Skip to content
Skip to main content
First Response & Preservation Operational Explainer

What questions should I ask the person who found or controls the system?

Establish who uses and controls the system, what happened before you arrived, what has already changed and which live risks or access routes may disappear.

Build the missing context

Ask what the device, account or service is; who owns and normally uses it; and who else has access. Clarify shared credentials, delegated accounts, employer or family management, remote-support tools and connected devices.

Construct a short timeline. When was the relevant activity noticed? Did anyone open messages, restart equipment, disconnect cables, change passwords, delete material, install software, contact a provider or attempt an export? Record actions even when they were well intentioned.

Ask about the present state: normal power behaviour, battery, screen locking, updates, networks, cloud synchronisation and the likelihood of remote access. Identify passcodes, multi-factor methods, recovery accounts and security keys without asking the person to demonstrate access before the effect has been assessed.

Separate knowledge from assumption

Record answers in the person's own terms and identify how they know. “Only I use it” is a reported access position; it does not by itself establish who performed a particular action. A device label may be a nickname rather than an ownership record.

Ask directly about immediate safety, safeguarding, financial or business-continuity concerns. Those facts may justify a different response from pure preservation.

Keep the conversation focused on volatility, access, prior changes and urgent risk. It is an early factual account, not a request for the person to conduct a technical examination on your behalf.

Key takeaway

Record control, shared access, prior actions, connectivity, credentials and urgent risks, while distinguishing what the person observed from what they infer.

Reference: FRP-009First Response & Preservation