Data Forensics
Recovering and examining the digital evidence behind a breach, a theft or a suspected intrusion — for businesses and individuals.
Data Forensics
When something has gone wrong — an account taken over, money moved, files copied, a system behaving in a way nobody can explain — the first question is almost always the same: what actually happened? Helium22’s data forensics service sets out to answer it, by recovering and examining the digital evidence an incident leaves behind.

Businesses and individuals are both targets. A compromised business can lose its data, its customers’ confidence and, in the worst cases, its ability to trade at all, taking jobs with it. For an individual, a stolen identity can empty a lifetime’s savings overnight and appear to leave almost no trace.
Almost no trace is not the same as none. Activity online leaves marks: sign-ins, file access, transfers, devices, timestamps, network records. They accumulate in places people rarely think to clear, which is why criminals can never completely erase the digital fingerprint they leave behind. The work lies in finding those marks, reading them correctly, and putting them back in order.
What an investigation establishes
- How they got in — the route taken, and whether it is still open.
- What was reached — which systems, files and accounts were touched, and which were not.
- What left — whether data was copied out, and if so, what and when.
- How long it went on — the first sign of entry is rarely the first thing noticed.
- Whether they are still there — the question most worth answering quickly.

It is a myth that attackers are only ever after money. Organisations are also targeted for leverage and influence, sometimes by state-backed actors, and intellectual property, commercial plans and personal records are all worth taking. Intrusions of that kind tend to be quieter and to run for longer than straightforward theft, which is precisely why they are so often discovered late.
So the work is not only about what happened after the fact. The same evidence that explains a breach can reveal unauthorised activity while it is still under way, and the signs that precede one. If you suspect something is wrong but cannot yet prove it, that is a good moment to talk to us rather than a premature one.
How we work
Evidence is fragile, and the first hours matter. Logs roll over, caches clear, and a well-meant clean-up can destroy the very record that would have shown who did what. We work from copies rather than originals wherever possible, keep a documented chain of custody, and record our method so that the findings stand up to scrutiny — whether they are read by your board, your insurer, a regulator or a court.
What you get back is a plain account of what happened, what it means and what to do next, written to be understood by the people who have to act on it. Where the findings point to weaknesses worth closing, we will say so plainly, and we can help you close them.
If you have had an incident, or you suspect one, get in touch. If nothing has happened yet and you would rather be prepared, that is a conversation worth having too — knowing in advance what evidence your systems retain, and for how long, is most of the battle.