Skip to content

Answers

Can our IT department do the forensic collection?

They can copy data, but a copy is not a forensic collection. IT tools change timestamps, omit deleted content, and produce no verifiable record of what was done — and the administrator who performed it becomes a fact witness. For preservation-only work under supervision it can be adequate; for anything contested it usually is not.

Three separate problems

The tools do different things. Backup and sync software copies the files the operating system presents. It does not capture deleted content, slack space, or the system artifacts that record activity — which in a departing-employee or misconduct matter are usually the evidence. See forensic image for what that difference actually contains.

The handling alters the evidence. Attaching a drive to a running workstation causes that workstation to write to it. Copying files updates timestamps. Opening documents changes access times. None of this is careless; it is what operating systems do, and it is why a write blocker exists. Once it has happened it cannot be undone.

The record does not survive challenge. A forensic acquisition produces a tool-generated log and a hash value verifying the copy against the source. An IT copy produces neither, so the only evidence of what happened is the administrator's recollection — which is now testimony.

The witness problem is the one people miss

Whoever performs the collection can be deposed about it. That means your systems administrator answering questions about their methodology, their training, what they touched, and what they might have altered. They will not have prepared for it, they are not a forensic examiner, and honest answers to reasonable questions will still sound bad.

It also means an internal employee — whose interests are aligned with the company — is the sole custodian of the evidence's integrity, which is precisely the point opposing counsel will make.

Where in-house collection is genuinely fine

This is not an argument that IT should never touch anything. Reasonable uses:

  • Preserving cloud and mailbox data through the platform's own compliance or eDiscovery export, which is designed for the purpose and produces a defensible record.
  • Suspending auto-deletion and retention policies — an administrator has to do this, and no outside firm can.
  • Identifying and mapping systems, which IT knows and nobody else does.
  • Targeted collection under an examiner's written instruction, where the method is specified by someone who will defend it.

The distinction is between IT operating systems it owns, and IT improvising a forensic process.

The practical rule

If the data might be contested, get it imaged first and analyse later. Acquisition is comparatively cheap and time-critical; analysis is expensive and can wait. The most common and most expensive sequence we see is the reverse: a well-intentioned copy made on day one, followed by a forensic engagement on day thirty, by which point the question is no longer what the evidence shows but what the first copy destroyed.

And if IT has already made a copy, say so early. That is a manageable fact disclosed by your own expert, and a damaging one discovered on cross-examination.

From our work

Need this looked at properly?

Our examiners and testifying experts work these questions for a living. Tell us what you're facing.

Reviewed by Law & Forensics. See our editorial standards.