TIERS Insights
Five Questions to Ask Before Collecting a Mobile Device
The authority, factual question, device condition, acquisition method, and intended deliverable should be clear before a mobile forensic collection begins.
A mobile device can contain years of personal and business information, but a forensic tool does not automatically turn that volume into an answer. Before collection, counsel and the examiner should resolve five questions that affect legality, preservation, cost, privacy, and the usefulness of the result.
1. What is the authority to access and collect the device?
Identify the device owner, custodian, account holder, organization, and person directing the work. Determine whether authority comes from documented consent, ownership, employment policy, administrator rights, legal process, court order, or another valid basis.
Authority should address more than physical possession. A device may contain personal accounts, third-party communications, privileged material, health information, location history, or data synchronized from services the organization does not own. Advanced acquisition, lock-related work, cloud access, and credential use may require additional review.
The examiner should receive written direction identifying the permitted scope and a contact for questions. Do not assume that knowing a passcode or having an unlocked device resolves the authority issue.
2. What facts must the collection help test?
Define the question in operational terms. Examples include:
- Did a particular conversation exist during a defined period?
- Was a file received, viewed, shared, modified, or deleted?
- Does device activity align with a disputed timeline?
- Was a specific account or application configured on the device?
- Can mobile records corroborate or contradict another data source?
The answer determines whether a limited backup or export is sufficient, whether a file-system acquisition is necessary, whether cloud records are more authoritative, and which artifacts deserve focused analysis.
3. What is the current device condition and preservation risk?
Record whether the device is on or off, locked or unlocked, charging, damaged, connected to Wi-Fi or cellular service, subject to remote management, low on storage, running an update, or actively used. Identify disappearing-message settings, application retention, account suspension, remote-wipe capability, and known synchronization behavior.
A blanket instruction to power off a phone is not always correct. Some devices preserve access better when maintained in a controlled powered state; others present network or remote-action risk. The examiner should provide device-specific handling instructions when possible.
Avoid repeated passcode attempts, updates, resets, application launches, manual message forwarding, or improvised “backups” until the preservation plan is set.
4. Which acquisition method is proportionate and technically suitable?
Mobile acquisition methods expose different categories of data. A screenshot, application export, cloud export, backup, logical acquisition, file-system acquisition, or advanced method may produce materially different results. The most invasive method is not always the best method.
Consider:
- Whether deleted records or application databases are important
- Whether the device can be unlocked and maintained lawfully
- Operating-system and model support
- Encryption and security state
- Time available and risk of altering the device
- Need for repeatability, validation, or testimony
- Whether another source contains a more complete or less intrusive record
The examination record should state the method, tool and version, material settings, warnings, identifiers, date and time, verification steps, and known limitations.
5. How will counsel use and review the output?
A full extraction can contain a large amount of irrelevant and sensitive information. Decide whether the legal team needs a portable report, a tagged export, a focused findings report, a timeline, selected native media, an RSMF messaging package, or data prepared for a review platform.
Define the date range, applications, participants, artifact types, metadata fields, context requirements, and redaction or privilege workflow. A review-ready deliverable should preserve enough context to avoid misleading interpretation without exposing unnecessary data.
One final question: what happens after collection?
Confirm custody, storage, access, retention, return, destruction, and follow-up responsibilities. Collection is not the end of the evidence lifecycle. The most defensible matter record explains what was collected, what was not, how the data was handled, and why the chosen method was appropriate.
Why “collect everything” is not a neutral choice
A full mobile extraction may expose unrelated family communications, health information, financial records, personal photographs, location history, authentication artifacts, and data belonging to third parties. That volume can increase privilege review, privacy risk, storage cost, and the chance that sensitive material reaches people who do not need it.
When a broader acquisition is technically necessary, the engagement can still limit who accesses the extraction, which artifacts are actively reviewed, what is exported, and how irrelevant information is retained or destroyed. The collection method and the review scope are separate controls. Counsel should define both before the examiner begins.