10 Questions to Ask Before Hiring a Digital Forensics Firm
Before you hire a digital forensics firm, ask ten things: who specifically will work your case and what they are certified in; whether that examiner has testified; how chain of custody is documented; how your evidence is stored and access-controlled; who the report is written for; when preliminary findings arrive and in what form; how estimates are re-baselined when scope moves; whether the firm is on your insurer's panel; who owns and retains the evidence images afterward; and what happens if the matter goes to litigation. The answers separate an investigation that holds up from an expensive PDF. A small senior-led firm will often answer all ten better than a large brand that assigns your case to whoever is free that week.
There is no meaningful public ranking of forensics firms, which is why the vetting has to come from you. This article gives the ten questions, the answers worth accepting, the answers that should end the conversation, and the situations where a boutique (including ours) is the wrong choice.
Key takeaways
- No credible ranking of forensics firms exists, so the buyer supplies the criteria. Ten questions, asked before the engagement letter, do most of the work.
- Ask about the named examiner, not the firm. Certifications such as GIAC's GCFA and GCFE and IACIS's CFCE attach to people, and people are what you are buying.
- Two questions come before the ten: is the firm on your carrier's panel, and is outside counsel engaging them. Both are close to irreversible once work starts.
- Chain of custody, evidence retention, and testimony scope belong in the statement of work. A firm that answers "industry standard" has no written procedure.
- A boutique is the wrong choice when you need round-the-clock coverage across several time zones at once, when your carrier's panel is rigid, or when the matter needs a name a jury already recognizes.
Two questions that come before the ten
Is the firm on your cyber carrier's panel? Most policies route response spend through a pre-approved roster, and engaging off-panel without written consent can mean partial reimbursement or none. This is the single cheapest phone call in the whole process: your broker can tell you the panel, the notice deadline, and whether a preferred firm can be pre-approved. Make that call before you take a sales meeting, including ours.
Is outside counsel doing the engaging? In serious matters the forensics firm should be retained by breach counsel, under an incident-specific engagement letter, for the purpose of informing legal advice. Get that order wrong and there is no undo. The reasoning, and the case law behind it, is in Is Your Breach Forensic Report Privileged? Probably Not.
With those settled, the ten.
Questions 1 to 3: who actually works your case
1. Who is the named examiner, and what are their certifications?
Sales engineers do not do examinations. Ask for the individual, and get the name into the statement of work. On credentials, the ones with public, verifiable syllabi are GIAC's GCFA (GIAC Certified Forensic Analyst), GCFE (GIAC Certified Forensic Examiner) and GNFA (GIAC Network Forensic Analyst), and IACIS's CFCE. None of these is a guarantee of judgment. All of them are evidence that somebody sat an examination on evidence handling rather than learning it from a vendor webinar.
2. Has that examiner testified, and how recently?
Testimony experience changes how a report is written even when the matter never reaches a courtroom, because an examiner who has been cross-examined writes conclusions that anticipate the cross-examination. In US federal proceedings, expert testimony is governed by Federal Rule of Evidence 702, whose 2023 amendment presses courts harder on whether an expert's opinion actually follows from a reliable application of the method, and makes clear the proponent must meet each requirement by a preponderance. Ask how many times, in what forums, and whether any opinion has been excluded.
3. Who else touches the evidence, and where are they?
Some firms triage in one country and examine in another. That is not disqualifying, but it changes your data-transfer analysis, and if you hold EU or UK personal data it may change it materially. Ask where images are processed, not just where the firm is headquartered.
Questions 4 to 6: evidence discipline and the report
4. How do you document chain of custody, and can I see a redacted example?
The right answer names a standard and offers a form. ISO/IEC 27037 is the ISO/IEC standard for the identification, collection, acquisition and preservation of digital evidence, and the Scientific Working Group on Digital Evidence publishes free, citable consensus documents through its committees. A firm that has these will show you a redacted custody form in about ninety seconds. A firm that says "industry standard" and moves on has told you the answer.
5. How is my evidence stored, encrypted, and access-controlled, and is acquisition hash-verified?
Forensic images are complete copies of your most sensitive systems, sitting on somebody else's infrastructure. Ask about encryption at rest, who can access the evidence store, whether acquisitions are hash-verified at collection and again at examination, and whether the firm can produce a certification of the copy. That last one matters: Federal Rule of Evidence 902 lets certain electronic records be self-authenticated through a certification by a qualified person, which saves live authentication testimony later.
6. Who is the report written for, and can I see a redacted sample?
This is the question that most reliably separates firms. A report written for your IT team is a remediation document. A report written for counsel, a regulator, or an insurer states scope, method, evidence relied on, findings with confidence levels, and, critically, what could not be determined and why. Ask for a redacted sample before you sign. Any firm that has written good reports is proud of them.
Questions 7 and 8: the clock and the money
7. When do preliminary findings arrive, in what form, and how are estimates re-baselined?
Get a committed point for a first read (verbal briefing plus a short written summary is normal) and a mechanism for what happens when scope grows. The pattern we would push for: an initial estimate with named assumptions, a written re-baseline when any assumption breaks, and no work beyond the estimate without written approval. On what any of this costs, we deliberately do not publish a separate forensics rate card; the reconciled responder rates the site does publish, with their sources, are in How Much Does Incident Response Cost in 2026?. One number per named thing beats a second page quoting a different one.
8. What is your capacity right now, and how are competing matters triaged?
During a mass-exploitation event, retained clients get staffed first and cold callers get whoever is left. Ask directly how many examiners the firm has, how many active matters they carry, and where you would sit in the queue. A firm that will not answer is answering.
