FAQ

Find answers to common questions about cybersecurity, digital forensics, and IT compliance — speak to us if you need further support

Cybersecurity FAQs

What should I do if my company experiences a data breach?

1. Immediate Actions (First Few Hours)

  • Activate Incident Response (IR) Team
    • Include IT, Legal, DPO, Management, and external DFIR (if needed)
  • Contain the breach
    • Disable compromised accounts
    • Isolate affected systems
    • Patch exploited vulnerabilities
  • Preserve evidence
    • Do NOT wipe or reformat systems
    • Take forensic images (disk + memory if possible)
  • Start incident log
    • Timestamp all actions (court-defensible)

2. Parallel Actions (Within 24–72 Hours)

  • Assess impact
    • Type of data, number of individuals, risk of harm
  • Determine PDPA notification requirement
    • Notify PDPC if:
      • ≥500 individuals affected OR
      • Significant harm risk
  • Mandatory notification timeline
    • Within 3 days of determining notifiable breach

3. Investigation (Forensics-led)

  • Establish:
    • Attack vector (phishing, credential theft, vulnerability)
    • Timeline (entry → persistence → exfiltration)
    • Data exfiltration scope
  • Use forensic methodology
    • Chain of custody
    • Immutable evidence handling

4. Remediation & Recovery

  • Remove attacker access
  • Reset credentials and tokens
  • Patch vulnerabilities
  • Rebuild compromised systems (clean baseline)

5. Post-Incident Actions

  • Notify affected individuals (if required)
  • Conduct root cause analysis
  • Update policies, controls, and user training
  • Document lessons learned (audit requirement)

A breach response is considered incomplete unless evidence is preserved, root cause is identified, and recurrence is mitigated (not just “system restored”).

How quickly should a company respond to a cyber incident?

Operational Reality

  • Immediate response required (minutes to hours)
  • Assessment must be “expeditious” under PDPA
  • Regulatory notification:
    • Within 3 calendar days after determining notifiable breach

AVBT Practical Guidance

PhaseExpected Response
DetectionImmediate
ContainmentWithin hours
Forensic captureBefore remediation
AssessmentWithin 24–72 hours
PDPC NotificationWithin 3 days of assessment
Full remediationDays to weeks

Assessment must be carried out promptly under PDPA, and any delay increases data loss, legal exposure, and the risk of evidence contamination.

What is digital forensics and when is it needed?

Digital forensics is the process of collecting, preserving, analyzing, and presenting digital evidence in a way that is legally admissible — ensuring evidence integrity, chain of custody, and court defensibility.

It’s typically needed for:

Mandatory scenarios

  • Data breaches involving personal data (PDPA)
  • Insider threats or employee misconduct
  • Financial fraud or email compromise
  • Litigation or disputes

Critical operational scenarios

  • Unknown root cause of an incident
  • Suspected persistence or backdoors
  • Ransomware or data exfiltration
  • Regulatory or audit requirements

If you can’t confidently answer what happened, how, and what was accessed — forensics is required.

Can deleted files or emails be recovered during an investigation?

In many cases, yes. Digital forensics can recover deleted files, emails and chat messages, metadata (timestamps, access logs), and hidden or partially corrupted data.

This is possible because deletion usually removes only the pointer to the data, not the data itself — it remains until overwritten. Backup systems and logs also provide additional sources.

Recovery depends on:

  • Time elapsed since deletion
  • Storage type (SSD TRIM reduces recoverability)
  • Overwriting activity
  • Encryption

In real investigations, metadata and logs are often more valuable than the file content itself for reconstructing events.

What is the difference between vulnerability assessment and penetration testing?
Aspect Vulnerability Assessment Penetration Testing
Purpose Identify weaknesses Exploit weaknesses
Method Automated scanning Manual attacker simulation
Output List of vulnerabilities Proof of impact / attack path
Depth Broad coverage Deep, real-world risk
Intrusiveness Low Higher (controlled)
Frequency Continuous Periodic (e.g. annually)

In short: a vulnerability assessment tells you what’s wrong, while a penetration test tells you what can actually be exploited.

We recommend using VA continuously, and pentesting for validation and high-risk systems.

Why is cybersecurity important for PDPA compliance?

PDPA requires organizations to:

  • Protect personal data from unauthorized access, disclosure, or misuse
  • Cybersecurity is the technical enforcement mechanism for this legal obligation

Digital Forensics FAQs

What is digital forensics?

Digital forensics is the process of collecting, preserving, analyzing, and presenting digital evidence in a legally defensible manner.

When is digital forensics needed?

Digital forensics may be needed for data breaches, insider threats, employee misconduct, financial fraud, email compromise, ransomware, litigation, disputes, or unknown incident root causes.

Can deleted files or emails be recovered?

In many cases, yes. Deleted files, emails, chat messages, metadata, timestamps, access logs, and hidden or partially corrupted data may be recoverable depending on the circumstances.

What should we do before starting a forensic investigation?

Do not wipe, reformat, or unnecessarily modify affected systems. Evidence should be preserved properly before remediation so the investigation remains reliable.

Digital forensic findings may support legal, regulatory, disciplinary, or internal proceedings when evidence is collected and handled with proper methodology and chain of custody.

What does a forensic investigation try to establish?

A forensic investigation typically aims to determine what happened, how it happened, when it happened, what was accessed, and whether data was deleted, copied, modified, or exfiltrated.

Have An Enquiry?
Leave Us A Message

Feel free to reach out to us using the contact form or directly via email.

Our knowledgeable and experienced team is ready to address your cybersecurity needs and provide tailored solutions to help safeguard your digital assets.

Scroll to Top

Clientele

Contact Us

Support

Sales

Accounts

Follow Us

About

People

Gov Grants

Partners

Contact

Contact Us

Support

Sales

Accounts

Follow Us