Mark McCluskie, EMEA Head Of Investigations, Nuix

Mark, you've recently joined Nuix as EMEA Head of Investigations. What does a day in your life look like?

Being new to both Nuix and a corporate environment, each day is turning out to be considerably different and very busy! In essence, it’s about working with our customers, helping them to get the most from Nuix; using my previous experience and knowledge I know what they need to do to be successful. Helping customers drive efficient workflows is one of my key objectives.An example I can share went like this:

I was in Cork where I met with my colleagues to discuss how we could improve various aspects of some of our products, I then travelled to the UK to meet with a customer who has just purchased a Nuix Lab and some Web Review & Analysis licences.

They were seeking advice and guidance on how best to approach some large-scale investigations and how to make the most efficient use of their hardware, software and digital forensic staff.

During the meeting we discussed plans that would enable them to have a collaborative view of all their data in the cases, and to enable both an intelligence and evidential review to be carried out simultaneously on the same data set. Then it was a quick journey to the airport and return flight home. A busy day.


Get The Latest DFIR News

Join the Forensic Focus newsletter for the best DFIR articles in your inbox every month.


Unsubscribe any time. We respect your privacy - read our privacy policy.

You previously worked in law enforcement – what's it like moving from LE to corporate forensics?

It’s a strange feeling; being so long in LE I felt sort of institutionalised to some degree. I knew all the various teams and units involved in investigating complex crimes, and knew who to turn to for specific assistance. I also had a great team of highly skilled forensic officers and detectives in my unit who were dedicated to solving complex digital crimes. That comfort comes from time, which I’m sure will build quickly in my new role too. Being in LE, we had an almost militaristic structure and discipline, which I suppose is not so evident in corporate work. That was a very noticeable change.

There are benefits of course. It’s a massive opportunity to continue doing what I used to do, help in a small way to keep people safe and put the bad ones away if possible. Also working in a corporate environment and it not being so structured I am enjoying the ability and freedom to grow ideas and am empowered to deliver on them.

Collaboration is one of the most frequently cited challenges in digital forensics, both between LE / corporate / academic and between nations. In your opinion, what can we as digital forensics practitioners do to address this?

I think this was more of a problem 5-10 years ago than it is now.

I’m sure we have all worked in, or been part of “little empires” where some in the industry strive to become experts, or highly skilled in some area of DF / Cyber, and want to build their lab/unit/firms up to be the envoy of others. That research, expertise or skill set is to be admired, yes, but if we as a community wish to grow, detect or prevent crimes, make our digital world a safer place, then I believe we need to share and work much closer together.

Part of the role of the Investigation Team in Nuix is to promote collaborative review, working with customers to ensure they get the ‘right data’ in the hands of the ‘right people’, whether that be internally or externally for them. We have seen massive growth with technology and its capabilities, but all that technology should not be a hindrance or barrier to collaboration, but rather a conduit to enable sharing of relevant data/ evidence / intelligence, all to help make the world a much safer place.

I fully understand the competitiveness between commercial firms, and indeed the fact that corporates are there to make money, but none of us can solve all the problems ourselves.

Courtesy and professional respect with each other will go a long way, and of course, a willingness to go the extra mile for others with a problem no matter which box they or their employer fits into.

Challenges between nations is I’m afraid, way above my pay grade! However, I can testify that in the majority of my recent large scale LE investigations, most of the nations we needed assistance from were more than willing to help; even if not at that high official level, than almost always between the LE agencies themselves.

The bigger problems of course are the nations who simply don’t want to, or be seen to, offer assistance to help solve crime. Nation states who promote or quietly endorse cyber crime for their agendas will become an even greater problem for both the majority of other nations, and indeed, the wider global population who will be affected on a personal level.

You have a lot of experience of working on large-scale investigations; what are some of the specific challenges associated with these, and how can they be addressed?

To some degree, this has been part answered the previous question; with challenges around assistance from corporates, or other nations.

However, I will cite just 2 other specific examples;

1) Where is the “data” and do UK (or indeed other) LE agencies, have full legal authorities to capture that? Examples (hypothetical of course) would be: you are examining a suspect’s or custodian’s mobile device, and it’s either damaged, or encrypted, but you would have access to their “Cloud” account; can you, should you, do you, pull that data down? (Presuming they don’t give permission.) Where is the cloud data? Which country? Which server farm?

2) The sheer volume of data from multiple devices in one case or investigation. Long gone are the days of single examinations, on single devices, with single reports. It doesn’t really matter if corporate or LE, but we now have problems with the scale of data from computers, home, office, laptops, 2 or 3 phones and tablets, all per SOI (Subject of Interest). Add multiple subjects to a large case and in reality, where do you start?!

This is one of the reasons I joined Nuix, who provide a solution to this problem. We need to look at tools that can deal with all the (big) data, structured or unstructured, from many sources, then provide that “single pane of glass” insight into the case, using things like, multiple / remote reviewers, advanced analytics and artificial intelligence. The latter is a reasonably new concept in DF, but I firmly believe, in a year or two, we will see great advances in using AI to progress a lot of the “bulk” in DF
investigations.

