IT Forensics in the Ruhr region

Secure evidence and bring clarity after an incident between Duisburg, Essen and Dortmund.

Clarify the cause with IT Forensics in the Ruhr region

After social engineering, digital sabotage or a ransomware attack, uncertainty often remains: What happened and what was the trigger? Which data was leaked?

aramido brings clarity:

  • Court-ready evidence preservation
  • Precise root-cause analysis
  • Traceable evaluation
Carry out IT Forensics now

IT Forensics in the Ruhr region: facts instead of assumptions

After a security incident, digital traces remain usable only for a limited time. Those who continue to work on the affected systems risk changing the evidence, because logs overwrite themselves continuously. Once that has happened, few reliable answers remain. That is why every hour counts for companies in the Ruhr region until the cause is clarified in good time and in a reliable way.

aramido proceeds calmly and deliberately and turns specifically to the systems that explain the trigger. Using a proven approach, we secure the traces while they are still intact. Between Duisburg, Essen and Dortmund, we are quickly on site when needed, whether in your power plant, the logistics centre or your office premises.

A stopwatch symbolizing fast evidence preservation

Fast Evidence Preservation

Every minute counts. We secure the volatile traces first and start the acquisition in the Ruhr region when needed.

A magnifying glass symbolizing clarity about the cause

Clarity about the Cause

After an incident, many questions arise. We examine the facts and show where the cause lies, especially when production and control data are affected.

Justitia symbolizing enforceable results

Enforceable Results

An expert report that stands up before courts and insurers needs an unbroken chain of custody. That is exactly what our analysis is designed to deliver, so you can assert your claims.

Structured analysis after an incident in the region

What is IT Forensics?

IT Forensics in the Ruhr region clarifies, after a security incident, what happened and how it came about. To do so, we follow the digital traces left on servers, in networks and in the cloud. This creates a reliable basis for the next steps: a report to the authorities, the compensation through your cyber insurance or the continuation of critical business processes. For companies from the region whose operations depend heavily on IT, this evidence is decisive.

Reliable means: the results must withstand scrutiny. That is why we document every acquisition and work with a chain of custody (Chain of Custody). Since all analysis steps remain traceable, the results are usable before courts, for insurers and for operational decisions. In the Ruhr region, aramido takes on this task as your partner for IT Forensics.

  • 1
    First we determine which data sources are relevant to the case and define the acquisition order in accordance with the order of volatility.
  • 2
    We create copies of the storage media without altering the originals and verify them with checksums.
  • 3
    We evaluate the secured data and put the traces into a chronological order. In this way we reconstruct the course of events.
  • 4
    Finally, a traceable expert report is produced, with an understandable summary for decision-makers, legal advisers and insurers.

Have evidence secured in the region.

Briefly describe in your message what happened. We will get back to you promptly and take over the forensic analysis. The sooner we start, the more likely the traces remain intact. If it is urgent, reach us directly on the emergency hotline: +49 721 451 99 112.

Status

Please enable JavaScript to use the form.

IT Forensics for the energy and industrial locations in the Ruhr region

The Ruhr region remains one of the most industrial regions in Europe. In Essen, RWE and Uniper generate electricity, the transmission system operator Amprion secures the supply, ThyssenKrupp operates one of the largest steel sites there, and the Port of Duisburg, as the largest inland port in the world, connects logistics with the Ruhr region. Those who experience a cyber incident here carry a responsibility that goes beyond their own organisation: for the electricity supply, steel production and supply chains. That is exactly why aramido is here in the region: we secure the affected traces before they are lost and clarify the cause.

In the Ruhr region, clinics, energy suppliers and logistics centres depend on reliable IT. Essen University Medicine was affected by data exfiltration after hackers had attacked the University of Duisburg-Essen. After an incident, clarification counts alongside restoration: what was stolen, altered or encrypted? That is precisely where aramido supports you with IT Forensics in the Ruhr region, preferably remotely and on site when needed. If you first need immediate help, you will find it on our page on IT emergency response and incident response in Essen.

Forensic disciplines for incidents in the region

Which methods we apply depends on the threat situation. Digital traces come from many sources: from persistent data, volatile artifacts and complex network flows.

For the analysis across all levels, we use specialized procedures. In the Ruhr region, aramido looks exactly where the decisive clues lie.

