1. Introduction
The rapid digitisation of South Africa’s socio-economic landscape has led to a parallel escalation in cyber-dependent and cyber-enabled crimes. As criminal activities increasingly transit through digital mediums, the search, access, and seizure of electronic evidence have become cornerstone functions of the modern criminal justice system. However, the transition from traditional physical evidence to volatile digital data presents a unique set of technical and legal hurdles for law enforcement agencies. This study investigates the systemic challenges associated with the procurement of digital evidence, focusing specifically on the operational experiences of the South African Police Service (SAPS) Cyber-Crime and Deep Web Investigation Unit and the National Prosecuting Authority’s (NPA) Specialised Commercial Crime Unit (SCCU).
The legal framework for these investigations is primarily governed by the Cybercrimes Act 19 of 2020, which seeks to modernise the state’s ability to handle digital “articles.” Despite this legislative progress, practical execution remains fraught with obstacles. Recent data underscores the severity of this gap: while over 100,000 banking breaches were reported in 2024 resulting in R1.8 billion in losses, SAPS official registers recorded only 544 cyber-related fraud cases for that same period. Furthermore, the SAPS Strategic Plan 2025–2030 explicitly identifies an “inability to utilise IT evidence optimally” and a “loss of cases due to lack of relevant IT skills” as critical institutional threats.
While existing studies have examined the technical capabilities of digital forensic tools, limited attention has been given to how investigators and prosecutors navigate the methodological and procedural challenges associated with producing court-admissible digital evidence. In particular, there is insufficient understanding of how forensic practices align or fail to align with legal expectations in the South African context. The primary problem addressed in this research is the perceived gap between the technical capabilities of investigators and the stringent admissibility requirements of the prosecution. For digital evidence to be legally viable, it must be acquired and preserved in its original state, a process requiring high-precision tools and a meticulously documented chain of custody. By exploring the views of 30 specialised participants, this study identifies the systemic barriers ranging from resource constraints to procedural complexities that hinder the effective prosecution of cybercrime in South Africa. This research contributes to the field by proposing actionable policy implications aimed at harmonising technical forensic practice with judicial standards.
Accordingly, this study is guided by the following research questions:
- (a)
How do digital forensic investigators and prosecutors in South Africa conceptualize and apply digital forensic methodologies in practice?
- (b)
What challenges emerge in the production, documentation, and presentation of digital evidence for legal proceedings?
- (c)
How do practitioners navigate tensions between investigative processes and evidentiary requirements?
1.1. Problem Statement
The rapid digital transformation of the South African socio-economic landscape has been mirrored by a sophisticated escalation in cyber-dependent and cyber-enabled crimes. While the Cybercrimes Act 19 of 2020 was enacted to modernise the state’s ability to search, access, and seize digital articles, a critical gap remains between this legislative intent and the practical execution of digital forensic investigations. Official reports from the SAPS [
1] reveal a staggering disparity between reported cyber-incidents and actual prosecutions, indicating that the mere existence of a legal framework is insufficient to counter institutional bottlenecks.
Current research underscores that law enforcement and prosecutorial units, such as the SAPS Cyber-Crime Unit and the NPA’s SCCU, are operating within a sophisticated ecosystem of cloud-based challenges and encrypted platforms that often outpace existing investigative methodologies [
2,
3]. The primary problem is two-fold:
Technical and Competency Gaps: There is a documented lack of specialised expertise and multidisciplinary frameworks required to integrate Artificial Intelligence (AI) and machine learning into the forensic workflow, which is essential for managing the massive data volumes found in modern criminal cases [
4,
5,
6].
Procedural and Legal Hurdles: Stringent judicial requirements for auditable continuity and forensic integrity, as mandated by Sections 26 and 29 of the Cybercrimes Act, often clash with the “ever-changing” nature of mobile and social media evidence [
7,
8].
