# Debate “Corporate forensics: arguing about what matters” Nikita Vyugin and guests · MKO Systems MOSCOW FORENSICS DAY ’26 · Day 2 — Friday, 4 September 2026 · Scheduled 11:40–12:10 · In the recording 02:54:17–03:43:37 Talk transcript · https://2026.moscow-forensics-day.workers.dev/en/transcript/08-debate Summary: https://2026.moscow-forensics-day.workers.dev/en/summary/08-debate · Slides: https://2026.moscow-forensics-day.workers.dev/en/slides/07-corporate-forensics · Watch from 02:54:17: https://youtu.be/WuMIv5sFPRs?t=10457 --- ## Moderator's introduction And now we have a somewhat atypical talk, because, as you've already seen in the program, we're going to talk about corporate forensics. But corporate forensics is a rather ambiguous thing. Sometimes you just can't find a single, unified answer. So today my colleague Nikita Vyugin has brought a whole team with him. And we're going to have a live debate here. Friends, I invite you to the stage. Let's give them a round of applause. ## The debate begins: who is on stage Thanks, Dima. So, as Dima rightly pointed out, talking on your own about corporate forensics is hard, ambiguous and rather one-sided. So I decided, or rather we decided that we needed to hold a debate. And so, to hold this debate, I invite our guests to the stage. Let me introduce them. This is Yuri Tikhoglaz. First of all, a man with a long forensic background. Yan Gorodetsky. A man with an equally long forensic past and present. And in order to, let's say, steer, or rather, reason on the topic, of today's debate from the business side, I invite on stage a man with CISO experience, that's probably right to say, and generally with lots of forensics experience from a business standpoint, Anton Antropov. Right. To kick off the discussion, as the first question, I want to tell you a bit of backstory. Not long ago we ran a training course. Not an ad, by the way, but do come. And one of the trainees was a person from the corporate world. And chatting with me in the smoking area, he said an interesting thing. He says, I did your training. It seems like we need to buy a fleet of those phones that are easy to control, and then we'll be sure that at any moment, if an incident occurs, we'll be able to get the information we need. So, our very first topic is BYOD versus COPE. For those not in the know, I'll explain simply. BYOD is when we bring our own: I, as an employee, buy myself a phone and use it for work, among other things. It's my personal phone. COPE is the story where my employer provides me with some device, and I use it. Under COPE, all sorts of personal stuff often gets used too, but in the sense that on work devices we can always find some personal things. So, how do I want to structure our debate? I'd like to ask the forensic examiners first to speak for and against one solution or another, and Anton, as a seasoned man from the business side, to have his weighty say on the subject of what practice shows, what works, what doesn't, what's right and what's wrong, from a practical standpoint. ## 1. BYOD versus COPE So, Yuri, Yan, who wants to go first? Okay, I'll do it differently. Yan, BYOD or COPE? We're looking at this from the standpoint of usefulness to us as specialists. Yes, from the forensic point of view. From a forensic point of view, of course, corporate devices in that regard, I think, come out ahead. Here we come to the fact that corporate devices are easier to obtain for examination, because we don't have to negotiate with the owner, we don't have to convince him that this is necessary, sometimes for him above all, so we simply go on-site to the client, we get the device through the analysts and analyze it, having all the keys, all the access, without running into the questions of enter the code, unlock it, and if you forgot, try to remember. Okay, but from a practical standpoint, let me remind you of the COVID times, when COPE practically disappeared, because a huge number of people went remote and there was a massive problem with people hired with personal devices. So from a practical standpoint, in your practice, Yura, and in yours too, how often did you run into BYOD, oops, COPE, I mean? If you take 10 cases, it's still COPE, probably 7 or 8, and 2 or 3 are BYOD, roughly. Well, that's how it is in my practice. Those are absolutely not the numbers that I encounter. Yura? If we're talking BYOD versus COPE, if it's a properly configured BYOD, then technically it makes no difference, because in the case where a corporate profile is rolled out onto the phone, it's already under the company's management, there's access to it. If it's the situation where the phone belongs outright to the user, and the company has no means of control over it, then that, in principle, is probably already a security hole. Right. From an organizational standpoint, yes. It's easier when it's COPE, because the phone went off to the support desk or for replacement, and from there you can work with it. Okay. Anton, anything to add on this topic so far? Well, I'm afraid there won't be much of a debate here, because, forgive the silly joke, "if he hits you, he loves you" is a whim and a fantasy. There is not a single advantage to BYOD that I know of. Unfortunately, our company has this free-for-all