When a security incident breaks, the company discovers it must answer to three audiences at once, and each demands something different. The ANPD (Brazil's National Data Protection Authority) wants to know what happened, which data was affected, and what was done, on a short deadline. The insurer wants technical evidence before paying out the cyber policy. And the data subjects, customers and former employees, want to know whether they can sue. All three answers depend on the same input: a technically demonstrated fact. This is where forensic examination comes in, and it almost always comes in late.
The LGPD draws the map. Article 48 of the law requires the controller to notify the ANPD and the data subject of any security incident that may create relevant risk or damage. The authority's regulations set a deadline of 3 business days for that notification, with a description of the nature of the affected data, the data subjects involved, the measures adopted, and the risks. Three business days is very little time for anyone who preserved nothing in the first hours.
An incident is not a synonym for a breach
The examination's first contribution is to delimit the fact. An anomalous access alert is not an intrusion; an intrusion is not exfiltration; exfiltration is not public exposure. Each step changes the legal obligation and the size of the damage. The forensic examination reconstructs the incident timeline over the preserved records: where the access came in, which systems it touched, what it copied, where it sent it. Without that reconstruction, the company notifies in the dark: it under-reports, and answers for the omission; or it over-reports, and pays the reputational cost of a breach that may never have happened.
When to engage the forensic expert
The honest answer is: before touching anything. Signals that justify immediate engagement include an exfiltration alert or anomalous traffic, ransomware executing or already executed, business email compromise (the BEC scam, which diverts payments through hijacked mailboxes), extortion with a data sample, and the discovery of company data for sale or published. In all these scenarios, the same rule: the IT team resolves the incident; it does not preserve evidence. They are different functions, with opposite gestures.
"Restoring the backup erases the intruder's trail. The company that only thinks about getting back to business usually destroys, on day one, the evidence it will need for years."
The classic mistake always has the same anatomy: wipe the compromised machine, restore the environment, change the passwords, and move on. Operationally correct, evidentially disastrous. Gone is the trace of the access's origin, gone is the real extent of the copy, gone is the chance to demonstrate that sensitive data was not affected. Months later, under ANPD scrutiny or in a damages action brought by data subjects, the company cannot prove even the facts that favor it.
What the examination delivers on each front
With the traces preserved, through a forensic image, an authenticated copy of the logs, and a documented chain of custody, the expert report feeds each front with what it demands. For the ANPD: the technical description of the incident, the delimitation of the affected data and data subjects, and the demonstration of the pre-existing security measures, which article 46 of the LGPD requires and the authority weighs when calibrating sanctions. For the insurer: the nexus between the event and the policy, with methodical evidence that the insurer's audit will accept. For litigation: proof of extent, which separates the compensation actually owed from speculation, and which sustains a possible recourse action against the vendor whose failure opened the door.
There is also the internal front. A relevant share of incidents involves inside participation, deliberate or negligent. The same examination that reconstructs the attack identifies the originating account, the access pattern, and any handover of credentials, with the corresponding labor and criminal consequences.
What the authority weighs during enforcement
The ANPD's sanction-calibration regulation grades penalties according to severity, good faith, and the offender's conduct, and two factors weigh in favor of the diligent company: proof that security measures were in place before the incident and the prompt adoption of measures after it. Both are proven with a technical document. The report that demonstrates the existing controls, reconstructs the incident, and records the response on a timeline turns the company's narrative into verifiable evidence. Without it, the same narrative is merely an interested party's allegation, and an interested party's allegation, in an enforcement proceeding, is worth little.
Ransomware: the evidence beyond the ransom
With ransomware, the temptation to resolve things fast is at its peak, and so is the evidentiary damage. To pay or not to pay the ransom is a business and legal-risk decision; proving what happened is a necessity on either path. Encrypting the files is rarely the only event: current groups exfiltrate data before encrypting, to extort twice. The forensic examination determines whether exfiltration occurred, from which databases and in what volume, which completely changes the obligation under the LGPD: an incident without a personal data leak may dispense with notification; an incident with exfiltration requires it, with the 3-business-day clock running. Restoring the environment without preserving the traces means making that legal decision in the dark, and explaining it later with no evidence at all.
The 72-hour plan
The difference between the company that comes through an incident well and the one that sinks in it is decided by simple conduct, defined before the crisis:
- Isolate the affected systems without powering off or wiping: isolation preserves, wiping destroys;
- Suspend automatic purges of logs and backups for the period;
- Engage legal counsel and a forensic expert on day one, not after the notification to the ANPD;
- Preserve with hash values before restoring operations;
- Document who knew what, when, and through which channel.
The LGPD turned the data incident into a legal event with a running clock. The technical response is not an appendix to the legal response; it is its foundation. A notification without a demonstrated fact is guesswork on letterhead, and guesswork, before a regulator, an insurer, and a judge, is expensive. What sustains all three conversations is the same expert report, and it only exists if someone preserved the trace while there was still a trace to preserve.
