Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
When do you need a DFIR firm?
Updated
Bring in a DFIR firm when you cannot preserve evidence forensically in-house, when regulated data, theft, litigation, or an insurer panel is in play, or when in-house capability is not enough. This is a decision tree, not a ranking. Not legal advice.
Operational guidance, last verified 7 September 2026 against NIST SP 800-86 (Guide to Integrating Forensic Techniques into Incident Response), CISA's Federal Government Cybersecurity Incident and Vulnerability Response Playbooks, CREST-style incident-response accreditation schemes as capability classes (CREST Incident Response company accreditation; UK NCSC Cyber Incident Response Standard and Enhanced as a regional class), and generic insurer panel-vendor norms in NAIC cyber-claims materials. It does not rank DFIR firms, does not name any, does not interpret YOUR policy, and is not a substitute for counsel, your insurer, or a retained DFIR firm. The what-is-dfir page on this site is the DFIR explainer. Not legal advice.
This is a retain-or-not tree, not a vendor list
Audience: a CTO, founder, CISO, or incident commander deciding whether in-house staff can handle the forensic work or whether to retain a DFIR firm. The what-is-dfir page on this site is the explainer (identify, preserve, analyze, report; forensic soundness; chain of custody). The who-to-call page on this site is the contact map. The contact-cyber-insurance page on this site is the notice-and-panel checklist. The contact-breach-counsel page on this site is the privilege-and-engagement checklist. This page is the retain-or-not step: in-house versus a firm, the insurer-panel constraint, and stated selection criteria. It does not rank DFIR firms, does not name any, and is not a directory.
NIST SP 800-86 is a guide to integrating forensic techniques into incident response — guidance, not a statute. It assumes trained people, procedures that preserve integrity, and a reconstructable method; it tells readers to consult management and legal counsel before applying the practices. CISA's incident-response playbook, written for US federal civilian executive branch systems (CISA notes other organizations may use it to standardize practice), includes capturing forensic images to preserve evidence for further investigation and, if applicable, legal use. CREST's published Incident Response accreditation is a company-level capability class; the UK NCSC Cyber Incident Response scheme (Standard Level and Enhanced Level) is a regional government-assurance class, with CREST as a delivery partner for Standard Level. None of those sources is a ranking of firms. Last verified 7 September 2026. Not legal advice.
- In-house DFIR is a capability: trained people, write-blocking or equivalent, hashes, a chain of custody, and time to do the work without destroying the original. NIST SP 800-86: collection should preserve integrity; personnel should be trained for the method they use.
- A DFIR firm is surge, independence, and method you do not currently have — not a trophy vendor. Page a firm when the decision tree below points there, not because a brand is famous.
- If you have a cyber policy, the panel or prior-consent clause is a contract constraint. It is not a quality ranking. Notice the carrier before you retain off-panel. The contact-cyber-insurance page on this site is that checklist. Verify YOUR policy.
- Counsel-directed DFIR is common practice so working papers can sit under attorney-client privilege and work-product. That is practice, not a ruling that privilege will attach. The contact-breach-counsel page on this site is the privilege-and-engagement checklist.
- This page does not rank DFIR firms, does not interpret YOUR policy, does not start a notification clock, and is not legal advice.
Decision tree — in-house versus a firm
Walk top to bottom with the commander and counsel. A 'yes' on an earlier row does not skip the later questions: a panel clause still applies if you already decided you need a firm; a CISA report does not replace insurer notice. Last verified 7 September 2026. Not legal advice.
