Cyber Forensics Explained: Investigating the Digital Crime Scene
Monday, 07 Jul 2025
Every time a major cybersecurity incident occurs, the Malaysian public is usually assured that investigations are being conducted, but with little detail about what actually happened.
This is where the cybersecurity subfield known as cyber forensics comes into play.
Cyber Sherlock
According to National Cyber Security Agency (Nacsa) chief executive Dr Megat Zuhairy Megat Tajuddin, cyber forensics plays a crucial role from the earliest stages of cybersecurity incident response.
At that point in the investigation, investigators work to preserve easily lost evidence such as memory dumps, system logs, and network traffic, which can easily disappear when compromised systems, virtual machines, or cloud containers are shut down.
“Cyber forensics is a specialized field within the broader field of cybersecurity that focuses on identifying, preserving, analyzing, and interpreting digital evidence after a cybersecurity incident.
“While cybersecurity emphasizes proactive defense, such as threat prevention, system hardening, and monitoring, cyber forensics is more reactive, providing crucial insights post-incident.
“It helps uncover how the breach occurred, assess the level of impact, and supports efforts to enhance security going forward,” he said, emphasizing that “both fields complement and are equally vital in a strong cybersecurity strategy”.
Cyber forensics expert and Graymatter Forensic Advisory principal Raymon Ram put it in simpler terms, saying that cyber forensics is “the process of identifying, preserving, analyzing, and presenting digital evidence following a security breach or suspicious cybersecurity incident”.
This comes with the ultimate goal of uncovering “what happened, how it happened, and who was involved” after a cybersecurity incident occurs. Raymon also serves as president of Transparency International-Malaysia.
During the actual investigation, Nacsa would evaluate the impact level of the incident and potential risks, while the technical team handles evidence collection and analysis, identifying signs of system compromise, and collaborating with stakeholders to minimize damage and contain threats.
In More Detail
Raw Security (rawSEC) community chairman and co-founder Tahrizi Tahreb further detailed the investigation stages, emphasizing that cyber forensics is not a standalone activity but “deeply embedded within the structured lifecycle of incident response”.
“While incident response focuses on real-time detection and containment, digital forensics provides crucial insights and evidence that inform and enhance the overall process.
“This typically plays a very early role, during the ‘Identification’ phase, to confirm whether a cyberattack has indeed occurred and to understand the scope and nearest nature of it.
“However, its most central role emerges during the ‘Containment’ phase. This is where specialists carefully identify, label, record, and acquire data from all relevant sources, such as hard drives, memory, network logs, and mobile devices, while strictly maintaining their integrity.
“Maintaining a ‘chain of custody’ is crucial to ensure the integrity and reliability of evidence for potential legal proceedings,” he said.
These findings are then used to guide the ‘Eradication’ and ‘Recovery’ phases, which, as their names suggest, aim to remove the threat and restore affected systems.
This is followed by the ‘Post-Incident’ phase, where a thorough review is conducted to identify root causes and exploited vulnerabilities as well as assess the effectiveness of existing defenses. Lessons learned are then used to proactively bolster security measures.
Megat Zuhairy emphasized that Nacsa plays a crucial role when incidents impact National Critical Information Infrastructure (NCII), with the agency taking a leadership role in forensic response, coordination, and oversight of affected organizations.
“When an entity lacks the technical capability or resources to conduct proper forensic analysis, Nacsa can deploy or assign a specialized response team to provide direct support.
“Additionally, a specialized team from the Royal Malaysia Police (PDRM) is embedded within Nacsa to assist in cases involving potential criminal elements.
“This integration ensures that legal considerations and law enforcement are factored in from the outset of the investigation, helping to preserve digital evidence and facilitate subsequent legal action,” Megat Zuhairy said.
He added that cases have become increasingly complex over the years, with a shift from opportunistic attacks like phishing and malware cases to well-planned, sophisticated, and targeted threats disseminated by highly coordinated operations.
