Computer Forensics Expert Witness


CALL US


Independent computer and digital forensic expert witness with over 20 years of experience, working in complex computer, network and digital evidence cases including:


  • Illegal image cases (including cases involving minors (IIoC), prohibited images and extreme images), rape cases and terrorism matters.
  • Various device types - USBs, memory cards, hard disks, computers, servers, NAS devices et al.
  • All major operating systems - Apple Macs, Windows, Linux and Unix-based.
  • Interconnections between devices - Disk/USB use with computers.
  • Document Forensics - use/chronology/creation and Metadata analysis.
  • Intelligence Reviews/Gathering (OSINT).
  • Network forensics - cases involving evidence relating to the use of routers, Wi-Fi, IP addresses, MAC addresses, logs and intelligence.   Spoofing.
  • Withholding of passwords.
  • Use of Cloud storage accounts.
  • Hacking, virus and Trojan allegations/defences.
  • Cases involving IT professions and/or detailed technical defences/allegations.
  • Bespoke digital evidence cases and solutions to difficult technical forensic issues.
  • Acting as a single expert by combining computer evidence with telephone handsets/tablets and other digital evidence including cell site analysis and location forensics.


All instructions, including those relating to appeals, are undertaken only via a solicitor, direct-access barrister, law centre or corporate legal department.  SRC does not accept direct instructions from members of the public (including LIPs, McKenzie Friends, and those representing themselves).   If you require SRC's expertise, please ask your solicitor or barrister to contact SRC on your behalf.


LAA rates are available.   Contact SRC with your instruction.


Commonly questions and answers about computer-based bases are addressed in the following (click drop-down arrow for information):  Alternatively find out further details about the data required and information to provide when instructing SRC in a computer case.

  • Windows, Unix, Linux and Macs including server-based systems

    SRC is able to assess most computer forensic cases including anything from a USB stick to a server.    Sam can review cases involving various types of operating systems, including Windows, macOS/Apple computers, Linux and Unix-based systems.


    SRC has access to the latest forensic software and has current licences for the use of Axiom, X-Ways Forensics, Forensic Explorer (including Live View), and Intella as well as other forensic/high level packages.  Sam can also manually review databases and write computer programs where required to process data or undertake analysis that may not be possible using commercial software, or where other analysts/experts have been unable to provide opinions.    She can also validate the data present in your case to ensure the evidence presented is accurate and complete, with the limitations fully explored.


    As a digital forensic expert, Sam is concerned with answering questions such as: What happened? How did it occur? Who did it? Where did it happen? She also provides overall opinions relating to the comparison of computer use with allegations and defences.    Sam does not provide data recovery or analyst level services. 

  • Network Forensics - WiFi, IP Address and Routers

    SRC is able to undertake instructions in complex cases involving potential use of WiFi points, routers, and the assignment of IP addresses (and logged MAC addresses).   This may also include evidence that has been gathered via intelligence or otherwise.


    Although it may sound reasonable to expect a device to know and log its IP address, in practice, such information is rarely logged, since a device does not need to know this information in order to function.    This means that, although a location-based assessment may examine for this evidence, the information is generally not stored.  In most cases, therefore, other types of evidence need to be considered. 


    Network forensics evidence can be technically complex and involve numerous technical terms and acronyms. Sam explains the underlying issues in clear, accessible language while maintaining technical accuracy.


    Sam can review network-based evidence independently or combine it with computer device evidence, mobile device evidence, location evidence and cell site analysis.

  • Intelligence Reviews/Gathering (OSINT)

    Sam is also able to take instructions in cases involving identifying and evaluating information available from publicly accessible sources.  This is sometimes technically referred to as Open Source Intelligence (OSINT).


    Using such information, Sam can review previous website content, domain name use and registrations,  and IP address use to determine what data may have been stored.


    Sam can also review for data stored on the Internet via websites, social media and other platforms.  Such reviews may be useful as part of an assessment of attribution evidence (e.g. where it is necessary to determine potential ownership of telephone numbers, usernames and/or email addresses).   For example, if a person states they do not own a specific mobile telephone number, as well as digital forensics involving devices and CDRs, searches can also be performed to establish if there is any public information stored about the number's use.    This can occur, for example, where a user registers a number with Companies House or uses the number in an advert on social media or other websites.


    Note that intelligence services, like all services offered by SRC, are only provided via a legal team as part of an instruction in a legal case.   Sam does not provide any private detective/investigation services to the public or otherwise.

