Jonathan Matkowsky

Jonathan Matkowsky

Threat-intel-backed investigation and domain takeover proceedings

Decades of experience spanning internationally recognized law firms, in-house legal teams, and elite cyber threat-intelligence teams.

I bring that experience together to investigate and disrupt malicious infrastructure, use legal process to pursue attribution, and where appropriate, make criminal referrals aimed at stopping threat actors from targeting or retargeting your organization.

Let’s explore together what makes practical sense for your organization.

When should a cyber investigation be escalated to law enforcement?

There is no single threshold for every organization or incident. Factors can include the nature and scale of the conduct, ongoing victimization, unauthorized access, financial loss, threats to critical systems, repeated targeting, evidence of an organized criminal operation, and whether government authorities may have investigative powers or visibility unavailable to the victim.

Evidence preservation matters even when the organization is not yet certain whether it will make a referral. Relevant logs, timestamps, domains, IPs, URLs, communications, technical artifacts, and a clear chronology can make later coordination more useful and reduce the risk that volatile evidence disappears.

The FBI encourages victims of cyber-enabled crime and fraud to report promptly, while CISA incident-response guidance emphasizes preserving evidence and coordinating with law enforcement where applicable. A referral should therefore be treated as an evidence and coordination decision, not merely the final step after every other option has failed.

Sources: FBI — Cyber · CISA — #StopRansomware Guide

AI can make mistakes. By using this site, you hereby agree to the Terms and Privacy Notice.