# Debate “Corporate forensics: arguing about what matters” Nikita Vyugin and guests · MKO Systems MOSCOW FORENSICS DAY ’26 · Day 2 — Friday, 4 September 2026 · Scheduled 11:40–12:10 · In the recording 02:54:17–03:43:37 Talk summary · https://2026.moscow-forensics-day.workers.dev/en/summary/08-debate Transcript: https://2026.moscow-forensics-day.workers.dev/en/transcript/08-debate · Slides: https://2026.moscow-forensics-day.workers.dev/en/slides/07-corporate-forensics · Watch from 02:54:17: https://youtu.be/WuMIv5sFPRs?t=10457 --- ## In brief Instead of a talk — a panel on four topics: BYOD versus COPE, whether to notify an employee that an investigation has begun, whether to keep a departing employee's device, and proactive forensics versus reactive. Calling it a debate is a stretch: on the first topic everyone agreed that BYOD has no advantages, on the last — that "proactive forensics" is an oxymoron to begin with. What the panel does have is practice: a company with a turnover of more than a billion, with no domain and personal laptops, where the key figure "forgot the password" and ran into BitLocker; a notice of an audit given three days in advance and met with bags of shredded paper; several hundred Macs left without control after the sanctions. The most honest conclusion — from a forensic examiner: the data turns out to be where it was expected, "twice in my practice". ## Key points - The format: Vyugin moderates, on stage are two practicing forensic examiners and a man with CISO experience — "from the business side". The scheme of the discussion: first the forensic examiners speak for and against, then business says what works in practice. - The trigger for the first topic — a remark from a trainee at a corporate training course: "we need to buy a fleet of those phones that are easy to control", so that in an incident the data is guaranteed to be obtainable. - **BYOD versus COPE, the forensic examiner's view**: corporate devices come out ahead — they are easier to obtain for examination, there is no need to negotiate with the owner or to deal with the questions of "unlock it, and if you forgot, try to remember", all the keys and all the access are already there. - The statistics diverge twofold and in both directions: for one of the forensic examiners COPE is there in 7–8 cases out of 10, for Vyugin it is the opposite — out of ten corporate clients only three have COPE, "seven… deal directly with BYOD", and in the regions that means "own phones" and a laptop mailed to the employee. - A clarification: a properly configured BYOD with a corporate profile is technically no different from COPE — the device is under the company's management. But a personal phone with no means of control at all — "probably already a security hole". Organizationally COPE is easier: the device went off to the support desk or for replacement, and from there you can work with it. - The business position is blunt: "There is not a single advantage to BYOD that I know of… Just not one" — and that is "from common sense in general", not only from forensics. The economics: bulk purchasing, a uniform fleet radically lowers the cost of ownership, while a "zoo" requires different training for the specialists; "the cost of hardware, against the annual payroll… is vanishingly small". - COPE — first and foremost uniformity and centralized management, and control is only a part of it. Responsibility for updating the device lies with the company, not with the user: the device is not theirs, and they have no rights to monitor non-obvious incidents. - **The case that became central**: a client with a turnover of more than a billion rubles a year, a client database leak, an office of up to 20 people. The computers are personal, there is no domain, "domain policy… they hadn't even heard of that", and the email is with Mail.ru for some, Yandex for others, Rambler for others. - The key figure had brought his own computer to work with the CEO's permission ("I need a better computer"), and at the collection said he had forgotten the password: "there's no trick against BitLocker". His data was not collected — and as the owner of a personal device he could have refused outright. - A forensic examiner's remark on this: "corporate policies by themselves don't mean they actually work and are configured". - An important piece of methodological advice: before seizing a device you have to understand where the information you want actually lives — often corporate correspondence, backups, email, corporate systems and network shares are enough. - On compliance on personal devices: you cannot fully force someone else's device to obey corporate rules, but there is a compromise — containerization on the phone, confidential information in a container, "at least the mail doesn't wander". At the same time "screenshots can be taken with a camera from any corporate computer", and the very existence of the MDM and EMM market says that "the security guys got bent". - The final position from the business side: for phones BYOD has a right to exist (there is less data there and the risk is lower), for computers — only corporate devices with proper control, "I don't want to slide into absolutism". - **The sanctions case**: a large international company with a "teal culture" had many remote employees on Macs. After the sanctions several hundred computers were left without control — the products to manage them were gone, and some of the machines were personal. Rolling out DLP on a remote Mac is practically unrealistic; with the DLPs available in Russia, on Macs "you have to reboot them four times, disconnect everything, then reconnect it" — "it doesn't work with policies, and even less on BYOD". - **Topic 2 — whether to notify the employee.