Following a cyberattack on a government agency, a court, a company, or an archiving system, it may be unclear which files remain unaltered and which may have been tampered with. This is particularly critical in the case of court records, administrative documents, contracts, or other documents relevant to evidence.
A cyberattack is not only an IT security incident but also an issue of evidence. If the integrity of digital records can no longer be verified, proceedings may be delayed, cases may be reevaluated, or documents may be deemed unreliable.
The integrity of documents, files, or archival items is verified and their timestamps recorded even while operations are ongoing. After an attack, the current files can be compared to the backed-up versions. This makes it possible to determine which files are unchanged, which have been tampered with, and which cannot be verified.
RECORDPROOF is particularly well-suited for this purpose, as it functions as middleware between the end system and the archive system, structures archive packages in a way that ensures their integrity, and implements the BSI guideline TR-ESOR for preserving the evidential value of cryptographically signed documents. eRecApp can be used as a supplement for large volumes of files or documents, while TSS 500 secures individual, particularly critical documents with split-second precision.