eDiscovery or Digital Forensics?

eDiscovery vs. Digital Forensics: What’s the Difference?

SHARE THIS
Learn the difference between eDiscovery and digital forensics, when each is used in litigation, and when your legal team may need both.
TABLE OF CONTENTS
    Add a header to begin generating the table of contents
    TABLE OF CONTENTS
      Add a header to begin generating the table of contents
      TABLE OF CONTENTS
        Add a header to begin generating the table of contents

        What is the difference between electronic discovery and digital forensics? The terms are sometimes used interchangeably, particularly in litigation, because both involve identifying, preserving, collecting, and working with electronic information. But they serve different purposes.

        The simplest distinction is this: eDiscovery is generally focused on finding, collecting, reviewing, and producing electronically stored information (ESI), while digital forensics goes deeper into the technical analysis of digital evidence.

        That distinction matters. Choosing the wrong approach can mean overlooking evidence, spending time reviewing information that does not answer the questions at hand, or bringing in forensic expertise later than necessary.

        In some matters, eDiscovery is enough. In others, digital forensics is necessary to understand what happened. And sometimes the most effective approach involves both.

        eDiscovery vs. Digital Forensics at a Glance

        eDiscoveryDigital Forensics
        Primary purposeIdentify, collect, process, review, and produce ESIExamine and analyze digital evidence
        Primary focusDocuments and communications relevant to a legal matterDigital activity, devices, files, metadata, and other electronic evidence
        Who typically analyzes the information?Attorneys and legal review teamsDigital forensic professionals
        Deleted informationMay be part of the matterOften an important area of investigation
        Typical outputInformation prepared for legal review or productionForensic findings, analysis, and reporting
        Common useDiscovery and document productionInvestigations and questions about digital activity

        What Is eDiscovery?

        Electronic discovery, commonly called eDiscovery, is the process of identifying, preserving, collecting, processing, reviewing, and producing electronically stored information in connection with litigation or another legal matter.

        ESI can include email, electronic documents, files stored on computers or servers, cloud-based information, messages, databases, and other business records.

        In an eDiscovery matter, the objective is generally to identify potentially relevant electronic information and make it available to the legal team in a usable format. Attorneys and legal review teams can then determine what is relevant to the matter, responsive to discovery requests, privileged, or otherwise significant.

        For many matters, that is exactly what is needed.

        But sometimes the documents themselves do not tell the whole story.

        What Is Digital Forensics?

        Digital forensics focuses on examining digital evidence to help determine what happened, when it happened, and what the available electronic information can tell us about the activity involved.

        Instead of simply collecting electronic information for review, a digital forensic professional may analyze computers, electronic files, storage media, applications, and other sources of digital evidence.

        Depending on the circumstances, a forensic examination may help with questions involving:

        • Timelines of computer activity
        • Deleted information
        • Electronic communications outside conventional email
        • Internet activity
        • Applications installed or used
        • Files, photographs, and other digital media
        • USB drives and other peripheral devices
        • Movement or modification of electronic information

        This is where digital forensics becomes different from traditional eDiscovery.

        The question is no longer simply, “What information do we have?”

        It may be, “What happened to the information?”

        What Is the Main Difference Between eDiscovery and Digital Forensics?

        There is significant overlap between the two disciplines. Both can involve identifying, preserving, and collecting electronic information.

        One of the most important differences is who performs the analysis and what they are trying to determine.

        In a typical eDiscovery engagement, electronic information is collected and processed so attorneys can review and analyze documents relevant to the matter.

        In a digital forensics engagement, the forensic professional performs a technical analysis of the digital information and reports on the findings.

        Consider a relatively simple example.

        A legal team receives a document production, but the volume of information is a small fraction of what was expected. There is also reason to believe electronic information may have been deleted.

        At that point, reviewing the documents that were produced may not answer the real question.

        The legal team may need to determine whether information was deleted, when that activity occurred, what happened on a particular device, and whether other evidence remains. Those questions can move the matter from eDiscovery into digital forensics.

        When Do You Need eDiscovery?

        eDiscovery may be the appropriate approach when the primary objective is to locate, preserve, collect, review, and produce electronically stored information.

        Common situations can include:

        • Civil litigation
        • Regulatory matters
        • Discovery requests
        • Large electronic document collections
        • Email and communication review
        • Preservation and collection of potentially relevant ESI

        The volume and complexity of the information involved will often determine the technology and resources required.

        When Do You Need Digital Forensics?

        Digital forensics becomes particularly valuable when the matter involves questions about digital activity, not just the documents available for review.

        For example, a forensic examination may be appropriate when there are questions involving:

        • Suspected deletion of information
        • Missing electronic records
        • When files were created, accessed, modified, or deleted
        • Transfer of information to USB drives or other external devices
        • Employee or user computer activity
        • Electronic communications outside standard email
        • Reconstruction of a timeline of events
        • Potential destruction or manipulation of digital evidence

        These issues can arise in litigation, internal investigations, suspected misconduct, fraud matters, and cybersecurity incidents.

