The organizational CP philosophy for incident response and digital forensics that focuses on the collection and preservation of potential evidence when responding to and recovering from an incident, with the expectation of possibly finding and prosecuting the attacker.