When should I seek specialist support for cloud evidence?¶
Seek specialist support early when cloud evidence is live, volatile, technically complex or central to a significant decision. The best time is often before containment or collection changes the environment, not after an avoidable loss or ambiguity appears.
Recognise the escalation points¶
Specialist input is particularly valuable for active compromise, stolen sessions or tokens, API and service-account activity, linked tenants or providers, short retention, large exports and attribution that depends on several technical systems.
Account deletion, tenant shutdown, broad token revocation, device reconnection and other irreversible actions can remove or generate evidence. Where operationally possible, understand and preserve the relevant state before acting.
Straightforward preservation or documented collection may remain suitable for local handling under the applicable process. Escalation should reflect the evidence risk and question, not cloud terminology alone.
Make the referral usable¶
Explain the decision to be made, records already available, known identifiers, actions taken and what is at risk. Supply original exports and collection notes, relevant screenshots and a working timeline.
Ask what the records support, what they cannot establish and which alternatives remain. A specialist should not be asked simply to endorse a preferred account of events.
If support is not immediately available, preserve available records and avoid unnecessary live interaction. A documented untouched state is generally more useful than an improvised technical intervention.
The point to remember
Escalate before volatile or attribution-heavy cloud evidence is changed, and frame the request around a defined decision, existing sources and evidential risk.