A recovery job is over once the files are back. A forensic job is over once an expert who has been paid to pull the report apart has failed to find anywhere to start, and that can be eighteen months after the invoice. So the disk is copied once, hashed while it is copied, and every conclusion is written to be understood by a tribunal panel rather than by another engineer. Instructions arrive from HR teams in the manufacturing and distribution estates around the M1 and M69, from professional firms in the Cultural Quarter and out along the Loughborough road, and from solicitors acting for clients across Leicestershire and the wider East Midlands.
◇ Authority first. Bench afterwards. The full examination, written up as a report, comes to £800 + VAT. Stop at a verified image with its deleted material extracted and nothing reported, and it is £400 + VAT — the rung a recorder disk already occupies. Diagnosis is free and the scope is agreed in writing beforehand. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Ordinary recovery bands are on the data recovery cost page.
Getting files off a failing disk is engineering, and a great many firms can do it competently. What forensics adds is a documented account of how they were obtained, built to hold together while somebody attacks it. Nothing in the order of work is improvised. Write-blocker first. Capture into E01 evidence files. SHA-256 taken during the write and checked again afterwards. Exhibit sealed, labelled and entered in the custody file. Notes made as each of those happens, not typed up on the Friday. Every question after that is put to the copy, and each finding is numbered, dated and attached to the artefact that supports it. Remove any of that and what remains is a recovery with an invoice on top, which is a different product sold under a better name.
Reports come out inverted compared with the way an engineer would naturally write one. Findings lead, in ordinary English. Reasoning goes to the back, in an appendix. Where two readings of the same artefact are both available, both are given rather than the one the instructing party would rather hear. None of that is house style. Under CPR Part 35 and its practice direction an expert in civil proceedings has to state the range of opinion where a range exists, record the substance of the instructions received, and sign a statement of truth. Employment tribunals follow their own procedure instead of the CPR, and they want the same independence from anybody offering them an opinion.
The ten pages beneath this one fall into three groups. The first group is the examinations — a removal, a device register, a mailbox, an entire endpoint — and answers the factual question. The second group is about how the material was looked after, which is where opponents start and where cases are most easily lost. The third group aims the first two at a single named dispute over a single fixed run of dates.
One further note, since this page is read as often by people wondering whether they need any of it. A good proportion of the calls that come in turn out not to be forensic at all. A drive that has died with the accounts on it is a recovery, priced on the ordinary bands. A server encrypted by criminals is a recovery too, on the same bands, and anybody quoting you a forensic fee for ransomware is charging for a report you did not ask for. The £800 + VAT product is bought on purpose, because a question needs answering in a way somebody else will have to accept.
Four examinations, each answering a question of fact. What was taken off and when. What went out on a stick or a card. What left through a mailbox or a cloud account. And what a single capture of the whole machine is still holding on to.
A piece of evidence is worth exactly what its handling can be demonstrated to be worth, and the obligation to look after it starts the moment proceedings become a realistic prospect. That turns capture, hashing, sealed storage and a legible paper trail into a discipline in its own right. Machines that are locked or that somebody has tried to erase are dealt with under workstation deep imaging, where an encrypted volume is taken while a key can still be produced and any wiping run is named, dated and attributed.
In this group the subject is somebody rather than something: authority exercised where it should not have been, the logs a server writes whether or not anyone reads them, and the four instructions that arrive here most often.
The page you arrived on decides the subject matter. It decides none of the following.
A hardware write-blocker sits between the device and the workstation for the whole of the capture, so nothing anybody does at this bench can reach the disk you sent in.
The disk becomes an E01 evidence container carrying its own metadata — a format any competent examiner can mount, verify and take apart without needing us to interpret it for them.
SHA-256 is calculated as the image is written and recalculated at every verification since. An image that has been altered fails the comparison and the log records that it did.
Contemporaneous notes record what was done, by whom, on which equipment and at what time. Notes reconstructed later are the first thing a competent opponent goes looking for.
Indexing, carving, artefact extraction and timeline reconstruction all happen against the copy in OSForensics. Where a protected file has to be opened, Passware is used only if the client holds the right to what is inside it.
Every seal, signature and movement is entered from booking-in at Cambridge through to the exhibit being posted back, and the record is compiled on the assumption that an opponent will go through it line by line.
