Investigation

Digital forensics services in Dubai, UAE

Our digital forensics services in the UAE establish how an incident happened, which systems and data were reached, and whether data left the environment, with evidence collected to a standard that can be relied on in a legal or regulatory process.

Hand touching a red investigation screen showing a wireframe face, file records and a padlock, representing evidence being examined
Preserving evidence

A rebuild removes the attacker and the forensic evidence together

After an incident there is pressure to restore service quickly: wipe the affected machines, restore from backup and resume work. Doing so before evidence has been collected destroys the record of what happened.

Once a machine has been rebuilt, three questions can no longer be answered from it. How the attacker got in, which is needed to close the route. How long they had access, which defines the scope. And whether personal data left, which under the PDPL decides whether notification is required.

Preserving evidence takes hours. Without it, the organisation cannot make a definite statement to a regulator, a client or a board about what occurred.

Before we arrive

Four steps that preserve forensic evidence

These steps can be taken in the first hour after an incident is discovered.

Isolate the system without powering off

Powering off destroys the contents of memory, which is a primary source of evidence. Disconnect the network and leave the machine running.

Prevent further logins

Every login writes to the disk and can overwrite data. Investigation by untrained staff can destroy evidence.

Preserve the logs

Log retention removes records on a fixed schedule. Export the relevant logs before the window closes, as this is a common and avoidable loss.

Record the timeline

Record who noticed what and when. Recollection fades quickly, and the sequence of events is needed for the investigation.

Services

Digital forensics services we deliver

Scope follows the question that needs to be answered, and is agreed with you at the start of the engagement.

Root cause analysis

Establishing how the intrusion began, so that the specific route in can be closed and verified.

Incident reconstruction

A timeline from first access to discovery, showing what was reached at each stage and how long the attacker had access.

Malware and keylogger analysis

What the payload did, what it communicated with and what it collected, which determines the scope of the exposure.

Exfiltration analysis

Whether data left the environment and what it contained, which decides your notification duties under the PDPL.

Forensic data acquisition

Disk and memory captured to forensic standards, with hashes taken at collection and verified afterwards, and the original preserved unchanged.

Chain of custody

Every handover recorded from collection onward, so the evidence can be relied on in a hearing or a court.

Mobile device forensics

Extraction from iOS and Android covering messaging, application data, location history and recoverable deleted content.

Data recovery and reconstruction

Recovery of deleted or damaged material where it is technically possible, with a clear statement of what could not be recovered.

Insider threat investigation

Discreet examination where an employee is suspected, with scope agreed with legal counsel or HR before work begins.

Email and mailbox investigation

Message flow, mailbox rule changes and forwarding, which record both account compromise and fraud.

Phishing investigation

What the message was, who received it, who acted on it and what happened next across the tenant.

E-discovery and litigation support

Collection, processing and production of electronic material to the standard a legal process requires.

Forensic readiness planning

Making sure the evidence will exist: retention set long enough, the right sources captured, roles assigned and an out-of-hours contact route agreed.

Log coverage assessment

Which systems log, where the logs are sent and how long they are retained, assessed before an incident.

Response plan development

A plan naming current staff with defined authority, written so that it can be followed by whoever is on duty.

Tabletop exercises

The plan rehearsed with the people who would carry it out, so that gaps are identified in an exercise.

How we work

How a forensic investigation runs

Monitors on a desk showing a world map and system dashboards, representing an investigator's workstation

On the first call you are given instructions for the next hour, before the affected systems are handled further.

  • Isolation guidance given immediately, because powering off destroys memory evidence
  • Log preservation started at once, before retention removes the records
  • Scope and objective agreed and written down

Evidence is collected to forensic standards, on the assumption that it may later be examined by an opposing party.

  • Hashes taken at collection and verified afterwards, so integrity can be demonstrated
  • Chain of custody recorded from the first handover
  • Analysis performed on a working copy while the original is preserved unchanged

The sequence of events, the scope and the route in are established, and early findings are shared as they are confirmed.

  • Timeline built from multiple sources so that it does not depend on a single log
  • Interim findings shared as they are confirmed
  • Working assumptions labelled as assumptions until the evidence supports them

What was reached, what was taken and which regulatory obligations that triggers.

  • Data categories identified, because the PDPL duty depends on what the data was
  • Systems reached listed with the evidence for each
  • Regulatory notification windows identified and their deadlines recorded

A factual report written to a legal standard, with a version for each audience.

