Home // FORENSIC UNITS // LITIGATION AND BUSINESS

Information Security and Compliance

Forensic examinations and audits in corporate environments: technical inquiry into internal fraud, IT contracts and projects, software licensing and digital assets, with documented evidence and a method that withstands adversarial scrutiny.

The nature of the work

Corporate forensic examination, not off-the-shelf consultancy

Under the label of compliance, the market offers standardised adequacy programmes that promise conformity within a few weeks. This forensic unit does something else. The work here is forensic: examining systems, contracts, records and devices in order to establish facts capable of supporting a decision, be it dismissing an employee for cause, terminating an IT contract, responding to a software audit notice or closing an acquisition.

That is why this forensic unit does not promise conformity. Conformity is a state that depends on the continuous conduct of the company; what forensic examination delivers is different and, in a dispute, worth more: the technical and documented demonstration of what happened, of who did what, and of what the records actually prove.

The method comes from computer forensics: preservation of the evidence before any analysis, cryptographic hashing, chain of custody under arts. 158-A to 158-F of the CPP (Brazilian Code of Criminal Procedure) and ABNT NBR ISO/IEC 27037, and conclusions confined to what the evidence supports. The difference lies in the setting: here the object is the company, its systems, its contracts and its people.

Those who turn to this forensic unit are usually the legal department, the board, the audit committee or the law firm advising the company: someone who needs an impartial technical answer before taking an expensive decision.

From protection to audit: information security with forensic method
e-Discovery and fact-finding

Finding, among millions of files, the ones that decide the case

Corporate litigation, regulatory investigations and international cooperation proceedings frequently require locating and producing electronic evidence scattered across mail servers, corporate systems, laptops and mobile phones belonging to dozens of custodians. Doing that without method means producing too much, exposing what did not need to be exposed, or producing too little and answering for concealment.

The work follows the ISO/IEC 27050 series framework, the international reference for electronic discovery, which organises the process into linked and documented phases. The result is a defensible body of evidence: every document produced has its origin, hash and processing trail on record.

IT contracts and projects

What was contracted, what was delivered, and the distance between the two

Technology projects fail often, and the contract alone rarely says where responsibility lies. Forensic examination reconstructs the project from the evidence: proposals, schedules, minutes, emails, support tickets, code and system logs.

ERP

Failed ERP implementations

A go-live postponed or disastrous, corrupted data migration, endless customisations. The examination separates what was the implementer's obligation, what depended on the client and what the product was never able to do, and sizes the breach in technical terms.

Contracts

Forensic examination of IT contracts

Item-by-item comparison between contracted scope and actual delivery: requirements, acceptance records, SLAs, schedules and technical evidence of operation. A basis for termination, claims, defence or well-founded renegotiation.

Systems

Audit of websites and systems

Technical examination of systems in production: how features actually work, availability, content published on a given date and adherence of what was developed to what was specified, with a record fit to support court proceedings.

M&A

Technology due diligence

Forensic assessment of technology assets in mergers, acquisitions and investments: ownership and quality of the code, licensing liabilities, critical dependencies and hidden risks that change the price of the deal.

Corporate investigations

From the report of wrongdoing to the document that supports the decision

The allegation arrives through the internal channel, from a manager or from a client: suspected fraud, misappropriation of funds, information leakage, conflict of interest, harassment documented by digital means. From then on, every wrong step is costly: accessing the computer of the person under investigation without formal preservation, confronting before collecting, inadvertently destroying what would have proved the wrongdoing.

A forensic inquiry begins with the silent preservation of the evidence: forensic images of corporate equipment, preservation of mailboxes and system logs, all with hashing and chain of custody.

The examination is impartial by definition: the commitment is to what the evidence shows, including when it clears the person under investigation. The final report documents method, findings and limits, and serves as the basis for the internal disciplinary procedure, for dismissal for cause, for a recovery claim or for a criminal complaint, according to the decision of the company and its lawyers.

The processing of personal data during the inquiry observes the limits of the investigative purpose, with access restricted to what is necessary and segregation of out-of-scope material.

Infrastructure and operations

Forensic diagnosis of the environment that sustains the business

Infrastructure

Forensic diagnosis of infrastructure

Documented technical survey of the estate: inventory of installed software and the corresponding licences, critical dependencies, single points of failure and business continuity risks. A faithful picture of the environment, backed by evidence, before it becomes the object of a dispute.

Licensing

Software licensing and infringement

Technical defence against audit and infringement notices sent by major software vendors: independent review of the vendor report, identification of counting inaccuracies and a technical basis for negotiation. Also in the opposite direction: investigation of irregular use of the company's own software.

