Written evidence from Mr Stephen Falkner (DIS0029)
Personal response on the disclosure of digital evidence in criminal cases.
There are a number of reasons why I believe cases have failed at court because of disclosure issues. I can say as a digital practitioner in policing, that I have seen these problems coming for quite some time and have been able to ensure cases I was involved in had a better chance of success, but have not had sufficient influence to convince those above me of the problem. I believe the problem us getting worse.
I have broken my response down into a number of headings (9 sections, starting in Section 2), with each factor being a reason why I believe cases have resulted in failures to disclose and where those cases are now under review.
I have tried to include only what I believe to be the most relevant issues and kept it as simple as possible.
Principally the reasons for the failures in these cases come down to the following things: -
In relation to these points complexity of data and quantity of data is increasing and will mean the challenge of managing this data in criminal cases will only get harder.
I have included suggested solutions in with my conclusions at the end of this document. Essentially funding is the key cause of the problem but this requires some explanation.
About Me
My name is Stephen Falkner and I have been employed as a Digital Forensic Investigator with the Metropolitan Police Service since February 2004. I am currently employed by the Counter Terrorism Digital Media Exploitation Unit in London. Before working in this capacity I worked for many years in the IT industry for both private and public sector employers in a number of technical positions.
As a Digital Forensic Investigator I have been the lead digital investigator in more than 700 criminal cases and have given evidence at Crown Court on more than 30 occasions, including as an independent expert on two occasions and at the High Court on one occasion.
I have written internal policies and operating procedures and have regularly produced training materials on digital forensics for exhibits officers, traditional forensic practitioners and to lead investigators. This has included providing formal class-based training, as well as writing the materials being used in class and as handouts.
Digital data is complex. It is rarely in a humanly readable format and requires converting into a format which is then viewable by the investigations team. Data structures frequently change and it is common to see significant changes from one version of a program to the next. This means that automated tools, designed to recognise the specific data structures of common programs, cannot always retrieve and convert this data in its entirety. This necessitates the examiner to manually search for and convert this data.
Even where there are automated tools available, and this is not the case with many types of data, it is never possible to say that a tool created for that data type will recognise all entries and decode them correctly. This is particularly true where forensic tools recover deleted entries which may have been partially overwritten.
The result of these two problems is that it cannot be guaranteed that all data of a particular type has been recovered and is available to review. It also demonstrates the amount of work involved in examining digital data.
A second technical consideration is the difficulty in extracting all of the data from some digital devices. For example it is not possible to extract all data from newer generation iPhones, meaning some data has to be reviewed on the handset itself.
A third consideration is that of encryption. This is becoming more common post-Snowden, with individuals being more privacy aware but more significantly, manufacturers of devices and software developers enabling encryption by default. Encrypted data cannot be examined or keyword searched. Breaking into this data may be possible but is something that requires considerable processing resource and ultimately may still prove unsuccessful.
The quantities of data involved in modern investigations cannot easily be quantified to the lay person. I can say that I have worked on a fraud case where there were 7.4 million emails, about a third of which had attached files. Another case consisted of over 300,000 chat messages, some of which were in a foreign language. A further case consisted of 5.2 million documents, a number of which contained scanned images, (which are not searchable). In this latter example OCR software was successful with a number of them but over 10,000 documents had to be reviewed manually, including most of the hand-written ones. Quantities like these examples are not exceptional.
Going back to the example of the iPhone and not being able to extract certain data, I recently assisted an officer in reviewing 300 WhatsApp conversation threads in a terrorism case where some threads consisted of hundreds of messages and every message was in a foreign language. The entire process took the officer six 10 hour days to simply record all of the data (into video format). This was followed by translation and review, requiring a similar number of days.
If you consider how much time people spend using their digital devices and with each activity likely to result in the creation of artefacts, it becomes easier to see how much data is commonly present. For example: -
These investigative findings are perhaps the most important facts to disclose, but you can only disclose the findings you have. Without any direction from the defence, it is difficult to predict which of the many tens of thousands of artefacts should be examined and reported on.
Once data has been extracted, the officers reviewing this data for disclosure purposes do not receive formal training in dealing with digital data. In many cases these officers have insufficient understanding of the devices from which the data was obtained and have limited skills in reviewing the data using software tools.
In addition to this they may not be aware of other factors, such as the suspect/victim/witness regularly spells words incorrectly, or uses pet names or nicknames for the other parties in the case. They can search for and produce all messages where “Raymond” is mentioned, but what about “Ray”, “Raymund” or his nickname “Statto”?
They may have been instructed that only communications between certain dates are to be reviewed, but do not understand that with some types of data, dates and times are not reliable. As such material is not included in the review that might have been sent or received during the notable time period.
Officers and staff responsible for reviewing the data from a disclosure point of view do not normally have access to help from digital experts, whose involvement in that investigation has usually finished before the disclosure stage begins.
Disclosure may not be revisited when new information is received. This can happen late on and from my own experience it is not uncommon for the defence to provide a defence statement very late on in the process, perhaps even on the first day of the trial. For example it was not thought money spent by the suspect’s cousin (and business partner) was of interest. As such those payments were marked as ‘not relevant’. If it was later suggested the cousin was responsible for the fraudulent transactions, the cousin’s finances become relevant. Disclosure officers are not equipped to respond to situations like these and need to be more attached to the active investigation rather than providing a separate function.
As mentioned earlier, problems extracting some data, foreign languages, incorrectly spelt words and the quantities of data, contribute to challenges in assessing data for the purposes of disclosure. This becomes compounded further where data is subject to Legal Professional Privilege (LPP). It may be difficult to assess the data for LPP purposes and this can result in the data being reviewed for disclosure purposes very late on in the investigation.