This research addresses the misalignment between digital forensic methodologies, specifically the processes of evidence acquisition, documentation, interpretation, and presentation and the evidentiary standards required by South African courts. Without addressing these structural impediments, including resource constraints, uneven digital literacy, and poor inter-agency coordination [
9,
10], the South African criminal justice system remains vulnerable to miscarriages of justice and a backlog of unprosecuted cyber-offences. This study empirically investigates these intersecting challenges to propose a sustainable roadmap for digital forensic practice in South Africa’s AI-driven era.
1.2. Literature Review
Digital forensic investigations have become indispensable to contemporary cybercrime policing as criminal activities increasingly exploit digital and networked environments. Digital forensics is defined as the application of scientific and analytical techniques to identify, preserve, extract, document, and analyse digital data while maintaining evidentiary integrity for legal proceedings [
11,
12]. Recent scholarship emphasises that the exponential growth of cloud computing, mobile devices, and encrypted platforms has intensified investigative complexity, requiring adaptable methodologies and specialised expertise [
2,
13,
14]. International studies demonstrate that the probative value of digital evidence depends heavily on procedural compliance and auditability; forensic soundness and reproducibility remain essential to evidentiary credibility [
15]. Recent research confirms that courts increasingly interrogate the acquisition and storage of digital evidence, where deficiencies in chain-of-custody documentation frequently result in exclusion [
16,
17].
In developing nations like South Africa, a persistent gap exists between investigative capacity and prosecutorial requirements. Empirical studies identify limited specialised training, inconsistent standard operating procedures (SOPs), and resource constraints within law enforcement units [
13,
18,
19]. These challenges are compounded by rapid technological change and offender sophistication, placing sustained pressure on institutions to update forensic toolkits [
14,
20]. Furthermore, recent African-focused research highlights structural impediments such as weak inter-agency coordination and victim reluctance to participate in proceedings due to reputational risks [
21,
22]. This study builds on this body of literature by examining how these technical and institutional challenges intersect within specialised units, contributing nuanced insights into South African cybercrime enforcement.
1.3. Legislative Framework: The Cybercrimes Act 19 of 2020
The legal regulation of digital search, seizure, and evidential use in South Africa is primarily governed by the Cybercrimes Act 19 of 2020, read alongside the Criminal Procedure Act 51 of 1977. The Cybercrimes Act represents a significant reform, extending the concept of articles to encompass electronic data and network-based systems while introducing extra-territorial jurisdiction [
23]. A defining feature of the Act is its recognition of the multi-stage nature of digital investigations. Specifically, Section 29 of the Cybercrimes Act 19 OF 2020 distinguishes between the physical seizure of a device and the subsequent search or extraction of data, each requiring independent legal authorisation. Legal analyses note that while this increases procedural safeguards, it elevates the risk of evidentiary exclusion if investigators fail to obtain specific warrants for each stage [
21,
24].
Evidentiary integrity is further mandated through Section 26 of the Cybercrimes Act 19 of 2020, which requires the National Commissioner of SAPS to establish Standard Operating Procedures (SOPs) ensuring that digital evidence remains authentic and unaltered. These statutory requirements align with international standards regarding hash-value verification and forensic reproducibility. Furthermore, Section 37 of the same Act reinforces these procedural safeguards by criminalizing wrongful or unauthorized searches, access, or seizures by officials, while Section 33 of this very Act strictly limits data access following a warrantless seizure upon arrest.
To address technical gaps, the Cybercrimes Act facilitates expert assistance and data preservation under the same integrated framework. Specifically, Section 34 of the Act allows investigators defined as fit and proper persons who are not police officials—to assist SAPS with specialized forensic tools during execution. Finally, Sections 41 and 42 of the same uniform legislation provide for the expedited preservation of data, legally compelling electronic communications service providers and entities to freeze data in its original state to prevent alteration. While this cohesive framework provides a robust foundation, recent scholarship argues its effectiveness is contingent on sustained investment in infrastructure and inter-agency collaboration. Consequently, this study illustrates how legislative intent and forensic practice converge or clash within South Africa’s practical enforcement landscape.
