How to Preserve Evidence After a Cyber Attack - System Force IT

How to Preserve Evidence After a Cyber Attack

In the rush of a cyber incident, evidence is the first casualty. Someone wipes the infected laptop “to be safe”. Someone deletes the phishing email. Someone resets everything and, without meaning to, erases the trail of how the attacker got in. Preserve the evidence badly and you spend the rest of the incident, and possibly a regulatory investigation or an insurance claim, guessing.

This guide explains how to preserve evidence after a cyber attack in a way that is realistic for a UK SME, without pretending you are running a forensic laboratory. It is a companion to our full cyber incident response plan guide.

Why evidence matters, beyond a court case

People assume evidence is only about prosecution. In practice it matters for far more everyday reasons: understanding what the attacker actually did so you can recover with confidence, satisfying your cyber insurer, answering a regulator such as the ICO, resolving a contractual dispute, and learning the genuine lesson afterwards. Destroy the evidence early and every one of those becomes harder. The good news is that useful preservation is mostly discipline, not deep technical skill.

The most damaging evidence mistakes are the well-meaning ones: rebooting or wiping a machine that “looks infected”, deleting suspicious emails, or resetting systems to “clean” them. Each can erase exactly what you need. When in doubt, isolate and preserve, then ask.

What to capture and keep

Capture and safely store the things that tell the story of the incident:

  • A timestamped incident log, your single most important piece of evidence.
  • Screenshots of what you saw, including any ransom note or error messages.
  • The full headers of suspicious emails, and the messages themselves, before anyone deletes them.
  • Authentication and sign-in logs, and firewall logs, exported before they roll off.
  • Endpoint security alerts and the names of affected files.
  • Any ransom note and attacker communications.
  • Indicators of compromise, such as suspicious IP addresses, domains or file names.
  • A record of changes made to accounts, and any administrator or configuration changes, whether the attacker’s or your own.

If your logs are only kept for a few days, some of this may already be gone, which is why logging matters so much. See our guide on the logs you need for a cyber investigation.

A light-touch chain of custody

“Chain of custody” sounds like a courtroom drama, but for an SME it just means being able to say, for each piece of evidence, where it came from and who has handled it. Keep it simple:

  • Work from a copy, and keep the original untouched.
  • Record who collected it, when, and from where.
  • Where it matters, record a hash or checksum, a digital fingerprint that proves a file has not changed since.
  • Note where it is stored and who has accessed it.

The free Cyber Incident Response Toolkit includes an evidence register that captures exactly these fields, so you are not inventing a system mid-incident.

Know your limits, and when to call a professional

Two cautions matter here. First, do not go beyond your competence. Non-specialists should not start imaging drives or poking around live compromised systems, because it is easy to overwrite the very evidence you are trying to keep. Second, know when to bring in professional digital forensics: any time the incident is serious, likely to involve a claim or dispute, or where you genuinely need to prove what did and did not happen. A specialist can capture evidence in a way that stands up later; an untrained hand can destroy it in seconds.

What not to do

  • Do not wipe, reimage or factory-reset a device just because it looks infected.
  • Do not delete suspicious emails before the headers and messages are preserved.
  • Do not reboot a compromised machine unnecessarily, as useful evidence in memory can be lost.
  • Do not reset or reconfigure systems in a way that erases the record of what changed.
  • Do not store evidence somewhere the attacker could still reach or alter it.

Get the evidence register before you need it

The free Cyber Incident Response Toolkit includes an evidence register and incident log built for exactly this, so if an incident happens you can preserve what matters from the first hour.

Get the free toolkit

Frequently asked questions

What evidence should I preserve during a cyber incident?

Keep a timestamped incident log, screenshots of what you saw, the full headers of suspicious emails and the messages themselves, authentication and firewall logs, endpoint alerts, the names of affected files, any ransom note, indicators of compromise, and a record of account and configuration changes. Capture these before anyone deletes or resets anything.

What is chain of custody, and do I need it?

For an SME it simply means being able to say, for each piece of evidence, where it came from and who has handled it. Work from copies and keep originals untouched, record who collected what, when and from where, use a hash where it matters, and note where it is stored and who accessed it. It is discipline, not a forensic system.

Should I wipe or reset an infected computer?

No, not before preserving evidence. Wiping, reimaging or even rebooting a machine that looks infected can erase exactly what you need to understand the attack. Isolate it from the network, leave it powered on where you can, and preserve the evidence before making any changes.

When should I call in professional digital forensics?

Any time the incident is serious, likely to involve an insurance claim or a legal dispute, or where you genuinely need to prove what did and did not happen. Non-specialists should not start imaging drives or working on live compromised systems, because it is easy to destroy evidence unintentionally.

Related reading: the full Cyber Incident Response Plan guide, what logs you need for a cyber investigation, and the free Cyber Incident Response Toolkit.

Practical guidance, not legal advice. From System Force IT, UKAS ISO/IEC 27001:2022 certified, supporting UK businesses since 2006.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name