UK · digital forensics & incident response

Forensic clarity, supporting justice.

CyberSight Forensics helps organisations outsource cybercrime investigation workload — reducing case backlog, preserving chain of custody, and strengthening defensive posture with affordable, scalable, legislation-compliant services.

EVIDENCE RECORD
CASE2026-0411
ACQUIRED11 JUN 26 · 09:42
IMAGE HASHSHA-256 VERIFIED
ANALYSTASSIGNED · CS-07
CUSTODYINTACT — DOCUMENTED
4
working-hour emergency response target (retainer clients)
24–48 h
Typical pilot intake turnaround
Every
exhibit handled under a documented chain of custody
24/7
On-call incident line for retainer clients
01 · Core services

Six capabilities, one documented standard.

Every engagement runs through the same evidence-led process — documented lab procedure, hashed imaging, and reporting designed to support use in legal proceedings.

Digital Forensics

Acquisition, imaging, analysis and reporting across mobile, cloud and endpoints, with secure evidence handling throughout.

Incident Triage & Response

Rapid containment, root-cause identification and remediation guidance — an around-the-clock service for clients on a retainer.

Forensic Penetration Testing

Evidence-preserving live tests, threat emulation and vulnerability assessments tailored to your environment.

Managed Forensics Support

Backlog processing, case intake and prioritised evidence analysis to accelerate stalled investigations.

Advisory & Training

Policy alignment, chain-of-custody procedure and upskilling for your staff — building capability that lasts.

Documentation Processing

Secure preparation, production, storage and access of case documentation — with full record keeping and controlled distribution to stakeholders.

02 · How it works

From intake to documented report.

01 · INTAKE

Case intake

If you are a retainer client with a live incident, contact our incident line and we begin triage; otherwise, send an enquiry through the form and we will respond.

02 · ACQUIRE

Acquisition & custody

Tamper-evident collection and hashed imaging, with chain of custody documented from first contact.

03 · ANALYSE

Forensic analysis

Prioritised examination by specialist analysts in controlled lab conditions, remote or on-site.

04 · REPORT

Report & guidance

Reporting designed to support use in legal proceedings, with remediation guidance for your teams.

03 · Engagement structure

Three ways to work with us.

Transparent structure, real budgets in mind. Pricing on engagement — no surprises.

Emergency Triage

RESPONSE WITHIN 4 HOURS

Immediate containment and forensic preservation for live incidents. Fixed call-out structure, 24/7 — available to registered clients on retainer.

Become a client

Imaging & Analysis

PER-DEVICE FIXED TIERS

Small device, workstation and server tiers with defined turnaround times and output designed to support use in legal proceedings. Start with a pilot intake to see the process end-to-end.

Book pilot intake

Backlog Retainer

MONTHLY CAPACITY BLOCKS

Guaranteed throughput and priority SLAs for sustained caseload reduction. Scales with demand.

Discuss a retainer
04 · Compliance & certifications

Lawful by design.

STANDARDS

Our standards

We are building CyberSight Forensics to operate to recognised forensic and information-security standards. We are working towards ISO/IEC 17025 accreditation for our forensic activities and align our work with the Forensic Science Regulator's Code of Practice. We also operate towards ISO 27001 information-security controls and are working towards Cyber Essentials Plus. We produce reports and maintain a documented chain of custody designed to support use in legal proceedings.

DATA PROTECTION

Lawful handling

Data minimisation, lawful access procedure and ICO-registered processing. Full cooperation with prosecuting authorities.

EVIDENCE

Chain of custody

Tamper-evident storage, hashed imaging and documented custody on every exhibit — from intake to disposal.

INDEPENDENCE

Independent provider

CyberSight Forensics is a private, independent provider. We are not part of, accredited by, or acting on behalf of any government department, police force, the National Crime Agency, the NCSC or any regulator. Where we refer to standards, codes or training, we describe how we align our work — not an endorsement of us by any body.

05 · Why CyberSight

Built for organisations under pressure.

Cybercrime caseloads are growing faster than in-house forensic capacity. CyberSight Forensics exists to close that gap — a specialist partner that takes on investigation workload without compromising evidential standards, so your teams can focus on outcomes.

Public-sector-grade rigour — procedures and reporting built to government standards, applied for clients of every kind.

Chain-of-evidence rigour — a documented chain of custody for every exhibit we handle.

Scalable analyst workforce — surge capacity for backlogs without permanent headcount.

Transparent pricing — fixed tiers and capacity blocks designed for predictable budgeting.

06 · FAQ

Common questions.

How quickly can you respond to a live incident?
Round-the-clock emergency triage is a service for clients on a retainer — our target is to respond to emergency incidents within 4 working hours. Containment and forensic preservation begin on response; remote-first, with on-site deployment where the incident requires it. All other enquiries are handled through the enquiry form during business hours.
How does the 24–48 hour pilot intake work?
You refer a single live case. Within 24–48 hours we complete intake, scoping and initial acquisition — demonstrating our chain-of-custody process and reporting standard before you commit to a wider engagement.
How rigorous is your evidence handling?
We maintain a documented chain of custody for every exhibit we handle — hashed imaging, tamper-evident storage and documented custody from intake to disposal — and produce reports designed to support use in legal proceedings. We are working towards formal ISO 17025 accreditation and align our work with the Forensic Science Regulator's Code of Practice.
Do you work remotely or on-site?
Remote-first for speed and cost, with secure on-site deployment when evidence, classification or organisational policy requires it.
How is pricing structured?
Three transparent models: fixed call-out for emergency triage (a service for clients on a retainer), per-device fixed tiers for imaging and analysis, and monthly capacity blocks for backlog retainers. Figures are quoted on engagement and hold for the duration.
07 · Get started

Book a 24–48 hour pilot intake.

Prove the process on a live case before you commit. For urgent incidents, retainer clients can reach our incident line at any hour.

WEBwww.cybersightforensics.com
Company, department, agency or local authority
Used only to respond to this enquiry
Optional — for urgent callbacks
Request received. We'll respond with secure intake details and next steps.

Fields marked are required. Please don't include case-sensitive or personal data in this form. Submissions are handled in line with our ICO-registered data protection procedures.