Figure 1 provides a conceptual overview of digital forensic domains, acquisition methods, and analytical processes, illustrating the multi-layered nature of digital investigations.
The chart below displays some main sub-categories and subject areas of Digital Forensics.
The figure distinguishes between domains of investigation (such as computer, mobile, and network forensics), modes of evidence acquisition (live and post-mortem), and analytical processes (including malware and traffic analysis). This differentiation addresses the complexity often conflated in digital forensic classifications. According to [
12], digital forensics is defined as “analytical and investigative techniques used for the identification, preservation, extraction, documentation, interpretation and analysis of computer system and digital information which is stored or encoded for evidentiary and root cause analysis.” The responses sourced from the participants made it appear that there is no different between the normal crime investigation and forensic investigation, let alone the digital forensic investigations. However, this perception obscures important distinctions. Unlike traditional investigations, digital forensic investigations involve highly volatile evidence, complex chain-of-custody requirements, reliance on verification of technical processes, and frequent jurisdictional challenges due to distributed data environments.
1.4. Identification of the Research Gap
Despite a growing body of international literature on digital forensics, a significant gap remains regarding the practical, lived experiences of practitioners operating within the South African criminal justice system. Existing research has predominantly focused on the theoretical provisions of the Cybercrimes Act 19 of 2020 or the broad socio-economic impact of cyber-attacks [
18]. However, there is a lack of empirical evidence addressing the specific translation of technical forensic findings into admissible legal evidence within the South African courts. Current scholarship often treats digital forensics as a standalone technical discipline, yet it lacks an integrated analysis of the inter-disciplinary silos between the SAPS Cyber-Crime Unit and the Specialized Commercial Crime Unit (SCCU). Previous studies have identified general resource constraints [
13], but have failed to interrogate the procedural bottlenecks, such as the 30-min chain of custody gaps and the regulatory lag in Section 34 of the Cybercrimes Act regarding mandatory technical assistance, that lead to case withdrawals.
In the South African context, Section 34 of the Cybercrimes Act 19 of 2020 explicitly governs the statutory provision of technical assistance required from electronic communications service providers, financial institutions, or private third parties during search and seizure operations. Delays or gaps in this specific legislative process may result in incomplete documentation of evidence handling. Even short disruptions, such as a 30-min break in documented custody, can compromise the continuity of digital evidence, thereby affecting its ultimate admissibility in court. This study fills this gap by providing first-hand, qualitative insights from 30 specialized practitioners, offering a rare dual-perspective (investigative and prosecutorial) that is missing from existing South African criminology literature.
1.5. Significance of the Study
This research holds profound significance for the NPA, specifically the SCCU, as it directly addresses the systemic prosecution-guided investigation gaps that currently hinder the successful adjudication of cyber-crimes in South Africa. As of early 2026, the NPA has transitioned into a sustained performance phase, yet it continues to face substantial hurdles in finalising complex matters, particularly in major economic hubs where numerous commercial cases await critical decisions. The study is instrumental in bridging the specialised skills deficit by providing empirical evidence needed to design cyber-warrant training programmes, ensuring that evidence is not only technically sound but legally bulletproof.
Furthermore, the study enhances prosecution-guided investigations (PGI) by identifying specific procedural bottlenecks, such as the thirty-minute chain of custody gaps, which allows for the refinement of SOPs to prevent high-profile acquittals. Improving conviction and clearance rates is a central focus, as the research provides the strategic insights required to ensure that digital paper trails perfectly align with forensic reports. Finally, this study informs the NPA’s Strategic Plan 2025–2030 by addressing the current regulatory lag in Section 34 of the Cybercrimes Act 19 of 2020 regarding mandatory technical assistance from service providers, assisting the NPA in lobbying for more effective international treaties and domestic protocols to secure cross-border electronic evidence. Ultimately, this research serves as a critical intervention for the NPA’s mandate to ensure justice for victims without fear, favor, or prejudice in an increasingly digitized society.
