(Chris Tappin, Managing Director of 5n6)

Managing Director

Chris Tappin

Sixteen years of reactive and proactive Digital Forensics & Incident Response experience, from Law Enforcement to enterprise, from Big 4 to boutique consultancy.

DFIR experience
16 years
Based in
Sydney, Australia
Available to work
Internationally

Learn more below

Experience

Career

  1. 2026 – present: Managing Director, 5∩6

    I founded 5∩6 in 2026 to provide Digital Forensics and Incident Response consulting at a tumultuous time in Information Security. 5∩6 aims to sit at the intersection of human expertise and technical innovation, creating something greater than the sum of its parts.

  2. 2020 - 2026: APAC Lead, IBM X-Force Incident Response

    Responsible for delivery excellence for all DFIR consulting in APAC. Managed all APAC-based consultants. Matrix managed Australia-based Red team. Incident Management internally and externally.

  3. 2015 - 2020: Principal Consultant, Verizon VTRAC IR

    Acting as the Digital Forensics & Incident Response Subject Matter Expert for the APAC region. Payment Card Industry Forensic Investigations (PFIs), including RAM dumping Point of Sale terminals looking for fileless malware.

  4. 2013 – 2015: Manager, Deloitte

    Subject Matter Expert for challenging Digital Forensics cases such as Anton Piller orders. Adding forensic rigour to other engagements, such as developing a method of tracking cryptocurrency transactions for an audit team.

  5. Moved to Australia in 2013
  6. 2010 - 2013: Computer Forensics Consultant, Kroll Ontrack

    Provide Expert Witness Testimony, witness statements and appear in court in England. Develop innovative processes to extract data for wider investigations, such as parsing Bloomberg messages for searching or building a database of SWIFT transactions.

  7. 2010: BSc Hons. Forensic Computing, University of the West of England

    Graduated from UWE Bristol with first class honours. Completed a final year project developing a forensic triage tool to efficiently identify the owners of stolen computers recovered by Law Enforcement.

  8. 2009 - 2010: Digital Evidence Investigator, Nottinghamshire Police Force

    Forensic imaging and case management. Provided forensic support on warrants executed by the Serious & Organised Crime Unit. Developed improved GPS forensics processes.

Experience

Selected Cases

Expert Witness Forensics Cases

London, United Kingdom

Convinced a wide variety of paedophiles to plead guilty at various points in the legal process between initial charging and a teleconference during a trial's adjournment. Often this involved reporting on evidence in excess of their formal charges. One notable exception was an in-court appearance for alleged offences under the Protection from Harassment Act 1997, leading to a not guilty verdict.

Need an expert witness? View 5∩6 services

Covert Insider Threat Investigation

Abu Dhabi, United Arab Emirates

When you suspect your company's own partners of acting against the business, how do you investigate? The answer in this case was covert forensic imaging of endpoints in offices in Dubai and Abu Dhabi, between close of business one day and start of business the next.

Get in touch to discuss your requirements

Covert Nine Figure Fraud Investigation

Kabul, Afghanistan

Many of the most sensitive investigations will never be discussed, but occasionally a third party will leak a report creating international headlines! I led the digital forensics for this investigation, which included parsing SWIFT transactions from a forensic image.

BBC article (external link)

Fileless Malware in Point-of-Sale

San Francisco, United States

I've worked on several cases in which payment card details were suspected to have been harvested by malware running in memory on the tills, including for a major retailer in the US.

Tricky forensics requirement? View 5∩6 services

Major Public Sector Data Breach

Sydney, Australia

Logistical concerns as well as technical can impact the speed of an investigation, which in this case required ferrying removable storage between data centres under strict chain of custody.

Get in touch for an extra pair of hands

Critical Firewall Vulnerability

Manila, Philippines

The customer of a global firewall vendor was compromised as a result of a significant product vulnerability. Working in partnership with the vendor's product support team, I developed a process to collect forensic triage data from the firewalls using UAC that was more extensive than the vendor's own Incident Response team's approach.

UAC GitHub page (external link)

Would you like to know more?

Get in touch via the contact form, or message Chris on LinkedIn.