going on, but one day I'll get my hands on the CEO's throat and try to fix this situation. Honestly, there's not a single advantage to BYOD. Just not one. You mean from the forensic point of view? From common sense in general. From the point of view of common sense. Okay, fine. Well, let's even talk money. So what's the advantage of BYOD? You don't have to buy. Buying is the least of it. First, bulk purchasing. Well, the margin there is small, so the benefit is small, but still. We buy in bulk. We maintain a uniform fleet of hardware. That radically lowers the total cost of ownership. I say this as someone who runs into this all the time. Once the zoo starts, Apple, non-Apple, Linux boxes, and, obviously, standard Windows, you need, we were just discussing this before the panel, you need completely different training for the specialists who deal with all of this. And none of that is free at all. And the cost of hardware, against the annual payroll, is vanishingly small. Unless we're talking about Mac Studios for running the AI on. But those aren't personal machines. — So am I right that when we talk in terms of COPE, it's not just some custom, well, basically a more or less chosen fleet of devices, roughly identical, so they're easier to control. With some Intune or some MDM system rolled out on them. So that's what we're talking about here, all of that. Or are there nuances? Well, my colleagues have already covered device control. A corporate device is first and foremost uniformity and centralized management. Control is a part of centralized management. So I'm not adding anything new here. You introduced me as the business guy, so speaking the language of business. First of all, it's simply easier to manage. At the same time, leak control, security functions and so on, they're obviously included in that concept too. And all of it is maintained, roughly speaking, from one place, in the good sense of the word. — Got it. When it comes to investigations, updating and maintaining the device, on the user's side, that is, in the COPE model, whose responsibility? Is it the user's responsibility to update on time when notified, or does the responsibility rest directly with the company? It's not the user's responsibility, because it's not their device, that's a), and b), because they don't have any meaningful rights to monitor any non-obvious incidents. If they get beaten up and their phone is taken, that's a different story. Okay. Anything else to add, maybe? Maybe an interesting case or an example? It's just that, again, I work in the corporate field, and apart from the very largest clients, which are mostly in the central region. Let's say, the banking sector. Very often the request is that, say, here in the Moscow central branch, everything at the head office is covered by their own devices. You start moving away from the center, and in the regions there are own phones, stories about how the admin mailed a laptop to a remote employee, then took it back, passwords changed, all of that changed, and so on and so forth. My point is that overall, for me, unlike Yan, I have a completely different picture, where out of ten corporate company representatives I meet, only three have COPE. Seven, on the contrary, deal directly with BYOD. — Well, I can tell an interesting case on this situation. I already shared it with colleagues on the sidelines. So, not long ago we were at a client's, and for context, the client has a turnover of more than a billion rubles a year. A pretty serious company. And we were doing a collection at one of their offices. As far as I remember, there was a client database leak, and they wanted to know who did it. So we came in, and it turned out to be such a mess it was hard even to look at. I don't even know how to put it, because everyone had their own personal device. A device without any control from the infrastructure, domain policy, they hadn't even heard of that; the computers weren't in a domain. So collecting the devices was complicated by these being the users' personal computers, where they did their business correspondence and kept their documents. And we needed to somehow take them for examination, image them, and then carry on with the case. And we ran into one of the users simply saying: "Here's the computer, but I forgot the password." Have you run into that? At moments like that you realize that... Oh, and the user was a key one, one of the key people. So, at moments like that you realize that with all its inconveniences COPE is still a must-have. Because if you come to a client who has COPE, everything under policies, everything is great, then, not counting the time spent getting access approved, everything is done almost instantly. But in a situation like the one we got into at this client, well, we tried to solve the issue on our own somehow, that is, we tried to look for workarounds, but in the end nothing worked, because, as they say, there's no trick against BitLocker. So unfortunately we didn't collect one of the key characters at that point. And potentially, since it was his personal device, he could have simply said "no". Yes, it's his personal computer that he brought to work, because he, well, he had the option to take some basic corporate device, but he said: "I need