Skip to content

Answers

How long does a digital forensics examination take?

Acquisition is usually a day or two and is largely predictable. Analysis is not: a bounded question against one laptop can be answered in under a week, while an open-ended examination across several custodians, phones and cloud accounts runs for weeks. How the question is framed matters more than the volume of data.

The stages have very different profiles

Acquisition is bounded by read speed and device count. A laptop is hours; a phone is usually hours but depends on the model and security state; a large server array is a multi-day job. This part can be estimated accurately in advance.

Processing — indexing, extracting artifacts, building a searchable set — is mostly machine time and scales with volume rather than complexity.

Analysis is where the range lives, because it depends on what the data turns out to contain. A targeted question against a single machine is days. An open-ended examination across multiple custodians, phones and cloud tenancies is weeks, and each new thread found extends it.

Reporting takes longer than clients expect. A report written to survive a Daubert challenge has to trace every assertion to an artifact, and that verification pass is real work rather than drafting.

What actually determines the duration

How the question is framed. "Find out what happened" has no natural end. "Determine whether these fourteen files were copied to external media between March and June" is answerable, and answerable faster. Narrowing the question is the single most effective way to shorten the engagement — and it produces a clearer opinion, because a narrow question yields a defensible answer.

Device type. Phones vary enormously. What can be extracted depends on the model, the OS version and the security state, and a device that resists the available techniques can consume days producing very little.

Encryption. A powered-down encrypted device without a key or passcode may not be examinable at all. This is a threshold question, not a delay.

Whether the data was preserved properly. An examination that begins with reconstructing what an earlier IT copy did to the evidence takes considerably longer than one starting from a clean image.

Parallelism. Several examiners can work concurrently on separate devices. This costs more per day and compresses the calendar, which is frequently the right trade when a deadline is fixed.

Getting a preliminary answer sooner

Most engagements can produce an early indication well before the full analysis concludes. A targeted first pass — checking USB connection records, recent-document activity and cloud sync artifacts — often answers the practical question within days of acquisition, even when the complete examination and report take weeks.

This is worth asking for explicitly. It informs decisions about injunctive relief and settlement posture at the point those decisions are actually made, rather than after.

The constraint nobody controls

Evidence degrades. Deleted content on a solid-state drive can be erased permanently by the drive's own housekeeping within hours, and short-retention logs rotate within days. The examination timeline is flexible; the preservation timeline is not, and the two should not be confused when scheduling.

From our work

Need this looked at properly?

Our examiners and testifying experts work these questions for a living. Tell us what you're facing.

Reviewed by Law & Forensics. See our editorial standards.