Kroll is the largest global incident response provider with unrivalled expertise and frontline threat intel to protect, detect and respond against attacks on the digital and physical frontiers.
No matter the type of data loss or cybercrime, Kroll has the experience and resources (human and technology) to move quickly, to discern, isolate and secure valuable relevant data and investigate the digital trail, wherever it may lead. For example, in the case of malicious insiders, we can combine computer forensic expertise with traditional investigative methodology, including interviews and surveillance, to retrace the behavior of people who may have had access to protected or proprietary information.
In the event of digital attacks, such as malware, ransomware or email account compromise, Kroll’s cyber investigation teams can collect and examine physical and digital evidence to uncover important information, such as where, when and how an incident occurred—and if systems are still at risk. We will determine what data was compromised and whether digital evidence was erased or modified. We will also work with your teams to recover data, whenever possible, and recreate events and exchanges so that you have an accurate diagnosis to develop an effective recovery plan.
Digital attacks oftentimes may include a physical component, including infiltration of local offices within an organization or tangible threats to staff, executives and boards. Our cyber team works hand-in-hand with Kroll’s enterprise security risk management experts to ensure that organizations are protected on all fronts following an incident.
Case Study – Insider Threat Investigation
A global software company based in Europe received an email from an anonymous source stating the sender had access to personally identifiable information, confidential financial data and IP source code for one of its subsidiaries. The sender gave Kroll’s client two weeks to pay a ransom of one million euros in bitcoin before it was leaked. Kroll's forensic investigators got to work – ascertaining that the information in question could only have come from an insider threat. Our experts identified the individual responsible – a former employee - and provided the necessary evidence to assist with a prosecution and eventual conviction.
For more details, read the full case study.