a better computer. Can I bring my own?" The CEO told him: "Sure, no problem." It's a small office, up to 20 people. And said: "Yes, please, go ahead and use your own computer." The IT department there didn't object at all; it consists of one person. And he calmly did all these corporate operations on his own computer. Well, of course, he was apparently against it, as we understood. And so he completely cut off all our paths to getting data from that computer. — Got it. Colleagues, anything to add on the question? Well, in support of the previous speaker. Unfortunately, corporate policies by themselves don't mean they actually work and are configured. It's banal and obvious, but I can't help saying it. I'm a security guy. And regarding this whole BYOD story. I think it's more a consequence of that whole COVID story, when even in large companies people started working from personal devices, connecting to some VMs or VDS boxes, using personal devices. Again, as lawyers say, it depends. It depends on what's being examined. What needs to be obtained. And if the scope is only corporate systems, do you even need to seize that device? Do you need access to it? And if you can, for example, get access to corporate correspondence, messengers and so on. There are always alternative ways to get the information you want. It could be backups, if there are any. It could be info from email. It could be information from corporate systems, network shares and so on. So, the device, sure, the device, but first you need to understand where the information we want to get and need to analyze actually lives. Yes, a micro-comment. They also had email there. Whatever anyone felt like. Mail.ru, Yandex, Rambler. Whatever each person used, they used. Multi-billion turnover, 20 people. Yes, yes, yes. That's a Russian thing. Yeah, we walked around like this for a week afterwards, just facepalming. And still, to wrap up the BYOD versus COPE topic, again, from my side I see BYOD prevailing so far, again, from my side, that's subjective experience, and nevertheless, giving this system one last chance, or however you'd put it, this policy, overall, would it be right to say that if... If we apply a BYOD policy to our employees, then full compliance with any standards, whatever they may be, is something we can hardly guarantee in reality, in practice. Or are there still some... You mean technical compliance, forcing a person on their own device to obey strict corporate rules? Yes, yes, yes, yes. Well, obviously there are a number of systems that let you substantially restrict the spread. For example, within the device. So I'd say it's a kind of compromise, because if laptops are bought for people as a means of production, a phone is more of an auxiliary thing, because it doesn't let you generate content well and so on, but it does let you very quickly reach an employee, even when they're on vacation, I know that from experience. So phones rarely get replaced, let's be honest. I don't run into that often either. Computers are most often corporate. And why am I saying this? Because installing MDM systems, or EMM, whatever, marketing is everything, marketing, sorry. It's a reasonable compromise when containerization is put on the phone, well, not Docker-style, but accordingly, confidential information is stored in some container. That seems a decent approach, at least the mail doesn't wander. Screenshots. Well, screenshots can be taken with a camera from any corporate computer. I'm not really against it, as it were. The systems exist, the market exists. Which tells you that one way or another, the security guys got bent. So apparently it's not all that scary. But for phones, for computers, for those machines where really large volumes are stored, which is wrong in itself, but you can go far down that road. I don't think that's right. On a computer you can do anything. On a phone too, of course, but less is stored there. The risks are lower. Roughly, it has a right to exist in a corporate environment for phones, but for computers definitely not, only corporate devices with proper control. Right? I don't want to slide into absolutism. Yes, I get it. It's just that from personal experience there was a case. One large organization had a lot of remote employees, including before COVID, because of, what's it called, a teal culture, the computers were often Macs. And when the sanctions hit, that entire hardware fleet ended up without control. Well, because the organization is large, it's international. And you couldn't violate technical compliance. Nor legal compliance. Several hundred computers were simply left orphaned, because there were no products to control them. Some of them were BYOD. Rolling out DLP on them was practically unrealistic, because forcing a remote employee, well, that's a separate task. The DLPs available in Russia for Macs that were abroad, the Russian ones, obviously, because of the same compliance issues, they don't work on Macs. I mean, Russian ones, Chinese ones, you have to reboot them four times, disconnect everything, then reconnect it. So, in short, it doesn't work with policies, and even less on BYOD. So it looks more like some kind of shamanic dancing. So the phone is a necessary evil, as I said. There isn't that much