Employment

Electronic time and attendance systems

Forensic examination of attendance records in high-volume employment claims: integrity of the clockings, processing and adjustments applied, consistency between the timesheet, the database and the working hours alleged. Mass analysis, with a method reproducible case by case.

How it works

The course of an inquiry

01 · ConsultationConfidential presentation of the problem and assessment of technical feasibility, at no cost
02 · ScopeWritten definition of the questions to be answered, the data sources and the limits of the inquiry
03 · PreservationForensic imaging and freezing of the relevant sources, with hashing and chain of custody
04 · ExaminationTechnical analysis on copies, with a record of every procedure applied
05 · ReportExpert report or technical report with method, findings and limits, fit to support a decision or court proceedings
06 · Court supportClarifications, supplementary questions to the expert and party-appointed expert support should the case turn into litigation
Completed cases
ANONYMISED CASE

Internal investigation of misconduct at a large manufacturer

Impartial technical inquiry with chain of custody control. The report provided the grounds for the internal disciplinary procedure.

ANONYMISED CASE

Defence against a software infringement notice from a major international vendor

An audit of the vendor report identified technical inaccuracies. Technical negotiation reduced the amount originally claimed by 60%.

Frequently asked questions in this area
Does this forensic unit implement compliance programmes or LGPD adequacy projects?
No. The work here is forensic: establishing facts, examining systems and contracts and documenting evidence to support decisions and proceedings. Continuous conformity programmes are a matter of legal and management consultancy, conducted by the legal department or by dedicated advisers. The two worlds meet when the programme fails or is put to the test: that is the moment when forensic examination comes in. (LGPD is the Brazilian General Data Protection Law.)
What is e-Discovery and when does it become necessary?
It is the structured process of identifying, preserving, collecting, processing, reviewing and producing electronic evidence for litigation, a regulatory investigation or an arbitral proceeding, following the ISO/IEC 27050 series framework. It becomes necessary when the evidence is scattered across large volumes of emails, systems and devices belonging to multiple custodians, and the way it is produced may be challenged by the opposing party or by the regulator.
The ERP implementation failed. What can forensic examination demonstrate?
The examination reconstructs the project from the records: proposal, schedules, meeting minutes, emails, support tickets, acceptance records and the system itself. On that basis it separates the implementer's obligations, the dependencies that fell to the client and the limitations of the product, and shows in technical terms where the project broke down. That picture supports renegotiation, termination, court action or arbitration, according to the lawyers' strategy.
The company has received a software infringement notice. What is the first step?
Not signing any terms or replying to the notice before an independent technical review. Vendor audit reports frequently contain counting inaccuracies: decommissioned machines, licences not taken into account, metrics applied incorrectly. In an anonymised case from this forensic unit, the independent review reduced the amount originally claimed by 60%. The reply is built on the real inventory, not on the spreadsheet of the party making the claim.
How is an internal allegation investigated without contaminating the evidence?
By preserving before confronting. The evidence is frozen quietly: forensic images of the equipment, preservation of emails and system logs, with hashing and chain of custody. Only then do the analyses begin and, where appropriate, the interviews. The most common error in informal inquiries is the opposite: confronting first, giving both time and motive for the destruction of the evidence.
Does the inquiry report work as evidence in court?
The report is produced for that purpose: documented method, chain of custody, hashes of the evidence and conclusions confined to what the examination supports. Like all evidence, it is subject to adversarial scrutiny; the difference is that technically rigorous work withstands challenge, whereas an informal inquiry tends to fall at the first objection. Should litigation arise, the work continues as party-appointed expert support.
Is it feasible to examine thousands of electronic attendance records?
Yes, and it is precisely at that volume that method makes the difference. The examination combines automated processing of the complete clocking database with technical verification of integrity: adjustments, processing, gaps and patterns incompatible with spontaneous clocking. The result is reproducible claim by claim, which matters in high-volume employment litigation portfolios.
What does technology due diligence examine before an acquisition?
What the target company says it has and what it actually has: ownership of the source code, use of third-party components and their licences, commercial licensing liabilities, dependence on critical people and suppliers, and continuity risks. Hidden technology liabilities change the price of the deal, and it is cheaper to find them before signing.

See also

Computer Forensics →   For Companies →   Expert Reports and Technical Opinions →

Before the expensive decision, the technical answer

Dismissal for cause, contract termination, response to a notice, closing an acquisition: decisions like these call for evidence, not impressions. The initial consultation assesses the technical feasibility of the inquiry, on a confidential basis.

Confidential consultation
Representative cases

The level of work you are engaging

Before deciding, it is worth seeing what has already come through this laboratory: cases described without identifying the parties, in the format of challenge, method and result.

See all representative cases →

The technical evidence your case requires. The authority courts respect.

Initial feasibility consultation at no cost. Reply within 24h on business days.
Request an Examination