| Question | If the facts point yes | If the facts point no |
|---|---|---|
| Can we capture memory, disk, and logs ourselves in a forensically sound way — trained people, working copy, hashes, chain of custody — before evidence rotates or is rebuilt? | Do that now. The first-15-minutes and first-24-hours pages on this site are the capture-and-hold checklists. You can still bring a firm later for analysis. NIST SP 800-86: acquire while preserving integrity; document the method. | After counsel and, if you have a policy, the insurer, page the retained or panel DFIR firm in the first 24 hours, not after you have rebuilt. They cannot image a host you already reimaged. This page does not rank firms. |
| Do we have a cyber insurance policy with a panel or prior-consent clause for DFIR, counsel, or restorers? | Notice the carrier (or the broker) before you pick a firm. Use the panel or get written consent. NAIC cyber-claims materials: some policies require a preapproved incident-response vendor list; others require prior mutual agreement to a particular provider. That is a contract role, not a ranking. Verify YOUR policy. The contact-cyber-insurance page on this site is the notice-and-panel checklist. | The tree still applies. Do not invent a panel. You can still retain a firm if you cannot capture evidence, but you are not using a carrier list as a substitute for criteria. |
| Might personal data, payment data, health data, or another regulated dataset be involved — or is theft / exfiltration still unknown? | Treat that as a retain signal. Scope and legal mapping are why you want method, independence, and counsel-directed work. 'Might' is enough to flag; whether a notification duty has started is counsel's question. This page does not start a clock. The was-data-stolen page on this site is how you reason from access to confirmed exfiltration. | You can still stay in-house if capture is sound and counsel agrees. Unknowns belong on the list, not in a guess that 'nothing left the network.' |
| Is litigation, a regulator inquiry, or law-enforcement involvement reasonably in view — or would an independent examiner matter to a later reader of the report? | Common practice is counsel retains DFIR. Independence from the team that operates the estate is a stated criterion, not a ranking. The contact-breach-counsel page on this site is the privilege-and-engagement checklist. FTC Data Breach Response guidance: assemble a team that can include legal and forensics; do not destroy forensic evidence. | In-house analysis can still be the right call when the event is contained, well-understood, and counsel is comfortable. Document that decision. |
| Is the environment (cloud identity, multi-account, OT, a tenant you do not image yourselves) beyond current in-house tools and training? | Retain a firm whose capability class matches that environment. Capability class is not a vendor name. CREST Incident Response accreditation and regional CIR schemes (below) describe classes of assessed capability, not a league table. | Stay with the in-house method if it covers the sources you actually have. Do not retain a firm as theatre. |
Signals you typically need a firm
These are retain signals, not a statute and not a scoring model. One signal can be enough. None of them is a notification determination. Last verified 7 September 2026. Not legal advice.
| Signal | Why it usually means a firm | What this page is not saying |
|---|---|---|
| No trained forensic capture in-house | NIST SP 800-86 treats forensic collection as trained work that preserves integrity. Untrained 'just copy the disk' is how originals get written. CISA's IR playbook includes capturing forensic images as part of containment and investigation. | Lacking a retainer yesterday is not a reason to skip the insurer notice today. Page the panel or the retained firm; do not shop on a blog list. |
| Suspected theft, unknown exfiltration, or an active actor / ransomware | You need surge, memory-and-disk capture, and analysis of what left. Waiting to 'know everything' is how evidence ages out. CISA: do not tip the actor; keep the out-of-band bridge. | This page does not decide that data was stolen. The was-data-stolen page on this site is that evidence-to-conclusion map. Access is not exfiltration. |
| Regulated or personal data might be in scope | Notification, regulator, and customer questions will ask what the evidence supports. Independent, documented method is why firms are retained. Counsel maps the duty. | Presence of personal data is not automatically a notifiable breach. This page does not start a GDPR, CRA, HIPAA, or US-state clock. |
| Insurer panel or prior-consent clause | The form may require a named list or written agreement before DFIR costs are covered. NAIC cyber-claims materials describe both designs. Ask first. | 'Panel' is not 'the best firms.' It is a contract role. This page does not interpret YOUR policy and does not rank carriers or panel members. |
| Litigation, regulator, or law-enforcement exposure | Chain of custody and an examiner who can reconstruct the method matter to a later reader. Counsel-directed engagement is common practice, not a privilege ruling. | This page does not file a report and does not decide whether you must notify law enforcement. The who-to-call page on this site is that map. |
| The operator of the estate would be investigating themselves | Independence is a stated criterion: the MSP, SOC, or internal team that runs the environment is a fact witness, not always the examiner. Common practice, not a statute. | Independence is not a ranking of boutiques over incumbents. An existing retainer your policy pre-cleared can still be the right call — ask the carrier and counsel. |
The insurer-panel constraint
If you have a cyber policy, read it before you retain anyone. Many forms treat prompt notice as a condition of coverage and require a pre-approved panel for DFIR, breach counsel, notification, and crisis communications — or prior written consent to someone else. NAIC Receivership and Insolvency Task Force materials on cyber claims record both designs. That is a description of common policy design, not a reading of YOUR form. Last verified 7 September 2026. Not legal advice. Not coverage advice.
- Notice the carrier (or the broker) as soon as the incident is a possible claim — often before you pick DFIR. The contact-cyber-insurance page on this site is the notice-and-panel checklist.
- Ask which DFIR firms the policy recognises, and whether an existing retainer is already cleared. If the form requires the panel or prior consent, a unilateral favourite-firm engagement is a coverage argument.
- Panel membership is a contract constraint, not a quality ranking and not this page's vendor list. This page does not name, endorse, or rank panel firms.
