Digital Forensics & Incident Response
Evidence-driven investigations for Windows, Linux, cloud and SaaS sources.
- Hard drive & memory forensics.
- Timeline, triage & artifacts.
- Chain-of-custody & reporting.
Investigations, incident response,cloud and email security reviews by a Gothenburg-based expert with decades of hands-on experience. Pragmatic, precise, and discreet.
What we typically help with
Work across finance, medical, manufacturing, real estate, automotive, and academia.
Let’s define a scope and timeline.
Start a conversationClear scopes, fast onboarding, and defensible outcomes.
Evidence-driven investigations for Windows, Linux, cloud and SaaS sources.
Spam and Anti-Malware filtering,Phishing Protection, and general vendor best practices.
Azure & AWS posture reviews mapped to CIS, NIST, and vendor best practices.
Digital forensics and incident response require precision, consistency, and defensibility. Our process is fully repeatable, leverages validated tools, and prioritizes clear, actionable communication to all stakeholders — from executives to legal teams.
The result should support both immediate response efforts and long-term security improvements.
A robust email security strategy and configuration reduce the risk of phishing, malware delivery, and business email compromise (BEC) by combining assessment, configuration, and continuous validation against industry standards. It is important to understand that email configuration directly impacts the level of trust in your brand’s domain. Properly configured security frameworks protect not only your organization but also anyone receiving emails that appear to come from your domains—including those not sent through your official email gateway.
Our cloud security assessment identifies risks, prioritizes them based on likelihood and impact, and provides practical recommendations aligned with your organization’s risk tolerance and compliance obligations. Findings are framed in business context so that decision-makers can weigh security improvements against operational and strategic priorities.
Since 1994, I’ve lived and breathed IT—shifting my focus to security in 1998. In 2018, I founded Nansec to share what I’ve learned from decades of hands-on work with infrastructure, operating systems, and cloud platforms. My experience leading Incident Response and Digital Forensics across industries has taught me that security isn’t just about tools—it’s about protecting people and enabling trust. That’s what I bring to every project.
Based in Gothenburg, Sweden.
Keep engagements small, focused, and confidential.
Prefer email with your scope, timelines, and any confidentiality requirements.
We support Signal, S/MIME and PGP.
Email: niklas.andersson@nansec.se
Phone: +46 707 92 04 05
Location: Gothenburg, Sweden
Organisation number: 559166-4411
S/MIME Certificate: Link
PGP Key ID: 3D2C2F789D3590342F83C9AF31BB76B1C60CAF62 Link