** The starting point: at some Western companies notification that an investigation had begun was mandatory. - The forensic examiner's answer: "not notifying isn't entirely legal", so the question is the lead time — "about two minutes ahead", at the moment the person comes with their laptop to a meeting with the lawyers and HR, and not a day or a month in advance. - An illustration: a client notified its employees of an internal audit three days in advance, prohibiting the destruction of documents within the scope — "the first thing that greets us is meter-high bags of shredded paper". The comment: "The fence says 'don't' too". - From the same speaker — a question he used to ask at interviews: you know they are coming for you, what will you do? "Many answer: 'I'll delete things'", while the first thing a forensic examiner looks at is exactly what was deleted. Hence the tactic: notify, but in such a way that "maybe a bit of panic kicks in", and then confront the person with the violation of the notice. - The second forensic examiner is personally against notification (an analogy with headlight flashes warning about a traffic police checkpoint), but separates his opinion from the process. His argument — the interference of the analyst colleagues in the notification procedure, after which "you come, and your list of deleted files is longer than the list of remaining ones". - On anti-forensics, stated outright: finding out how to wipe data so that not even residual magnetization on spinning hard drives helps is not hard these days — "what if they delete it properly. Nobody's saying 'dig all you want, we'll find it anyway.' No, unfortunately, reality doesn't work that way". - The conclusion on the topic: you do need to notify — it is part of the business process and a matter of how the person is treated — but the interval has to be one "during which the person can't do anything": they are notified in front of the lawyers and the device is taken straight out of their hands. - The infosec view: for effective DLP monitoring, warning anyone "isn't just unnecessary, it's not allowed". But the technical side devalues the argument: to destroy the contents of a drive four keystrokes are enough — "Win+E, Ctrl+A, Shift+Delete, Enter", and for Linux there are instructions too. - The conclusion from the same speaker: there is no need to choose between "warn or not" if you comply with the law — under the trade secrets law there is a set of documents an employee signs when hired (or re-signs after the fact), and they state in no uncertain terms that the computer may be monitored. "Strangely enough, some laws do work", and there are cases taken all the way to court. - A sobering remark: among the deleted material, "given the level of trust in the impartiality of the authorities", what turns up more often is holiday pictures and "side gigs" rather than stolen data — "people don't actually steal that often". - **Topic 3 — whether to keep a departing employee's device.** The trigger was an account of cases with a "time depth" of eight years, where BitLocker had to be brute-forced on machines eight years old. - The first answer: it depends on the case — "at the job before last my laptop is still in a safe, not wiped", because deleting data can sometimes mean a fine from the regulator that is significant. If there is no intention of going to court and the image has been taken and properly documented, keeping the hardware is not required. - The second answer: an image is always taken, and there is no point in holding the device itself — "you switch it off, the RAM is gone, and we already have the image". The image is kept for at least six months ("law enforcement has it written down"), longer at the client's request; the practice — onto a separate hard drive and into a safe. - The business view: "I don't see why you'd keep the laptop, not the data from it", while the eight-year horizon is explainable — "the statute for especially serious economic crimes is 10 years". - **Topic 4 — proactive versus reactive.** The framing: an ordinary company has to choose between constant monitoring with its own staff and tools and calling in an outside team once an incident has happened. - Business: "it's as if proactive forensics doesn't exist, because forensics is investigation… the term itself is an oxymoron". DLP across the whole organization is unrealistic even for large banks — "substantial costs that don't pay off" — hence focus groups and a step-by-step expansion of coverage, "so you're not just burning money". - A forensic examiner: proactive — prevention and infosec's territory, reactive — mitigation; he himself leans towards reactive, partly because "it's more interesting", since under constant prevention a person "either starts screwing up less or hides the traces better". - The second forensic examiner: proactive forensics — "something strange, like fortune-telling. You can't conduct an investigation in advance without conducting one". What it is about is readiness: knowing where the data you need and the backups are, documenting systems, understanding who is responsible and how to get access — then the reactive