Mobile Forensics in the Corporate World: BYOD and Security Risks

1. Introduction

In today’s corporate landscape, mobile devices play a pivotal role in day-to-day operations. Mobile forensics involves the investigation and analysis of data from mobile devices to uncover evidence, making it an essential component of corporate security.

2. BYOD (Bring Your Own Device) Trend

The rise of BYOD in the corporate sector has revolutionized the way employees work. While it offers flexibility and increased productivity, it brings along its own set of challenges, including compatibility issues and security concerns.

3. Security Risks in Corporate Mobile Devices

Security breaches in corporate mobile devices are on the rise. From data leaks to unauthorized access, these risks pose a significant threat to organizational integrity. Real-life examples underscore the importance of proactive security measures.

4. The Need for Mobile Forensics

Understanding the need for mobile forensics is crucial in mitigating security risks. Forensic investigations help in uncovering the root causes of security incidents and provide insights for preventing future breaches.

5. Mobile Forensics Tools and Techniques

This section provides an overview of popular mobile forensic tools and the techniques employed in mobile forensic investigations. Highlighting the advancements in technology, it sheds light on how investigators extract valuable information.

6. Legal Implications

Corporate investigations must adhere to legal requirements. Balancing the need for evidence with employee privacy is a delicate task, and this section explores the legal considerations associated with mobile forensic investigations.

7. Case Studies

Real-world case studies showcase the successful application of mobile forensics in corporate settings. These stories provide valuable insights and lessons that organizations can learn from to enhance their security measures.

8. Best Practices for Corporate Mobile Forensics

Establishing a robust mobile security policy and providing regular training for employees are crucial. This section outlines best practices for organizations to ensure the effectiveness of their mobile forensic efforts.

9. Challenges in Mobile Forensic Investigations

The ever-evolving landscape of technology presents challenges for mobile forensic investigators. Encryption and secure communication methods are discussed, highlighting the difficulties in accessing and analyzing encrypted data.

10. Collaboration with IT Security Teams

Collaboration between mobile forensic teams and IT security teams is essential. This section emphasizes the importance of a cohesive approach to corporate mobile security, ensuring a unified front against potential threats.

11. Continuous Monitoring and Updates

Staying ahead of emerging threats requires continuous monitoring and regular updates to forensic tools and procedures. This section explores the significance of keeping security measures up-to-date in the fast-paced world of cybersecurity.

12. Future Trends in Mobile Forensics

Predicting the future trends in mobile forensics is essential for organizations looking to stay ahead of potential risks. Emerging technologies, such as artificial intelligence and machine learning, are discussed in the context of their impact on mobile forensic investigations.

13. User Education and Awareness

Employee education is a critical component of reducing security risks. This section advocates for creating a culture of cybersecurity awareness within organizations, empowering employees to play an active role in maintaining security.

14. Conclusion

In conclusion, mobile forensics is indispensable in the corporate world, particularly with the prevalence of BYOD policies. This article has delved into the challenges, tools, legal considerations, and best practices, emphasizing the proactive role of mobile forensics in securing corporate environments.

15. FAQs

Q1: How does mobile forensics contribute to corporate security? Mobile forensics helps uncover evidence of security incidents, providing insights to prevent future breaches.

Q2: What are the legal considerations in mobile forensic investigations? Balancing the need for evidence with employee privacy is crucial, and investigations must adhere to legal requirements.

**Q3: Are there challenges in accessing encrypted data during mobile forensic investigations?

Best Cybersecurity & Digital Forensics Company – Greater New York

As digital devices and the cloud became an integral part of life, the field of cybersecurity was developed to protect companies and individuals from online criminals. Axiana is abreast of all these developments. It has evolved with the times and technology to help its clients stay ahead of these developments themselves. Here we take a closer look as it wins this respected accolade.

Axiana is a company on a mission. It provides digital forensics, eDiscovery, cybersecurity, and data protection services in an “efficient and budget friendly” way. Established over 20 years ago, Axiana offered specialised services in digital forensics when the industry was in its infancy and was commonly termed “computer forensics”. Numerous small to mid-sized organisations have trusted Axiana with their most valuable data and ESI for forensic analysis, management, and security – and they have not been disappointed.

One of the more significant questions that companies face today is how to protect their most important and valuable data. Not only from people outside the business, but from the inside too.

In addition, government regulations and compliance requirements – to protect data involving personally identifiable information – are increasing by the day. Fortunately, Axiana is at the forefront of these changes and is ready to help its clients face future data security challenges. Understanding this, Axiana takes pride in teaching its clients and customers how to protect essential data, and their digital infrastructure.