Memory Forensics

Memory Forensics

We secure volatile data from working memory, reconstruct processes and thereby uncover active attacks.

Disk Forensics

Disk Forensics

Storage media and forensic images show which data and traces of use can be reconstructed.

Network Forensics

Network Forensics

By analyzing network traffic, we prove communication between compromised endpoints and data exfiltration.

Host Forensics

Host Forensics

System and file artifacts reveal which user activities took place and how the attack unfolded.

Malware Forensics

Malware Forensics

When examining malicious software, we recognize attack patterns and prevent reinfection.

Cloud Forensics

Cloud Forensics

In cloud environments, we clarify incidents of a tenant across multiple regions.

Frequently asked questions about IT Forensics in the Ruhr region

If the cause of a security incident is not clarified, it can occur again in the same or a similar form. It is therefore important to determine the cause. In addition, there are statutory reporting obligations to supervisory authorities, for example in the context of GDPR or NIS-2. Cyber-risk insurers also require professional processing before granting coverage. And the extent of the damage shows why documented processing pays off: data breaches at German companies regularly cause damage in the millions. Forensics provides the facts that make the damage, the cause and the scope comprehensible.
Data recovery restores lost files so that they can be used again. IT Forensics goes further: it delivers the evidentiary value and explains the cause of a particular situation. This includes, for example, patient zero, the point where a hacker group first intruded.
The chain of custody (Chain of Custody) documents completely where an item of evidence is located. It records who accessed the original media and when, and how copies were created. Only in this way does the securing of evidence remain admissible in court and the case traceable.
A backup records the state of the data, not the state of the system at the moment of the attack. Open network connections and the contents of working memory are not included. Moreover, attackers can nowadays encrypt or compromise the backup itself.
This can often be proven. If internal data access is suspected, we check which systems were used and which data was read, copied or forwarded and when. From system logs, access rights, file metadata and network communication we read the course of events, and if necessary we also reconstruct fragments of deleted files or chat histories. The report is factual and evidence-based, without speculation. It serves an internal review, an insurance claim or a report to the authorities.
In the Ruhr region, valuable data lies with energy suppliers, steel and logistics companies. If economic espionage is suspected, we examine which systems were reached from outside and which data was exfiltrated. We secure the traces before they are lost and document the findings so that they are usable for a report or an insurance claim.
Usually not. In live forensics, we secure volatile data while the systems are running. In post-mortem forensics, we analyze forensic copies in a controlled environment.
Usually we assess the situation within the first few hours, in the region on site if needed. How long the detailed analysis takes depends on the volume of data and the complexity of the case: it can take from a few days up to several weeks.
The price depends on the incident, the number of affected systems and the required analysis effort. In an initial conversation we identify the essential requirements and provide you with a transparent cost estimate.
Yes. We secure evidence in accordance with ISO/IEC 27037 and maintain an unbroken chain of custody. Courts, public prosecutors, lawyers and insurers can use the expert report. This standard is especially relevant in North Rhine-Westphalia: the Central Contact Point for Cybercrime at the Düsseldorf Public Prosecutor General centralizes investigations into serious cybercrime. A report that is meant to withstand such scrutiny must be created cleanly and in a traceable manner from the outset.
In addition to the major cities Dortmund, Essen, Duisburg, Bochum, Gelsenkirchen, Oberhausen, Mülheim and Hagen, we support companies from the entire Ruhr region, including the Ennepe-Ruhr district, the district of Recklinghausen, the district of Unna and the district of Wesel. Depending on the case, remotely and on site when needed. For the neighbouring regions you will find our pages for Düsseldorf and for Cologne.

Your contribution to IT Forensics

After an incident in your company in the region, it is important to act quickly and correctly. Whether traces remain usable later is usually decided in the first few minutes. So involve us early and leave your systems unchanged until they are secured.

Your knowledge of the systems and infrastructure complements our specialist expertise, so that we can carry out digital forensics together. In accordance with the order of volatility, we define what is secured and in which order. Using your access, forensic copies are created, which we then examine.

How you preserve your traces

  • Report the incident early
  • Leave affected systems unchanged
  • Name the systems you consider affected
  • Share your knowledge of the infrastructure with us