Insights
Articles, guides, and explainers.
Practical writing on digital forensics, for Canadian counsel and businesses.

Digital forensics expert witness requirements in Canada: what counsel need to know
Qualifications, duties, and admissibility rules for a digital forensics expert witness under the Canada Evidence Act and provincial court rules — including BC Supreme Court Civil Rule 11-2.
How digital forensic teams collect data remotely across Canada
Remote acquisition is now the default in modern digital forensics. Here is how it works, why it is defensible in Canadian court, and when a device still needs to travel to the lab.

Physical vs logical mobile acquisitions: what Canadian counsel needs to know
A plain-language comparison of physical and logical mobile phone acquisitions — what each method captures, when each is available, and how the choice affects the strength of evidence in a Canadian court.
Why deleted text messages can't be recovered from a modern phone
A plain-language explanation of why deleted SMS and iMessage/Android messages are gone for good on modern phones — full-disk encryption, per-file keys, the Secure Enclave, and flash TRIM.

BYOD investigations in Canada under PIPEDA and BC PIPA
What employers can and cannot do when investigating BYOD devices in Canadian workplaces, with practical scoping guidance under PIPEDA and BC PIPA.

Are deleted text messages admissible in BC court?
When deleted text messages are admissible in BC court, how they are recovered, and what counsel needs to know about authentication under the Canada Evidence Act.

Sedona Canada Principles 3rd edition: what changed for forensic teams
A practitioner's summary of the changes in the Sedona Canada Principles 3rd edition, with implications for forensic teams and Canadian e-discovery counsel.

Ransomware in Canada: PIPEDA notification and the forensic report
When PIPEDA notification is required after a ransomware event, what the forensic report needs to support the determination, and how to coordinate with the OPC.

Chain of custody for digital evidence in Canada: a litigator's guide
What chain of custody means for digital evidence under the Canada Evidence Act, how it is documented, and what happens when it breaks.

Cryptocurrency tracing in matrimonial cases
How forensic teams discover hidden cryptocurrency in Canadian divorce matters, including device examination, on-chain tracing, and exchange subpoena workflow.

Cloud-only employees: where the evidence actually lives
When an employee works entirely in cloud services with no company-issued device, where does the forensic evidence live? A practical guide for Canadian counsel.

EnCase vs Magnet AXIOM vs Cellebrite in 2026: a practitioner comparison
A practitioner's comparison of the three major forensic platforms in 2026, with practical guidance on when each is the right tool.

Anton Piller orders in BC: a forensics execution guide
How forensic teams support Anton Piller order execution in BC, from pre-execution scoping through on-site imaging to the post-execution affidavit.

How to preserve mobile phone evidence: a checklist for Canadian counsel
Step-by-step preservation checklist for mobile phone evidence in Canadian litigation, from initial seizure through forensic acquisition.

Departing employee data theft: 12 signs and the playbook
Twelve signs an employee may be exfiltrating data, plus the forensic and legal playbook for investigating, documenting, and acting on departing-employee theft.

Microsoft 365 forensic investigation: what survives, what to capture first
A practitioner's guide to M365 forensic investigation: audit log retention, what each event captures, and what counsel should preserve first.
Need digital evidence handled defensibly?
Book a confidential consultation. Our team will reach out as soon as possible.