It helps attorneys review large amounts of data and clients protect their most valuable digital assets and limit and monitor who has access to them. It also helps them navigate the new technologies, guides them in all aspects of digital evidence, and supports them in processing and reviewing digital documents to ensure nothing slips through the cracks. In a world where cyber-attacks grow, experts like Axiana are essential allies.

To assist its customers, Axiana leverages significant advancements in its field to remain on the cutting edge. Beyond simple digital forensics, it utilises and harnesses technology to investigate digital devices for digital evidence.

Its forensic examiners conduct investigations using the latest technology, software, and methods. The team forensically captures, processes, and analyses electronically stored information (ESI) that is both visible and invisible. If it exists on a computer, mobile device, the cloud, or an office network, Axiana will find it.

With computers, laptops, and servers, Axiana carefully analyses all relevant artefacts to determine user activity, internet activity, and USB access to not just gather what is available but to recover hidden or deleted data.

When investigating mobile devices – from cell phones to tablets – Axiana has expertise across all operating systems. The devices it investigates are imaged and examined to retrieve data such as messages/chats, images, calls, contacts, calendars, and more. Finally, in its cloud-based investigations, the team successfully retrieves and examines emails, backups, and data stored on cloud services, social media accounts, websites, and collaboration apps. The future for its company is to continue offering the best possible digital forensic services and bring technology to its clients that will enable them to protect their most important data – and restrict access to only those who are trusted with that data. Furthermore, in the near future, more companies will require cyber insurance which Axiana seeks to be at the forefront of. It already helps its clients fulfil data protection requirements and comply with relevant legislation. Also, pivoting to supply customers with insurance coverage, at a reasonable price, is a logical and exciting next step for Axiana. Cybersecurity will only become a greater focus as the digital space evolves. From soft-skill hackers to outright DDOS attacks, there are a veritable sea of options for malefactors, but Axiana consistently stops these actions in their tracks. Remaining vigilant, in the know, and responding swiftly with cutting-edge technology highlights Axiana as the Best Cybersecurity & Digital Forensics Company for Greater New York. Numerous companies have placed their faith in Axiana and more will in the future, all sharing their satisfaction with its exemplary work.

Contact: Tino Kyprianou

Company: Axiana Digital Forensics & Cybersecurity

Web Address: https://www.axiana.com

10 Strategic Steps for Defensible Search

E-Discovery in litigation today presents a number of challenges in creating a defensible, efficient, and iterative search protocol. A defensible keyword search protocol should contain, at a minimum, the following ten strategic steps:

1. Define the data you are looking for and determine where it is located.

It’s important to first define and identify the potentially relevant documents that will be needed for a request of production (RFP). However, defining the universe of required documents is not necessarily an easy task. The attorney should know which electronic devices may contain the data, such as network servers, computer workstations, laptops, cellphones, etc., as well as the custodians of the data, retention policies, and record keeping practices. To ensure compliance and efficiency in RFP and to reduce e-discovery costs, maintain an electronically stored information (ESI) “Data Map” that identifies and details the flow of data and how it can be retrieved.

2. De-duplicate & filter.

Simply put, de-duplication replaces duplicate data on a disk with references to a shared copy. When duplicate data is detected, the instance is referenced back to the saved shared copy. Thus, only one copy of similar documents is stored. The search will therefore be faster and more cost efficient.
Filter out any unnecessary file extensions. For example, exclude sound files, design files, and any unresponsive system files. Exclude custodians not relevant to the case, time periods that are outside the scope of the RFP, and identify any other parameters that will help reduce the volume of data to be searched.

3. Understand the limitations of technology.

Know what e-discovery technology tools are capable of (and what they are not). Understand how fast the tools work; how data is captured and indexed; whether embedded data can be searched; whether the tools have the ability to perform searches across metadata or the ability to search important file formats; and any other essential functions in the overall discovery process. Determine whether the processes are understandable and defensible in court.
Keep in mind that searching tools cannot search image format files such as faxes or pdfs/tiffs that contain no detectable textual content and have not been previously converted for electronic search or storage (OCR’d). These documents must be identified and handled separately. Wherever possible, render those documents searchable. Maintenance, licensing issues, available resources and capabilities are also important factors to consider.

4. Consult all relevant persons.

To ensure the most relevant keywords for the search are utilized, all data custodians and any key players in the possession of potentially relevant information should be consulted. These persons are most likely to help create a keyword list that will yield the most relevant results. Also, in the absence of a properly configured “data mapping,” these persons can help identify the various devices on which ESI resides.

