Digital Forensics Services in South Africa

When a breach, fraud case, or cybercrime incident happens, what you do in the first few hours determines whether the evidence will hold up later. Our digital forensics team collects, preserves, and analyses electronic evidence the right way, under proper chain of custody and South African legal procedure, so it stands up in a disciplinary hearing, civil claim, or criminal case.

Speak to a forensic investigator →  |  Urgent incident response available  |  Chain-of-custody documentation included

What Is Digital Forensics?

Digital forensics is the practice of identifying, preserving, collecting, and analysing electronic evidence from computers, phones, servers, and other digital devices in a way that’s scientifically sound and legally defensible. It’s used to reconstruct what happened during a security incident, prove or disprove suspected fraud, recover deleted or hidden data, and produce findings that can withstand scrutiny in internal disciplinary processes, civil litigation, or criminal prosecution under the Cybercrimes Act 19 of 2020.

The defining feature of forensic work, as opposed to ordinary IT troubleshooting, is the discipline around evidence integrity. Every action taken on a device is documented. Original evidence is preserved untouched wherever possible, and analysis is performed on a forensic copy. This is what separates “we looked into it and think X happened” from evidence a court or disciplinary panel can actually rely on.

When You Need Digital Forensics

Common triggers include a suspected data breach where you need to establish what was accessed and by whom; suspected employee fraud, such as financial manipulation or unauthorised data exfiltration ahead of resignation; business email compromise or invoice fraud, where funds were diverted through a compromised account; intellectual property theft, where a departing employee may have taken confidential data; and incidents requiring a clear, evidence-backed account for an insurer, regulator, or legal team.

Our Forensic Process

1. Identification. We work with you to identify which devices, accounts, and data sources are likely to hold relevant evidence.
2. Preservation. Affected devices are secured in their current state, powered on or off as found, to prevent loss of volatile data or accidental alteration.
3. Collection. A forensic image, an exact, verifiable copy of the original data, is created using industry-standard tooling, so all analysis happens on the copy, never the original.
4. Analysis. We examine the forensic image to reconstruct events, recover deleted material, and identify the evidence relevant to your case.
5. Documentation. Every step is logged, maintaining an unbroken chain of custody from collection to final report.
6. Reporting. You receive a clear findings report, written to be understood by non-technical stakeholders, with technical detail available where legal proceedings require it.

What We Investigate

Data Breach Investigations

Establishing what was accessed, how the attacker got in, and what data was affected, to satisfy both your internal response and any regulatory notification obligations under POPIA.

Employee & Internal Fraud

Forensic review of company devices, email accounts, and file activity to investigate suspected internal fraud, data theft, or policy violations, with findings suitable for disciplinary proceedings.

Business Email Compromise & Invoice Fraud

Tracing how a business email account was compromised and how fraudulent payment instructions were issued, often a critical step in recovery efforts and insurance claims.

Mobile & Computer Forensics

Recovery and analysis of data from phones, laptops, and external storage devices, including deleted files, communication records, and metadata.

Why Chain of Custody Matters

South African courts test digital evidence on two fronts: whether it was altered during collection or analysis, and whether the methods used to gather it were reliable. A chain of custody, the documented, unbroken record of who handled the evidence, when, and why, is what proves both. Skip this discipline and even technically accurate findings can be challenged or thrown out entirely. It’s the single biggest difference between an in-house IT team “having a look” and a proper forensic investigation.

Frequently Asked Questions

Can digital forensic evidence be used in a South African court?

Yes, provided it’s collected correctly. Courts assess whether evidence was altered and whether collection methods were reliable, which is why documented chain of custody and proper authorisation matter.

What is the Cybercrimes Act and how does it affect an investigation?

The Cybercrimes Act 19 of 2020 defines cybercrime offences and law enforcement investigative powers in South Africa. It shapes how evidence must be handled to remain admissible if a case is reported to police or proceeds to court.

What is chain of custody and why does it matter?

It’s the documented record of who collected, handled, and analysed evidence, and when. Without it, even sound evidence can be challenged or excluded from proceedings.

How quickly should we start an investigation after discovering an incident?

As soon as possible. Volatile data and logs can be lost within hours. Preserve affected devices in their current state until a forensic practitioner can image them properly.

Get Started

If you suspect a breach, fraud, or cybercrime incident, speak to us immediately, evidence loses integrity quickly without correct handling.

Contact our forensics team →

LinkedIn
Facebook
Threads
X
Pinterest
Reddit
WhatsApp
Instagram
]