How we work
Frequently Asked Questions
The questions attorneys ask us most often, answered plainly.
01What does Cyber Agents do?
Our digital forensics experts specialize in evidence review, expert witness testimony, and eDiscovery. Our services include cell phone location data analysis, data recovery, data preservation, trial consultation, and discovery and evidence review.
02Do you work for the prosecution or the defense?
Both. Our agency is nonpartisan and we collaborate readily with prosecution or defense counsel, at all levels of government and all branches of the military, as well as with private individuals and attorneys. We do not work for both sides on the same case, as that would be a violation of the trust we have built over the years. Data doesn’t take sides; neither does Cyber Agents.
03Have you ever been disqualified from trial?
No. We have testified in state, federal, and military courts in more than 100 trials, and we have never been disqualified from trial.
04How much experience does your team have?
We have been practising since 1999. We have performed 1,000’s of examinations, assisted in hundreds of trials, and provided consultation for countless more. Our experts have more combined experience than any other company in the state of Kentucky.
05Will an examination cost more than it needs to?
Not if we can help it. Each case we are involved in is different; each computer different than the last. Not every case calls for us to examine every aspect of a computer—that would cost our customers far more than it needs to. A good forensic examiner knows which threads to pull to achieve the desired results. We also have strict policies in place to prevent double billing.
06What kinds of devices and data sources can you examine?
Mobile devices, computers, external storage media, email accounts, and cloud accounts. On the cloud side that includes Dropbox, OneDrive, SharePoint, Google Drive, iCloud, major webmail platforms, social media accounts, and encrypted messaging applications with cloud backup components.
07Can you collect evidence remotely, or do you need to come on site?
Either. We use industry-leading forensic tools to gather data from digital devices and cloud accounts without compromising any of the collected data, and we can perform collections either on-site or remotely, adjusting our approach to fit our clients’ specific needs.
08Do you provide expert witness testimony?
Yes. Since 1999 we have assisted in hundreds of trials and provided consultation for countless more, testifying in state, federal, and military courts. We also provide independent review and rebuttal of opposing forensic work product, pre-trial briefings, and cross-examination preparation.
09Do you handle military and courts-martial matters?
Yes. Cyber Agents is veteran-founded and has experience working with all branches of the military, including the Army, Navy, Marine Corps, Air Force, and Space Force. Our familiarity with CG approval processes helps to streamline the hiring of our experts.
10Can you host data for document review?
Yes. We partner with Oasis Discovery to offer data hosting on a Relativity-based review platform, and we work closely with individual clients to tailor hosting plans to their specific case needs and budgeting concerns.
11Do you offer CLE presentations or training?
Yes. Our team of examiners are also experienced instructors. We offer presentations and training about topics in digital forensics to groups of all sizes and experience levels, and have recently presented to the Kentucky Bar Association, the Tennessee Public Defenders’ Office, and at the annual Techno Security and Digital Forensic Conference.
12A document’s date is disputed. What should I preserve?
Preserve more than the printed page: the native file exactly as received, the original email message in a container format such as EML or MSG, all alternate versions and attachments, the source computer or a forensically sound image of it, relevant cloud-storage history, the surrounding communications, and hash values recorded at collection. Printing should be the last resort, not the first investigative step.
13How quickly do I need to act?
Sooner is better. Cloud evidence in particular is time-sensitive: retention policies vary by platform, and evidence that exists today may be automatically deleted within days or weeks if a forensic hold is not implemented. In insider threat matters, every hour that passes increases the risk that evidence will be deleted, devices will be wiped, and cloud storage accounts will be cleared.
Free consultation
Talk to an examiner before the evidence moves.
Digital evidence degrades, overwrites and expires. The earlier we are involved, the more of it survives to be examined.