2. Materials and Methods
2.1. Research Design
This study adopts an empirical qualitative research design utilising semi-structured interviews to critically explore the lived experiences, technical workflows, and operational perspectives of digital forensic practitioners and specialised prosecutors handling cybercrime investigations within the South African criminal justice system. A qualitative approach was deemed scientifically necessary to decode the complex procedural, methodological, jurisdictional, and institutional bottlenecks that characterise digital evidence processing—nuances that standard quantitative instruments fail to capture [
25].
2.2. Sampling Strategy and Participant Profile
A non-probability, purposive sampling strategy was deployed to recruit elite practitioners possessing direct operational exposure to cybercrime adjudication [
26]. To safeguard institutional integrity while providing maximum transparency, the finalised sample comprised 30 specialised participants (
n = 30) stratified across critical law enforcement and judicial matrix nodes: 18 digital forensic investigators actively serving within specialised police units, and 12 specialised state prosecutors affiliated with the NPA’s SCCU. The strict inclusion criteria mandated that participants possess a minimum of three years of active field experience in the forensic preservation, extraction, or judicial presentation of digital evidence under the Electronic Communications and Transactions (ECT) Act 25 of 2002 and the Cybercrimes Act 19 of 2020.
2.3. Data Collection and Interview Instrument Development
Data collection was executed through a rigorous semi-structured interview framework. To guarantee the instrument’s construct validity, the semi-structured interview guide was systematically developed across three stages: first, extracting core operational variables from contemporary digital forensic and cyber-criminological literature; second, aligning questions directly with the study’s primary research objectives; and third, subjecting the preliminary guide to a formal panel review by two independent senior digital forensic specialists to ensure technical and legal accuracy [
12,
25].
To verify the operational feasibility, clarity, and linguistic accessibility of the instrument, a formal pilot study was conducted with two independent forensic practitioners who met the inclusion criteria but were excluded from the final n = 30 dataset [
12]. The pilot study confirmed that the questions were optimally structured, resulting in minor adjustments to the phrasing of technical prompts regarding digital chain-of-custody challenges.
The finalised interviews were administered through a hybrid model determined by participant availability and institutional security clearance protocols: 12 interviews were conducted face-to-face within secure office environments, while 18 were executed synchronously online via encrypted Microsoft Teams video channels. The duration of the sessions was tightly monitored, with each interview lasting between 45 and 65 min (mean duration: 52 min). The semi-structured architecture provided the necessary analytical flexibility for elite participants to elaborate on highly complex, technical case challenges while maintaining structural consistency across the entire sample group. All sessions were audio-recorded with explicit, signed participant consent and subsequently transcribed verbatim using secure, automated transcription software, followed by a manual line-by-line verification pass to eliminate technical terminology errors.
2.4. Data Analysis and Systematic Coding Procedures
The verified transcripts were subjected to a rigorous thematic analysis following the formalised six-phase framework established by Braun and Clarke. To eliminate analytical drift and ensure strict reproducibility, coding procedures were executed systematically using computer-assisted qualitative data analysis software (CAQDAS), specifically NVivo (Version 14.23 or newer/applicable, 2023; Lumivero, Denver, CO, USA).
The analysis advanced through three distinct coding phases mapping standard qualitative synthesis parameters [
25]:
Phase 1 (Initial Open Coding): A line-by-line reading of the transcripts was conducted to assign descriptive codes to manifest text fragments detailing technological and prosecutorial barriers.
Phase 2 (Axial Coding): These initial codes were clustered into categories based on conceptual intersections, linking operational field failures directly with institutional legislative gaps.
Phase 3 (Selective Coding): Themes were locked into a definitive codebook structure, establishing clear boundaries, inclusion rules, and descriptive definitions for each parental node.