5. Collaborate with the other side.

Courts not only expect to see collaboration with the other side, they welcome it. Be proactive and discuss keywords you are considering with your adversary in an effort to reach mutually acceptable keywords and search methodology. Doing so will save you time and help avoid arguments about irrelevant searches. The collaborative process might also help you identify search terms that you haven’t previously considered.

6. Address synonymy, misspellings, word variations, and ambiguity.

Looking for words with identical or similar meanings, common misspellings, and word variations are helpful tools for finding specific documents. The human language is full of ambiguity and variations. Make use of available tools, such as the website www.dumbtionary.com, which can be used to find the most common misspellings for a given word. Similarly, www.synonymy.com and www.wordhippo.com can be used to find words that are synonymous. Be aware that instant messaging and text messages often contain slang known as “txt-speak.” The key players involved can help identify some of this language commonly used in their environment.

7. Utilize statistical sampling.

The Sedona Conference expressed the position that the document review process is well suited to the application of statistical sampling to improve quality and reduce costs. In the case of search terms, it’s desirable to run them against a statistical sample of your data set and the custodians that are most representative of that sample. In utilizing statistical sampling, however, use care in the actual selection methodology used, especially if the ESI collection is incomplete. Sampling cost considerations should be evaluated against the costs of more extensive document review due to inefficient keyword selection.

8. Evaluate hits.

Review the results to determine whether the number of relevant documents returned is satisfactory and identify any files that are not searchable, encrypted, etc. Eliminate any noise hits, and refine and tweak your keywords to increase the potentially responsive documents and eliminate non-responsive ones. Test, retest, and make refinements as you go along.

9. Quality Assurance: Review unresponsive documents.

Courts demand quality assurance on keyword searches to ensure all necessary steps have been taken and potentially relevant documents have not been missed. Review a representative sample of the documents deemed unresponsive by keyword searches to confirm their status. If potentially responsive documents are found, then the search methodology utilized must be revisited.

10. Document your search strategy.

A defensible search strategy and methodology should be adequately documented and choices justifiable. As you work through different steps of the search process, keep a log of your actions in as much detail as possible. This will help you convince the court that the search used the appropriate terms, the appropriate data sets, and produced the highest number of potentially responsive documents. A log will also enable you replicate your search process for verification, if necessary.
Finally, courts don’t require perfection in e-discovery, but instead look for a reasonable, reliable, and defensible approach. Taking time to craft a defensible keyword search protocol will help protect an attorney from possible sanctions and enable him or her to offer a satisfactory methodology for finding responsive documents for production.

Kyprianou is president of Axiana LLC in Morristown (www.axiana.com), which specializes in computer forensics and e-discovery. He is a certified examiner and a member of the International Society of Forensic Computer Examiners and the Association of Certified Fraud Examiners.

Legal Strategy of Computer Forensics

As technology advances by leaps and bounds, digital devices are now an integral part of our lives. Every day we use cell phones, laptops, iPads, iPods, GPS systems — the list is endless. A large part of our activities and transactions are captured on these devices or on a network server somewhere. So what happens when an individual or organization is accused of wrongdoing or winds up in a legal dispute? For the legal process to be thorough, comprehensive and equitable, electronic evidence inevitably becomes a part of the discovery process.

So what’s an attorney to do? The technologies involved are so numerous, complex and ever evolving, the existence or location of the evidence is not so obvious, the client is not knowledgeable of the consequences of using technology, and the adversary is more resourceful and well versed in the complexities of digital devices and e-discovery.

Based on my experience as a computer forensics examiner, below are some areas where collaboration between an attorney and an examiner proved to be invaluable.

Do you trust your adversary to provide you with all the electronic evidence relevant to the case?

In the normal course of litigation, attorneys exchange documents that are relevant to the case. However, how can an attorney be sure that all relevant documents have been produced? Can you leave it to the opposing attorney to search deep and wide for the existence of relevant documents? How would you know if documents exist but are left out because the opposing attorney is not technologically savvy to guide his client to produce all available evidence including those in digital devices? In several of our cases, fragments of deleted files found on a computer after a forensic analysis proved to be pivotal to a case and the parties quickly settled in order to avoid further embarrassment. In other cases, having examined the opposing side’s computers we produced thousands of relevant emails that caused them to settle to avoid a time consuming and expensive review process.

Your adversary has a court order to produce your client’s computer. Do you know what’s in it?