        In the case of a suspected cybersecurity event, the immediate priorities may be broader than litigation. Organizations also need to consider containment, preservation of relevant evidence, investigation, and recovery. Our article on how to respond when a security breach occurs discusses those considerations in more detail.

        When Do You Need Both eDiscovery and Digital Forensics?

        Not every matter fits neatly into one category.

        In some cases, a hybrid approach is the most effective option.

        A legal team may need a large collection of electronic documents processed for attorney review while also needing a forensic professional to investigate activity involving specific devices, users, files, or events.

        For example, digital forensic analysis might help establish the activity surrounding a set of electronic documents, while the eDiscovery process makes the larger document population available to attorneys for review.

        The two disciplines can complement one another.

        This is also why it can be useful to identify the potential need for forensic expertise early in a matter. An engagement that begins as a relatively straightforward discovery exercise can change quickly if questions arise about missing information, deleted files, unusual computer activity, or the integrity of the available evidence.

        Why Context Matters in a Digital Forensic Investigation

        A forensic examination is not simply a technical exercise.

        The more an expert understands about the matter, the better positioned that expert is to focus the analysis on the questions that actually need to be answered.

        Relevant complaints, depositions, known events, individuals involved, allegations, and other case information can provide important context. An early conversation between the forensic professional and the legal team can also help establish the objectives of the investigation and determine what digital information may be relevant.

        That upfront work matters.

        A technically interesting finding is not necessarily a useful finding. The goal should be to connect the digital evidence to the issues that matter in the case.

        What Should You Look for in a Digital Forensic Professional?

        Digital forensic professionals can vary considerably in experience, capabilities, and communication skills. Technical expertise is important, but it should not be the only consideration.

        When evaluating a digital forensic professional, consider:

        Relevant investigative experience. Does the professional understand the type of matter and digital evidence involved?

        Sound preservation and collection practices. Digital evidence needs to be handled appropriately throughout the engagement.

        Experience working with legal teams. The forensic analysis should support the objectives of the matter rather than operate independently from them.

        Clear communication. A forensic professional may need to explain highly technical findings to attorneys, executives, judges, regulators, or others who do not have a technical background.

        The ability to work across disciplines. When eDiscovery and digital forensics overlap, coordination between the technical and legal review processes can help maintain momentum in the matter.

        LBMC’s Litigation and Forensic Accounting team works with attorneys, organizations, and other parties on complex litigation and investigative matters.

        Frequently Asked Questions About eDiscovery and Digital Forensics

        Is eDiscovery the same as digital forensics?

        No. Although both disciplines involve electronic information, they generally have different objectives. eDiscovery focuses primarily on identifying, collecting, processing, reviewing, and producing electronically stored information. Digital forensics involves technical examination of digital evidence to help answer questions about activity, events, and the information available on digital systems or devices.

        Can digital forensics recover deleted files?

        In some circumstances, deleted information may be recoverable or other digital evidence may provide information about what occurred. The answer depends on factors such as the device, storage technology, subsequent activity, and condition of the available data.

        Importantly, recovering a file is not always the only objective. Other forensic artifacts may help establish activity surrounding a file even when the file itself is no longer available.

        When should an attorney involve a digital forensic professional?

        Consider involving a digital forensic professional when questions arise about deleted or missing information, computer or device activity, movement of files, electronic communications, potential destruction of evidence, or the timing of digital events.

        Early involvement can be particularly important when electronic evidence needs to be preserved.

        Can a legal matter require both eDiscovery and digital forensics?

        Yes. A matter may require eDiscovery to collect and prepare a larger body of electronic information for attorney review while requiring digital forensics to investigate particular devices, users, files, or events.

        The appropriate approach depends on the objectives of the matter and the questions the legal team needs answered.

        What is the difference between digital forensics and incident response?

        The disciplines can overlap, but their objectives are different.

        Digital forensics focuses on examining digital evidence and understanding activity. Incident response focuses on responding to and managing a cybersecurity incident, which can include containment, investigation, remediation, and recovery.

        A cybersecurity incident may require both.

        eDiscovery or Digital Forensics: Which Do You Need?

        A useful place to start is with the question you are trying to answer.

        If the primary question is:

        “What electronic information needs to be collected, reviewed, or produced?”

        The matter may primarily require eDiscovery.

        If the question is:

        “What happened on this device or within this digital environment?”

        The matter may require digital forensics.

        If you need to understand both the relevant documents and the activity surrounding them, you may need a combination of the two.

        The distinction is important, but the disciplines do not have to compete with one another. The right approach is the one that gives the legal team the information it needs to make informed decisions about the matter.

        How LBMC Can Help

        When litigation or an investigation involves complex electronic information, determining the appropriate approach early can help focus the work on the questions that matter.

        LBMC’s digital forensics professionals work with attorneys and organizations on matters involving digital evidence as part of LBMC’s broader litigation and forensic accounting capabilities.

        Learn more about LBMC’s Digital Forensics and Litigation Support services.

        Subscribe to Get Insights In Your Inbox 

        Scroll to Top
        LBMC
        Privacy Overview

        This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.