Where there are multiple defendants, whose defences conflict, there may also be challenges in producing materials where redaction is required. This is also true when data is obtained from a witness or victim and where the entirety of data cannot be produced to the defence.
The process of redacting data can be very challenging and where required, is one of the most onerous tasks we engage in.
This point relates to the following two points in particular. Currently, all digital forensic units providing services to the criminal justice service are expected to achieve accreditation to ISO 17025, (by October 2017). Whilst the choice of standard is another matter for discussion, (it was designed for scientific test and calibration laboratories), the overall cost of delivering this standard is having a serious impact on resourcing.
I have been in departments where we had to take staff off operational duties, and budgets for training and equipment were swallowed up in order to pay for the requirements of accreditation.
Fewer staff working on cases, spending less time on cases, with less training and less equipment is affecting quality and is reducing our ability to find material that may be relevant to the case, and therefore make the job of the disclosure officers easier.
The cost of achieving accreditation is likely to result in the further loss of private companies providing services to the criminal justice system and this relates to both those providing services to the defence and those providing services to the prosecution. In both cases the very similar work of cyber security, insider threat management, internal investigations and due diligence work provides vastly better rates of pay and with there being no requirement to achieve accreditation.
Police units that subcontract work to private companies may find the number of providers diminishing such that more pressure is put on their own internal unit.
The effect of accreditation is that without extra funding, less time is being spent on each job in the criminal justice system.
The Metropolitan Police Service was tasked with achieving a 20% saving over 2010 levels by 2015, but was also tasked with a 20% increase in productivity. Such assertions are not achievable and whilst improvements can always be made, the reality is that most digital forensic units have not grown in number, despite seeing very significant increases in numbers of submissions year on year. Further, the number of disclosure officers has fallen, despite the increase in quantities and complexity of data since 2010.
The job of a disclosure officer was more straightforward in 2010, when it was unusual all data could not be extracted, where there was less material in foreign languages, less encrypted material and where users were less dependent on their digital devices, (and therefore stored less artefacts relating to activity).
The timing of the requirement to accredit digital forensics units at a time of greatest financial difficulty is very unfortunate.
With current funding levels, insufficient numbers of digital forensic practitioners are available to examine all devices in the case. This means fewer exhibits in the case are being examined and generally to a lesser extent.
Data acquired from digital devices is stored in a bespoke format requiring expertise and the right tools in order to examine that data. Whilst some data can be extracted into a humanly readable format, it is not possible to produce very much to defence solicitors to review.
Where a defendant receives legal aid to instruct their own expert, it is possible for us to provide ‘everything’ and the expert representing the defendant can conduct their own examination and advise their client. This is an excellent solution but is becoming less common following the introduction of reduced rates for legal aid some years ago.
An expert can only claim £72 /hr for defence work, but can usually command two or three times this amount for private corporate work. As such the number of people I know, professionally and personally, who conduct examinations as experts for the defence has gone from nine to one in the last three years.
This problem is further compounded by the introduction of a requirement to achieve accreditation to ISO 17025 by the Forensic Regulator. The cost of achieving such accreditation means that there is a very real prospect of losing what few practitioners we have who conduct examinations on behalf of the defence.
In cases where there is no defence expert, it can be difficult to predict what possible defences might be presented and what that will look like in terms of artefacts on a device. Defence solicitors are very reluctant to engage with the police and this makes it harder to know what might be relevant outside of the information provided by the prosecution investigators.
There are occasions when it is advantageous from both an investigative and disclosure point of view to have investigators sit with digital experts during parts of the examination process.
Where police units subcontract work to private companies, it is not always possible to do so to companies that are local to the issuing police service. For example in the Metropolitan Police, we have used companies in Manchester, Bolton, Stafford, Stratford upon Avon and, Nuneaton. Should the investigating officer need to review any data with the assistance of the digital expert, this has been problematic.
More funding for policing is a must if we are to avoid further cases like the ones that have precipitated this review. That funding needs to go in equal measures into; more staff, (both digital experts and disclosure officers), training for disclosure officers and in better software tools and equipment to facilitate the reviewing of data.
The loss of defence experts is deeply concerning, from a justice point of view alone. The current funding level of £72 /hr, coupled with the requirement for expensive accreditation, will reduce the number of experts available. It is no longer financially viable for businesses to continue to provide services at these rates and this figure has to be reviewed, especially now that accreditation is a requirement to receive work.
The loss of experts providing services to the defence has a cost implication for the criminal justice system. This is because a key role they play, is in explaining the evidence to the defence solicitors and to the defendant. This frequently results in a quicker resolution than where a defendant believes he/she has a realistic prospect of being found not guilty, when clearly the evidence strongly demonstrates guilt.
The loss of companies providing services to police forces will put further pressures on police units who are reliant on having an overspill capability at busier times. It is vital that funding levels for companies providing services to the prosecution are sufficient to ensure they will continue to offer these services.
Training is another key issue when it comes to helping investigation and disclosure teams understand the nature of digital data and to understand its provenance as well as its content. Very often it is the provenance which is more important than the content.
Defence solicitors are often not held to agreed dates to provide a statement of defence and in one case I was even challenged on a ‘brand new’ defence whilst under cross examination at trial, where it had never previously been indicated this might be part of their defence.
Failure to invest properly in these areas will increase the number of cases in which failures will occur and ultimately the costs will be much greater in terms of case reviews, overarching enquiries and possibly compensation to suspects/defendants.
March 2018