Gordon Digital Forensics is dedicated to bringing awareness and advancing technology and techniques to ensure the security of data infrastructures across the globe”

Mission Statement

Gordon Digital Forensics’s core purpose is to support business continuity by securing data infrastructures and promoting cybersecurity awareness for the benefit of innovation and excellence across all industries.

Vision Statement

Gordon Digital Forensics will be essential to the international cybersecurity community and to security professionals everywhere, and be universally recognized for the contributions of cybersecurity and of cybersecurity professionals in improving information systems.

Value Statement

Gordon Digital Forensics will foster a collaborative environment that is open and will continue to sustain strength, reach, and vitality for future generations.

6 Core Values of GDF

They shape our culture and define how we make decisions

Goals

  • Drive global innovation through broad collaboration and the sharing of knowledge 
  • Enhance public understanding of cybersecurity and digital forensics and pursue standards for their practical application 
  • Be a trusted source of educational services and resources to support life-long learning 
  • Provide opportunities for career and professional development   
  • Inspire a worldwide audience by building communities that advance technical interests, inform public policy, and expand knowledge for the benefit of humanity

A Systematic Approach: The Incident Response Methodology

The complex nature of a breach requires an organized approach.

  1. Preparation – before a breach: In this phase an organization will engage in Incident Response Planning and Securing Resources.
  2. Detection and Analysis – detection of the breach: A quality AI-driven detection systems or human observation will flag the intrusion. This will be followed by forensics analysis to find the vector and discover network movement.
  3. Containment, Eradication, and Recovery – The breach clean up will first seek to contain the attack followed by its removal so the recovery process can begin.
  4. Post-Incident Activity – Reflection on breach activities will answer the question, what have we learned? and How to improve performance to ensure business continuity?
  5. Expert Witness Testimony – is the culmination of all breach activities needed to determine how an attacker accessed, traversed and planted malware on your network and more.