// EXPERT OPINION AND FAILURE INVESTIGATION · HANS STUDY · ONTARIO, CANADA
Expert opinion and failure investigation
The system did not do what it was supposed to do, and now there is a disagreement about why. An opinion is only worth reading if the person writing it has nothing to gain from the conclusion, which rules out almost everyone else in the room.
I write independent technical opinions on security and network systems, and I investigate systems that failed. I sell no hardware, no software and no installation, take no commissions, and hold no margin on anything specified, so I have no relationship with any manufacturer or integrator that a finding could threaten. The independence policy sets that out in specifics, and on this page it is the entire reason the work has value.
When this is the right call
- The footage was not there. An incident happened, the recording was supposed to exist, and it does not. Somebody needs to establish why, and whether it was a design fault, a configuration fault, or a failure nobody was monitoring for.
- A project has broken down. The owner says it was not built to spec, the integrator says the spec was unclear, and both are partly right. An independent read of what was specified against what was delivered.
- An insurer is asking questions. Whether the system was adequate, maintained, and functioning at the time of a loss.
- A system keeps failing and nobody can say why. Intermittent faults, recording gaps, access control that drops, problems that disappear when anyone looks.
- Counsel needs a technical position that will not fall apart under examination by the other side's expert.
How the work runs
- Scope and conflict check first. Any prior relationship with a vendor, integrator or party involved is disclosed before the engagement starts, not after. If it would compromise the opinion, the engagement does not proceed.
- Evidence gathering. Configuration, logs, as-builts, specifications, correspondence, and where useful a site visit. What exists is recorded as found.
- Analysis against a standard. The contract documents, manufacturer guidance, applicable codes, and ordinary professional practice. Not against opinion.
- A written opinion stating what was found, what it means, what remains uncertain, and the reasoning that connects them.
Findings are written as found, including where they are inconvenient for whoever commissioned the work. That is the arrangement, and it is stated at the outset so nobody is surprised by it later.
What an opinion covers
- Whether the design was adequate for the stated requirement.
- Whether the installation matches what was specified and paid for.
- Whether the system performed as claimed, and what it was actually capable of.
- Whether maintenance and monitoring were adequate to catch the failure.
- Root cause where it can be established, and the limits of what the evidence supports.
What this is not
This is technical opinion and investigation work. It is not digital forensics, evidence acquisition, or chain-of-custody handling, and it is not legal advice. If a matter requires forensic evidence handling, you need someone engaged specifically for that, and I will say so rather than stretch the scope.
One practical note that matters more than it sounds: preserve the evidence before anyone tries to fix anything. Logs roll, recorders overwrite, and configurations get changed by well-meaning people during troubleshooting. The first hours after a failure routinely destroy the answer.
Get a straight answer on what happened
Disputes get more expensive the longer the technical question stays open. An early independent read often settles a matter that would otherwise run for months.
Related work: access control failures traced to cause across a multi-tower complex.