info on it, though mail is important of course, but it's in a container, at least. So, absolute protection doesn't exist, we all know that, I don't need to tell you. But as I said, some kind of reasonable compromise seems to be visible. There's probably room for debate here. Yura, Yan, want to add anything? ## 2. Should you notify an employee that an investigation has begun Well, overall, a compromise, we agree. Okay, the second important topic, one I've only run into a couple of times in my practice. Or rather, our users, or people in the hallways, told me about all sorts of interesting nuances. And the topic for discussion: whether or not to notify an employee an investigation has started. So on the one hand this is a philosophical and moral thing, on the other an absolutely practical thing. And, having talked to people from Western companies that left Russia at some point and stopped operating here, some of them had a practice of mandatory notification that an investigation involving them had begun. I'd like to hear your thoughts on this, for and against. Well, obviously I can churn out the "against" right away. Are there any potential arguments for notifying an employee when an investigation is initiated against them? — Let me start, I suppose. Go ahead, Yura. First of all, if you do notify, how far in advance? Because, properly speaking, not notifying isn't entirely legal. About two minutes ahead. Right. But you can notify them at the moment they come with their laptop to a meeting with the lawyers, I don't know, the HR director and some management, or you can notify them a day or two in advance, for example, or a month. — A case from practice. We arrive at a client who received a notice of an internal audit three days earlier. That notice states that employees are prohibited from destroying documents and information relating to a certain scope. The first thing that greets us is meter-high bags of shredded paper. — The fence says "don't" too. Yes. Paper that says it must not be destroyed. On the other hand, my favorite interview question for the people I used to hire was this: "You know they're coming for you. You're about to go to a meeting and they'll take your computer, which has hot stuff on it. What will you do?" Many answer: "I'll delete things." What do they look at first? A forensic examiner, getting a device in hand, looks at what was deleted. So to notify or not to notify, again, depends on the case we're investigating. Most often, probably, notify, but with the shortest possible lead time, so that maybe a bit of panic kicks in. So that some of those rash actions happen. And then, after that notice, you confront the person with: "Well, dear comrade, right here you violated that notice. Such-and-such data was deleted. Please explain why." — You're a dangerous man, Yura. Outdated. — Yan, anything on this? Well, it's hard to argue here. So, on the one hand, a lot of drivers may hate me for this now, but I believe: follow the rules, live honestly, don't break anything, and you won't need headlight flashes about a checkpoint. So in that sense I think you shouldn't notify the person at all, but that's only my opinion, it doesn't apply to the process. I'll say more about that in a moment. For one simple reason. When you try to build the notification process properly, as a rule, the people working the case together with you get into the game. That is, for example, analysts may be working with us forensic examiners, and they have their own view on this, which very often, to some extent, harms a proper investigation. Because, as Yuri already said, then you come, and your list of deleted files is longer than the list of remaining ones. Yes, it's clear that the anti-forensics issue in any given case may be tiny, but you can't rule it out, you especially can't rule it out under a bring-your-own-device policy, especially if it's all somehow badly, let's not even say badly, just not configured. Now, in the digital age, with our neural networks, it's quite easy to find out how to wipe all the data, all the deleted data, so that afterwards, even by residual magnetization on spinning hard drives, it can't be recovered. That's not hard these days. So such moments need to be constrained. What time frame is reasonable? Well, one in which the person really can't get started on any deleting. That is, literally: you've come in, sat down with the lawyers, the analysts, notified them, took the device, so they hand it over right in front of you. Because if you give them a chance to delete something, what if they delete it properly. Nobody's saying "dig all you want, we'll find it anyway." No, unfortunately, reality doesn't work that way. I believe you need to notify within a really, really short time frame, but on the other hand, from a human point of view, the employee must be notified in any case, because it's part of the business process, especially if our forensics isn't spontaneous but some sort of preventive one, then the person definitely has to be notified. And if it's spontaneous, it's stress in any case, for employees, and if the employee has nothing, if they're good, why make them suffer and go through that moral torment. So I think you do need to notify, but you absolutely have to build in that time