> For the complete documentation index, see [llms.txt](https://www.iblue.team/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://www.iblue.team/general-notes-1/the-reasonable-investigation-standard.md).

# The Reasonable Investigation Standard

Every digital forensics engagement starts with a negotiation. The client wants certainty, the investigator has a budget, a deadline, and tooling that can only answer so much in the time available. The deliverable sits somewhere between those two positions, and it rarely resembles the textbook version of a "complete" investigation.

I don't think that's a failing of the profession. It's the nature of the job. But right now most practitioners are making the scope call implicitly, case by case, without a shared standard for what "reasonable" means - and that becomes a problem the moment the work is challenged later.

**TL;DR - a narrower investigation is defensible when the scope was chosen deliberately, tied to a stated hypothesis, and documented before the fact. It stops being defensible the moment the shortcut was silent, regardless of whether it was taken due to time or budget pressure.**

#### A full forensic acquisition is not the baseline most engagements deliver

Full acquisition - imaging every relevant endpoint, exporting mailboxes in native format, preserving volatile memory, correlating logs across every system in scope - is the standard most of us trained on. It is not the standard most of us are resourced to deliver. Clients frequently assume it's what they're getting even where the engagement letter says otherwise, because "digital forensics" carries an assumption of exhaustiveness the underlying economics rarely support.

The shape of the trade-off changes with the size of the organisation, but it doesn't go away at either end.

At the enterprise end, the constraint is rarely budget, it's scale and internal process. A global business with 10,000 endpoints and a mature SOC still can't image every device a threat actor plausibly touched during a multi-week dwell time. Legal, comms, and the board all want a notification decision inside a regulatory clock that has nothing to do with how long log correlation across a dozen business units actually takes.

Triaging helps investigators decide which systems were likely impacted or are relevant, and the investigation is scoped to the systems judged most likely to matter. This often does not include all of them and that judgment call is where the exposure is.

At the small/medium end, the constraint is budget and time. A 40-person firm with no in-house security function wants an answer in 48 hours for a few thousand dollars, not the two weeks and five-figure spend a full investigation would need. A compromised finance mailbox, a ransomware note on a file server, a departing employee's laptop that's already been wiped and reissued to the next starter - in each case, the honest options are triage or nothing, because a full acquisition simply isn't going to be funded. The question isn't whether corner are going to be cut, because they will be. The question is which corners, and whether that decision is defensible when being questioned months (or years) later.Police / prosecutors Full acquisition as the default posture on every job, regardless of the matter's actual complexity or value - because the standard is set by what a criminal proceeding might one day require, not by what this particular case looks like today.

#### Who actually sets the bar

"Reasonable" isn't defined by the investigator alone. It's usually the collision of several parties, each with a different and sometimes conflicting view of what's good enough:

<table><thead><tr><th width="185">Party</th><th width="475">What they're actually optimising for</th></tr></thead><tbody><tr><td>Legal counsel</td><td>A defensible narrative and privileged work product - not necessarily the most technically complete one.</td></tr><tr><td>Cyber insurance carrier</td><td>Hours and tooling capped before scope is even set. Coverage terms often dictate the investigation rather than the reverse.</td></tr><tr><td>Regulatory notification deadline</td><td>Time-based conclusions, often unrelated to how long the evidence actually takes to acquire or process.</td></tr><tr><td>The client</td><td>Ranges from minimum defensible work to wanting everything, regardless of cost - and rarely states which up front.</td></tr><tr><td>Police / prosecutors </td><td>Full acquisition as the default posture on every job, regardless of the matter's actual complexity or value - because the standard is set by what a criminal proceeding might one day require, not by what this particular case looks like today.</td></tr></tbody></table>

Each of these parties can reasonably believe they're the one setting the standard. It's uncommon for anyone to step back and reconcile them before the engagement starts.

Law enforcement sits apart from the rest of that table. A criminal brief has to survive a standard nobody else in this list is held to - beyond reasonable doubt, tested by defence whose entire job is to find the gap in the acquisition and analysis, not just the gap in the argument. That pushes the default stance to full acquisition on every job, low-value and high-value alike, in a way that would be considered wildly disproportionate in a civil or commercial engagement. It's the right posture for that context. It is not a benchmark the rest of this article is arguing everyone else should be held to - and treating it as the universal baseline is exactly what makes triage and targeted acquisition feel, wrongly, like corner-cutting rather than proportionate scoping for a different standard of proof.

#### A tiered way to scope the work

I find it more useful to treat "investigation" as a set of tiers rather than a single deliverable, and to be explicit with the client about which tier they're buying.

<table><thead><tr><th width="163">Tier</th><th>What it answers</th><th>What it costs you</th></tr></thead><tbody><tr><td>Triage</td><td>Are we still bleeding, and do we have a notification obligation. Log review and indicator checks, no acquisition.</td><td>No recoverable deleted-item view, no confirmed initial access vector.</td></tr><tr><td>Targeted acquisition</td><td>Confirms or rejects a specific hypothesis - the one mailbox, the one endpoint, the relevant cloud audit logs pulled before the retention window closes.</td><td>Anything outside the hypothesis stays unexamined, including lateral movement you weren't looking for.</td></tr><tr><td>Full forensic acquisition</td><td>Comprehensive imaging and log correlation across scope. The version taught in training courses.</td><td>Time and cost most engagements aren't funded for.</td></tr></tbody></table>

Each tier's blind spots are specific, not vague, and they compound. Skip native-format mailbox export and you lose the ability to recover deleted items later. Skip endpoint forensics and initial access vector becomes a working assumption and not supported by findings. Skip the early log acquisition and you discover after the fact that the retention window has already closed on the exact period you needed.

