When should the organisation or cloud provider be contacted?¶
The organisation or cloud provider should be contacted when preservation, access control, audit records or ongoing risk depend on systems they control.
Avoid this assumption: A live cloud session contains everything the investigation needs. Providers and organisations may hold audit logs, deleted-item records, retention data, account identifiers, administrator actions and security events that are not visible to the user.
Contact may be urgent where another user could delete material, permissions are changing, an account is being disabled or retention is about to expire.
Before making contact, preserve the service, tenant, account, file or object identifiers, relevant URLs, timestamps, visible users, roles and current state.
Define the request clearly. Are you asking for preservation, technical assistance, safeguarding action, account containment, audit information or a lawful disclosure route?
Do not ask a provider to reset, disable or alter an account without understanding the evidential and operational consequences.
Where the system belongs to an organisation, identify the appropriate administrator, legal contact, security team or records owner rather than relying on general support.
Record who was contacted, when, through which route, what identifiers were supplied and exactly what was requested.
Preservation is not the same as disclosure. A provider may preserve material while a separate lawful process is required to obtain it.
Do not assume that a verbal assurance means the relevant data has been preserved. Obtain and retain any confirmation, reference number, scope and stated retention period.
Where contact itself could alert a suspect or compromise an operation, seek supervisory or specialist advice before proceeding.
Operational takeaway¶
Contact the organisation or provider when preservation or control depends on their systems, using exact identifiers, a defined request and a complete record of the response.