2.5. Determination of Data Saturation
To neutralise subjectivity regarding sample size adequacy, data saturation was monitored dynamically during the data collection and simultaneous coding passes. Saturation was defined using a modified operational threshold: the point at which three consecutive interview transcripts yielded zero novel open codes, distinct concepts, or thematic shifts relating to the core research variables. Operational saturation was definitively achieved by the 24th interview; however, all remaining 6 scheduled interviews were fully executed, transcribed, and processed through the coding pipeline to ensure absolute data density and to confirm that no latent insights were omitted.
2.6. Trustworthiness, Rigor, and Validation Procedures
To secure publication-grade trustworthiness across the qualitative architecture, specific verification measures were implemented against the gold standards of qualitative validation [
25,
26]:
Intercoder Reliability (ICR): To eliminate single-researcher subjectivity and confirm coding stability, an independent academic peer blindly coded a randomly selected subset comprising 20% of the verified transcripts using the finalised codebook definitions. A statistical agreement review was executed across this overlapping coding array, yielding an intercoder reliability Cohen’s Kappa score of κ = 0.88, indicating an excellent level of analytical agreement and coding consistency [
25].
Credibility and Member Checking: Credibility was maintained through strict transcript verification and continuous engagement with the raw dataset. To prevent interpretive bias, member-checking procedures were operationalised by returning anonymised transcript drafts to 25% of the participants (n = 8), who formally confirmed that the textual records accurately Fire-represent their operational perspectives and technical inputs.
Ethical Safeguards: Institutional ethical clearance was formally secured prior to field entry. Strict identity protection measures were enforced: all organisational markers, institutional unit identities, and personal names were completely scrubbed from the main files and replaced with alphanumeric identifiers (e.g., Participant_DF_04, Participant_WP_11), guaranteeing absolute confidentiality and anonymity.
3. Results
The analysis of the qualitative data collected from 30 specialised practitioners reveals a criminal justice system in transition. The following five themes illustrate the friction between rapid technological advancement and the rigid requirements of South African law.
3.1. The Multi-Stage Complexity of Investigations
Multi-stage complexity refers to the multiple interconnected phases of digital forensic investigations, including acquisition, preservation, analysis, and reporting. These phases are not discrete or linear but form part of an iterative and interdependent process that requires careful coordination to ensure both technical accuracy and legal admissibility of digital evidence [
26,
27]. Digital investigations are therefore no longer localised events but prolonged, multi-stage lifecycles requiring diverse technical and procedural expertise. Participants emphasised that this complexity extends beyond technical processes to include strict procedural requirements that must be satisfied at each stage of the investigation. Errors occurring during the initial stages were identified as particularly critical, often undermining the entire investigative process. As
Participant P09 (SAPS) explained, “
People think we just grab a laptop and it’s over. It’s a cycle. If we don’t follow the exact SOPs during the initial seizure, the entire analysis at the lab is compromised before we even start.”
Similarly, Participant P21 (SCCU) highlighted the evidentiary burden associated with this complexity, noting that “The complexity isn’t just technical; it’s procedural. We have to prove to the court exactly what happened at the scene, during transit, and in the forensic mirror imaging process.”
In addition, participants pointed to the increasing role of technological advancements, particularly encryption in intensifying investigative complexity. Decisions made at the point of evidence acquisition were described as highly consequential and time-sensitive. As Participant P14 (SAPS) indicated, “With modern encryption, the complexity starts before we even touch the device. We must decide whether to perform a ‘live’ capture of volatile RAM or a ‘dead’ pull. One wrong choice and the data is encrypted forever.”
These findings illustrate that complexity arises from the interaction between technological constraints and procedural accountability requirements. These findings are consistent with existing literature, which describes digital forensic investigations as iterative, non-linear processes requiring coordination across multiple stages and adherence to strict evidentiary standards [
26,
27]. Prior research further emphasises that shortcomings in early-stage evidence handling and documentation can compromise the integrity, reliability, and admissibility of digital evidence in court proceedings [
28,
29]. This study extends these insights by demonstrating how such complexities are experienced and managed in practice within the South African cybercrime enforcement context.
