
Incident response has become a crucial component in the information security management process of every well-prepared organization. Performing effective incident response takes resources and planning, and forensically sound evidence preservation is one of the pieces most likely to get overlooked. Incident responders are focused on containing an active threat, and the rapid, changing nature of a live incident makes it easy to destroy or contaminate evidence before anyone realizes it mattered.
This blog covers evidence preservation and the incident handling steps that protect evidence integrity, what to preserve first, and how to keep digital evidence usable for post-incident analysis, an insurance claim, or a criminal investigation.
Why is evidence preservation important?
Preserving critical electronic evidence during a security incident is a must to obtain a full incident overview and to establish a basis for further investigation and threat containment/eradication. Evidence preservation is crucial to successful incident analysis and depends on strict data preservation standards to ensure that all potentially relevant data is captured and remains uncompromised throughout the investigation.
After detecting a cyber attack, most incident responders are prepared to contain and remediate it as soon as possible. Responders still need to be careful not to rush evidence collection. Rushing can destroy or potentially compromise items of evidentiary value that could identify the attacker’s methodology or avenues of compromise. These evidence items, appropriately collected in accordance with established regulations and/or best practices, could further assist law enforcement in prosecuting the crime. That’s why preserving evidence should be the first priority in any incident.
The NIST incident response phases, and where evidence preservation fits
NIST SP 800-61 organizes incident response into four phases, and evidence preservation touches every one of them:
- Preparation: Have forensic tools, storage, and chain-of-custody procedures ready before an incident happens, not during one.
- Detection and analysis: Capture the alerts, logs, and system state that first revealed the incident. This is also where you decide what evidence is in scope.
- Containment, eradication, and recovery: Contain the threat without destroying evidence in the process, a real tension every incident response team (IRT) has to manage in real time.
- Post-incident activity: Write a report, document lessons learned, and formally close out the evidentiary record.
Within that lifecycle, NIST SP 800-86 defines the digital forensics process specifically: collection, examination, analysis, and reporting. During collection, you identify, label, record, and collect evidence while actively preserving its integrity, which is the step we’re focusing on.
Primarily, the IRT should be prepared for an incident, or one similar in nature, so it can recognize what’s happening quickly and begin forensic analysis of the affected assets right away. The next step is to contain and minimize the damage, then recover as much of the affected data and systems as possible.
After an incident, an organization should produce a post-incident report with a detailed explanation and proposed solutions to prevent similar incidents. As soon as the IRT reaches the affected environment, properly recognizing digital evidence is what keeps risk from compounding.
Criteria for recognizing digital evidence
Whether you’re gathering digital evidence from a single source or several, you need forensically sound methods to preserve key evidence. Doing so helps establish a clear picture of the incident and supports an effective response.
Evaluating the digital environment
Assess which alerts generate the most false positives and optimize your parsing rules to reduce them. Being able to tune an alarm that is unnecessarily broad will significantly reduce the number of alerts you must review daily, whether from your SIEM, Syslog or other feeds. More precise analysis of relevant alerts will significantly reduce not only alert fatigue for your analysts but also dwell time for malicious activity in your network, as they are identified and remediated faster.
Seizing evidence
As previously mentioned, the fundamental responsibility of those collecting evidence is to ensure that measures are in place to avoid contaminating evidence during collection. It may be necessary to shut down the machine/systems/network due to collection requirements, forensic best practices, or to ensure that the virus/malware has been contained. Additionally, it may be necessary to preserve the evidence and perform backups before proceeding. The backups could also include copies of specific items of evidentiary value related to the incident in order to assist investigators at a later date in the event of litigation. Each piece of evidence should be protected from damage or alteration, labeled and a proper chain of custody maintained.
As soon as this stage is completed, the IRT can continue the process to contain, eradicate and recover all affected systems and computers from the attack or data breach. If there is further law enforcement involvement, or at their request, the IRT should be prepared to transfer a copy of items being seized, as well as a detailed log or history of all activities performed.
Preparing computers, devices and media
Upon arrival at a forensic laboratory, all evidence and equipment should be properly inspected to verify that no tampering occurred during transport. All evidence is placed in the evidence preservation lab for safekeeping and for detailed examination. The search-and-seizure evidence log and shipping manifest are also stored in the lab after this procedure is complete.
Final note
The importance of evidence preservation is therefore critical during any cybersecurity-related incident, including the need for collaboration between IRT and forensic examiners to best handle digital evidence for future use and analysis.
A SIEM solution like Sumo Logic can help organizations respond faster and more effectively to an incident.
See how it can help your organization. Request a demo.



