Fraud and cybercrime investigation
After a fraud, the pressure is to name someone quickly. Our job is to establish what the evidence actually shows, in what order events happened, and which control failed, before anyone draws a conclusion.

What the engagement covers
- 01Account takeover and payment fraud analysis
- 02Business email compromise investigation
- 03Insider activity review
- 04Transaction and log reconstruction
- 05Evidence packaging for counsel or law enforcement
A factual account of the incident, the control failures behind it, and the evidence supporting each conclusion.
From containment to an evidence package.
Speed matters, but nothing is asserted that the record cannot support.
- Step 01
Containment
Stop the loss where it is still running, and preserve the systems and records that hold the answer.
- Step 02
Reconstruction
Rebuild the sequence from logs, transactions, devices and accounts, timestamp by timestamp.
- Step 03
Attribution
Establish what the evidence supports about who acted, and state where it stops short.
- Step 04
Control failure analysis
Identify the gaps that made the incident possible, and what closes them.
- Step 05
Evidence package
Deliver findings and supporting material in a form counsel, regulators or law enforcement can use.
Scope first, quotation second.
Tell us what the estate looks like and what concerns you about it. We will say plainly whether this engagement is the right one.
Contact Cyber Keen