KONCYBER

Investigations & Evidence

Cybercrime Investigations: A Practical Guide to Solving Complex Cases

October 5, 2026

Most complex cybercrime investigations don't stall because the investigators lack technical skill. They stall because, at some point in the file, nobody can answer three questions on demand: what do we actually know, how do we know it, and what are we doing next? Almost everything I teach about investigating cybercrime comes back to making those three questions easy to answer.

That's why I developed TRAPS™: Trace, Reconcile, Attribute, Prepare, and Select Outcome. It isn't a tool, and it isn't a checklist you complete once. It's a sequence of questions that tells an investigator what the dominant problem is at this point in the file, and what disciplined work looks like in response. TRAPS™ can stand entirely on its own, and it can sit inside a larger case management structure when a file is big enough to need one. Either way, the goal is the same: keep the investigation moving forward without losing track of why you believe what you believe.

TRAPS™ methodology, developed by Kenrick Bagnall. © 2026 KONCYBER Inc.

Why complex cases go sideways

Start with the problem the framework solves. Evidence in a cybercrime file is spread across the victim's systems, cloud providers, financial intermediaries, and sometimes several jurisdictions, and each source has its own custodian, its own retention period, and its own process for getting at it. Those clocks run at different speeds, and the slowest one is usually the one you needed. On top of that, technical identifiers don't identify people. An IP address is a lead, not a person, and an account in someone's name is not proof of who was typing. When information isn't controlled, leads get missed and the same work gets done twice.

Trace: build the foundation before the theory

Trace is where the file is established. Start with what is actually being reported, and keep three things separate: what the victim described, what a responder concluded, and what an investigator directly observed. They look alike in a complaint. They are not the same kind of evidence.

Then map the sources. For every place relevant material might live, whether that's victim systems, service providers, accounts, communications, or financial records, write down the custodian, the date range, how volatile it is, and what action is needed. Preservation and production are different things. Getting a provider to hold data does not entitle you to receive or search it, and the lawful route depends on the facts and the jurisdiction. The habit that matters most here is refusing to treat a sent request as a confirmed preservation. Record that it went out, that it was received, what it covered, and for how long, or record plainly that you don't know yet. Marking a task complete because an email was sent is one of the quietest ways evidence gets lost.

What comes out of Trace is small and concrete: an initial case brief, an evidence source map, a first chronology, and a list of urgent tasks with a name beside each one.

Reconcile: make the timeline something another investigator can challenge

Reconcile turns isolated observations into a sequence you can test. Every entry in the timeline should point back to a specific source: an exhibit, a record identifier, a statement. Keep the original timestamp and its stated time zone, and record how and why you converted it. A clean-looking timeline built on hidden time assumptions is worse than a messy one that shows its work.

Be just as disciplined about relationships. "This account is registered to a person," "this account was accessed by a device," "this device used this address at this time," and "this person controlled this device" are four different propositions with four different kinds of proof. Label each link as observed, reported, or inferred, and when two records contradict each other, treat the contradiction as a task, not an annoyance. Take a common IP address that appears in two sessions. Before treating them as one person's activity, check the time, how the address was allocated, whether access was shared, and what else could explain it. If the link stays uncertain, show the uncertainty on the chart. Don't strengthen the label because the briefing is tomorrow.

A negative result belongs in the record too. A search that came back empty is useful if you wrote down what was checked and under what conditions. It doesn't prove the event never happened.

Attribute: test the story, don't tell it

Attribution is a reasoned assessment of responsibility, not something you arrive at by landing on a name. State the proposition precisely: this person, this act, on this basis. Then put the supporting material and the contradicting material side by side. Seek corroboration from genuinely independent sources. Three reports that all trace back to the same original intelligence are one source, repeated, and that dependency should be written down.

Take a hypothetical. A contractor's account appears in suspicious cloud activity during a ransomware extortion. The account is assigned to the contractor. That's a lead, not an identification. Ask what would distinguish the contractor from another authorized user, or from someone using a compromised credential, and name the record or witness that could settle it. If the provider then confirms several staff shared that credential, the claim you can support just got narrower. The right response is to write that down and task the next test, not to defend the original theory.

That's why I build one habit into every attribution review: state the strongest alternative explanation, and identify the evidence that would weaken the preferred one. Tunnel vision rarely feels like tunnel vision from the inside, so the challenge has to be routine rather than optional. And keep a rejected hypothesis visible in the record even after it's been disproved.

Prepare: plan the action, and what happens after it

Prepare is where findings become lawful action: a request for records, a device examination, an interview, an enforcement operation. Define the objective, confirm the authority and scope for that specific action, name who is responsible for what, and check the dependencies and contingencies. Management sign-off doesn't create legal authority and can't cure a defect in an authorization, so get the right legal input on what that particular action requires.

Then plan the part most people skip: what happens after. Intake, custody, examination priorities, who reviews what comes back, and which hypothesis it could confirm or break. Evidence that's collected but never reviewed doesn't answer the question that justified collecting it. And if new material undermines a key assertion shortly before the action, stop and route it to the decision maker. Once the action is done, the results go back into Trace, Reconcile, or Attribute. They are not an automatic step toward a prosecution package.

Select: choose what the evidence supports

Select Outcome is broader than preparing for a conviction. Depending on what the evidence supports, the right outcome might be a prosecution referral, a referral to another agency, a lawful protective or disruptive measure, further inquiry aimed at one defined gap, or documented closure with the reasons and the conditions that would reopen it. A police recommendation and a prosecutor's independent decision are different things with different standards, and they should stay separate in the record.

A harmful incident can be proven while individual responsibility stays unresolved. In that situation, the honest and defensible outcome is often continued investigation of one specific question, protection for victims, and a named owner. What it should never be is an invented fact that carries the file to a more satisfying ending. The test I use for the completion record is simple: could someone who never worked the case understand why this outcome was chosen, what was rejected, and who owns whatever is still open?

What runs underneath all five

Four activities don't belong to any single phase: evidence preservation, legal and ethical review, information and disclosure management, and victim and partner communication. Their intensity changes, but their responsibility never disappears. Disclosure is the one I'd press hardest. Start a working disclosure index at intake, keep the contradictory findings and anything that might assist the defence, and never resolve a privilege question by quietly leaving material out of the record. The prosecution narrative and the disclosure collection are not the same thing.

Control the information the same way. Give sources, findings, tasks, and decisions stable identifiers and link them in both directions, so any conclusion can be traced back to the evidence behind it and forward to the decision that followed. Don't let a personal spreadsheet become the only record of significant work.

The phases aren't a one-way street, either. New evidence that contradicts the timeline sends you back to Reconcile. A challenged attribution can send you back to Trace for a source you never preserved. That isn't the method failing. That's the method working.

Where to start on Monday

Take a live file. Work out which phase it's really in, regardless of which one it feels like. Write down the next question that has to be answered, who owns it, what source material it needs, and where the result will be recorded. Then ask the five questions I'd put to any case review: what is known, what remains open, who acts, where is it recorded, and when is it reviewed. If you can't answer them, you've just found the work.

Complex cases aren't solved by genius. They're solved by teams that can show their reasoning and stay honest about what they don't know yet. That's what TRAPS™ is for.

Get the next issue