- Counsel-first for privilege is common practice, not a reason to miss a notice clause. Privilege is a legal question for counsel. Coverage is a contract question on YOUR form.
- Verify YOUR policy, including endorsements and the current panel list. This page does not interpret it.
Stated selection criteria, not a ranking
If the tree says retain, use criteria you can defend, not a blog's 'top firms' list. The rows below are selection criteria. They are not a league table, not an endorsement, and not a directory. This page does not rank DFIR firms and does not name any. Last verified 7 September 2026.
| Criterion | What to ask | Limit |
|---|---|---|
| Insurer panel / prior consent | Does YOUR form require this firm, or written consent to this firm, before DFIR costs are incurred? | A contract role, not a quality score. NAIC cyber-claims materials describe panel and prior-agreement designs. Verify YOUR policy. |
| Counsel-directed statement of work | Will counsel retain and direct the firm, with a SOW that says the work is to assist counsel in giving legal advice? | Common practice, not a ruling that privilege or work-product will attach. Dual-purpose ordinary-course IT work is a known waiver risk. Confirm with counsel. |
| Forensic method (NIST SP 800-86 class) | Working copy, integrity preservation, hashes, chain of custody, documented tools and versions, trained handlers? Can another examiner reconstruct the work? | Method is guidance, not a guarantee of admissibility. NIST SP 800-86 is not a statute. The preserve-evidence page on this site is the order-of-volatility checklist. |
| Capability-class accreditation (not a ranking) | Does the company hold a current incident-response company accreditation in a scheme that applies to YOUR jurisdiction and the work you need — for example CREST Incident Response (the published CREST service-specific standard; older materials say CSIR), or a regional government-assured CIR list such as the UK NCSC CIR Standard or Enhanced levels? | Accreditation is a capability class, independently assessed against that scheme's standard. It is not a league table, not a licence in every country, and not 'these are the best firms.' Verify the CURRENT published list for YOUR jurisdiction; this page does not reprint one. |
| Regional CERT / CSIRT-style and government-assured classes | Is there a national or regional assured-provider or authorised-responder list (CERT/CSIRT-style, NCSC CIR-style, or a CREST-partnered government programme) that YOUR sector or geography actually uses? | These are regional classes, not a global ranking. A UK NCSC CIR assurance does not, by itself, authorise work everywhere. CREST is a delivery partner for NCSC CIR Standard Level; NCSC Enhanced is a separate NCSC-assured class. Last verified 7 September 2026. |
| Individual competence class | Are the people on the engagement assessed (CREST CPIA / CRIA / CCIM as examples of an intrusion-analyst / incident-manager class; other schemes use their own names)? | People qualifications are a competence class, not a firm ranking. CREST's published accreditation standards do not make individual CREST exams mandatory for company accreditation; they assess team skill and experience. Confirm what YOUR engagement actually staffs. |
| Environment fit | Have they done this class of work (cloud identity, endpoint, OT, the tenant model you actually have) as a capability, with 24/7 surge if you need it? | Fit is a class of experience, not a named case study this page will invent. Do not treat a logo list as evidence. |
| Independence from the estate operator | Is the examiner independent of the MSP, SOC, or internal team that runs the environment, unless counsel and the insurer have a reason to use the incumbent? | Independence is a conflict criterion, not a preference for boutiques. An insurer-cleared retainer can still be the right firm. |
| Reporting that states limits | Will the report say what the evidence supports, what it does not, the methods, and who handled what — need-to-know, on the out-of-band channel? | A forensic report is not a GDPR Article 33 notice, not a CRA Article 14 filing, and not insurer notice. Counsel owns what you may say. CISA: do not tip the actor. |
How engagement typically works
Order is the failure mode. Shopping a favourite firm, then asking counsel to 'wrap privilege around it,' then telling the carrier, is the reverse of common practice and a coverage argument. The sequence below is practice, not a statute. Last verified 7 September 2026. Not legal advice. Not coverage advice.
- Commander names the incident and opens the out-of-band bridge. The we've-been-breached and who-to-call pages on this site are that map.
- Page in-house legal, then outside breach counsel when privilege or a notification question is on the table. Common practice: counsel retains DFIR. The contact-breach-counsel page on this site is that checklist.
- If you have a cyber policy, notice the carrier before you pick a non-panel firm. Ask which DFIR the form recognises. The contact-cyber-insurance page on this site is that checklist.
- Retain under counsel's SOW. Hand over the UTC timeline, the evidence-hold list, what you have already imaged, and what you have not. Do not reimage first.
- The firm collects and examines a working copy (NIST SP 800-86: collection, examination, analysis, reporting). You stay the commander. They do not replace counsel, the insurer, or the executive owner.