It’s fairly common that a law enforcement agency or your adversary is successful in getting a court order to examine your client’s computer/s or other electronic devices. It would be prudent therefore for an attorney to anticipate the possibility of a court order and preemptively find out what’s on the digital devices so she can have all the information at her disposal to intelligently determine the best legal strategy for her client.

Is there a chance that your client forgot to tell you about files she deleted?
It’s often possible for clients to forget details of their actions that happened two or three years ago. You ask all the relevant questions and you are confident that all facts are known to you. During discovery the other side asks for a forensic examination of your client’s hard drive. You confidently agree knowing that there is nothing incriminating to your client. The opposing site having examined the computer finds that some files containing important evidence have been deleted. Your client could have been genuine in her forgetfulness but can you take the chance? It would therefore be prudent to review the hard drive before it’s turned over or having examined it decide not to produce it without a court order.

Do you have all the devices that might contain discoverable data?

Attorneys are not always up to date with new technologies nor are they fully cognizant of how companies and individuals store or back up electronically stored information; after all they are not technologists but law practitioners. The labyrinth of compliance issues covering different industries can also complicate matters even further. Data now can reside not only on PC’s, laptops, flash drives, cellphones, corporate networks/servers, back-up tapes but also on GPS’s, the cloud, social networking sites, virtual machines, ISP providers, cameras, iPads, iPods, smartphones, digital copiers, swipe cards and more. A computer forensics consultant will act as the attorney’s own technologist in identifying where digital data may reside and take the necessary steps to recover it or advise in sending the opposing attorney a request for documents from specific devices.

Discovery and document production don’t always reveal all the evidence. You might need to explore deeper.

Discovery and production of documents deal with documents that are available for production. Sometimes however more important are the actions of the computer user; what he did and didn’t do. Artifacts found in the computer’s registry, applications logs, Internet browsing, recently accessed files, software used, unallocated space just to name a few, can be extremely important to a case. A computer forensics expert can analyze all these important system files to find if and when a USB device was plugged in, files copied to external devices, the user’s log on/off times, the system’s last shutdown, whether the system’s date and time have been manipulated, the user’s Internet usage, hidden and encrypted files and much more. Furthermore what attorneys don’t know can handicap and hinder them in getting the best results for their clients. In many of our cases collaboration between an attorney and a computer consultant resulted in refocusing a case to areas not previously considered, and subsequent computer examinations uncovered information that completely changed the outcome of a case.

Protect the integrity of the evidence and maintain proper and defensible chain of custody.
The protection of the integrity of the evidence and a defensible chain of custody are of paramount importance to every case. This necessitates proper training and experience. IT employees, computer technicians and computer shops by and large are not trained to properly handle evidence or follow methodologies in the collection of evidence that can withstand legal challenge. The attorney’s responsibility is to ensure that the evidence is adequately protected, all evidence collection protocols have been followed and no spoliation or evidence tampering has occurred.

Design an effective keyword search and defensible search methodology.

In my experience, keyword selection and design is one of the least understood areas. Attorneys understand what a keyword is but unfortunately not much thought is given to the possible effects on e-discovery. In order to be thorough and all-encompassing, an attorney will use as many keywords as possible in different combinations and variations. Poorly designed keyword searches, however, can result in hundreds of thousands or even millions of worthless hits that are very costly and time consuming to sort through. One must also consider whether the search will include the free space of the computer, the handling of non-searchable documents (fax images, zip archives, etc.) and generally the search methodology to be followed. These can become a point of contention between attorneys and, absent an agreement, can result in legal challenges.

Engage an expert witness.

A computer forensics consultant, by virtue of his knowledge, training and experience, might be called to testify in court. It would therefore be advantageous for the attorney to retain the services of a competent computer forensics expert who will not only uncover the relevant electronic evidence, but who also has the ability to write comprehensive, intelligible reports on his findings and rigorously defend and explain those findings in court.

File effective court certifications.

In many cases an attorney is required to file a certification to compel a computer inspection in response to the other party’s refusal to produce electronically stored information. The knowledge and expertise of a computer forensics consultant will be helpful in drafting a meaningful and defensible certification, thus increasing the chances of success. Working closely with the attorney, the consultant will offer guidance and advice as to the best way to approach the unique technical challenges of each case, while at the same time presenting all the relevant facts with sufficient clarity to help the judge make an informed decision.

Kyprianou is president of Axiana LLC in Morristown (www.axiana.com), which specializes in computer forensics and e-discovery. He is a certified examiner and a member of the International Society of Forensic Computer Examiners and the Association of Certified Fraud Examiners.

To contact Tino Kyprianou please call:
1-800-262-3552