3.2. Ensuring Data Credibility and Original State
The credibility of digital evidence depends on its integrity, authenticity, and reproducibility, often ensured through cryptographic hashing and consistent forensic procedures [
27,
29].
Participants stressed that even minor inconsistencies can render evidence inadmissible. As Participant P04 (SAPS) stated “Hash values are our best friend. We calculate the MD5, or SHA-1 hash immediately upon imaging. If that value changes by even one digit later, the evidence is ‘tainted’, and the defence will have a field day.”
Similarly, Participant P27 (SCCU) noted that “In court, ‘credibility’ means repeatability. If an independent expert cannot take the same device and produce the same data using the same tools, the evidence is inadmissible.”
Participants also identified growing challenges in preserving the “original state” of evidence, particularly with cloud-synchronised devices. As Participant P11 (SAPS) explained, “Ensuring the ‘original state’ is becoming harder with cloud-synced devices. While we are imaging a phone, it might be receiving new data or being remote wiped. We need signal-blocking technology just to keep the evidence ‘original.”
These findings reflect broader concerns in the literature regarding the preservation of digital evidence in dynamic and networked environments [
28].
3.3. The Need for an Auditable Trail (Continuity)
Maintaining an auditable trail, particularly through a continuous and well-documented chain of custody, is essential to ensuring the integrity and admissibility of digital evidence. Any gaps or inconsistencies in documentation may compromise evidential continuity and result in cases being dismissed. This highlights the procedural fragility of digital investigations, where accountability must be clearly demonstrated at every stage [
27,
29]. Participants emphasised that strict documentation of evidence handling is critical. As
Participant P02 (SAPS) stated, “
Every person who touches that device must sign the chain of custody log. If there is a 30-min gap where we can’t account for who had the keys to the evidence locker, the integrity is gone.”
Similarly, Participant P19 (SCCU) highlighted the need for alignment between forms of documentation, noting that “We often face challenges where the ‘paper trail’ doesn’t match the ‘digital trail.’ An auditable approach means the forensic report must perfectly align with the investigator’s diary entries.”
Participants also pointed to additional complexities in specialised contexts such as deep web investigations. As Participant P25 (SAPS) explained, “In the Deep Web unit, the trail is even harder. We must log every hop through a VPN or Tor. If we can’t audit how we got to a specific server, the magistrate calls it ‘illegal hacking’ instead of ‘legal search.”
These findings are consistent with existing literature emphasising the importance of auditability, documentation, and procedural transparency in establishing the legitimacy of digital evidence in court [
28].
3.4. Use of Digital Forensic Tools to Achieve Goals
Digital forensic tools are essential for transforming raw data into admissible evidence while ensuring data integrity and procedural compliance [
27,
28]. Participants emphasised their role in maintaining evidence integrity and supporting specialised investigations. As
Participant P07 (SAPS) stated, “
We rely on tools like EnCase or FTK Imager. These aren’t just software; they are legally recognised methods that ensure we are ‘writing’ nothing to the original drive while we extract the evidence.”
Participant P13 (SAPS) added that “The Deep Web unit faces unique challenges. We need specialised virtual environments to capture live data before it disappears, which requires tools that provide a timestamped, auditable log of our actions.”
Participants also highlighted the importance of presenting evidence in a format understandable in court. As Participant P30 (SCCU) explained, “We need tools that don’t just find data but present it in a ‘human-readable’ format. Showing a judge a hexadecimal dump is useless; we need visual timelines that prove the suspect’s intent.”
These findings reflect the dual role of forensic tools in both data extraction and evidentiary presentation [
29].
3.5. Challenges with the Cybercrimes Act Implementation
Despite the introduction of the Cybercrimes Act, significant challenges remain in its practical implementation, particularly in relation to search warrants, technical assistance, and cross-border data access. These challenges reflect ongoing gaps between legislative provisions and operational realities [
9].
