Cyber risk / AI-assisted forensics
Bring the evidence together.
Give your security team an investigation capability grounded in the evidence you hold. AI can help plan approved read-only investigations, correlate records and prepare findings for human review.
Build the capability inside your environment
Our engineers connect approved evidence sources and tailor the investigation workflow inside infrastructure your organisation controls. Your team defines what it can access, the work it can perform and the approvals it needs.
The capability supports your security team with organisational context available before a case begins. Deployment and operating choices are agreed around your environment and the investigation requirements.
Turn an investigation question into reviewable findings
- Define the case. State the question, affected systems, time period and approved evidence boundary.
- Plan the read-only investigation. Identify the queries, sources and hypotheses needed to examine the question.
- Correlate the evidence. Relate identity, endpoint, cloud and other approved records into a timeline, preserving references to the source evidence.
- Prepare the finding. Assemble an executive summary, technical explanation and evidence index, with uncertainty and unresolved questions made explicit.
- Review and authorise. Accountable people examine the evidence and decide on further collection, response actions and closure.
Useful outputs include a unified incident timeline, a view of affected people, systems and data, and an explanation of what the available evidence supports about a breach or data exposure.
Keep authority with accountable people
Approved read-only work
Queries, correlation, hypothesis testing, timeline construction and report drafting can be performed within the agreed scope.
Human authorisation
Isolation, remote execution, disruptive collection, remediation, broad scope expansion and incident closure require human authority. The investigation workflow makes these boundaries explicit.
Evidence and assurance
Provenance references, an audit trail and explicit uncertainty help reviewers assess the findings. Cases with regulatory or legal requirements need case-specific chain-of-custody controls, expert review and approval gates agreed with counsel or the relevant stakeholder. Admissibility and acceptance depend on jurisdiction, process and the reviewing authority.
Agree the delivery and operating model
Design
Select the first investigation mission, evidence sources, autonomy boundary and success criteria with your team.
Deploy and integrate
Place the selected model and orchestration on customer-controlled infrastructure. Connect approved evidence sources and encode access, provenance and audit controls.
Enable the team
Prepare runbooks and train the people who will operate and review the capability. Agree whether operation will be handled by your team, jointly or with Cornerstone Red’s support.
Specialist expertise can support novel malware, independent validation, expert testimony and counsel-directed matters as the case requires.