Chain of custody compounds this further. Cloud-native evidence doesn't behave like a seized hard drive, custody of an audit log export is a materially weaker position than custody of a disk image, and treating them as equivalent in a report invites exactly the kind of challenge the report was meant to withstand.

Similarly, tool selection sits inside the same realm of compromises. A cloud provider's native audit and eDiscovery tooling gets you fast access to logs and mailbox data, but leans entirely on that provider's own retention and logging completeness. This would be fine for an SMB that needs an answer this week, thinner ground for a matter that ends up in litigation a year later.

A dedicated forensic platform gives deeper artefact-level analysis but demands acquisition time and licensing cost that most triage-tier budgets, and plenty of enterprise ones, don't have spare. Neither is categorically better - the right tool is the one that matches the tier the case actually calls for, and reaching for a heavier tool than the engagement can fund creates its own kind of exposure.

#### Write down why you stopped

The single highest-leverage habit in a resource-constrained investigation is documenting the scoping decision itself - not just the findings, but why the investigation stopped where it did. "Endpoint X was not acquired because of Y, and the resulting limitation is Z" is a sentence that protects everyone in the engagement. Its absence is what turns a reasonable trade-off into a liability months later, when someone asks why a full investigation wasn't run and the honest answer is that nobody wrote down that a decision had been made at all.

This matters more, not less, in matters that go nowhere. Most fraud and intrusion cases involving an SMB are never prosecuted - funds are gone, attribution is weak, and law enforcement triages by dollar value, so the file quietly closes. Enterprise matters close too, just differently - an internal incident gets written up, remediated, and shelved once the immediate risk is handled, with no external process ever testing the findings. In both cases the investigation record is precisely why it needs to stand on its own. It's often the only surviving artefact, and it can resurface in a civil claim, an insurance dispute, or a board inquiry long after the case itself was considered closed.

#### Governance Controls

**Scope decisions in writing, before work starts.** State the tier, the hypothesis driving it, and what's explicitly out of scope. A verbal agreement with the client is not a record.

**Carrier and breach-coach constraints documented separately from findings.** If hours are capped or tooling is restricted before scope is set, record that as a constraint on the investigation, not folded silently into the conclusions section.

**Retention-aware triage.** Know the retention window on every relevant log source before deciding what to pull first. A targeted acquisition plan built without checking retention limits is a plan built to fail quietly.

**A standing decision on who signs off scope.** Client, counsel, or carrier - name the party authorised to accept a narrower tier, and get that acceptance in writing rather than inferring it from silence. In an enterprise this is usually a named executive or the GC's office; in an SMB it's often the owner or a single director, which makes the written record more important, not less - there's no second layer of governance to catch an undocumented decision later.

#### Internal vs external capability

Not every part of a constrained investigation belongs with the same team, and getting that boundary wrong is its own source of exposure.

**What can reasonably be handled internally**

* Triage-tier log review and indicator checks
* Preservation actions - extending retention, isolating an account or device from reissue
* Contemporaneous documentation of who did what and when, from the moment the issue was identified

**What should sit with a suitably qualified provider**

* Targeted or full forensic acquisition intended to support a report relied on externally
* Any output that may be relied on in litigation, arbitration, or a regulatory response
* Analysis where provenance and methodology will be tested, not just the findings

The split isn't just a compliance formality. A report carries weight partly because of who produced it and how. An internal team running a targeted acquisition without a documented methodology creates an obvious line of challenge - and that challenge is often easier for the other side to win than one aimed at the substance of the findings.

#### Agreements to have in place before an incident, not during one

* A standing arrangement with a DFIR provider, so acquisition doesn't wait on procurement while retention windows close
* Pre-agreed tiers and triggers, so "which tier applies" isn't negotiated for the first time mid-incident
* Chain of custody and reporting requirements specified in the engagement terms, not left to be decided case by case
* A named party authorised to accept scope trade-offs under time pressure, agreed before the pressure exists

Get this in place before it's needed. The gap between "we think we need a forensic provider" and "a provider is actually engaged and pulling evidence" is exactly the window in which logs age out and devices get reissued. Enterprises with an existing panel arrangement still lose this window when the incident falls outside the panel's pre-agreed scope. SMBs without any standing arrangement lose it by default, because the first call anyone makes is to find a provider, not to engage one.

#### Summary

The full forensic investigation isn't the standard most engagements are actually held to, and pretending otherwise doesn't make the work more defensible - it just moves the argument from "was the scope reasonable" to "why didn't you disclose it wasn't complete." Set the tier deliberately, document the reasoning before the fact, get scope trade-offs signed off by someone authorised to accept them, and keep the acquisition boundary between internal and external work where provenance actually needs it. The standard isn't completeness. It's whether you can show your work.
