CDFS is Australia and New Zealand’s premier and most trusted supplier of digital forensic tools, training and certification. Our team of specialists provide innovated solutions to clients across numerous sectors throughout Asia Pacific, as well as Law Enforcement and Government panels across ANZ.

Certified with relevant industry qualifications including Certified Computer Examiner (CCE), X-Ways Professional in Evidence Recovery Techniques (X-PERT), EnCase Certified Examiner (EnCE), Cellebrite Certified Physical Analyst (CCPA), and Data Recovery Expert Certification, CDFS is a leading specialist in the identification, preservation, analysis, and management of digital evidence.

CDFS is at the forefront of providing end to end digital forensic solutions in Australia and New Zealand.
Our digital forensic experts have experience in a range of matters involving ESI, including:

  • Intellectual property (IP) theft
  • Employment disputes
  • Family law
  • Fraud
  • Expert testimony for Family, Magistrates, Supreme and
  • Federal Courts
  • Government agencies, Law Enforcement, and regulatory bodies, including assisting with the execution of Search warrants.

We specialise in providing the following services for our clients:

  • Planning, intelligence gathering, and case preparation
  • Identification, preservation and management of digital evidence
  • Forensic data collection
  • Processing and Forensic analysis
  • Data conversion
  • Reporting and presentation
  • eDiscovery services
  • Secure data hosting and hosted review services
  • Additional resource services to supplement existing digital forensics teams
  • Lab accreditation and proficiency testing

Our facility in Canberra includes two secure digital forensic laboratories, including safes and a secure enclosed cage, for the recovery, analysis, and storage of electronic evidence. Our team employs robust, repeatable, defensible procedures. We undertake a rigorous end to end process for all matters, ensuring the highest level of professionalism, risk mitigation, and compliance with standards. We use a consistent, phased approach to our workflow & capabilities.


Our specialists take the time to understand the client’s needs to ensure we recommend the most practical solution. We ascertain whether the client qualifies for the requested services, including identifying any potential conflicts. Please note; our standard procedure is a one hour consultation service before undertaking any engagements.

Engaging CDFS

We provide an official request for services form, which details the basis for our Letter of Engagement; setting out the scope of works, indicative costs, and our terms and conditions. Please note; our standard procedure for engagements is a minimum 10 hour retainer to be paid in advance.

Identification and preservation of ESI

Our team’s diverse background in information technology, corporate and enterprise environments, advisory, Government, and banking sectors, provides a unique combined skill set for the identification and preservation of ESI. We help our clients to identify, isolate, and collect electronic evidencefrom a variety of data sources, regardless of scale or locale. We specialise in collecting evidence from a wide range of repositories; from desktops, laptops, mobile devices and servers, to web, database, large scale storage, archive, virtual, and cloud based environments. A preliminary discussion regarding the potential sources of ESI is included in the initial one hour consult.

Processing and analysis

We employ a tool agnostic philosophy, leveraging the strong relationships we have built with vendors, to ensure the right tools are used for the right matter, with access to a high level of support as required throughout any engagement. Forensic analysis our team specialises in includes, but is not limited to:

  • Indexing and keyword searching of documents and emails
  • Artefact analysis such as Internet History, recent user activity,
  • Registry analysis, and log file analysis
  • Timeline analysis
  • File system analysis
  • Network forensics
  • Mobile/smart device forensics
  • Security systems such as cameras and DVRs

Reporting and expert testimony

Our expert has over 10 years’ experience providing testimony in civil and criminal trials in the Family, Supreme, and Federal Courts, at hearings, arbitrations and depositions on numerous matters. He also provides training to investigators nationally and internationally, on matters involving digital forensics and eDiscovery.
He is familiar with and adheres to the duties and responsibilities of an Expert stated in various courts’ codes of conduct, and court rules and guidelines, including:

  • Practice Note CM7 – Expert witnesses in proceedings in the Federal Court of Australia
  • Supreme Court Expert Witness Code of Conduct (UCPR 2005 Schedule 7)

His qualifications include; Masters of e-Forensics and Enterprise Security, Diploma of Government Investigations, Diploma of Security & Risk Management, Certified Computer Examiner (CCE), IACIS Certified Forensic Computer Examiner (CFCE), Certified Computer Hacking Forensic Investigator (C|HFI), and is a certified INTERPOL Computer Forensics TT Instructor. He is also an International Assessor – American Society of Crime Laboratory Directors Laboratory Accreditation Board (ASCLD/LAB),and a Technical Assessor – National Association of Testing Authorities, Australia (NATA).

Hosted review

We increase the efficiency of your team, by giving them the ability to:

  • Access documents from any device, anywhere, 24×7.
  • Assign documents to pools of users.
  • Control access levels of your legal team on a need-to-know basis.
  • Download documents without slowing other team members down.
  • Track the overall progress of the review.
  • Eliminate multiple reviewing of the same document.
  • Share searches across the review.
  • Easily see and jump to linked documents, such as email attachments.
  • Read redacted text before it is permanently burned on.
  • Tag privileged documents