Police Are Mishandling Digital Forensic Evidence

Police officers are trampling over vital forensic evidence, are under-trained, and often do not know what they are looking for, MPs investigating digital disclosure problems have been told.

Giving evidence to a justice select committee inquiry into failures to hand over material that have led to multiple court cases collapsing, leading digital forensic experts warned of funding shortfalls and inadequate skills.

“One of the problems is the sheer amount of digital evidence the police have to look at,” said Dr Jan Collie, of Discovery Forensics, who specialises in defence work.

“You have to consider the cloud [for digital storage], too. There’s evidence everywhere. With cuts in funding, officers don’t have the time to do all that.

“When I first started, the police had their own digital forensic units and knew what they were about. Now you are getting very sketchy evidence. People give me screenshots of pictures of a phone. I need to see [a copy of the] original, be able to repeat and verify tests.”

Police forces do not have sufficient resources, she added: “When they have the people, they haven’t got the money to send them on courses.” Officers do not always understand the context of where digital information is found – whether it has been inadvertently hoovered up through a browser or purposefully searched for, Collie said.

“A lot of police stations have mobile phone extraction kiosks where they put a mobile phone in and press a couple of buttons, but it’s not enough analysis. A police officer who has been trained for about a day can use the equipment. He can click it in and handle the buttons, but often they spoil the evidence by mishandling. It’s like they have trodden on the evidence. Interpretation of data is being carried out by ordinary officers – they are not trained to do it.”

Many recent cases that collapsed involved rape charges where crucial text message exchanges were either missed by investigators or only released belatedly. 

Prof. Peter Sommer, an expert witness in digital forensics cases, told MPs: “These kiosks are designed for preliminary inquiry, to see if it is worth pursuing. They don’t really produce reliable evidence. 

“It’s cherry picking. The posh phrase is confirmation bias. It’s got worse because the volumes you have to deal with have got much greater. These tools have deskilled [people]. Unless you know what you are looking for, the results can be very misleading.”

He also pointed out that underfunding of the criminal justice system was leading to many digital forensic experts to quit. “People are ceasing to do it because it’s uncompetitive,” he said. “In criminal work, it’s £72 an hour. If you work for civil case clients, it’s £250 an hour.”

Dr Gillian Tully, who is the official forensic science regulator, told the committee: “Police digital forensic units are quite good at extracting information and making copies. They then pass copies to the general police, and investigators don’t necessarily have the tools to search the information or make good use of it.” 

Tully has called for additional funding for forensic science, adding: “When it comes to legal aid funding, it’s largely awarded to the business with the lowest quote – which is not helpful for quality.” 

Sommer suggested one way to solve disclosure failures would be for all the digital material to be handed over to the defence. But Rebecca Hitchen of charity Rape Crisis, told the committee that disclosure of highly personal evidence often leads to victims refusing to testify, particularly in sexual assault cases.

“When a complainant learns of the level of intrusion into their lives, they often decide it’s not in their best interest to continue,” she said.

“There’s incredibly high levels of withdrawal [from police investigations around the issue of personal history, for example if someone had an abortion at an earlier stage and the police can’t give an assurance that it won’t be revealed. The sensation of sex crime survivors is often that they are being put on trial.”

College of Policing:      Guardian:         Met Police

You Might Also Read: 

UK Police Give Cybercrime Warning:

Terrorists Deploy New Techniques To Counter Digital Forensics:

« Terrorists Deploy New Techniques To Counter Digital Forensics
Bank of England CIO Sets A Cybersecurity Challenge »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 8,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Tines

Tines

The Tines security automation platform helps security teams automate manual tasks, making them more effective and efficient.

OpenSphere

OpenSphere

OpenSphere is an IT company providing security consultancy, information system risk management and security management services.

Australian Cyber Security Growth Network (AustCyber)

Australian Cyber Security Growth Network (AustCyber)

AustCyber brings together businesses and researchers to develop the next generation of cyber security products and services.

Nuvias Group

Nuvias Group

Nuvias Group is a specialist value-addedd IT distribution company offering a service-led and solution-rich proposition ready for the new world of technology supply.

Ntrepid

Ntrepid

Ntrepid products provide protection from web threats and enable organizations to safely conduct their online activities.

National Cyber Security Authority (NCA) - Saudi Arabia

National Cyber Security Authority (NCA) - Saudi Arabia

The NCA is the government entity in charge of cybersecurity in Saudi Arabia and serves as the national authority on its affairs.

FRSecure

FRSecure

FRSecure is a full-service information security management company that protects sensitive, confidential business information from unauthorized access, disclosure, distribution and destruction.

Cyberstarts

Cyberstarts

Cyberstarts’ vision is to become the leading platform for amazing teams of entrepreneurs to solve the next big problems of the cybersecurity world.

Conatix

Conatix

Conatix was formed to apply recent advances in AI and other fields of technology to insider fraud, one of the most intractable problems in cybersecurity.

SecureAge Technology

SecureAge Technology

We’re a rapidly growing cybersecurity company with an 18-year history of ZERO Data breaches. Our security solutions place security and usability on equal footing. Learn more about our technology.

SynSaber

SynSaber

SynSaber is a data collection, detection, and visibility solution that forms the foundation of industrial cybersecurity.

Trenton Systems

Trenton Systems

Trenton Systems are committed to providing high-performance computing solutions to customers running mission-critical applications in harsh settings worldwide and across various industries.

Digital Intelligence

Digital Intelligence

Digital Intelligence offer a full array of products, forensic and e-discovery consulting services and training.

One82

One82

Serving emerging small and medium-sized businesses in California and neighboring regions for over 20 years, One82 has established itself as the most dependable provider of IT support services.

Board of Cyber

Board of Cyber

Board of Cyber offers Security Rating: a fast, non-intrusive, continuous, 100% automated solution to evaluate the cyber performance of an organization.

CHERI Alliance

CHERI Alliance

CHERI Alliance is an industry initiative spearheading the global adoption of the Capability Hardware Enhanced RISC Instructions (CHERI) security technology across the computing industry.

CyberSentriq

CyberSentriq

CyberSentriq provides an unmatched combination of proactive AI-driven email and web security, advanced data protection, and operational resilience.