
The first actions after a suspected digital incident can determine what an examiner will later be able to establish.
An organization may know that something is wrong without yet knowing whether it is dealing with employee misconduct, data theft, fraud, unauthorized access, a ransomware event, or an ordinary technical failure. That uncertainty is not a reason to wait. It is a reason to preserve the record before routine activity, well-intentioned troubleshooting, or automatic retention processes change it.
Preservation is not the same as proving what happened. It protects the sources from which a later examination may draw conclusions. A preserved laptop does not establish who used it. A saved audit log does not establish intent. A screenshot does not necessarily preserve the underlying metadata or surrounding context. Those are questions for examination.
The immediate objective is narrower: prevent avoidable loss, document the condition of the evidence, and create a reliable path from the original source to the material eventually examined.
This article provides general preservation guidance, not legal advice or a fixed collection procedure. The correct response depends on the organization's authority, the system involved, the type of matter, applicable Canadian law and policy, and the risk created by acting or waiting. The technical principles here align with ISO/IEC 27037, the international standard for the identification, collection, acquisition, and preservation of digital evidence, which is written to apply across jurisdictions. The cited United States guidance supports the same technical principles, but its jurisdiction-specific procedures do not govern Canadian matters. ISO/IEC 27037:2012
What preservation has to protect under Canadian evidence law
In Canada, the applicable rules of evidence depend on the proceeding and the jurisdiction. The Canada Evidence Act applies to criminal proceedings and to civil proceedings and other matters within federal jurisdiction. Provincial evidence statutes govern other matters. Both federal and provincial frameworks address the authenticity and integrity of electronic records.
The Canada Evidence Act treats electronic documents through a distinct set of provisions. A party seeking to admit an electronic document carries the burden of proving its authenticity, which means evidence capable of supporting a finding that the document is what it purports to be (s. 31.1). The best evidence rule is then satisfied by proving the integrity of the electronic documents system in or by which the record was recorded or stored (s. 31.2). That integrity can be established through the statutory presumptions in s. 31.3, including evidence that the system was operating properly, that the record was stored by a party adverse in interest, or that it was recorded in the usual and ordinary course of business by a person who is not a party. Section 31.5 allows a court to consider the standards, procedures, and practices used to record or store the record.
Section 31.1 establishes a threshold inquiry: the party offering the record must produce evidence capable of supporting a finding that the document is what it purports to be. That is not a reason to be casual. Authenticity and integrity still have to be demonstrated from the available evidence. A record collected without provenance, custody, or a reliable account of the system that produced it invites an integrity challenge that proper documentation could have answered. Manitoba's Evidence Act contains closely parallel provisions for electronic documents in sections 51.1 through 51.6.
Sound preservation and documentation give counsel evidence with which to establish system reliability, account for what happened after collection, and connect the examined copy to its source. Canada Evidence Act, ss. 2 and 31.1 to 31.8 The Manitoba Evidence Act, ss. 51.1 to 51.6
Start with authority and the question
Before collecting data, identify who is authorizing the work and what question the organization needs answered. This determines which systems, accounts, dates, people, and records may be relevant. It also helps prevent indiscriminate collection.
The question may initially be broad:
- Was confidential information transferred outside the organization?
- What occurred before encryption began?
- Were records altered or deleted?
- Which account performed a disputed action?
- Can a document's history or authenticity be established?
That question should not be treated as a conclusion. "Investigate whether files were transferred" is a legitimate examination question. "Preserve proof that the employee stole the files" selects the conclusion before the evidence has been examined.
Authority also sets the collection boundary. Organizational ownership of a device or account may provide one form of authority, but privacy, employment, contractual, regulatory, and litigation obligations may still affect what can be collected and how it may be used. NIST cautions that forensic practices should be applied in consultation with management and legal counsel where laws and regulations are engaged. NIST SP 800-86
Preserve volatile and short-retention evidence first
Not all digital evidence disappears at the same rate.