“These include ransomware used for financial extortion, coordinated malware infections that can cause multiple layers of impact, beacons used for external command-and-control communication, backdoors that enable stealthy remote access, and spyware designed for surveillance,” he said.
Talking Transparency
A crucial part of the cyber forensics process is communication with the public, which is managed carefully to avoid misinformation or premature conclusions on cybersecurity incidents.
Megat Zuhairy acknowledged that while transparency is important, caution is necessary to prevent incidents from escalating, with a focus on conducting comprehensive and accurate investigations rather than immediate disclosure.
“Sharing technical details too early can be risky, as it may alert threat actors, enabling them to launch a second wave of attacks, change their tactics, or cover their tracks. For this reason, public updates are often limited during active investigations.
“As Malaysia’s national cybersecurity agency, Nacsa is committed to sharing information responsibly while protecting national security interests.
“All external communications undergo meticulous validation to ensure sensitive data, particularly that related to critical infrastructure or national systems, remains secure.
“Our goal is not to withhold information unnecessarily but to balance transparency with operational security,” he said, adding that transparency nonetheless remains a guiding principle for Nacsa.
He further said that the agency does share more information such as Tactics, Techniques, and Procedures (TTPs) used in attacks, along with recommended mitigation strategies when possible.
“Through this measured and strategic approach, we ensure that forensic investigations not only effectively resolve incidents but also contribute to long-term national and regional cybersecurity resilience,” he said.
Similar thoughts were shared by Raymon and Tahrizi, who believe in taking a more measured approach to transparency with the public.
“The balance lies in sharing general findings – such as the nature of the breach, affected systems, and response measures – without revealing sensitive forensic techniques or evidence trails.
“After the investigation is concluded, sharing lessons learned can enhance public trust and help others strengthen their defenses,” Raymon said.
Megat Zuhairy said that full conclusions of investigations can only be shared after all necessary legal actions have been concluded, as otherwise, it could jeopardize trials involving perpetrators, adding that such investigations take time.
He added that while the agency usually does not publicly announce the full conclusions of investigations, it publishes key findings in the form of advisories that may be useful to others. These are regularly published on Nacsa’s website without explicitly referencing specific incidents.
“Updates may be issued when they serve the public interest, enhance compliance with regulations, or provide clarity on systemic issues, while ensuring that confidential or sensitive details remain protected,” he said.
Meanwhile, Tahrizi believes that nuance is required, with sufficient information provided to build public trust and accountability without jeopardizing cyber forensics investigations.
“Privacy concerns are also paramount. Digital forensics often involves highly sensitive data, including personal communications, medical records, and financial transactions.
“Forensic professionals have an ethical responsibility to avoid unauthorized data access, respect individual privacy, and ensure proper evidence handling.
“In Malaysia, the Cybersecurity Act 2024 and the newly introduced Publicly Accessible Data Universe (Padu) database have sparked significant debate regarding privacy, particularly as the Personal Data Protection Act 2010 (PDPA) does not apply to government agencies, leaving citizens without legal recourse in cases of misuse or breach,” he said.
Manpower Woes
All three agree that Malaysia suffers from a significant shortage of manpower in the broader field of cybersecurity, which also affects cyber forensics.
From Tahrizi’s perspective, the shortage is something Malaysia is grappling with, particularly given the country’s rapid digital transformation, with talent pipelines not keeping pace with development.
“The numbers paint a clear picture: by mid-2024, Malaysia had around 16,765 cybersecurity personnel.
“However, projected demand is expected to reach 26,430 by the end of 2025 and 28,068 by 2026.
“This talent gap is not just abstract numbers; it is a real vulnerability. Over 90% of organizations in Malaysia and neighboring countries have reported security breaches that were at least partly attributed to a lack of skilled cybersecurity professionals.
“This directly impacts our national security and economic stability,” he said, adding that the reasons for this gap are multifaceted, with a disconnect between academia and industry, limited industry-aligned training, and intense global competition making it difficult to attract and retain top talent in Malaysia.