window during which the person can't do anything. — Anton, anything to add? I really do have something to say. But first, a question. Employee tied up? Good. Seriously, though, what kind of investigation case are we talking about? Because a lot depends on that. I'm not involved in computer forensics, I'm a general-purpose CISO, so to speak. And even that's more in the past by now. But as we know, there's no such thing as a former one. In my practice there were cases with DLP. DLP, if we can count it as a case here, is continuous monitoring. Or it's monitoring that starts on some reasonable suspicion. And for it to be effective, it's completely obvious warning anyone isn't just unnecessary, it's not allowed. Colleagues said that. But come on, if we're talking Windows: Win+E, Ctrl+A, Shift+Delete, Enter. That's all it takes to destroy a hard drive. Shift. I can write up instructions. For Linux too. Not for Mac. So what am I getting at with all this? To the point that for all this to work, and for there to be no need to choose whether to warn, like, you get it, crow, the question of giving up the cheese doesn't arise. You need to comply with current legislation. If I remember the trade secrets law correctly, there's a set of internal regulations an employee has to sign when they're hired. Or, if we're rolling out the policies after the fact, we go around and get all those documents re-signed. They spell out perfectly clear things, requirements: how you may and may not use it. And it's stated in no uncertain terms the computer may be monitored. So there's no need to remove anything, just do everything as the law says. Strangely enough, some laws do work. And there are cases, cases successfully taken all the way to court, I mean, well, if you're interested: two young guys were on their way to success, stealing subscriber data and selling on the side, and when it got to court, it took effort, serious effort. It was in the regions, quite a while ago, admittedly. In short, they were offered a fine or probation. They said, "We've got no money," took probation. Well, everyone who gets the difference realizes that was the wrong choice. Now, as for deleting files, just as a detached comment, it seems to me that in most cases, given the level of trust in the impartiality of the authorities, among the deleted stuff we'll find photos, if not home videos then holiday pictures, and maybe some side gigs, that the person just doesn't want to show, like "I did a little freelance job on this computer." People don't actually steal that often. I'll leave it there. ## 3. Should you keep a departing employee's device Okay. Before we move on... Yuri, Yan and Anton all touched on a story that leads into the next question. The only thing that remains a question in this format is notifying or not notifying, but overall it's probably not even about that. So, we've had an incident. We've figured it out, the employee is at fault, we're firing them. Does it make sense, and I'll explain why after, to keep their device, not wipe it and hand it to the next employee, but store that device for some time, because last year a man came to me and said he had cases from a corporate financial environment going back 8 years. That is, he's got that time depth, he's got a number of devices where the investigation was supposedly finished, but then something happened, and it turned out to be connected, and he had to bruteforce BitLocker on machines eight years old. I don't know how it ended, it's very interesting, but in general: you've finished the investigation, you wipe it and hand it to the next hire, or does it still make sense to bury it somewhere for a while, or back it up? If anyone has thoughts on this, go ahead, Yuri. Depends on the case, because I know, for example, that at the job before last my laptop is still in a safe, not wiped. Simply because there are situations where deleting data like that can, among other things, mean a fine from the regulator that's significant for the company. If we understand we're never going to court over this particular employee, and the information is preserved in a forensic image that's properly documented, then maybe we don't need to keep it. Well, from my side I'll add: in any case, at least in my work, we always create an image of the device. So keeping the device itself, just holding it in a safe and not handing it on to the next employee, I don't see much point, we won't extract anything more from it. You switch it off, the RAM is gone, and we already have the image, so that's it, nothing left in it. So the image needs to be kept for a certain amount of time, law enforcement has it written down, we also try to keep it all six months. And again, as Yuri said, it depends on the case. Some cases, where clients ask us to keep the images longer, on the assumption that in the future this may be connected to some other matters as well. The image is stored by practice, that is, best practice is onto a hard drive and into a safe, and let it sit as long as needed. Anton, anything to add? Well, honestly, I don't see why you'd keep the laptop, not the data from it. Maybe there are cases I'm not aware of. As for 8 years: the statute for especially serious economic crimes is 10 years, so it makes sense. Okay, got