Between 1999 and 2015, the Post Office prosecuted more than 700 subpostmasters, many for theft or false accounting, in cases that relied on data from the Horizon accounting system. English courts applied a presumption that a computer was operating correctly unless evidence was produced to the contrary. The people challenging Horizon were therefore expected to raise doubt about a system they did not control and could not independently examine. The Criminal Cases Review Commission records that they lacked access to the software information needed to challenge the figures and that Horizon provided no chain of evidence comparable to the previous paper-based accounting methods. The system's output was treated as a finding. Only under independent scrutiny, including the civil litigation Bates v Post Office, did the courts accept that software errors could have produced the apparent shortfalls. The Court of Appeal then found that the Post Office had not adequately considered or disclosed problems with Horizon in any of the Horizon cases before it. Those failures prevented the appellants from challenging the reliability of the data and denied them a fair trial on whether it was reliable. Convictions have since been quashed in a scandal widely described as “the biggest miscarriage of justice in our history” in the government's 2024 explanatory notes.
The failure was not a shortage of data. It was the absence of a discipline that would have required the reliability of that data to be established, tested, and disclosed before it carried the weight of a conviction. The same gap sits less visibly inside a common practice in corporate security.
Organizations combine digital forensics and incident response into a single function and label it DFIR. The pairing is practical. It can also blur a distinction that surfaces at the worst possible moment, when a conclusion is challenged by someone who has no reason to accept it.
A cybersecurity investigation and a digital forensic investigation can reach the same factual conclusion. But if the evidence and reasoning were not handled from the beginning so they could survive independent challenge, the work was not digital forensics. It was a cybersecurity investigation. The difference is the discipline, not the tools or the job title.
The two overlap considerably. Both may examine the same systems, logs, devices, accounts, and events. Both may be rigorous. Digital forensics carries an additional obligation that changes how the work is conducted from the first decision about evidence.
What each investigation is built to do
A cybersecurity investigation is designed to answer practical questions: what happened, what is the risk to the organization, and what needs to be done about it. That work can identify malicious activity, contain an incident, determine affected systems, reconstruct events, establish root cause, support remediation, and reduce organizational risk. Those are legitimate objectives. Achieving them does not, by itself, make an investigation forensic.
Digital forensics introduces a further requirement: the evidence, methodology, and reasoning must withstand scrutiny by someone who does not take the investigator's account at face value. That requirement governs how evidence is identified, acquired, preserved, documented, analyzed, and interpreted. It demands attention to provenance and integrity, documentation of handling and chain of custody where applicable, and methods that can be explained, reviewed, and where feasible reproduced or independently validated.
It also requires discipline in the conclusions. A forensic conclusion has to separate:
- what was directly observed;
- what was inferred;
- what assumptions were necessary;
- what evidence was unavailable;
- what alternative explanations remain possible; and
- what limitations affect the result.
A forensic conclusion should go no further than the evidence allows. A security investigation asks whether the organization has enough reliable information to make a decision. Digital forensics also asks whether the evidentiary process supporting that conclusion can withstand independent and legal scrutiny. That is a different standard.
The dividing line is not the job title
This distinction is not law enforcement versus corporate practice. Good forensic work can occur inside a corporation, a consulting firm, a government agency, a police service, or an incident response team, and poor forensic work can occur in any of them. The dividing line is how the evidence is treated and what standard governs the examination.
A capable cybersecurity team can conduct a forensic investigation. An incident response team can preserve evidence and follow sound procedure while containing an attack. A forensic examination can serve operational and risk objectives at the same time. The disciplines are not mutually exclusive, but neither are they interchangeable.
In some operational investigations, the working threshold is practical: we have enough reliable information to determine what happened and decide what to do next. For protecting the organization, that can be appropriate. Forensic work has to contemplate a harder environment in which the investigator must show what was concluded, how the evidence supports it, and what happened to the evidence throughout the examination.
Legal defensibility does not mean criminality
Saying that forensic work should be legally defensible does not mean every forensic investigation involves criminal conduct, prosecution, or a courtroom. Legal defensibility is a characteristic of the work, not a description of the allegation.
Forensic evidence arises in employee misconduct matters, intellectual-property disputes, civil litigation, regulatory investigations, insurance matters, contractual disputes, workplace proceedings, data breaches, insider-risk investigations, and ordinary cybersecurity incidents. None must involve criminality. The relevant question is whether the evidence and process could withstand appropriate legal or formal scrutiny if challenged. That requires showing where the evidence came from, that its integrity was preserved, how it was handled and analyzed, and why the conclusion follows, with limitations disclosed and inference separated from fact.
Court is not the starting point
A common question is whether an investigation is going to court, and it is often asked too late. At the beginning, we may not know where a matter will end. An internal investigation can become an employment dispute, an insider-risk matter can become civil litigation, a cybersecurity incident can lead to regulatory proceedings, and a matter handled entirely inside an organization can later be referred to law enforcement.
