset discovery, ICS security architecture, segmentation validation, operational consequence ranking, and OT incident readiness.
Review service02 / OT / ICS / SCADAPassive-first OT asset discovery
Build and reconcile OT and ICS asset inventories through passive traffic analysis, engineering records, operator interviews, and controlled validation.
Review service03 / OT / ICS / SCADAOT network segmentation validation
Validate OT zones, conduits, firewall policy, remote access, jump hosts, IT/OT boundaries, and practical reachability under operating constraints.
Review service04 / OT / ICS / SCADAOT incident response
Operationally safe response, evidence preservation, scoping, containment, recovery support, and readiness planning for OT, ICS, and SCADA events.
Review service05 / OT / ICS / SCADANERC CIP technical evidence support
Technical evidence support for Registered Entity NERC CIP scope, covering asset, access, configuration, vulnerability, change, and incident records.
Review serviceDiscuss your technical requirement
Tell us what is disputed, which devices or systems may hold the answer, and the next deadline. Counsel retains all legal decisions.