Digital forensic readiness in IoT-enabled organisations and forensic investigation analysis in real-time [Thesis]

Kuku, Oyeyemi (2026) Digital forensic readiness in IoT-enabled organisations and forensic investigation analysis in real-time [Thesis]. Doctoral thesis, London Metropolitan University.

Abstract

The rapid growth of the Internet of Things (IoT) has transformed organisational digital environments into highly distributed, data-driven ecosystems. While many organisations invest heavily in cybersecurity tools to detect and respond to threats, far fewer are equipped to systematically identify, collect, preserve, and analyse digital evidence in a timely, cost-effective, and legally compliant manner. This gap in Digital Forensic Readiness (DFR) is particularly critical in IoT-enabled organisations, where potential evidence is distributed across diverse, often volatile devices, networks, and platforms. This research presents a Digital Forensic Readiness Model aligned with ISO/IEC 27043, specifically tailored for organisational IoT environments. The model combines governance, technical infrastructure, and security preparedness into a unified framework, emphasising forensic readiness as an ongoing organisational capability rather than a reactive, post-incident measure. It supports proactive evidence identification, real-time collection, secure preservation, and reliable chain of-custody management, thereby protecting the integrity of forensic processes within complex IoT ecosystems.
The model was tested through practical deployment within a controlled organisational setting using real-world security monitoring and forensic tools. Several simulated cyberattack scenarios were conducted to evaluate their effectiveness in realistic operational environments. Machine learning-based analysis was also used to prioritise forensic artefacts and identify key evidential features, enhancing investigative efficiency while adhering to legal and evidential standards. The results demonstrate that the proposed model significantly improves organisational forensic readiness by reducing investigation time, maintaining evidence integrity and traceability, and enabling automated, standards-compliant forensic procedures. This study offers a practical, implementable DFR model that links international forensic standards to real-world IoT deployments, strengthening organisational cyber resilience and digital investigative capabilities.

Documents
11845:58633
[thumbnail of Oyeyemi Kuku_21053307.pdf]
Preview
Oyeyemi Kuku_21053307.pdf - Published Version

Download (8MB) | Preview
Details
Record
View Item View Item