System memory, active network connections, running processes, temporary cloud records, firewall buffers, and short-retention security logs may be lost quickly. Devices and services may also continue writing new data over deleted or historical material. CISA's ransomware guidance specifically identifies memory, Windows Security logs, and firewall log buffers as examples of volatile or limited-retention evidence that may require prompt preservation. CISA StopRansomware Guide
RFC 3227, an established IETF evidence-collection guideline published in 2002, describes this as an order of volatility: collect from the most transient sources toward the most persistent. Processor and memory state, network connections, and running processes can be lost on shutdown or reboot. Disk, logs, and archival media persist longer. The guideline also sets out two rules that protect later analysis. Perform collection before analysis. Record the difference between the system clock and coordinated universal time (UTC) so that timestamps can be reconciled across sources. It remains useful as a statement of these principles, but it is not a substitute for a current, environment-specific collection procedure. RFC 3227
This does not mean an untrained person should begin running forensic tools. Live collection changes the system being examined. The correct action depends on the event, the operating state, the available expertise, and the consequence of shutting a system down or leaving it running.
The practical first step is to identify what may expire and who is qualified and authorized to preserve it. Ask:
- Which logs rotate automatically, and when?
- Which cloud services retain detailed audit events, and for how long?
- Are affected systems still running?
- Could disconnection, shutdown, restart, or login destroy useful state?
- Are backups available, and could normal backup cycles overwrite the relevant period?
- Do service providers require an immediate preservation request or account-level action?
The answers should be recorded. If a source could not be preserved, that limitation belongs in the investigation record.
Do not investigate through the original evidence
Ordinary interaction can change digital evidence. Opening files may update timestamps or application history. Logging into an account may create new authentication events. Running cleanup, antivirus, recovery, or administrative tools may alter the system. Forwarding an email can change its representation and omit original transport information. Exporting cloud data may produce a transformed copy with different metadata.
This is why forensic work normally separates preservation from examination. The original source or a verified forensic acquisition is protected, and examination is conducted from an appropriate working copy. ISO/IEC 27037 distinguishes evidence-handling roles and provides guidance for identification, collection, acquisition, and preservation. That role distinction does not necessarily require different people. The operational requirement is to protect the source and prevent examination activity from altering the evidence on which the conclusions depend. SWGDE's current collection guidance calls for maintaining evidence integrity, documenting chain of custody and evidence inventory, and recording the device state and identifying characteristics at collection. It also recommends acquisition and verification hashes when forensic images are created. ISO/IEC 27037:2012 SWGDE Best Practices for Digital Evidence Collection
If immediate operational needs require changes to an affected system, document them. Record who acted, when, why, what commands or tools were used, and what was observed. Incident containment may take priority over ideal preservation. The resulting changes do not automatically invalidate the evidence, but they must remain visible to the examiner.
Preserve more than the device
A modern digital event rarely exists in one place. A laptop may contain local artifacts, while the records needed to interpret them exist in identity systems, email platforms, collaboration tools, endpoint security products, network infrastructure, mobile devices, backups, and cloud services.
Depending on the question, potentially relevant sources may include:
- computers, phones, removable media, and external drives;
- email messages in their original form, including headers and attachments;
- identity, authentication, and access-control records;
- endpoint detection and response telemetry;
- firewall, VPN, DNS, proxy, and network-flow records;
- cloud audit logs and administrative events;
- file-sharing, synchronization, and collaboration-platform records;
- application, database, and server logs;
- backups, snapshots, and retention archives;
- photographs of the device, workspace, connections, and screen state;
- policies, access assignments, role definitions, and approval records; and
- contemporaneous notes from the people who discovered or responded to the event.
Cloud evidence requires particular care. SWGDE notes that collection authority must be understood and that cloud metadata may not always reflect the original evidence in the way an examiner expects. Provider preservation, enterprise retention controls, legal holds, exports, and direct provider records serve different purposes and may preserve different parts of the record. SWGDE Cloud Service Provider Guidance
A screenshot can be useful, especially for dynamic or online content, but it is usually a representation rather than a complete acquisition. SWGDE recommends auditable and repeatable methods for online content and recognizes that provider records may verify or supplement material captured through ordinary collection methods. SWGDE Best Practices for Acquiring Online Content
Record provenance and custody from the beginning
Preservation must leave a record that another person can follow.
For each item or data source, record:
- what it is;
- where it came from;
- who identified or collected it;
- the date and time, including the time zone;
- the device or account state;
- the collection method and tool version where applicable;
- any errors, interruptions, or deviations;
- cryptographic hash values where appropriate;
- where the preserved material is stored; and
- every transfer of possession or control.
