Forensic clarity, supporting justice.
CyberSight Forensics helps organisations outsource cybercrime investigation workload — reducing case backlog, preserving chain of custody, and strengthening defensive posture with affordable, scalable, legislation-compliant services.
Six capabilities, one documented standard.
Every engagement runs through the same evidence-led process — documented lab procedure, hashed imaging, and reporting designed to support use in legal proceedings.
Digital Forensics
Acquisition, imaging, analysis and reporting across mobile, cloud and endpoints, with secure evidence handling throughout.
Incident Triage & Response
Rapid containment, root-cause identification and remediation guidance — an around-the-clock service for clients on a retainer.
Forensic Penetration Testing
Evidence-preserving live tests, threat emulation and vulnerability assessments tailored to your environment.
Managed Forensics Support
Backlog processing, case intake and prioritised evidence analysis to accelerate stalled investigations.
Advisory & Training
Policy alignment, chain-of-custody procedure and upskilling for your staff — building capability that lasts.
Documentation Processing
Secure preparation, production, storage and access of case documentation — with full record keeping and controlled distribution to stakeholders.
From intake to documented report.
Case intake
If you are a retainer client with a live incident, contact our incident line and we begin triage; otherwise, send an enquiry through the form and we will respond.
Acquisition & custody
Tamper-evident collection and hashed imaging, with chain of custody documented from first contact.
Forensic analysis
Prioritised examination by specialist analysts in controlled lab conditions, remote or on-site.
Report & guidance
Reporting designed to support use in legal proceedings, with remediation guidance for your teams.
Three ways to work with us.
Transparent structure, real budgets in mind. Pricing on engagement — no surprises.
Emergency Triage
RESPONSE WITHIN 4 HOURSImmediate containment and forensic preservation for live incidents. Fixed call-out structure, 24/7 — available to registered clients on retainer.
Become a clientImaging & Analysis
PER-DEVICE FIXED TIERSSmall device, workstation and server tiers with defined turnaround times and output designed to support use in legal proceedings. Start with a pilot intake to see the process end-to-end.
Book pilot intakeBacklog Retainer
MONTHLY CAPACITY BLOCKSGuaranteed throughput and priority SLAs for sustained caseload reduction. Scales with demand.
Discuss a retainerLawful by design.
Our standards
We are building CyberSight Forensics to operate to recognised forensic and information-security standards. We are working towards ISO/IEC 17025 accreditation for our forensic activities and align our work with the Forensic Science Regulator's Code of Practice. We also operate towards ISO 27001 information-security controls and are working towards Cyber Essentials Plus. We produce reports and maintain a documented chain of custody designed to support use in legal proceedings.
Lawful handling
Data minimisation, lawful access procedure and ICO-registered processing. Full cooperation with prosecuting authorities.
Chain of custody
Tamper-evident storage, hashed imaging and documented custody on every exhibit — from intake to disposal.
Independent provider
CyberSight Forensics is a private, independent provider. We are not part of, accredited by, or acting on behalf of any government department, police force, the National Crime Agency, the NCSC or any regulator. Where we refer to standards, codes or training, we describe how we align our work — not an endorsement of us by any body.
Built for organisations under pressure.
Cybercrime caseloads are growing faster than in-house forensic capacity. CyberSight Forensics exists to close that gap — a specialist partner that takes on investigation workload without compromising evidential standards, so your teams can focus on outcomes.
Public-sector-grade rigour — procedures and reporting built to government standards, applied for clients of every kind.
Chain-of-evidence rigour — a documented chain of custody for every exhibit we handle.
Scalable analyst workforce — surge capacity for backlogs without permanent headcount.
Transparent pricing — fixed tiers and capacity blocks designed for predictable budgeting.
Common questions.
How quickly can you respond to a live incident?
How does the 24–48 hour pilot intake work?
How rigorous is your evidence handling?
Do you work remotely or on-site?
How is pricing structured?
Book a 24–48 hour pilot intake.
Prove the process on a live case before you commit. For urgent incidents, retainer clients can reach our incident line at any hour.