Participants highlighted delays in obtaining cooperation from service providers. As Participant P18 (SCCU) stated, “While the Act gives us more power, the ‘technical assistance’ clause in Section 34 is often slow to execute. Getting service providers to cooperate in real-time is still a major hurdle.”
Similarly, Participant P05 (SAPS) noted that “The Act assumes we have the capacity to act immediately. But if we need data from a provider in the US or Europe, the Mutual Legal Assistance Treaty (MLAT) process still takes months.”
Participants also emphasised jurisdictional limitations in cybercrime investigations. As Participant P22 (SCCU) explained, “We are struggling with ‘jurisdictional shielding.’ Criminals use servers in countries that don’t recognise our Cybercrimes Act, and our warrants mean nothing there without an international framework.”
These findings are consistent with literature highlighting the difficulties of enforcing cybercrime legislation across jurisdictions and the limitations of existing international cooperation mechanisms [
9].
4. Discussion
This study demonstrates that challenges in cybercrime prosecution are not purely technological but are rooted in methodological and procedural misalignments between digital forensic practices and legal evidentiary requirements. The findings align with existing literature on key issues such as chain of custody management, investigative backlogs, and the admissibility of digital evidence. However, the present study extends this understanding by demonstrating how these challenges manifest in practice within the South African context, particularly in relation to the interaction between investigators and prosecutors.
4.1. Interpretation of Findings
The findings highlight that digital forensic investigations are inherently multi-stage and non-linear, requiring coordination across interconnected phases such as acquisition, preservation, analysis, and reporting. This is consistent with established frameworks that conceptualise digital investigations as iterative processes [
26,
27]. However, the present study shows that this complexity is not only technical but also procedural, as each stage must meet strict legal standards. This reinforces the argument that methodological rigor, rather than technological capability alone, is central to successful cybercrime prosecution.
Ensuring the credibility of digital evidence emerged as a critical concern, particularly in relation to maintaining data integrity, authenticity, and reproducibility. These findings align with established digital forensic principles [
27,
29], but also highlight emerging challenges associated with cloud-synchronised environments, where preserving the ‘original state’ of data is increasingly difficult. This demonstrates that digital evidence management is becoming more dynamic and requires adaptive investigative strategies.
The importance of maintaining an auditable chain of custody was strongly emphasised, with findings indicating that even minor gaps in documentation can compromise evidential continuity and lead to case dismissal. While this reflects well-documented principles in forensic science [
27], the study further reveals practical tensions between investigative documentation and forensic reporting. These inconsistencies represent a key point of procedural vulnerability and suggest the need for greater alignment between investigative and forensic processes.
The study also highlights the dual role of digital forensic tools in both data extraction and evidentiary presentation. While prior research emphasises the technical capabilities of such tools [
29], the findings demonstrate that their effectiveness depends equally on their ability to produce outputs that are understandable and persuasive within a legal context. This underscores the importance of bridging the gap between technical analysis and courtroom interpretation.
Finally, the implementation of the Cybercrimes Act was identified as a significant challenge, particularly in relation to cross-border investigations and delays in obtaining technical assistance. These findings are consistent with literature on jurisdictional limitations in cybercrime enforcement [
9], but further demonstrate how such constraints directly impact investigative timelines and prosecutorial outcomes.
4.2. Cross-Theme Analysis
Taken together, these findings illustrate that the challenges facing cybercrime investigations are interconnected rather than isolated. The multi-stage complexity of investigations increases the risk of errors in maintaining data credibility and chain of custody, while the effectiveness of forensic tools is constrained by legal and jurisdictional limitations. This demonstrates that technological capability alone is insufficient without strong procedural alignment and institutional coordination.
