Police Are Mishandling Digital Forensic Evidence

Police officers are trampling over vital forensic evidence, are under-trained, and often do not know what they are looking for, MPs investigating digital disclosure problems have been told.

Giving evidence to a justice select committee inquiry into failures to hand over material that have led to multiple court cases collapsing, leading digital forensic experts warned of funding shortfalls and inadequate skills.

“One of the problems is the sheer amount of digital evidence the police have to look at,” said Dr Jan Collie, of Discovery Forensics, who specialises in defence work.

“You have to consider the cloud [for digital storage], too. There’s evidence everywhere. With cuts in funding, officers don’t have the time to do all that.

“When I first started, the police had their own digital forensic units and knew what they were about. Now you are getting very sketchy evidence. People give me screenshots of pictures of a phone. I need to see [a copy of the] original, be able to repeat and verify tests.”

Police forces do not have sufficient resources, she added: “When they have the people, they haven’t got the money to send them on courses.” Officers do not always understand the context of where digital information is found – whether it has been inadvertently hoovered up through a browser or purposefully searched for, Collie said.

“A lot of police stations have mobile phone extraction kiosks where they put a mobile phone in and press a couple of buttons, but it’s not enough analysis. A police officer who has been trained for about a day can use the equipment. He can click it in and handle the buttons, but often they spoil the evidence by mishandling. It’s like they have trodden on the evidence. Interpretation of data is being carried out by ordinary officers – they are not trained to do it.”

Many recent cases that collapsed involved rape charges where crucial text message exchanges were either missed by investigators or only released belatedly. 

Prof. Peter Sommer, an expert witness in digital forensics cases, told MPs: “These kiosks are designed for preliminary inquiry, to see if it is worth pursuing. They don’t really produce reliable evidence. 

“It’s cherry picking. The posh phrase is confirmation bias. It’s got worse because the volumes you have to deal with have got much greater. These tools have deskilled [people]. Unless you know what you are looking for, the results can be very misleading.”

He also pointed out that underfunding of the criminal justice system was leading to many digital forensic experts to quit. “People are ceasing to do it because it’s uncompetitive,” he said. “In criminal work, it’s £72 an hour. If you work for civil case clients, it’s £250 an hour.”

Dr Gillian Tully, who is the official forensic science regulator, told the committee: “Police digital forensic units are quite good at extracting information and making copies. They then pass copies to the general police, and investigators don’t necessarily have the tools to search the information or make good use of it.” 

Tully has called for additional funding for forensic science, adding: “When it comes to legal aid funding, it’s largely awarded to the business with the lowest quote – which is not helpful for quality.” 

Sommer suggested one way to solve disclosure failures would be for all the digital material to be handed over to the defence. But Rebecca Hitchen of charity Rape Crisis, told the committee that disclosure of highly personal evidence often leads to victims refusing to testify, particularly in sexual assault cases.

“When a complainant learns of the level of intrusion into their lives, they often decide it’s not in their best interest to continue,” she said.

“There’s incredibly high levels of withdrawal [from police investigations around the issue of personal history, for example if someone had an abortion at an earlier stage and the police can’t give an assurance that it won’t be revealed. The sensation of sex crime survivors is often that they are being put on trial.”

College of Policing:      Guardian:         Met Police

You Might Also Read: 

UK Police Give Cybercrime Warning:

Terrorists Deploy New Techniques To Counter Digital Forensics:

« Terrorists Deploy New Techniques To Counter Digital Forensics
Bank of England CIO Sets A Cybersecurity Challenge »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Mielabelo

Mielabelo

Belgian consulting firm providing services in the security and compliance of information systems and IT service management.

Portnox

Portnox

In 2007, Portnox set out to create one of the world’s easiest to use, most loved, value-driven network security solutions — and our customers will tell you we’ve succeeded.

SOTI

SOTI

SOTI is an industry leader in Enterprise Mobility Management (EMM).

AhnLab

AhnLab

AhnLab provides a range of information security solutions including network security, endpoint security, antivirus and consulting services.

International Federation of Robotics (IFR)

International Federation of Robotics (IFR)

The International Federation of Robotics connects the world of robotics around the globe. Our members come from the robotics industry, industry associations and research & development institutes.

StrongKey

StrongKey

StrongKey (formerly StrongAuth) is a leader in Enterprise Key Management Infrastructure, bringing new levels of capability and data security at a price point significantly lower than other solutions.

Vehere

Vehere

Vehere specialises in mission critical signals aquisition and analytics platform and cyber defence systems.

NFIR

NFIR

NFIR is a specialist in the field of cyber security incident response and digital forensics.

Southwest Research Institute (SwRI)

Southwest Research Institute (SwRI)

Southwest Research Institute SwRI are R&D problem solvers providing independent services to government and industry clients. Areas of expertise include Cybersecurity, Intelligent Networks and IoT.

Trusona

Trusona

Trusona is a pioneer and leader in passwordless two-factor authentication (2FA).

Coviant Software

Coviant Software

Coviant Software delivers secure managed file transfer (MFT) software that integrates smoothly and easily with business processes.

Rocky Mountain Cybersecurity

Rocky Mountain Cybersecurity

Rocky Mountain Cybersecurity's mission is to provide value by dramatically improving the cybersecurity posture of our clients and business partners.

Acora

Acora

Acora provide a range of best-in-class managed services, Microsoft-centric business software, and cloud solutions designed to help mid-market organisations succeed in the digital economy.

Oxeye

Oxeye

Oxeye fills the gap between cloud and code to show exploitable vulnerabilities, and their path from API to code. More visibility. Less noise. More time to build.

SeeMetrics

SeeMetrics

SeeMetrics is an automated cybersecurity performance management platform that integrates security data and business objectives into a simple interface.

Bores Security Consultancy

Bores Security Consultancy

Bores Security Consultancy are an established family-run business delivering expertise in security and technology.