What can awe expect to see from Nuix's investigations team over the next year or so?

We are starting to really see an increase in the number of ‘labs’ using ‘labs’! It’s a confusing term sometimes, but whilst there is tremendous value in using some of our stand alone products such as Workbench, I understand it is just another tool in the DF’s toolbox, and I appreciate we all have had our favourites tools, the ones we have used for a long time, or become highly familiar or skilled with using.

As a discipline, we are moving (slowly) away from that single examination / report to more of a collaborative approach. Forensic Labs are growing in size, due to demand. Our Nuix Lab solution is being deployed in more and more of these physical DF labs, and agencies, but there is a lot more work to do here. Yes, the ‘big’ data bit is sorted and scalable, yes the multiple and remote viewers are sorted, yes, we have advanced analytics, but there is still room to grow and develop.

Thankfully, Nuix has had the vision to employ Subject Matter Experts (SMEs) and Industry Specialists, in order to become ‘trusted advisors’ to our customers. We have people in our teams that have been in the customer’s’ shoes, and know / understand the challenges that they face. Our mission, and specifically of our team, is to help those customers get the best from our technology, whilst at the same time listening to them to ensure we build the right and best technology. Examples of recent feedback
and developments include integration with Project Vic & O Data compatibility, Photo DNA, Mobile Integration & partnership with MSAB. I see a lot more of these types of developments coming in the next year or two.

Finally, when you're not working, what do you enjoy doing in your spare time?

What is “spare time”? Only joking.

I spend a lot of it motorcycling. Both in a club with my ex LE colleagues, and with my Local Institute of Advanced Motorists (IAM), which is a UK charity, where I volunteer as an Advanced Observer to those bikers wishing to improve their riding skills.

Holidays are of course also a firm favourite, along with good food and wine. I used to play the piano many years ago, and have recently taken the notion to get another one and start trying that again, I pity the neighbours!

Mark McCluskie is EMEA Head Of Investigations at Nuix, a full-service digital forensics company covering small and large-scale investigations.

Leave a Comment

Latest Videos

Subscribe to the Forensic Focus Podcast: https://www.forensicfocus.com/podcast/

Si and Desi are joined by Brittany and Ailsa from digital forensics software company ADF Solutions. They discuss how ADF is addressing key challenges for digital forensics practitioners, including handling the massive volumes of data from mobile devices and the cloud.

The guests outline ADF's focus on developing their software as an easy-to-use onsite triage tool that can help quickly identify pertinent evidence. Key features include advanced handling of video files, AI-assisted classification of images, and new screen recording capabilities for mobile devices that allow suspects to safely share relevant data. 

The hosts and guests also explore ADF's ongoing research into areas like facial recognition, handling new device types like games consoles and smart watches, and identifying deepfake media.

00:00 – Introduction to Ailsa and Brittany
03:00 – The challenge of vast amounts of data
05:50 – Recovering data from Chromebooks
08:50 – Triaging using ADF tools
12:30 – Benefits of using ADF Solutions’ tools
15:50 – Limitations in types of apps
17:20 – Keeping up with technological advancements
19:15 – ADF customer base
21:00 - Artificial intelligence in classifying images
30:00 – ADF Solutions’ triaging kit
37:00 – Training with ADF
40:00 – Target user
44:50 – Roadmap of future devices to examine
51:30 – Main focus for ADF Solutions going forwards

Show Notes:
AI-generated CSAM article on Sky News - https://news.sky.com/story/thousands-of-ai-generated-child-abuse-images-being-shared-online-research-finds-12991727

Subscribe to the Forensic Focus Podcast: https://www.forensicfocus.com/podcast/

Si and Desi are joined by Brittany and Ailsa from digital forensics software company ADF Solutions. They discuss how ADF is addressing key challenges for digital forensics practitioners, including handling the massive volumes of data from mobile devices and the cloud.

The guests outline ADF's focus on developing their software as an easy-to-use onsite triage tool that can help quickly identify pertinent evidence. Key features include advanced handling of video files, AI-assisted classification of images, and new screen recording capabilities for mobile devices that allow suspects to safely share relevant data.

The hosts and guests also explore ADF's ongoing research into areas like facial recognition, handling new device types like games consoles and smart watches, and identifying deepfake media.

00:00 – Introduction to Ailsa and Brittany
03:00 – The challenge of vast amounts of data
05:50 – Recovering data from Chromebooks
08:50 – Triaging using ADF tools
12:30 – Benefits of using ADF Solutions’ tools
15:50 – Limitations in types of apps
17:20 – Keeping up with technological advancements
19:15 – ADF customer base
21:00 - Artificial intelligence in classifying images
30:00 – ADF Solutions’ triaging kit
37:00 – Training with ADF
40:00 – Target user
44:50 – Roadmap of future devices to examine
51:30 – Main focus for ADF Solutions going forwards

Show Notes:
AI-generated CSAM article on Sky News - https://news.sky.com/story/thousands-of-ai-generated-child-abuse-images-being-shared-online-research-finds-12991727

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_4z-EgH54KZk

The Power Of Digital Forensics: How ADF Solutions Is Revolutionizing The Digital Forensics Industry

Forensic Focus 13 hours ago

Si and Desi interview Emi Polito from Amped about how to become an Amped FIVE Certified Examiner (AFCE). They discuss the exam requirements, format, timeline for certification, and Amped’s future plans. Emi explains that the certification is aimed at demonstrating competency with the Amped FIVE video analysis software after completing training. The exam consists of multiple choice questions on theory and practical exercises using the software. Emi talks about the online exam format and process for passing or failing.

