Legitimate by Design, Weaponised by Intent: A Mobile Forensics Case Study
An Android examination where no spyware was found — but a single permission-audit timestamp placed an active screen mirroring session inside the…
Read more →Digital forensics & cybersecurity · Greenpoint, Brooklyn
When something isn’t right with your technology, you need someone who can look at the
situation, understand what’s really going on, and tell you what to do next.
That’s
what we do.
Incident response and digital forensics are at the core of our work, with particular experience in Apple and mobile devices — the hardware many firms would rather hand to somebody else. We also help businesses secure networks, identities, and the systems around them.
With 25 years of hands-on cybersecurity work and a CISSP certification, Arkadian’s founder works directly with businesses and individuals across New York City from our base in Brooklyn.
The first call is with the person who will do the work — whether that is examining a device, containing an incident or rebuilding a network. You get a straight technical answer about what is possible, not an estimate relayed second-hand.
A good share of first calls end with an explanation of why the work being asked for would not solve the problem being described. That costs us the job and saves you the fee, and it is why people send their colleagues here.
Every report states what the evidence does not show. Certainty about a device, offered without qualification, is a sales technique rather than a finding.
Professional forensic tools for iOS and macOS — the same class of tooling licensed to law enforcement agencies — matched to the exact device, chip generation and OS version in front of us.
What we do
Some clients come once, with a device and a question. Others keep us on call. Both start the same way.
Establishing what happened on a device or in an account, and documenting it so it can be relied on. Deleted material, account activity, timelines — with the method and its limits written down.
How an examination works →iPhone, iPad, Android, MacBook and iMac. Apple hardware is where we are strongest — most firms in this city pass it to somebody else, because the tooling is specialised and changes with every OS release.
What we examine →When someone knows things they should not. We examine the device for monitoring software, management profiles and account access that does not belong there — discreetly, and on a channel you choose.
What we look for →The infrastructure a business runs on: firewalls, segmentation, the laptops and phones your people actually work from. Designed around how you operate rather than a vendor catalogue.
How we work →Ransomware, a compromised Microsoft 365 tenant, an account someone else is using. Containment first, then the work of establishing what happened and how far it reached.
When it is happening now →Regulatory compliance
If a contract, a regulator or an insurer requires you to demonstrate a security programme, the work is mostly documentation, evidence and honest gap analysis — not buying products. We help establish what is actually required at your size, and what is being sold to you that isn't.
Our work
An Android examination where no spyware was found — but a single permission-audit timestamp placed an active screen mirroring session inside the…
Read more →
An access controls audit that uncovered two unauthorised actors: one with admin privileges in Active Directory.
Read more →
Migrating a growing business off legacy email and file systems: mailboxes, shared drives and calendars moved from a hybrid setup.
Read more →Fifteen minutes on the phone is usually enough to establish whether we can help, what it would take and what it would cost. If the answer is that you need someone else, you will hear that instead.
Please don't put passwords, account details or case material in an email. Bring those to the call.
Tech insights
Five security steps recommended by CISA — MFA, updates, password managers, spotting phishing, and phishing-resistant MFA with passkeys.
Read more →
Foreign Router Ban: Business Impact, Remote Work Risks, and What Comes Next On March 23, 2026.
Read more →
The New Wave of Cyber Threats: Typosquatting and Deepfake Attacks Targeting Your Data Introduction The cybersecurity landscape is evolving at an…
Read more →