investigation goes faster. - A reality check: citing a conversation with a pentester — companies where the rules are written the way the textbook says are "less than 1%". And to the question of how often the data is where it is expected to be, the answer: "Twice in my practice". - An unexpectedly effective practice from the business side: an internal mailing saying "from Monday we're monitoring all of you" — it "significantly reduces potential incidents, at least for a while. Unbelievable, but true. Everyone lies low". - The final recipe: carry out the first two or three points of the e-discovery procedure — identify the information and define where it is located and how it is used — and "any reactive forensics will go like clockwork". The panel's conclusion: "Good reactive forensics still starts with preparation… Including regulatory". ## Tools, artifacts, technologies - **Ownership models**: **BYOD**, **COPE**, a corporate profile on a personal device, **MDM** / **EMM**, containerization of work data, **Intune** as an example of a management system. - **Control and monitoring**: domain policies, **DLP** (continuous and on reasonable suspicion), the restrictions on Macs after the sanctions. - **Obstacles**: **BitLocker**, a forgotten password, the absence of a domain, anti-forensics and wiping data, residual magnetization on spinning hard drives. - **Procedures**: the forensic image and its documentation, storing the image (at least six months, a drive in a safe), **e-discovery** as a framework for preparation, completeness, integrity and reproducibility of evidence. - **Legal**: the trade secrets law and the documents signed by the employee, Federal Law 73 on forensic expert activity, the statutes of limitations for economic offenses, regulator fines for destroying data. ## Legal and organizational context The most legal panel of the conference. Notifying an employee is treated as an obligation — "not notifying isn't entirely legal" — but with the caveat that the company chooses the lead time. The basis for monitoring is derived from the trade secrets law: documents signed on hiring that state that the work computer may be monitored, and a recommendation to have them re-signed if the policies were rolled out after the fact. A corporate investigation is tied to the electronic document disclosure procedure so that the evidence meets the requirements of completeness, integrity and reproducibility under Federal Law 73 — otherwise "it won't be accepted as evidence". Time frames were named too: images are kept for at least six months, with a reference to the practice of the law enforcement agencies, and the eight-year horizon is explained by the ten-year statute for especially serious economic crimes. Separately — the pragmatics: to fire an employee a forensic investigation is not always needed, "it's probably easier to run it through some HR mechanisms". ## Questions from the audience - **1** (name not given, the moderator addresses him as "Igor Evgenievich"): where is the field in which such services are in demand? Small organizations cannot afford an outside team, large ones keep specialists on staff. → Three answers. From the infosec side: 3–4 times a year mid-size companies come in with a few dozen encrypted servers, and "so far, in 100% of cases I've talked them out of it" — there is no point in restoring a fully encrypted infrastructure, and in most cases no point in buying the keys either, "especially now, when it's not encryption but wiping, for geopolitical reasons". From the forensics side: demand goes hand in hand with the document disclosure procedure — you have to know how to properly present electronic evidence to the regulator, to the court and to law enforcement agencies. From the consulting side: what the Big Four does — supporting lawyers in major international arbitrations and corporate investigations whose result goes to court. - There were no other questions: the panel was closed because time was up, the moderator announced the break and reminded the audience about the portal with seven articles by authors from the conference. ## The participants' positions The forensic examiners speak from the position of "what will I get for examination", and both put COPE above BYOD for purely practical reasons; at the same time both admit that configured policies and readiness are rare. The man from the business side is the bluntest of all: BYOD has no advantages, what decides it is the economics of a uniform fleet, and everything comes down to the internal regulations signed by the employee. The general tone — not a vendor one: their own product is not being sold, but they readily tell of failures — the key computer that was not collected, the bags of shredded paper, the hundreds of uncontrolled Macs. The downside of the format: there is almost none of the advertised debate, the participants quickly agree with each other, and the contentious pieces of advice (notify in order to trigger panic; the intimidation mailing) go unchallenged. ## Quotes - "There is not a single advantage to BYOD that I know of… Just not one". - "…as they say, there's no trick against BitLocker". - "The first thing that greets us is meter-high bags of shredded paper". - "Nobody's saying 'dig all you want, we'll find it anyway.' No, unfortunately, reality doesn't work that way". - "Proactive forensics, from my point of view, is something strange, like fortune-telling". - "Twice in my practice".