  • Are you able to comply with MOUs?

    Yes.   SRC has been working in cases with MOUs for over 15 years.   Sam is able to examine computers and devices in accordance with the required level of security specified by UK police force Digital Forensic Units (DFUs).


    Sam can also provide in-person collections of data from police forces throughout the UK.

  • FSR - Code of Practice

    Since 2nd October 2023, computer device forensics is subject to the requirements of the Code of Practice from the Forensic Regulator(388 page PDF Document opened from an external site).   


    ISO/IEC 17025 accreditation applies to the forensic organisation/unit and its defined scope of activities; it is not a personal accreditation held by an individual expert witness.


    SRC follows strict procedures in terms of securely reviewing mobile and tablet device cases including working to MOUs.   Sam also fully reviews raw data and otherwise to ensure all reports are prepared accurately and are not "push-button" forensics.   However, SRC is currently not ISO17025 accredited and is non-compliant.


    A full discussion of this will be provided prior to estimating, and where the instruction is accepted, the required non-compliance declarations made.   SRC can work within the ACPO Guidelines as is appropriate.

  • Hacking and Virus Allegations and Defences

    Sam receives instructions in cases where there are allegations of hacking.   She can review the technical evidence of such cases.


    SRC also undertakes instructions in cases whereby hacking/viruses and/or third party use are part of the defence case.   She will fully review how material has come to reside on a device and provide opinion-based evidence as to whether this may have been caused by a virus, hacker, third party or user-initiated activity, and how.


    It is important to note that these cases tend to involve a much more detailed assessment than a simple virus scan.  A conventional virus scan provides only a snapshot of what may be present on a device at the time of examination, it may not establish what was present or occurring during previous relevant use.   Therefore, it is important that such use is considered fully to ensure that the correct assessment is made and that the defence case is fully explored.

  • Instructions involving Illegal Materials

    SRC is experienced in dealing with a range of materials that are illegal to possess and that require secure procedures and a Memorandum of Understanding (MOU) to be signed with the police.  When funding is granted and the appropriate permissions are in place, Sam can liaise directly with the police to obtain disclosure of this material following the required procedures.


    SRC can undertake cases where there are charges relating to terrorism, including articles.   Sam can also deal with the issues and sensitivities involved in rape cases including those that involve minors.


    SRC also takes instructions involving alleged indecent images of children, extreme images and prohibited images.   Sam is experienced in reviewing such cases, including assessing the imagery, and is familiar with caselaw and the legal requirements in this area.

  • Bespoke Testing/Evaluations

    SRC can test and consider how applications work in very specific circumstances, including bespoke systems, and compare this with the evidence present within cases, as well as evaluating an organisation's policies and procedures. In the past, this has involved Sam testing and reviewing bespoke hospital, tax, military and police systems as well as systems and security procedures used by large organisations. 


    Sam also takes instructions for a range of digital evidence cases involving ‘bespoke’ investigations requiring novel solutions which may not be achievable using commercial forensic software.   



Obtaining Access to Data and Instructing SRC in a Computer case


Digital-forensics opinions depend on the specific evidence available in each case.  SRC therefore does not provide generic or theoretical opinions without first assessing the underlying data.  In criminal computer cases involving computer devices, this usually requires a set process whereby Sam will liaise directly with the police Digital Forensic Units (DFUs) to obtain forensically verifiable copies of the computers, hard disk drives and USB sticks.   Since Sam is also an expert in telephone handset, she can work on cases involving both computer and telephone device evidence. 


In more technical network-forensic based cases (involving intelligence, IP address based evidence, the use of routers, server logs etc.), the data required will usually need to be evaluated so that Sam can establish what is required and assist you with your disclosure request.


In order for SRC to assess what is required in your criminal case, it is useful if you can initially provide the following information/papers:


  1. Trial date and any Court or other deadlines.
  2. Statements and reports in relation to the technical evidence and seized digital devices.    Where available, any Stage 1 or 2 forensic reports.
  3. MG5 or case bundle.
  4. Details of defence or a defence statement.
  5. Any specific instructions you have and/or Counsel's advice.
  6. Any data files that you have currently been supplied with in the case.


Sam may also be able to undertake civil/family matters particularly if they involve the investigation of a death/serious injury, involve children or are insurance related matters.  Please provide details of the case when contacting SRC so that Sam can advise you accordingly.


Sam has acted as an experienced expert in a range of computer, security and software evaluation cases - see casework list for a examples of previous computer, security and software-evaluation case.