FAQ
Find answers to common questions about cybersecurity, digital forensics, and IT compliance — speak to us if you need further support
Cybersecurity FAQs
1. Immediate Actions (First Few Hours)
- Activate Incident Response (IR) Team
- Include IT, Legal, DPO, Management, and external DFIR (if needed)
- Contain the breach
- Disable compromised accounts
- Isolate affected systems
- Patch exploited vulnerabilities
- Preserve evidence
- Do NOT wipe or reformat systems
- Take forensic images (disk + memory if possible)
- Start incident log
- Timestamp all actions (court-defensible)
2. Parallel Actions (Within 24–72 Hours)
- Assess impact
- Type of data, number of individuals, risk of harm
- Determine PDPA notification requirement
- Notify PDPC if:
- ≥500 individuals affected OR
- Significant harm risk
- Notify PDPC if:
- Mandatory notification timeline
- Within 3 days of determining notifiable breach
3. Investigation (Forensics-led)
- Establish:
- Attack vector (phishing, credential theft, vulnerability)
- Timeline (entry → persistence → exfiltration)
- Data exfiltration scope
- Use forensic methodology
- Chain of custody
- Immutable evidence handling
4. Remediation & Recovery
- Remove attacker access
- Reset credentials and tokens
- Patch vulnerabilities
- Rebuild compromised systems (clean baseline)
5. Post-Incident Actions
- Notify affected individuals (if required)
- Conduct root cause analysis
- Update policies, controls, and user training
- Document lessons learned (audit requirement)
A breach response is considered incomplete unless evidence is preserved, root cause is identified, and recurrence is mitigated (not just “system restored”).
Operational Reality
- Immediate response required (minutes to hours)
- Assessment must be “expeditious” under PDPA
- Regulatory notification:
- Within 3 calendar days after determining notifiable breach
AVBT Practical Guidance
| Phase | Expected Response |
|---|---|
| Detection | Immediate |
| Containment | Within hours |
| Forensic capture | Before remediation |
| Assessment | Within 24–72 hours |
| PDPC Notification | Within 3 days of assessment |
| Full remediation | Days to weeks |
Assessment must be carried out promptly under PDPA, and any delay increases data loss, legal exposure, and the risk of evidence contamination.
Digital forensics is the process of collecting, preserving, analyzing, and presenting digital evidence in a way that is legally admissible — ensuring evidence integrity, chain of custody, and court defensibility.
It’s typically needed for:
Mandatory scenarios
- Data breaches involving personal data (PDPA)
- Insider threats or employee misconduct
- Financial fraud or email compromise
- Litigation or disputes
Critical operational scenarios
- Unknown root cause of an incident
- Suspected persistence or backdoors
- Ransomware or data exfiltration
- Regulatory or audit requirements
If you can’t confidently answer what happened, how, and what was accessed — forensics is required.
In many cases, yes. Digital forensics can recover deleted files, emails and chat messages, metadata (timestamps, access logs), and hidden or partially corrupted data.
This is possible because deletion usually removes only the pointer to the data, not the data itself — it remains until overwritten. Backup systems and logs also provide additional sources.
Recovery depends on:
- Time elapsed since deletion
- Storage type (SSD TRIM reduces recoverability)
- Overwriting activity
- Encryption
In real investigations, metadata and logs are often more valuable than the file content itself for reconstructing events.
| Aspect | Vulnerability Assessment | Penetration Testing |
|---|---|---|
| Purpose | Identify weaknesses | Exploit weaknesses |
| Method | Automated scanning | Manual attacker simulation |
| Output | List of vulnerabilities | Proof of impact / attack path |
| Depth | Broad coverage | Deep, real-world risk |
| Intrusiveness | Low | Higher (controlled) |
| Frequency | Continuous | Periodic (e.g. annually) |
In short: a vulnerability assessment tells you what’s wrong, while a penetration test tells you what can actually be exploited.
We recommend using VA continuously, and pentesting for validation and high-risk systems.
PDPA requires organizations to:
- Protect personal data from unauthorized access, disclosure, or misuse
- Cybersecurity is the technical enforcement mechanism for this legal obligation
Digital Forensics FAQs
Digital forensics is the process of collecting, preserving, analyzing, and presenting digital evidence in a legally defensible manner.
Digital forensics may be needed for data breaches, insider threats, employee misconduct, financial fraud, email compromise, ransomware, litigation, disputes, or unknown incident root causes.
In many cases, yes. Deleted files, emails, chat messages, metadata, timestamps, access logs, and hidden or partially corrupted data may be recoverable depending on the circumstances.
Do not wipe, reformat, or unnecessarily modify affected systems. Evidence should be preserved properly before remediation so the investigation remains reliable.
Digital forensic findings may support legal, regulatory, disciplinary, or internal proceedings when evidence is collected and handled with proper methodology and chain of custody.
A forensic investigation typically aims to determine what happened, how it happened, when it happened, what was accessed, and whether data was deleted, copied, modified, or exfiltrated.
Have An Enquiry?
Leave Us A Message
Feel free to reach out to us using the contact form or directly via email.
Our knowledgeable and experienced team is ready to address your cybersecurity needs and provide tailored solutions to help safeguard your digital assets.