The least popular sentence first. Forensic work does not sit under no fix, no fee. That guarantee belongs to logical recovery, and the exclusions published beside it are electronic and mechanical failures, chip-level work, DVR jobs and forensic jobs. An examination is bench hours spent answering a question you have asked, and the hours are the same whether the answer helps your case or wrecks it. Against that, two figures are printed here rather than quoted on application, which is two more than most laboratories will commit to in public. Where the examination finishes with a full written report the fee is £800 + VAT. Where it finishes at the evidence — a verified binary image with the deleted material lifted out of it, handed to your solicitor or to another examiner to interpret — the fee is £400 + VAT. That lower figure is the same rung as a recorder disk or a BitLocker volume, so nothing on this page invents a sixth band.
The examination plus the written report it produces, set out so that an expert paid to disagree with you can follow every step and try to break it.
The verified binary image with its deleted material extracted, and no report written. The rung a recorder disk or an encrypted volume already occupies, not an extra band.
Both assume a single machine and a single question asked of it. Eleven laptops, a file server and a tenancy export is a larger exercise altogether, so anything spanning several devices is measured during the free diagnostic and written down before you are asked to agree to it. Working out what is there costs nothing and still closes 2 working days after the device is booked in at Cambridge, and the fee is settled before an examiner opens the image rather than after the findings are known. Two things are often mistaken for forensic work and priced accordingly elsewhere. A recorder disk and a BitLocker volume both reach £400 + VAT by the ordinary route, on the strength of what the media is, and DVR jobs carry their own exclusion from the guarantee. Ransomware is not forensic casework and is never billed as though it were: encrypted media takes the hardware bands like any other loss, £300 + VAT for one drive and from £500 + VAT for a server, NAS or array. Anything that is not forensic keeps the band it has always had on the prices page.
The bulk of this work is instructed by employers, by HR departments and by solicitors; a private client gets exactly the same terms and the same questions. Three routes reach this bench and there has never been a fourth. Kit the business bought and issued to somebody. A written instruction from a solicitor, an insurer or the court. Or a device that genuinely belongs to the person asking, which in a family matter means owned outright or owned jointly. Nothing is broken into here. Somebody else's password is not worked out, monitoring software is not installed on a device the client does not own, and live traffic is never intercepted — interception belongs to the bodies named in the Investigatory Powers Act 2016 and to no private laboratory. Where a client has no lawful right to look inside a device, instructing us does not manufacture one. Handsets and tablets are outside the practice altogether.
Evidence does not go in the post the way an ordinary drive does. Ring 0800 689 0668 first, and the box, the forms and the timing are agreed before anything is sealed. Nobody in this network collects and Leicester has no counter, so it goes to Cambridge by tracked, insured post, or across the Cambridge counter if you would rather hand it over — seventy miles, M1 to Junction 19 then the A14 east, and the lab is two minutes off Junction 32 with parking outside. Custody opens the moment it is booked in.
The general rule is the drive travels and the machine stays behind — out of the laptop, out of the tower, out of the iMac, out of the recorder under the counter. This bench does not dismantle equipment, and a repair shop will do it while you wait. Three things are the other way round, and getting them wrong costs you the recovery: an external drive stays sealed in its own case, a NAS comes as a complete unit, and a WD My Passport or My Book travels whole with its cable, because on those the encryption key is held on the bridge board rather than on the disk — separate the two and the data becomes unreadable even to us. A Fusion Mac needs both of its drives, each labelled. The one thing nobody can work round is flash soldered onto the mainboard, as on Apple Silicon machines: if it will not come off, there is nothing to post.
↓ Print the shipping & booking-in form (PDF)
Address it to Cambridge Data Recovery. It is about seventy miles from Leicester if you fancy driving it — M1 south to Junction 19, then the A14 east — and the lab is two minutes off Junction 32 with parking at the door. Posting costs you a stamp and a day instead. Whichever you choose, you hear from us the moment it is booked in, and the free diagnostic closes two working days after that.
Not certain what belongs in the box? Ring 0800 689 0668 before you tape it up, or let the free online diagnostic ask the questions for you.
Diagnosis costs nothing, the scope goes in writing, and the images verify. One call will tell you which questions a disk can answer and which ones it never could.