// Technical Investigations for Sydney Small Business

Something has happened. Start with what you know.

An unfamiliar sign-in, missing files or a device nobody recognises. You do not need to know which specialist to call. Tell me what you have noticed. I will help work out what to preserve, what can be checked and what the next step should be.

I am Angus. I look at the computer, the accounts and the network together, so you do not have to diagnose the problem before asking for help. I explain what the records support, what they do not, and what remains unknown.

  • A free consultation to work out where to start
  • Preservation before a rebuild or clean-up
  • Devices, accounts and network records checked together
  • A written summary in plain English
  • Practical next steps for your business

// The first call

Do not wipe it yet.

Start with what you saw and when you saw it. You do not need a technical explanation or a tidy folder. A reinstall, reset or clean-up can remove the records needed to understand what happened. Call before changing things.

  • Tell me what changed. Describe the affected computer, phone or account, when the problem started and what you have already tried. I start there, including what your business needs to keep running.
  • Keep the records you have. Keep alerts, emails and screenshots. Write down dates, times and any changes already made. I can then work out which records need preserving before they disappear.
  • Leave the reset button alone. Reinstalling a computer or factory-resetting a phone can erase logs, settings and local files. Ask me about preservation before starting a rebuild or installing recovery tools.
  • Keep accounts and hardware. Deleting an unknown account can remove useful history. Binning a device takes its storage and records out of reach. Keep them available so I can assess what matters.
  • Deal with immediate risk. Preserving records does not mean leaving an incident to continue. Tell me if access is still being misused. I can help identify what needs isolating and what can be kept before changes are made.

My support hours are Monday to Friday, 8:30am to 5:30pm. A suspected security incident takes priority over routine work.

// The approach

Eight stages, with an explanation at each step.

I agree the scope with you first. These stages give the work a clear order, from understanding the concern to handing back useful findings. I explain where missing records or access limits prevent an answer.

  • Understand. I listen to what happened, identify the devices and accounts involved, and work out the immediate risks and questions to answer.
  • Preserve. I identify the records worth keeping and preserve the available material before changes remove it.
  • Analyse. I examine the agreed devices, accounts and records for information relevant to your concern.
  • Correlate. I compare times and events across the available records. An account ownership map shows which email addresses, recovery numbers and devices control access.
  • Explain. I separate what the records show from possible explanations and unanswered questions. You get the findings in plain English.
  • Recover. I work on recovering files, account access or systems where possible, with preservation needs considered first.
  • Secure. I address the agreed gaps in accounts, devices, networks and backups once the relevant records have been preserved.
  • Handover. I organise the findings and technical material for you and any agreed recipient, with the next actions written down.

// What I look at

Follow the problem across the business.

The clue may be on a different system from the one showing the problem. I agree which sources to check and explain what I can access. An unfamiliar entry alone does not establish that someone got in.

  • Computers and phones. I check the available device records, settings and activity relevant to your concern. Access and the records still present determine how far the work can go.
  • Accounts and ownership. I map who controls each account, its recovery email and phone number, multi-factor authentication and trusted devices. That helps explain how access connects across the business.
  • Cloud sign-in records. I review available Microsoft 365 and Google Workspace sign-in records alongside account alerts. I compare them with the activity you recognise and note gaps in the history.
  • Routers, firewalls and Wi-Fi. I check available router and firewall logs, Wi-Fi connections and unknown devices. A device name you do not recognise is a starting point for checking, not a conclusion.
  • Cameras and connected devices. I include cameras, recorders and Internet of Things devices where relevant. I look at their connections, settings and available records as part of the wider network.
  • Deleted files and USB history. I assess what may remain of missing files and check available USB connection history. A record of a USB connection does not, by itself, establish which files were copied.

// The workshop and lab

More than twenty years of useful one day.

I have spent more than 20 years reinvesting in equipment because I wanted to understand how it worked. That workshop and lab gives me tools to investigate an odd business problem without expecting you to buy a bench full of gear.