The eventual destination does not determine whether the earlier handling of the evidence was sound, and some deficiencies cannot be repaired afterward. If provenance was never established, it cannot be recreated when litigation begins. If material examiner actions were never documented, later testimony does not reconstruct them. If evidence was altered without preserving its original state, the integrity that should have been protected cannot be restored later. Defensibility has to be designed into the process from the beginning. The better question is not whether the matter will reach court, but whether the path from the original evidence to the conclusion can be defended if it is challenged.
Forensics carries an evidentiary boundary
The distinction is sometimes described as a legal boundary, meaning whether the investigator had authority to access a system, account, or dataset. Authority and scope are part of it, but the boundary is broader. Digital forensics operates within an evidentiary and legal discipline governing how evidence is obtained, preserved, handled, analyzed, interpreted, and presented.
That boundary becomes visible when investigative convenience conflicts with evidentiary preservation. An operational responder may reasonably prioritize containment, recovery, system availability, and reduction of business risk. A forensic examiner has to also consider what actions will change the evidentiary state, what could be lost, what needs to be preserved first, and how later examination will distinguish original evidence from changes introduced during response. The two functions can work together, but their objectives are not always identical. That is one reason collapsing everything into "DFIR" can obscure a professional distinction. Incident response describes an operational function. Digital forensics describes an evidentiary discipline. NIST's guidance on integrating forensic techniques into incident response treats preserving evidentiary integrity and maintaining chain of custody as core parts of the forensic process. Those obligations persist whether or not the combined label is used.
The word makes a claim
When an organization says it has a Digital Forensics and Incident Response function, the word forensics makes a stronger claim than saying the organization conducts cybersecurity investigations. It implies something about how evidence will be treated. It sets an expectation that evidence will be preserved, that provenance and integrity can be established, that material actions will be documented, that methods can be explained, that limitations will be acknowledged, and that conclusions can be defended.
That claim is now made at commercial scale. Digital forensics and incident response is marketed as a service line by consulting firms, professional services firms, and specialist providers. When a firm offers DFIR to a client, the word forensics is part of the offer. It signals that the work will meet a forensic standard, not only an operational one.
If the underlying work was conducted only to answer the immediate operational questions, without regard for evidentiary integrity, provenance, documentation, methodological review, limitations, or eventual scrutiny, the label promises more than the work delivers. That does not make the investigation poor. It may have been an excellent security investigation. The distinction is about what kind of work was performed.
The gap is rarely tested
In my experience, much of the work performed under the DFIR label is built to protect the organization. It responds to the incident, contains the damage, preserves operations, and answers the questions leadership needs answered. Chain of custody, provenance, and defensibility are treated as secondary, when they are addressed at all.
The reason this persists is structural. Most of these matters are resolved without a courtroom. They end in remediation, a report to management, an insurance claim, or a private settlement. They rarely meet a regulator or an opposing expert. The defensibility of the work is therefore rarely tested. A conclusion that would not survive challenge is never challenged, and the gap between the label and the discipline stays invisible.
That invisibility is not evidence of quality. It is the absence of a test. The Horizon prosecutions show what happens when the test finally arrives at evidence that was presumed reliable and never built to withstand it. Most corporate matters never reach that point. The work is accepted because no one with reason to contest it ever examines it closely.
This is not an argument against security investigations
I am not claiming that corporate digital forensics is less legitimate than law-enforcement forensics, or that most teams and firms offering DFIR fail to meet forensic standards. Establishing either would require evidence far beyond personal observation.
The argument is narrower. The term digital forensics is sometimes used as though it names a category of tools, a job title, or any technical investigation involving digital evidence. That definition is too weak. Digital forensics should describe the evidentiary discipline under which the investigation is conducted.
A security investigation can be competent, rigorous, technically sophisticated, and exactly what an organization needs without being a forensic examination. Calling it a security investigation, an incident investigation, or an internal investigation takes nothing away from the quality of the work. The problem arises when the forensic label creates an expectation the underlying process cannot support.
Forensics is the standard
The question worth asking is not who conducted the investigation or which tools were used. If an investigation was conducted without adequate regard for evidentiary integrity, provenance, documentation, methodological defensibility, limitations, and the possibility of independent challenge, should we call it digital forensics only because forensic practitioners or forensic tools were involved?
I do not think we should. Forensics is not conferred by a job title, an imaging tool, an EDR platform, a SIEM, or a line in an org chart. The word makes a claim about the standard under which evidence was treated and conclusions were reached. It means the investigator can move from evidence to conclusion through a process that can be examined, explained, challenged, and defended.
If we are going to use the word, that is what it should mean.
Sources
- Criminal Cases Review Commission, Post Office “Horizon” Cases.
- Bates and Others v Post Office Ltd (No 6: Horizon Issues) [2019] EWHC 3408 (QB); Hamilton and Others v Post Office Ltd [2021] EWCA Crim 577; and Post Office (Horizon System) Offences Act 2024: Explanatory Notes.
- P. B. Ladkin and others, The legal rule that computers are presumed to be operating correctly.
- National Institute of Standards and Technology, Guide to Integrating Forensic Techniques into Incident Response, SP 800-86.