Answers
The questions counsel actually ask
Direct answers to the questions counsel actually ask about digital forensics, expert testimony, eDiscovery and investigations — costs, timelines, procedure, and what the evidence can and cannot show.
Digital forensics
Can deleted files be recovered?
Often, but it depends on the storage and on elapsed time. Deleting a file usually removes the pointer rather than the content, so it survives until overwritten. On a traditional hard disk that can be weeks; on a solid-state drive the drive's own housekeeping may erase it permanently within hours.
Can our IT department do the forensic collection?
They can copy data, but a copy is not a forensic collection. IT tools change timestamps, omit deleted content, and produce no verifiable record of what was done — and the administrator who performed it becomes a fact witness. For preservation-only work under supervision it can be adequate; for anything contested it usually is not.
How do I challenge the other side's forensic expert?
Challenge the engagement, not the field. Digital forensics comfortably satisfies Rule 702, so attacks on the discipline fail. What succeeds is narrower: unverified acquisitions, gaps in chain of custody, a method that cannot be reproduced from the report, or an opinion that reaches past what the artifacts support.
How do I preserve a departing employee's laptop?
Stop using the device, do not let IT reimage or reissue it, and have a forensic image taken before anything else happens. The most common way evidence is destroyed in departing-employee matters is routine IT hygiene — wiping and redeploying the laptop — carried out in good faith days before anyone suspects there is a dispute.
How long does a digital forensics examination take?
Acquisition is usually a day or two and is largely predictable. Analysis is not: a bounded question against one laptop can be answered in under a week, while an open-ended examination across several custodians, phones and cloud accounts runs for weeks. How the question is framed matters more than the volume of data.
What does a digital forensics expert witness cost?
Digital forensics experts bill hourly, with testimony and deposition time at a higher rate than analysis. Cost is driven by scope rather than rate: the same expert on the same matter varies enormously depending on how many devices are imaged, how much data reaches review, and whether the engagement ends at a report or runs to trial.
What does a digital forensics report contain?
Scope and questions asked, evidence received and how it was handled, tools and versions used, the acquisition and verification record, findings tied to specific artifacts, and an explicit statement of limitations. A report that states conclusions without the steps behind them cannot be reproduced, which is a methodology problem rather than a drafting one.
What makes digital evidence admissible in court?
Digital evidence has to clear the same hurdles as any other: authentication, relevance, a hearsay exception where one is needed, and expert testimony that satisfies Rule 702. What is distinctive is how it is authenticated — through documented acquisition, hash verification, and an unbroken account of handling.
eDiscovery
What should an ESI protocol include?
Scope, form of production, an enumerated metadata field list, search methodology and its validation, de-duplication treatment, privilege logging and a Rule 502(d) order, and explicit handling of chat and mobile data. Anything left out becomes a motion later, at many times the cost of agreeing it now.
When does a court appoint a special master?
Courts appoint special masters under Rule 53 when a matter needs sustained attention the judge cannot practically give it — recurring discovery disputes, technically specialised questions, privilege review at volume, or claims administration. Most appointments come by joint motion of the parties rather than on the court's own initiative.
Who pays for a special master?
The parties do. Rule 53 requires the appointing order to state the basis, terms and procedure for compensation, and courts most often split the cost evenly. Allocation can be adjusted — weighted toward the party generating the disputes, or shifted entirely where a master's time was consumed by one side's conduct.
Investigations
Can we examine an employee's personal phone?
Not unilaterally. A personal device is the employee's property and imaging it without clear authority creates privacy and statutory exposure that can exceed the underlying dispute. The routes are consent, a negotiated preservation agreement, a court order, or a neutral examiner protocol that produces only responsive material.
We think an employee took data. What do we do first?
Preserve before you investigate. Hold the device out of the reissue cycle, suspend deletion on their accounts, and capture the access and egress logs that expire fastest. Do not confront the employee, and do not let anyone browse the laptop — both destroy evidence and both are difficult to explain afterwards.
Cybersecurity
How should we respond to a ransomware attack?
Preserve evidence before remediating, capture the short-retention logs immediately, notify your insurer before retaining anyone, and engage counsel early. The decisive question is not whether to pay but what data left the environment — notification and regulatory duties follow from the theft, not from the encryption.
Your question isn't here?
Most of what we're asked is matter-specific. Call and describe the situation — the answer is usually a short conversation.