  • Findings separated clearly from interpretation
  • An executive summary for the board and a technical account for the engineers
  • A version suitable for a regulator where notification is required

The route in is closed, and the gaps the investigation exposed are corrected.

  • The specific entry route closed and the fix verified
  • Log retention and coverage corrected where gaps slowed the investigation
  • Findings incorporated into the response plan
Compliance

What UAE frameworks require after an incident

Several UAE obligations require you to establish scope and impact and to notify within a defined window. The investigation provides the evidence for both.

UAE PDPL

A personal data breach carries notification duties, and whether one occurred depends on what left the environment. Establishing that is a forensic question, and the answer determines whether you notify and what you report.

ADHICS

Abu Dhabi healthcare entities must notify within a fixed window once an incident is confirmed. The investigation timeline provides the evidence that the window was met.

DESC ISR

Dubai government and semi-government bodies carry incident reporting duties and are examined on whether the response was documented and evidenced.

ISO 27001 and Central Bank

Both require incident records and evidence of the response, including root cause and the corrective action taken. The report is written so that it can be filed as that evidence.

Why iConnect

Why choose iConnect for digital forensics

Guidance in the first hour

What is done before the investigators arrive decides which evidence survives. Isolation and log preservation instructions are given on the first call.

Collected to a legal standard

Hashes, chain of custody and a preserved original from the outset, so the evidence can be used if the case becomes a legal matter.

The exfiltration question is answered

Whether data left the environment is the question a regulator and a board both ask, and the investigation is scoped to answer it with evidence.

Interim findings

Interim findings are shared as they are confirmed, so that containment and notification decisions do not wait for the final report.

Local and available

Investigators based in Dubai, reachable in your working hours, with reports written in the form UAE regulators ask for.

Readiness in advance

Retention, log coverage and a working contact route arranged in advance mean that the first day of an investigation can be spent on analysis.

Client feedback

What our clients say

“Whenever an issue arises, iConnect is there immediately: quick, efficient and proactive in keeping everything running without disruptions. iConnect has become a crucial part of our operations.”

Head of IT Infrastructure and Network SecurityDragon Oil
FAQ

Digital forensics questions

Whenever you need to know what the attacker reached or took. Rebuilding a machine removes the attacker and the evidence at the same time, so the route in, the duration of access and whether personal data left cannot be established afterwards. Under the PDPL, the last question determines your notification duties, and it can only be answered from evidence that has been preserved.

Isolate the affected systems, but do not power them down. Powering off destroys the contents of memory, which is a primary source of evidence. Disconnect the network, leave the machine running, prevent further logins to the system, and export the relevant logs before the retention period removes them.

The chain of custody exists for that purpose. Acquisition is performed to forensic standards, with hashes taken at collection and verified afterwards, every handover recorded, and analysis performed on a working copy while the original is preserved unchanged. Every case is handled from the outset on the assumption that it may become a legal matter.

Initial findings on a contained incident are provided within days, and a full report is scoped at two to four weeks. Scope determines the timeline: a single laptop can be examined quickly, while an intrusion across many systems in an environment with incomplete logging takes longer. Interim findings are shared as they are confirmed.

Yes. These cases carry legal and employment consequences, so the scope is agreed with your legal counsel or HR before work begins. The investigation is conducted discreetly, and the evidence is collected in a form that supports whatever disciplinary or legal action follows.

Yes. Extraction and analysis from iOS and Android devices covers messaging, application data, location history and deleted content where it is recoverable. Mobile devices are a frequent source of evidence in insider and misconduct cases.

Several UAE frameworks require an organisation to determine the scope and impact of an incident and to notify within a defined window. ADHICS sets this out for Abu Dhabi healthcare, DESC ISR applies to Dubai government bodies, and the PDPL governs personal data breach reporting. The investigation establishes whether an obligation was triggered, and the timeline evidence shows that the deadline was met.

Forensic readiness means making sure the evidence will exist when it is needed. Log retention has to be long enough, the right sources have to be captured, roles have to be assigned, tooling agreed, and an out-of-hours contact route established. With this in place, the first day of an investigation can be spent on analysis.

Contact us

Talk to our team about your requirement

We’re happy to answer any questions you may have and help you determine which of our services best fit your needs.

Our Value Proposition

What happens next?

1

We’ll arrange a call at your convenience.

2

We do a discovery and consulting meeting 

3

We’ll prepare a detailed proposal tailored to your requirements.

Schedule a Free Consultation