This documentation does not prove that every record is accurate. It establishes provenance and helps a reviewer assess integrity, handling, and continuity. A cryptographic hash can show that two digital representations are identical at the point measured. It does not establish who created the content, whether the source was complete, or whether the recorded event occurred as someone later describes it.
ISO/IEC 27037 frames these practices through four principles: auditability, repeatability, reproducibility, and justifiability. A preserved record should let an independent examiner trace what was done, repeat the method used, obtain a consistent result through an equivalent method, and understand why each decision was made. Documentation is what makes those four properties testable after the fact.
NIST describes digital forensics as identifying, acquiring, and protecting relevant data before processing, analysis, and reporting. It also emphasizes documented procedures because electronic records can be altered or manipulated. NIST forensic practices overview
Keep operational response and forensic conclusions separate
An incident manager may need to isolate a system, disable an account, block network traffic, restore a service, or communicate with affected parties before a forensic examination is complete. Those decisions may be necessary. They should not be confused with findings about cause, intent, attribution, or responsibility.
For example, disabling an account because it appears compromised is a protective action. It does not establish that the account owner caused the incident. Isolating a server because it is communicating with a suspicious address does not establish the full attack path. Preserving an employee's laptop after a data-loss alert does not establish misconduct.
Document the operational reason for each action and preserve the evidence available at the time. This allows the later examination to distinguish what responders observed, what they inferred, what they changed, and what remained unresolved.
What counsel, employers, and incident managers should avoid
Several common actions can reduce the evidence available for later review:
- asking the subject of an investigation to explain or demonstrate activity on the device before preservation;
- allowing routine reimaging, replacement, account deletion, or equipment return to proceed once a dispute, investigation, or litigation is reasonably anticipated;
- forwarding messages instead of preserving their original form;
- relying only on screenshots when original files, exports, logs, or provider records may exist;
- repeatedly logging into the affected account or device to "see what happened";
- running broad searches or cleanup tools without recording their effects;
- assuming that backups contain every relevant record;
- collecting everything without a defined question or authority; and
- describing a suspicion as an established fact in preservation instructions.
Some situations require immediate action despite these risks. The governing principle is not inactivity. It is controlled action with documented reasons and known effects.
A practical initial-preservation record
When specialist assistance is not yet in place, create a contemporaneous record without experimenting on the evidence. Document:
- The question or event that triggered concern.
- Who discovered it and the time it was discovered.
- The systems, devices, accounts, and services believed to be involved.
- Their current operating and connection state.
- Known log and retention deadlines.
- Actions already taken and by whom.
- People who had possession, access, or administrative control.
- Available photographs, alerts, tickets, messages, and system-generated records.
- Legal, contractual, privacy, or operational constraints already identified.
- The person authorized to approve preservation and examination.
This record is not a substitute for forensic acquisition. It gives the examiner a traceable starting point and exposes early gaps before they become hidden assumptions.
Preservation protects the question
Effective preservation is selective. It protects the sources needed to answer a defined question while maintaining authority, integrity, provenance, and documented custody. Freezing every system or collecting every record is neither necessary nor, in most matters, achievable.
A strong early response does not settle what happened. It keeps the question open to examination and preserves the material needed to address the authenticity and integrity requirements that may later apply.
Sources
- NIST SP 800-86, Guide to Integrating Forensic Techniques into Incident Response
- NIST, Digital Evidence Preservation: Considerations for Evidence Handlers
- ISO/IEC 27037:2012, Guidelines for identification, collection, acquisition and preservation of digital evidence
- IETF RFC 3227, Guidelines for Evidence Collection and Archiving
- Canada Evidence Act, RSC 1985, c. C-5, ss. 31.1 to 31.8
- The Manitoba Evidence Act, CCSM c. E150, ss. 51.1 to 51.6
- CISA, StopRansomware Guide
- SWGDE, Best Practices for Digital Evidence Collection
- SWGDE, Best Practices for Acquiring Online Content
- SWGDE, Best Practices for Digital Evidence Acquisition, Preservation, and Analysis from Cloud Service Providers