Questions 9 and 10: what happens after the report
9. Who owns the evidence images after the matter closes, how long are they retained, and what does destruction cost?
Matters revive. A litigation hold can land eighteen months after everyone stopped thinking about the incident, and if the images were destroyed at day 90 under a default retention policy nobody read, reopening is not possible. Get retention, ownership, return, and certified destruction into the statement of work with prices attached, because a firm quoting a retrieval fee after the fact has all the leverage.
10. If this goes to litigation, is testimony in scope, at what rate, and are you conflicted?
Confirm that declaration and deposition work is available, that the rate is stated up front, and that the firm has no relationship with the vendors, MSPs, or software suppliers who might turn out to be the vector. Which leads to the conflict question people forget to ask: if your existing IT vendor or penetration testing provider is a plausible entry point, they cannot investigate it. That includes us. We have declined forensic work for exactly that reason, and the disclosure should come from the firm before you have to ask.
Answers that should end the conversation
- "We can just add forensics to the existing SOW." A pre-existing services agreement is precisely what undermined the privilege claim in the Capital One breach litigation. A firm suggesting it either does not know that or is not telling you.
- "We image everything, to be safe." Imaging volume is the largest cost driver in most investigations. Scope discipline means imaging what the investigative questions require and documenting why the rest was excluded.
- "Our report will confirm you were not at fault." Nobody knows the finding before the examination. A firm selling the conclusion is selling the wrong product.
- "Certification details are proprietary." Certifications are published registries. This answer means there are none.
- A refusal to name the examiner in the statement of work. You are buying a person's judgment; the contract should say whose.
When a boutique is the wrong choice
We are a small senior-led firm, so treat the following as the section where we argue against ourselves.
You need genuine follow-the-sun coverage. An active intrusion across offices in three time zones needs shifts, not a very good examiner who has to sleep. Large DFIR practices have staffing depth that a boutique does not, and that depth is a real product.
Your carrier's panel is rigid. If the policy requires panel firms, the panel firm is the right answer regardless of who you would prefer. Paying out of pocket to use us instead is rarely worth it.
The matter needs a name the audience already trusts. In some litigation and regulatory postures, the brand on the report cover is doing work that the report's contents cannot do on their own. That is not a technical judgment, and your counsel is better placed to make it than we are.
The scale is genuinely enterprise. Tens of thousands of endpoints, a global e-discovery component, and a dedicated internal SOC point to a firm built for that scale. Where we would still add value is as an independent second read for the board, which is a much smaller engagement.
Where Top Floor fits
Our digital forensics work is senior-led by design: the examiner who acquires the evidence writes the report and would be the one to defend it, and the name goes in the statement of work. We scope to the investigative questions rather than to the endpoint count, and we say in writing what could not be determined, which is the part of a report that gets omitted most often and questioned hardest later.
Where an incident is live, that runs alongside incident response so that containment and preservation decisions are made by people who can price both sides of the trade rather than in sequence by two vendors who have never spoken.
How to decide this week
1. Call your broker: panel list, notice deadline, pre-approval process, in writing.
2. Pick outside breach counsel before you need them, and agree the engagement structure while nothing is on fire.
3. Shortlist two firms and send them these ten questions by email. Written answers are comparable; sales calls are not.
4. Ask both for a redacted sample report and a redacted chain-of-custody form. The gap between the two samples will usually decide the matter for you.
5. Put the named examiner, the evidence retention terms, and the testimony rate into the statement of work before signature, not after.
If you only have time for three of the ten, make them these: who is the named examiner, who is the report written for, and who owns the images afterward. Those three predict the rest.
Frequently asked questions
What certifications should a digital forensics examiner have?
The examiner credentials with published, checkable programs are GIAC's GCFA (GIAC Certified Forensic Analyst), GCFE (GIAC Certified Forensic Examiner) and GNFA (GIAC Network Forensic Analyst), and IACIS's CFCE (Certified Forensic Computer Examiner). Each publishes what the examination covers, so you can check a claim against the certifying body rather than take it on trust. Certifications attach to individuals rather than to firms, which is why the useful question is which certified examiner will work your matter, not how many the company employs overall. Treat them as evidence of trained method, not as a substitute for asking about testimony experience and sample reports.
How do I know a forensics firm's report will hold up in court?
Look at three things before you sign. First, whether the named examiner has testified and whether any opinion of theirs has been excluded, since US federal expert testimony is tested against Federal Rule of Evidence 702. Second, whether chain of custody is documented against a named standard such as ISO/IEC 27037 or SWGDE guidance, with a form the firm will show you. Third, whether a redacted sample report states scope, method, evidence relied on, confidence levels, and the questions that could not be answered. A report that only lists conclusions is the one that struggles under cross-examination.
Should my IT provider or MSP do the forensic investigation?
Generally no, for two reasons. Operationally, MSPs are built to run and fix environments rather than to acquire evidence defensibly, and they usually lack forensic tooling and evidence-handling procedure. Structurally, the MSP's own remote access is itself a plausible entry point in many incidents, which makes them the wrong party to scope the intrusion: they would be grading their own homework with a contract renewal riding on the answer. Keep the MSP in the room as hands under direction, and bring in an investigator with no stake in your IT supply chain.
Who owns the forensic images after the investigation ends?
Whatever your statement of work says, which is why it needs to say something. The terms to fix in advance are who holds title to the images, how long the firm retains them, whether copies are returned to you or to counsel, what certified destruction costs, and what retrieval costs if the matter reopens. Litigation holds and regulatory inquiries commonly arrive long after an incident is closed, and a default retention period that quietly expired is the difference between reopening a matter and explaining why you cannot.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.