  • Computers and storage. My lab includes computers, storage arrays, NAS units and servers. I can bring different kinds of hardware into the work when the problem calls for them.
  • Adapters and test equipment. Imaging adapters, cables and test equipment help with hardware that does not fit a current laptop. I probably already have the adapter. I check compatibility before committing to the work.
  • Networks and radio hardware. My equipment includes networking gear, SDR radio receivers and antennas, plus ESP32 and LoRa boards. Specialist RF surveys sit under my separate practice, Alien Security.
  • Local computing capacity. I have local AI and GPU compute alongside the workshop hardware. Equipment supports the investigation. The findings still need to stand on the available records.

// Findings and limits

Leave with something you can use.

You get a plain English written summary of the agreed work, the findings and the next steps. I explain the limits alongside the results, so a missing record is not mistaken for proof that nothing happened.

  • A readable written summary. I set out what I checked, what the records show, what remains uncertain and what I recommend next. You should not need to translate a folder of logs to understand the result.
  • An organised handover. I can organise the technical material for handover to your insurer, your solicitor or the police, as agreed with you. I explain where each finding came from and what supports it.
  • Specialist work has its own scope. I carry out specialist forensic examination, digital forensics and legal evidence reports under my separate practice, Alien Security. Personal cyber safety work also sits there. I explain that scope before proceeding.
  • Some data cannot come back. Deleted data may no longer exist. Overwritten data may be unrecoverable, and missing logs leave gaps. I explain what is available and what I cannot establish from it.
  • Findings have a time and a limit. My findings describe the material and period examined. They do not establish the state of every device at every time. I provide technical findings, not legal advice.

Day to day protection, the controls that stop most of this happening, is on the cyber security page. The order to do it in is in cyber security for small business in Sydney: where to start, and a backup that survives an incident is on the backup and disaster recovery page.

// Indicative pricing

What it roughly costs.

Real numbers, because "contact us for pricing" is code for "brace yourself." The first consultation is free and the quote comes before any paid work.

Initial assessmentFixed quoteafter free consultation
Investigation day rate$1,000per day, ex GST
Follow-on security review and written reportfrom $1,650one-off, ex GST
Essential Eight assessment$2,750fixed price, ex GST

The first consultation is free. I quote the initial assessment and agree investigation scope before paid work. Follow-on reviews are separate. I confirm GST in the quote.

// Questions

Technical investigations, your questions answered.

I think my business has been hacked. Who do I call?

Call me and describe what you have noticed, even if you cannot explain it yet. I start with the affected devices and accounts, immediate risks and what to preserve. My support hours are Monday to Friday, 8:30am to 5:30pm. A suspected security incident takes priority over routine work.

Should I wipe my computer or reset my phone after a suspected hack?

Call before wiping or resetting it. A reinstall or factory reset can remove logs, settings and files that help explain what happened. Keep alerts and note what you saw and when. I can help work out what to preserve and what needs isolating to limit further harm.

Can you check who accessed my business email?

I can review available Microsoft 365 or Google Workspace sign-in records and account alerts. I compare those with the activity you recognise and map account recovery routes. The records may show access without establishing who was behind it. I explain that distinction in the findings.

Can deleted business files be recovered?

Sometimes. It depends on what remains on the device or in another copy. Stop using the affected storage and call before installing recovery software or saving more files to it. Deleted or overwritten data may be unrecoverable. I assess what is available before recommending the next step.

How much does a technical investigation cost?

The first consultation is free. I give you a fixed quote for the initial assessment, then agree the scope before investigation work at $1,000 per day ex GST. If you need a follow-on security review, that starts at $1,650 ex GST. An Essential Eight assessment is $2,750 ex GST.

Can I give your findings to my insurer, solicitor or the police?

Yes. I provide a plain English written summary and can organise the technical material for an agreed handover. Specialist forensic examination and legal evidence reports are handled under my separate practice, Alien Security. I explain when that scope is needed. I do not provide legal advice.

Tell me what happened, in your own words.

Start with a free consultation. Tell me what you noticed, which systems are involved and what has already changed. I will help work out the next step.

Talk to Angus