ServingNew York, New Jersey, and Connecticut
24/7 incident response1-800-868-8189Contact GDF

Services

Digital forensics, expert witness, cybersecurity, and OT services

Preserve and explain digital evidence, prepare an expert opinion, respond to a cyber event, test a reachable attack path, or assess an OT environment within safety and uptime limits.

Technical map connecting a computer, mobile device, cloud account, verified evidence set, and documented timeline
Sources, handling, verification, and stated limits define a defensible digital record.
How to use this directory

Choose the evidence source, security exposure, or operating constraint that defines the assignment.

A useful scope begins with the question, the available devices and systems, the deadline, and the limits on collection or testing. GDF defines what will be preserved or tested, who is authorized to act, and what the client will receive. Counsel retains legal strategy. Security and operations leaders retain business and safety authority. GDF documents the examination, findings, assumptions, and limits they rely on.

For counsel and litigants

GDF can join at preservation, protocol design, early case assessment, expert reporting, rebuttal, deposition, hearing, or trial. Workpapers identify the device or system examined, acquisition method, queries, assumptions, contrary facts, validation, and limits behind each opinion. This supports a defensible chain of custody, eDiscovery data preservation, expert witness testimony, and Frye/Daubert challenge readiness without promising that any court will admit a particular item or opinion.

The phrase court-admissible digital forensics describes a legal objective, not an outcome a practitioner can guarantee. Courts determine admissibility. GDF supplies the documented methods and technical foundation; counsel controls legal theory, disclosure, and argument.

  • Computer, mobile, email, cloud, database, and media examination
  • Affirmative and rebuttal reports with assumptions and limits stated
  • Declarations, demonstratives, deposition, hearing, and trial support

For CISOs and IT teams

GDF handles active response, human-led penetration testing, vulnerability assessment, application review, and incident readiness planning. Analysts test how identities, configurations, networks, applications, and business processes combine into adversarial attack paths. Findings connect the affected system to an observed consequence, a responsible owner, vulnerability remediation guidance, and a defined retest.

Retesting checks whether the original demonstrated route remains reproducible after the change. The report identifies the test date, approved scope, result, residual exposure, and paths that were not tested. Leadership uses that evidence with business context to judge material risk reduction. Engineers receive the same chronology and decision record at the depth needed to plan corrective work.

  • 24/7 incident response, scoping, containment, and recovery support
  • Network, cloud, identity, application, API, wireless, and source-code testing
  • Prioritized corrections with evidence for remediation and retesting

For OT operators and engineers

OT work begins with the process, not a generic IT test plan. Passive-first asset discovery, operator interviews, engineering records, and traffic analysis establish what the assets do and which changes require a controlled window. ICS security architecture and network segmentation validation are assessed against real data flows, vendor access, recovery dependencies, and safety constraints.

Operational consequence ranking separates findings that could affect control, visibility, availability, or safety from ordinary hygiene work. Incident readiness planning and NERC CIP compliance audit evidence remain tied to actual configurations, access records, change history, and test results. Management and counsel retain compliance decisions; GDF provides the technical examination and supporting evidence.

  • Asset inventory and engineering-record reconciliation
  • Zones, conduits, remote access, jump hosts, and IT/OT boundary testing
  • OT response plans, tabletop exercises, recovery dependencies, and audit support

Specialist expert witnesses

Independent analysis, reports, rebuttal, and testimony matched to the technology and disputed technical proposition.

01 / Expert witness

Computer forensics expert witness

Computer forensics expert witness analysis for endpoint imaging, mobile and cloud evidence, timelines, rebuttal, reports, and testimony in New York.

Review service
02 / Expert witness

Biometrics expert witness

Biometrics expert witness analysis for facial recognition, fingerprints, voice, identity matching, reports, rebuttal, and testimony in New York.

Review service
03 / Expert witness

Database expert witness

Database expert witness analysis for transactions, queries, schemas, data lineage, calculations, rebuttal, reports, and testimony in New York.

Review service
04 / Expert witness

Source-code expert witness

Source code expert witness analysis of repositories, behavior, development history, similarity, security, and technical claims for New York matters.

Review service
05 / Expert witness

Wireless technology expert witness

Wireless technology expert witness analysis for Wi-Fi, cellular, Bluetooth, RF coverage, interference, device records, rebuttal, and testimony.

Review service
06 / Expert witness

Cloud and SaaS expert witness

Cloud and SaaS expert witness analysis of tenant records, audit logs, architecture, exports, APIs, retention, and system behavior in New York matters.

Review service
07 / Expert witness

Technology expert witness

Technology expert witness analysis of systems, architecture, software, hardware, databases, networks, and disputed performance in New York matters.

Review service
08 / Expert witness

AI expert witness

AI expert witness analysis of models, prompts, retrieval, outputs, evaluations, provenance, human review, and technical reliability for New York matters.

Review service

Digital forensics and evidence

Preservation, examination, recovery, and production methods tied to the source, question, and required use.

01 / Digital evidence

Digital forensics and analysis

Digital forensics, documented chain of custody, evidence preservation, technical analysis, and expert reporting for New York counsel and organizations.

Review service
02 / Digital evidence

Computer and storage-media forensics

Forensic imaging and examination of Windows, macOS, Linux, servers, removable media, and damaged drives for New York legal and business matters.

Review service
03 / Digital evidence

Mobile device forensics

Preservation and analysis of iPhone, iPad, Android, messaging, application, photo, and location records for New York matters.

Review service
04 / Digital evidence

Email and Microsoft 365 forensics

Email, Microsoft 365, Exchange, Google Workspace, header, mailbox, audit-log, and business email compromise analysis for New York organizations.

Review service
05 / Digital evidence

Cloud and SaaS forensics

Cloud and SaaS forensic analysis for Microsoft 365, Google Workspace, AWS, Azure, identity, collaboration, audit, and content records in New York matters.

Review service
06 / Digital evidence

eDiscovery preservation and collection

Defensible eDiscovery data preservation, custodian collection, cloud export, processing coordination, and production support for New York counsel.

Review service
07 / Digital evidence

Departing-employee evidence preservation

Preserve and examine corporate laptops, cloud accounts, USB activity, email, file transfers, and access records after an employee departure.

Review service
08 / Digital evidence

Audio, video, and image authentication

Technical authentication of photos, video, audio, metadata, edits, compression, provenance, and suspected AI-generated media.

Review service
09 / Digital evidence

Evidence-aware data recovery

Data recovery triage, forensic preservation, damaged-media imaging, deleted-file reconstruction, backup comparison, and documented recovery results in New York.

Review service

Cybersecurity

Human testing, 24/7 response, application review, and technical evidence tied to material risk reduction.

OT, ICS, and SCADA

Passive-first discovery, architecture, segmentation, incident readiness, and audit evidence under operator control.

Discuss your technical requirement

Tell us what is disputed, which devices or systems may hold the answer, and the next deadline. Counsel retains all legal decisions.

Contact GDF