
10.07.2026
A cyber attack is only truly overcome when companies can understand how the attacker proceeded. This is precisely where digital forensics lays the foundation for sustainable security measures.
A successful cyber attack raises many questions: How did the attacker gain access to the company? Which systems were affected? Which data did the attacker compromise? And above all: Is there a risk that the incident will be repeated?
Digital forensics provides the answers. It is a central component of professional incident response and helps to systematically reconstruct attacks, secure evidence and derive effective measures for the future.
In an interview, Thomas Ringhof explains how forensic analyses are carried out in practice, what mistakes companies should avoid in an emergency, and why successful incident response goes far beyond mere damage limitation.
How does a forensic analysis proceed after a cyberattack? Which data is particularly important? And how can concrete improvements be derived from an incident? Thomas Ringhof answers all these questions in the full video interview.
Digital forensics refers to the systematic examination of digital traces following a security incident. Forensic investigators secure log files, memory dumps, network data and other artifacts to reconstruct the sequence of an attack without gaps.
Unlike a classic vulnerability scan, digital forensics examines an incident that has already occurred: how did the attacker get in, which systems did they compromise, and what data was affected?
Digital forensics thus provides the robust factual basis for any further decision in Incident Response, from containment to reporting to authorities or insurers.
Following a security incident, the initial focus is on containing the attack. However, just as important is the question of how the incident could have happened in the first place.
This is precisely where digital forensics comes in. It reconstructs the sequence of an attack, identifies the entry point, and makes it understandable which systems were affected and what activities the attacker carried out.
This provides the basis for informed decisions, both during incident response and for the long-term improvement of security strategy.
Every cyber attack leaves digital traces. These include log files, memory dumps, network data, and artefacts on end devices, among others.
The sooner responsible parties secure this information, the more completely the attack progression can be reconstructed. At the same time, clean evidence preservation is crucial in order not to inadvertently alter data or lose important clues.
A structured data backup is therefore one of the most important tasks in the first hours of an incident.
A single log file rarely answers all questions. Only by combining different data sources does it become possible to trace the entire attack path, from initial access through lateral movement to persistence mechanisms or potential data exfiltration. .
Methodologies and frameworks such as the Cyber Kill Chain or that MITRE ATT&CK® Framework aid in contextualising individual activities within an overall picture and recognising typical attack patterns.
The insights gained from digital forensics are directly incorporated into technical and organisational improvements. These include, for example, the adaptation of detection rules, the hardening of affected systems, improvements in identity and access management, or optimisations to existing incident response processes.
The goal is to manage the current incident and to detect or prevent similar attacks in the future at an early stage.
„An incident is only truly concluded when we can retrace the attacker's steps – anything else remains speculation.“
— Thomas Ringhof, Digital Forensic Specialist at r-tec (part of the accompio group)
In many incident response operations, precisely the information needed for a complete analysis is missing.
Unactivated logging, retention periods that are too short, or incomplete data significantly hinder reconstruction. At the same time, incident response teams must work under severe time pressure, balancing rapid response with careful analysis.
Good preparation therefore often determines how successful a subsequent forensic investigation will be.
Automation and artificial intelligence are increasingly supporting forensic analysis in the evaluation of large datasets and the identification of conspicuous patterns.
However, the actual assessment of an attack will continue to be the task of experienced experts. Complex attack scenarios in particular require contextual knowledge, experience, and the ability to translate technical findings into concrete recommendations for action.

accompio analyses the attack patterns and vulnerabilities in your IT infrastructure so that an incident does not reoccur.
Incident response doesn't end with the restoration of business operations. Only when companies understand how an attacker operated, which vulnerabilities they exploited, and what traces the attack left behind, can effective protective measures be derived.
Digital forensics provides exactly this understanding, thereby creating the foundation for a more resilient security strategy.
Thomas Ringhof is an Incident Responder and Digital Forensic Examiner at r-tec (part of the accompio group) and supports companies with the forensic investigation of security incidents.
Digital forensics is the systematic analysis of a cyber attack. The goal is to secure digital evidence, reconstruct the attack sequence, and gain reliable insights into the attacker's cause, impact, and methods. It is an essential component of professional incident response.
Incident response encompasses all measures to detect, contain, and remediate a security incident. Digital forensics focuses on securing evidence, technically analysing the attack, and fully reconstructing the sequence of events. Both disciplines are complementary and closely linked.
Log files, memory dumps, network data, endpoint information, authentication logs, and artefacts on affected systems are particularly important. The more complete this data is, the better the attack can be reconstructed.
Many digital traces change quickly or are lost due to restarts, system changes, or cleaning measures. Early backup of relevant data increases the likelihood of fully reconstructing the attack path.
The analysis begins with securing relevant data sources. Subsequently, forensic investigators chronologically order events, identify attack techniques, and reconstruct the entire attack path. Frameworks such as the Cyber Kill Chain or that MITRE ATT&CK® Framework assist in systematically classifying the observed activities.
A memory dump is a snapshot of a system's RAM. It often contains clues about running processes, malware, network connections, or encryption keys, and frequently provides information that is no longer present in log files.
Forensic analysts examine, among other things, active processes, network connections, persistence mechanisms, user accounts, and unusual activities. The aim is to determine whether the attacker still has access to systems or if the team has already removed them completely.
MITRE ATT&CK describes known attack techniques and tactics in a structured model. Incident response and forensics teams use the framework to systematically classify attacks, improve detection rules, and strategically develop security measures.
No. AI analyses large amounts of data, identifies anomalies, and supports experts in their evaluation. However, the assessment of complex attack scenarios and the derivation of suitable measures still require the experience of specialised incident response and forensics experts.
Companies should ensure comprehensive logging, retain log data for a sufficient period, define incident response processes, assign responsibilities, and conduct regular drills or attack simulations. Good preparation significantly improves the quality of forensic analyses and reduces response times in the event of an incident.

Arrange an initial consultation