Emi also discusses the broader challenges many organizations face with validation and accreditation. He emphasizes Amped's commitment to developing tools that facilitate that process. The hosts reflect on the confusing accreditation landscape and Amped’s passion for improving training and certification in forensics. This episode provides an overview of Amped's new certification and perspective on challenges in the field of video forensics.

Show Notes:

Introducing The AFCE Certification (Amped FIVE Certified Examiner) - https://www.forensicfocus.com/news/introducing-the-afce-certification-amped-five-certified-examiner/

Video Evidence Principles With Amped Software - https://www.forensicfocus.com/podcast/video-evidence-principles-with-amped-software/

Digital Image Authenticity And Integrity With Amped Authenticate - https://www.forensicfocus.com/podcast/digital-image-authenticity-and-integrity-with-amped-authenticate/

File Analysis And DVR Conversion Training From Amped Software - https://www.forensicfocus.com/reviews/file-analysis-and-dvr-conversion-training-from-amped-software/

Amped FIVE Speed Estimation 2d Filter And Training From Amped Software - https://www.forensicfocus.com/reviews/amped-five-speed-estimation-2d-filter-and-training-from-amped-software/

Amped Software’s Martino Jerian on Key Challenges and Opportunities for Video Evidence - https://www.forensicfocus.com/podcast/amped-softwares-martino-jerian-on-key-challenges-and-opportunities-for-video-evidence/

LEVA 2023 Training Symposium - https://www.leva.org/

Forensic Collision Investigation & Reconstruction Ltd - https://www.fcir.co.uk/

Amped FIVE Certified Examiner - https://ampedsoftware.com/afce-certification 

Introducing the Amped FIVE Certification Program - https://blog.ampedsoftware.com/2023/10/04/introducing-the-amped-five-certification-program

Amped Software YouTube - https://www.youtube.com/ampedsoftware
How to Use the Validation Tool in Amped FIVE - https://blog.ampedsoftware.com/2023/03/29/how-to-use-the-validation-tool-in-amped-five

Si and Desi interview Emi Polito from Amped about their new certification called Amped Five Certified Examiner (AFCE). They discuss the exam requirements, format, timeline for certification, and Amped’s future plans. Emi explains that the certification is aimed at demonstrating competency with the Amped FIVE video analysis software after completing training. The exam consists of multiple choice questions on theory and practical exercises using the software. Emi talks about the online exam format and process for passing or failing.

Emi also discusses the broader challenges many organizations face with validation and accreditation. He emphasizes Amped's commitment to developing tools that facilitate that process. The hosts reflect on the confusing accreditation landscape and Amped’s passion for improving training and certification in forensics. This episode provides an overview of Amped's new certification and perspective on challenges in the field of video forensics.

Show Notes:

Introducing The AFCE Certification (Amped FIVE Certified Examiner) - https://www.forensicfocus.com/news/introducing-the-afce-certification-amped-five-certified-examiner/

Video Evidence Principles With Amped Software - https://www.forensicfocus.com/podcast/video-evidence-principles-with-amped-software/

Digital Image Authenticity And Integrity With Amped Authenticate - https://www.forensicfocus.com/podcast/digital-image-authenticity-and-integrity-with-amped-authenticate/

File Analysis And DVR Conversion Training From Amped Software - https://www.forensicfocus.com/reviews/file-analysis-and-dvr-conversion-training-from-amped-software/

Amped FIVE Speed Estimation 2d Filter And Training From Amped Software - https://www.forensicfocus.com/reviews/amped-five-speed-estimation-2d-filter-and-training-from-amped-software/

Amped Software’s Martino Jerian on Key Challenges and Opportunities for Video Evidence - https://www.forensicfocus.com/podcast/amped-softwares-martino-jerian-on-key-challenges-and-opportunities-for-video-evidence/

LEVA 2023 Training Symposium - https://www.leva.org/

Forensic Collision Investigation & Reconstruction Ltd - https://www.fcir.co.uk/

Amped FIVE Certified Examiner - https://ampedsoftware.com/afce-certification

Introducing the Amped FIVE Certification Program - https://blog.ampedsoftware.com/2023/10/04/introducing-the-amped-five-certification-program

Amped Software YouTube - https://www.youtube.com/ampedsoftware
How to Use the Validation Tool in Amped FIVE - https://blog.ampedsoftware.com/2023/03/29/how-to-use-the-validation-tool-in-amped-five

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_atEaNas9xnE

The Amped FIVE Certified Examiner (AFCE)

Forensic Focus 29th November 2023 10:28 am

This error message is only visible to WordPress admins

Important: No API Key Entered.

Many features are not available without adding an API Key. Please go to the YouTube Feed settings page to add an API key after following these instructions.

Latest Articles