BlackRainbow NIMBUS Nebula – 28th – 29th September 2026
BlackRainbow NIMBUS Nebula - 28th - 29th September 2026 More information coming soon. We look forward to seeing you there! Apply today
The request lands in the digital forensics inbox late on a Tuesday afternoon.
Legal wants to know whether an employee has taken confidential information. HR is already managing a conduct matter. The security team has raised an insider risk alert. IT has been asked not to disable the employee’s account until somebody confirms what data needs preserving.
The request itself contains one line:
“Can you look into this urgently?”
That is where the investigation begins.
Not with examining a laptop. Not with collecting a mailbox. Not with reviewing audit logs.
It begins with a series of phone calls, emails and Teams messages to work out what everybody is actually asking for.
Who is the employee? What is suspected to have happened? Which devices and accounts are involved? Has Legal authorised the collection? Is the employee aware of the investigation? Does any data need to be preserved immediately? Who needs the findings, and when?
Before the team can investigate the incident, it first has to investigate the request.
The problem is rarely a shortage of systems.
HR has a case management platform. Legal has a matter management system. IT has ServiceNow or Jira. The security team has its SIEM and insider risk tools. Digital forensics may have a spreadsheet or legacy system. The eDiscovery team records collections and review activity in another platform.
Each system contains something useful.
None contains the whole story.
HR knows why the employee is under investigation. Legal knows what has been authorised. IT knows which assets are assigned to the employee. Security has the alerts. The forensic examiner knows what has been collected. The eDiscovery team knows what has been processed and loaded for review.
Important decisions may exist only in an email thread.
Everyone has part of the picture, but nobody can see the entire investigation.
That leads to familiar questions:
The answers are usually somewhere.
Finding them is the difficult part.
ServiceNow, Jira and similar systems are very good at managing requests and technical work.
But an investigation is not a broken printer.
It does not always move neatly from open, to in progress, to resolved.
An initial alert may concern one employee and one laptop. The examination identifies a personal cloud account. Email analysis reveals another custodian. Legal expands the scope. HR asks for an interim finding before an interview.
The investigation changes as new information becomes available.
A ticket can show that a laptop was collected or a mailbox was exported. It may not explain why the collection was authorised, what restrictions applied, what was discovered or how the work relates to the wider matter.
This is where teams begin creating their own workarounds.
A spreadsheet tracks forensic requests. A Word document holds the investigation plan. Evidence is stored in a shared folder. Approvals remain in email. Progress is discussed in Teams. Findings are copied into the HR system when the work is complete.
The ticketing platform may be the front door, but the investigation itself is spread throughout the building.
The same problem applies to specialist technology.
A forensic tool is designed to acquire and examine devices. An eDiscovery platform is designed to process, search and review data. An insider risk tool is designed to identify and investigate alerts.
Those systems perform important jobs. They are not necessarily the investigation record.
The forensic platform may contain an image of the employee’s laptop, but not the Legal approval that authorised its collection.
The review platform may show which documents were tagged as relevant, but not why those custodians and date ranges were selected.
The insider risk platform may contain the original alert, but not the subsequent device examination, HR decision or legal outcome.
The technical work is recorded, but the reasoning around it becomes fragmented.
At that point, the organisation is no longer reviewing the investigation. It is reconstructing it.
Connecting the investigation does not mean giving everybody access to everything.
A sensitive employee matter may contain privileged legal advice, personal information, security intelligence and detailed forensic findings. Different teams require different levels of access.
HR may need to know that the examination is underway and when findings will be available.
Legal may require details of preservation, collection and disclosure.
The forensic examiner needs an authorised technical request with clear scope.
The eDiscovery team needs confirmed custodians, data sources, search dates and review instructions.
Senior management may only need to understand demand, risk, progress and expected completion dates.
Each team needs the right information for its role, not access to the entire case file.
The objective is not to put everybody into the same system and show them the same screen. It is to connect the work while maintaining appropriate control over sensitive information.
Requests, approvals, tasks, evidence, decisions and outcomes should form part of one joined-up process, even when different teams continue using their own specialist tools.
Copying an employee’s name or a case reference into another system may not seem particularly risky.
Repeat that across HR, Legal, IT, digital forensics, eDiscovery and security, and the problems begin to appear.
One system uses the employee’s full legal name. Another uses their preferred name. The laptop asset number is entered incorrectly. A preservation date is changed in the Legal record but not in the forensic request. Another custodian is added directly to the review platform without the original matter being updated.
One team marks its task as complete while another assumes that means the investigation has closed.
Eventually, people stop asking which record is correct and start asking which record was updated most recently.
This is not simply inefficient. It affects the organisation’s ability to explain and defend what it did.
Integration should therefore be viewed as more than a way to save a few minutes of administration.
It provides the thread connecting the original request, the authority to act, the work completed, the evidence produced and the final decision.
HR, Legal and IT do not necessarily need to replace their existing platforms. The investigation process needs to connect with them.
Most teams have found a way to make their current process work.
Experienced staff know which spreadsheet to check. They know who in Legal normally provides approval. They know where reports are stored and which person in HR needs to receive them.
That knowledge keeps work moving.
It also creates a process that depends heavily on individuals remembering what to do next.
People chase approvals. People copy information between platforms. People update trackers. People reconcile different case references. People remind other teams that work is still outstanding.
The investigation team becomes the integration layer between systems that do not communicate.
That approach can survive at low volumes. It becomes much harder to manage as demand increases, teams expand or experienced staff leave.
The answer is not another forensic tool, another review platform or another ticket queue.
Those systems already perform their specialist functions.
What is often missing is the operational layer around them: the process that connects intake, triage, authorisation, collection, examination, review, reporting and closure.
NIMBUS provides that layer across digital forensics, eDiscovery and insider risk operations.
It creates a structured record of the request, the people involved, the scope, the approvals, the tasks completed, the evidence handled, the decisions made and the eventual outcome.
Specialist teams can continue using the tools they rely on. HR, Legal and IT can continue operating within their existing environments. NIMBUS maintains the connected investigation record between them.
The aim is not to replace every system in the organisation.
It is to ensure that when someone asks what happened, what was examined, who authorised it and where the matter now stands, the answer does not depend on finding the right spreadsheet, ticket or email thread.
Because when an investigation involves employees, sensitive information, legal risk or the reputation of the business, piecing the story together afterwards is not good enough.

Carl Barron is VP, Global Solutions & Sales Engineering at BlackRainbow, leading the company’s global Sales Engineering function. With a background in digital forensics, eDiscovery, investigations and technology transformation, he works with law enforcement, government and enterprise organisations to translate complex operational challenges into effective technology solutions.
![]()
If you have a question about Black Rainbow or the NIMBUS ecosystem, visit our FAQs page or get in touch.
VIEW FAQSWe love showing off our next-gen product suite so please get in touch for a demo of the NIMBUS ecosystem.
REQUEST A DEMOA wide range of guides, white papers, thought leadership articles and videos authored by our expert team.
LEARN MORELooking for technical support? Visit our customer support portal where someone will be on hand to assist you.
GET SUPPORTComplete the form below and one of the team will get back to you as soon as possible.
"*" indicates required fields
"*" indicates required fields
Request a Demo