Boston · Since 1992
Digital evidence. Forensically sound. From the Hub.
Certified examiners, former federal agents and veteran responders helping counsel, corporations, utilities and government investigate breaches, recover data, and prevail in court — across New England and nationwide.
- 30+
- years on the stand
- 10,000+
- devices examined
- 48 states
- matters supported
- < 1 hr
- incident triage
What we do
Five practice areas. One chain of custody.
Whether you’re defending litigation, responding to a breach, or hardening a substation against tomorrow’s headline, our examiners and engineers operate under a single documented, defensible workflow.
Computer Forensics
Court-admissible acquisition and analysis of computers, drives, mobile devices and cloud artifacts.
Learn moreCybersecurity
Offensive testing, defensive hardening and 24/7 incident response for business networks.
Learn moreICS / SCADA Security
Specialized protection for utilities, manufacturing, and critical-infrastructure control systems.
Learn moreeDiscovery
EDRM-aligned collection, processing, review and production for litigation and regulatory matters.
Learn moreExpert Witness
Deposition and trial testimony from certified examiners with Federal and state courtroom experience.
Learn moreIncident Response
Rapid-deploy IR for ransomware, BEC, insider threats and data-breach notification.
Learn moreData Recovery
Physical and logical recovery from failed disks, RAID arrays, SSDs and mobile devices.
Learn moreInsider Threat & HR
Covert workstation imaging, DLP review and misconduct investigations for GC and HR teams.
Learn moreHow we work
A workflow built for the witness stand.
Every engagement — whether a single phone or a 400-custodian collection — follows the same chain of custody, hashing, and documentation protocol. The report you receive has been written to withstand cross-examination for 30 years.
- 1
Intake & scope
NDA, conflicts check, and forensic plan within hours. Hotline available 24/7.
- 2
Preservation
Write-blocked imaging, documented hashing (MD5 + SHA-256), and custody logs.
- 3
Analysis
Artifact timelining across endpoints, cloud, and mobile — always reproducible.
- 4
Report & testify
Plain-English affidavits, exhibits, and courtroom-ready testimony.
Industries
Trusted by New England’s law firms, hospitals, utilities, and universities.
Legal
AmLaw, regional, and solo firms — across plaintiff and defense.
Healthcare
HIPAA-aligned IR for hospitals, insurers, and biotechs.
Financial services
SEC/FINRA-ready investigations and e-discovery.
Energy & utilities
ICS/SCADA and NERC CIP engagements across the grid.
Higher education
Title IX, research-misconduct, and policy investigations.
Manufacturing
OT security audits and IP-theft investigations.
Government
State, municipal, and federal support on contract.
Startups & VC
Founder disputes, trade-secret and BEC incidents.
BCF’s report was the single most effective exhibit in a decade of my practice. The opposing expert folded on cross before lunch.
Insights
From our practice
Incident Response
BEC wire-fraud recovery: a 96-hour playbook
Business Email Compromise losses are rarely recovered — except when they are. The specific steps that move the needle in the first four days.
Oct 28, 2025 · 2 min read
Insights
Welcome to the Hub — the new bostoncomputerforensics.com
A refreshed site, the same forensic rigor. A note on why we redesigned and what’s new for counsel, CISOs, and plant engineers.
Jan 20, 2026 · 1 min read
Legal & Regulatory
Authenticating text messages in Massachusetts: what Rule 901 wants
A practitioner’s guide to getting SMS, iMessage, WhatsApp and Signal exhibits admitted in MA Superior and Federal court.
Dec 4, 2025 · 1 min read
Under attack? Under subpoena? Under pressure?
Our intake line is staffed by a licensed investigator 24/7/365. Engagements are covered by NDA before any details leave your office.