Raymon drove the point home, saying that the issue is compounded because “forensics is even more specialized – it demands a unique blend of technical acumen, investigative meticulousness, and legal awareness”.
“Few institutions offer focused training in this area, and most graduates are drawn to more general roles such as security operations center (SOC) analysts or network engineers.
“As a result, many organizations rely on a small group of specialists or outsource to consultants like us,” he said.
Megat Zuhairy said that this is related to how cyber forensics as a whole is perceived by the public. He called for a rebranding of how the field is perceived to make it more appealing to Malaysians.
“Cybersecurity is not just about coding or working in a high-tech environment. It plays a vital role in protecting everyday aspects of modern life, from digital banking and transportation systems to healthcare data and national infrastructure.
“Presenting cyber forensics as a purpose-driven, problem-solving profession can make it more relatable, impactful, and aspirational to a broader audience. This is a field where individuals can make a real difference.
“What is important is that we must break the misconception that talent can only come from traditional IT backgrounds. The field of cyber forensics greatly benefits from a multidisciplinary approach. Individuals from engineering, mathematics, and science can bring analytical and technical strengths.
“At the same time, those with a psychology background offer valuable insights into human behavior, particularly in areas like social engineering and behavioral analysis during forensic investigations,” he said.
He added that many officers in the cyber forensics team of the PDRM “enter the field without formal technical training but develop their cyber investigation skills over time through targeted training and practical experience”.
What’s Next?
Besides the manpower shortage, Megat Zuhairy believes that the rapid growth and evolution of the cyber landscape, including malicious actors and threats to the nation at large, outpace existing laws and operational frameworks, posing a significant challenge to cyber forensics teams.
Both Tahrizi and Raymon similarly pointed out that cross-border cooperation becomes complicated due to time-consuming processes, such as Mutual Legal Assistance Treaties (MLAT), to share information and evidence for criminal enforcement.
This is something Nacsa is currently addressing through legislation, according to Megat Zuhairy.
“Most digital evidence today is encrypted or stored in various jurisdictions, often within cloud infrastructure.
“This complicates access and creates legal barriers, particularly when cross-border data sharing requires mutual legal assistance treaties or diplomatic coordination,” he said.
While Malaysia leads with the Computer Crimes Act 1997, Megat Zuhairy said that it has since become outdated and “inadequate” to address the modern complexities of cybercrime.
“In particular, the Act does not differentiate between cyberattacks targeting national critical information infrastructure (NCII) and those affecting individuals or non-critical systems.
“This legal gap hinders the ability to impose proportionate penalties and prioritize national security interests.
“In response, Nacsa is in the process of drafting the Cybercrime Bill, which is designed to provide a stronger, technology-neutral, and future-ready legal framework.
“The Bill will introduce enhanced penalties for cyberattacks targeting NCII and will also explicitly address emerging and sophisticated threats such as ransomware, social engineering attacks, AI-driven exploits, malware, and supply chain attacks,” he said.
The Cybercrime Bill will also be aligned with international legal standards, particularly the Budapest Convention on Cybercrime and the UN Convention against Cybercrime, which he expects will facilitate cross-border cooperation.
Related Articles
Lawyer Says Cash, 74 Kg of Gold Do Not Belong to Febrie Adriansyah
Former Deputy Attorney General Febrie Adriansyah, through his lawyer Hotman Paris, firmly denies ownership of the 74 kg of gold and millions …
Read more
Indonesia Bars Ex-Prosecutor Febrie Adriansyah From Leaving the Country
The Indonesian government has officially imposed a six-month travel ban on former prosecutor Febrie Adriansyah, preventing him from leaving the country. The …
Read more
KPK Demands 8 Years in Prison for Former Garuda Boss
KPK seeks 8-year sentence, $1 billion fine, and $86 million in restitution for Emirsyah Satar over corruption in aircraft procurement that caused …
Read more