it, thanks. ## 4. Proactive forensics versus reactive And now, what we've already started touching on in passing. Proactive forensics versus reactive forensics. What to bet on? Why "what to bet on"? Because, unfortunately, in the real world, very often in companies that aren't big IT or financial giants, people have to choose. Either we bet on monitoring everything all the time, surrounding ourselves with tools, and, well, by then there's nothing important left there anyway. Broken? — Some technical glitches, never mind. So the first option: we monitor all the time and are constantly in a state of readiness, while keeping a stock of tools, and a staff of people who service all this, watch it, collect, analyse. Or the second option: an incident happens, and either on our own or with hired teams, well-known ones, some of whom I know are here, we call them and say, "Mate, I'm in trouble, come and help, I'll pay." One doesn't rule out the other, we all get that basically, but overall, the case for reactive and for proactive forensics. When is one better applied, and when the other? Bearing in mind that we don't live in an ideal world and the budget isn't unlimited. Anton, you're smiling very slyly, go on, I can see it. Well, I just like to talk, I think everyone's figured that out by now. It's as if proactive forensics doesn't exist, because forensics is investigation. It can't be proactive, the term itself is an oxymoron. But, again, from personal practice: covering the whole organisation with DLP is unrealistic, because even for large banks these are substantial costs that don't pay off. So yes, obviously, you need to narrow it to focus groups and so on, and that can probably count as some kind of proactive practice. In general, I think that in the real world it makes sense to act incrementally, as always, step by step. — First cover a small number of people, then, if necessary, if you can clearly see problems are happening, expand the coverage, so you're not just burning money but delivering real benefit, obviously. There was one more thought, I've forgotten it, I'll come back to it. Yan, from your point of view? Well, I think that, as Anton said, proactive forensics is really something from infosec, because it's closer to prevention. Whereas reactive forensics is already, you might say, mitigation. So if we go back to the whole point of the forensics procedure, I lean towards reactive here, because, first of all, it's more interesting. Because if a person is constantly in prevention mode, they either start screwing up less or hide the traces better. That's not interesting. Like, you look into the computer, and there's less there than there could be. So, in my practice, there simply is no proactive forensics, because when the next case comes along, we grab the equipment and run off to extract data. That is, we run specifically to look at what happened, where it came from, why it happened at all, who's to blame. As for prevention, I think that's more something the infosec folks deal with, or some separate, dedicated department of in-house forensic examiners, or maybe someone uses outsourcing for this. So it's more, as I said, a matter of information security inside the company. Overall, yes, the question isn't quite right, I probably didn't phrase it correctly. What I meant was the story of preliminary and ongoing collection of information for the purpose of prevention and, let's say, essentially, prophylactic, to understand where an incident might potentially start. Not when it's already happened, and you've been called in and you run to extract. Exactly, that's closer to infosec, indeed. Yes, here the tasks of proactive examiners would be very similar to how a DLP system works. Yuri? Proactive forensics, from my point of view, is something strange, like fortune-telling. You can't conduct an investigation in advance without conducting one. Here it's probably more a question of readiness to conduct investigations. That is, understanding where the data is that you'll have to work with if something happens. Backups of the information on computers, corporate systems. And an understanding among employees, IT people, security guys, of what to do when an investigation is needed. — Right now this seems to sit on the side of having regulations ready and monitoring users' compliance with those regulations. Documenting systems. Yes, understanding where the information you'll need is located, who's responsible for that information, how to get access to it. Then, when the need arises for reactive forensics, everything goes somewhat faster and easier. That's really what it's about. Reactive forensics goes easier, than... If the client has done a certain amount of preparatory work so these investigations can be conducted. I'll be honest, from my own subjective experience, this now sounds like Alexander Dmitriev's take when we were sitting at that meetup. And he says, "Look, in general, it's all written down, there are golden rules." And I asked him in reply, I said, "Sasha, how many companies in your whole life and in your work as a pentester have you seen that had these written, where the rules were written by the Golden Book?" He answered: less than 1%. And my point is, about what you're saying, we should know, and