- The preserve-evidence page on this site is the order-of-volatility checklist. The never-delete-after-breach page on this site is the do-not-destroy list. Isolate — do not wipe — and keep the hold.
Where this shows up in ShipReady Metrics
The signed-in app does not image hosts, keep a chain of custody, produce a forensic report, retain a DFIR firm, notice an insurer, or file with a regulator. It does not rank forensic vendors and does not keep a copy of your policy. If you already have a session: signed-in app → Compliance → CRA reporting tracks the 24-hour / 72-hour / 14-day ladder from your recorded awareness for findings the org has classified as CRA-in-scope. That ladder is not a forensic exam, it does not start a clock for you, and it is not a determination that CRA applies. A named human still submits. None of those surfaces is a substitute for the commander, counsel, the insurer, or DFIR.
Primary sources (last verified 7 September 2026)
Every operational claim on this page is taken from one of these. If a later revision of a source changes the advice, the date above is how you can see we have not re-checked yet.
NIST SP 800-86 (August 2006), Guide to Integrating Forensic Techniques into Incident Response, remains the current final guide this page cites for the forensic process, integrity, chain of custody, trained personnel, and the instruction to consult management and legal counsel — guidance, not a statute, last verified still final on 7 September 2026. CISA's Federal Government Cybersecurity Incident and Vulnerability Response Playbooks are operational procedures for US FCEB systems; CISA notes other organizations may use them to standardize practice; they include capturing forensic images. CREST publishes a company Incident Response accreditation standard (six domains, expert-led assessment) and a separate Incident Exercising standard; individual CREST intrusion-analyst / incident-manager exams (CPIA, CRIA, CCIM) are a people competence class. The UK NCSC Cyber Incident Response scheme assures providers at Standard Level and Enhanced Level; CREST is a delivery partner for Standard Level; NCSC recommends UK organisations use an NCSC-assured CIR provider — a regional class, not a global ranking. NAIC cyber-claims materials describe panel-vendor and prior-agreement conditions as they appear in policies; they do not interpret YOUR policy. The FTC Data Breach Response guide is US regulator guidance for businesses: a team that can include legal and forensics; do not destroy forensic evidence. NIST SP 800-61 Revision 2 remains the current final Computer Security Incident Handling Guide this cluster cites — guidance, not a statute.
Frequently asked questions
When do you need a DFIR firm?
When you cannot preserve memory, disk, and logs in a forensically sound way in-house; when regulated data, suspected theft, litigation, or law-enforcement exposure is in play; when an insurer panel or prior-consent clause applies; or when the environment is beyond current in-house tools. Walk the decision tree with counsel. This page does not rank firms. Not legal advice.
Can we handle the incident in-house instead of hiring a DFIR firm?
Yes, when you have trained people, a method that preserves integrity (NIST SP 800-86), a chain of custody, and counsel (and, if you have a policy, the insurer) are comfortable that the event is contained and well-understood. In-house capture now does not bar a firm later for analysis. Untrained copying is not in-house DFIR. Not legal advice.
Does cyber insurance require a panel DFIR firm?
Often, but only YOUR form answers it. NAIC cyber-claims materials: some policies require a preapproved incident-response vendor list; others require prior mutual agreement to a particular provider. Notice the carrier before you retain off-panel. Panel is a contract role, not a ranking. Verify YOUR policy. Not coverage advice. Not legal advice.
How should we select a DFIR firm?
Use stated criteria: insurer panel or consent, counsel-directed SOW, NIST SP 800-86-class method, capability-class accreditation (CREST Incident Response; regional CIR schemes such as UK NCSC CIR Standard or Enhanced), environment fit, independence from the estate operator, and a report that states limits. Those are criteria, not a ranking. This page does not name firms.
Is CREST or NCSC CIR a ranking of DFIR firms?
No. They are capability classes. CREST Incident Response is a company accreditation against a published standard. UK NCSC CIR Standard and Enhanced are regional government-assurance levels; CREST delivers Standard Level for NCSC. Accreditation is not 'best firms,' not a global licence, and not this page's vendor list. Verify the CURRENT list for YOUR jurisdiction. Last verified 7 September 2026.
Is this legal advice?
No. It is operational guidance distilled from NIST SP 800-86, CISA incident-response playbooks, CREST-style accreditation classes, NAIC panel-vendor norms, the FTC Data Breach Response guide, and NIST SP 800-61r2. Whether privilege attaches, whether a panel clause is satisfied, whether a notification duty applies, and which firm to retain are questions for counsel and YOUR policy. This page does not rank DFIR firms.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.