ABOUT SANDPIPER
Sandpiper Forensics was created to provide specialist Microsoft 365 security and digital investigation services with a straightforward approach: understand what happened, explain it clearly and help organisations decide what to do next.

The experience behind Sandpiper
Sandpiper Forensics was founded by Aaron Short, a digital forensics and incident response professional with more than a decade of investigative experience.
Aaron spent around seven years working in law enforcement digital forensics, progressing to a team leadership role. During this time, he worked on thousands of digital forensic examinations involving computers, mobile devices and other sources of digital evidence.
He then spent four and a half years working in incident response at Sophos, investigating cyber incidents affecting organisations in the UK, Europe and internationally. During this time, Aaron developed a specialism in Business Email Compromise and became the subject matter expert for BEC investigations across the UK and European incident response team.
His commercial incident response work included hundreds of cyber investigations, with a particular focus on Microsoft 365 and Business Email Compromise incidents.
Sandpiper was created to bring together that digital forensic and incident response experience and make it available directly to businesses and organisations that need specialist investigative support.
10+ years
Digital forensics & incident response
Thousands
Digital forensic investigations & examinations
Hundreds
Commercial cyber investigations
UK & EU BEC Specialist
Former specialist role in incident response
A practical approach to investigations
Cyber incidents are already complicated enough. The investigation doesn’t need to make them harder to understand.
Understand the evidence
Examine the available evidence to establish what happened and determine the scope of the incident.
Explain what it means
Translate technical findings into clear information that technical and non-technical stakeholders can understand.
Decide what happens next
Provide practical recommendations based on the findings, helping organisations make informed decisions about containment, recovery and security improvements.
Specialist, not generic
Microsoft 365 and Business Email Compromise investigations require an understanding of identity, authentication, email, audit data and attacker behaviour. Sandpiper focuses on these areas rather than trying to be everything to everyone. Alongside incident investigation, Sandpiper provides Microsoft 365 security reviews designed to identify weaknesses before they contribute to a compromise.
WHO WE WORK WITH
Independent expertise when you need it.
Businesses
Independent investigation and Microsoft 365 security support.
MSPs
Specialist escalation support when customers experience complex Microsoft 365 or email security incidents.
Cybersecurity & Incident Response Teams
Additional investigative capacity and specialist Microsoft 365 expertise.
Legal & Professional Services
Clear, evidence-led investigation and reporting to help establish what happened.
CONTACT
Tell us what’s happened or what you’re concerned about. We’ll help determine the appropriate next steps.
Speak to an Investigator