we should have procedures for responding to an incident. That's clear. How often is expectation, well, expectation vs reality, how often is the data actually where we expect it to be, especially if it does turn out to be an incident? Twice in my practice. — Well, there's your answer. You're a lucky man. A lucky man indeed. On that, I've remembered a thought. On proactive defense, or rather proactive forensics, whatever you call it. The intimidation approach works relatively well. It's a very controversial approach in itself, but an internal company-wide mailing saying, guys, from Monday we're monitoring all of you, significantly reduces potential incidents, at least for a while. Unbelievable, but true. Everyone lies low. Yes, that's a well-known thing. Well then, do you have anything else to add? Just a small aside about how best to live so that even reactive forensics gives greater results. You started discussing this with Yuri. You don't have to look far, we have this wonderful procedure called e-discovery. There are the first two or three points there, it's enough to follow them, and any reactive forensics will go like clockwork, if those points are carried out properly and precisely. That is, we will clearly define the information, identify it and define the scope of where it's used and located. And everything will be fine. Good reactive forensics still starts with preparation. — Absolutely. Including regulatory. ## A question from the floor and the close of the debate Dima, tell me please, do we have a Q&A section in this? If anyone has questions, we'll gladly let our guests answer. Anything to add, Igor Evgenievich? — I have a question for your guests along these lines. What is the field of application of their knowledge, their services? Well, obviously, small organizations simply can't bring you in to solve their problems and will solve them themselves. And big ones, like Sber, they can just buy specialists themselves, that's exactly what they do. A level of qualification sufficient to avoid bringing in outsiders. If I may, where is the area in which you feel you are in demand? If we broaden forensics to include external attacks, then personally I talk three or four times a year to companies, let's say, if not small, then mid-size, I'm not ready to throw out figures, I won't go into detail. These are small infrastructures, a few dozen servers that got encrypted, for example. They come and tearfully beg for help recovering and figuring out the causes. So far, in 100% of cases I've talked them out of it. Because there's no point in trying to restore a 100% encrypted infrastructure. In most cases there's no point trying to buy the keys. Especially now, when it's not encryption but wiping, for geopolitical reasons. So the question could, I'd say, be broadened. Who needs this and what to do. But here I'll hand over to more specialized colleagues. In my practice forensics, digital forensics specifically, goes hand in hand with the discovery procedure, for one simple reason. Because the electronic document disclosure procedure isn't as developed here as in the West, but still. Why? Because you need to know how to properly present electronic evidence to the regulator, to the court, at the request of some law enforcement agency, and so on. So in a corporate investigation we use the algorithms of the discovery procedure in order to ensure something like, probably, the points of Federal Law 73 on forensic expert activity. That's completeness, integrity and, probably, reproducibility, because if we present evidence unsubstantiated, it won't be accepted as evidence. Fulfilling these points lets us give our analysts a full-fledged report they can take anywhere. So we currently exist at the junction of these two fields, in this way, even given the current situation. And still, to answer your question, who needs this and why: what, for example, the Big Four companies do, is supporting clients in, say, major international arbitrations. There the clients are, say, lawyers in major international arbitrations, or, for example, corporate investigations, also in large companies, where the result is also submitted to court in one form or another. Because to fire an employee, conducting a forensic investigation doesn't always make sense. It's probably easier to run it through some HR mechanisms. And sometimes it's easier to just fire them. Yes, like that. — Thank you very much. Nikita, we're out of time. Got it. Thank you very much. Yuri, Yan, Anton, thank you so much, it was interesting. If there are any questions, we're still here for now. Thanks. Thank you all. Colleagues, I have a small announcement. Now we'll take a break and come back to the hall at 1:10 p.m. Meanwhile you can grab a bite, have a smoke. I also remind you about the booth area. And now we'll put up a QR code. That's the information portal Valeria Mikhailovna told you about yesterday. Here you can find articles by authors who, basically, took part in our conference. There are a full seven of them. And also, if you're a client of MKO Systems, you can get extended access to the portal, where there'll be our articles, training videos and also test cases that you can use both for training and simply for investigation. Have a look, play around. Please.