4.3. Practical Implications
The findings have important practical implications for cybercrime enforcement in South Africa. They suggest a need for improved coordination between investigators and prosecutors, particularly in aligning forensic methodologies with evidentiary requirements. Strengthening standard operating procedures, enhancing training in digital evidence handling, and improving documentation practices may reduce procedural errors that lead to case failures. Additionally, addressing delays in cross-border data access is critical to improving the effectiveness of cybercrime investigations.
4.4. Contribution to Knowledge
This study contributes to the existing body of knowledge by shifting the focus from technological tools to the broader methodological and procedural dimensions of digital forensic investigations. By incorporating both investigator and prosecutor perspectives, it provides a more comprehensive understanding of how digital evidence is produced, managed, and evaluated within the criminal justice system. In doing so, it highlights the importance of aligning forensic practices with legal frameworks in increasingly digitised crime environments.
Overall, the findings underscore the need for a holistic approach to cybercrime prosecution, where technical, procedural, and legal dimensions are closely integrated. This provides a foundation for strengthening the reliability, admissibility, and effectiveness of digital evidence in court proceedings.
4.5. Implications of the Study
This study provides important practical and institutional insights into the challenges facing cybercrime prosecution in South Africa. The findings highlight that many of the obstacles encountered by practitioners are not purely technological, but arise from procedural and methodological misalignments within prosecution-guided investigations. In particular, the study identifies critical bottlenecks such as gaps in chain-of-custody documentation and delays associated with Section 34 technical assistance that directly affect the admissibility and reliability of digital evidence. These findings have significant implications for the NPA, particularly the SCCU, which operates within increasingly complex digital environments. The results suggest that improving cybercrime prosecution outcomes requires strengthening procedural consistency and aligning investigative practices more closely with legal evidentiary standards. This includes the refinement of standard operating procedures (SOPs) to address vulnerabilities such as short but consequential disruptions in evidence handling. Furthermore, the study underscores the importance of enhancing practitioner capacity through targeted training in cyber-warrant procedures and digital evidence management. The alignment between investigative documentation and forensic reporting emerges as a critical factor influencing case outcomes, particularly in complex commercial crime cases within major economic hubs. Finally, the findings point to broader systemic challenges, including regulatory delays in accessing electronic evidence and the need for improved mechanisms for cross-border data acquisition. Addressing these issues requires not only technical solutions but also institutional coordination and policy-level interventions to ensure that digital investigations are both operationally effective and legally robust.
4.6. Limitations of the Study
While this study provides significant insights into the challenges of digital search and seizure, several limitations must be acknowledged. First, the sample size of 30 participants from the SAPS Cyber-Crime and Deep Web Investigation Unit and the SCCU, while providing rich qualitative depth, may not be fully representative of the broader South African law enforcement landscape, particularly in resource-constrained rural jurisdictions. Second, the findings rely on self-reported data, which introduces the possibility of participant bias or the withholding of sensitive operational details due to the classified nature of cyber-investigations. Furthermore, the rapidly evolving nature of digital technology means that the specific forensic tools and methodologies discussed are subject to frequent updates, potentially limiting the long-term technical relevance of the findings. Finally, because the Cybercrimes Act 19 of 2020 is in its early stages of implementation, this research captures a transitional snapshot of the legal and procedural landscape, and as such, does not account for future judicial precedents or evolving case law that may redefine the standards for admissibility and credibility in South African courts.
To address the limitations identified and build upon the findings of this study, the following Suggestions for Further Research are proposed:
Future research should conduct a longitudinal analysis of the Cybercrimes Act 19 of 2020 to evaluate how judicial precedents and case law evolve over the next five to ten years. This would provide a clearer picture of how South African courts specifically interpret forensic soundness and original state in high-profile cyber-crime trials.
- 2.
Comparative Jurisdictional Analysis
A comparative study between the SAPS/SCCU framework and international counterparts, such as the FBI (USA) or the High-Tech Crime Units (UK/The Netherlands), could identify global best practices for Auditability and Continuity. This would help determine if South Africa’s “obstacles” are unique or part of a global trend in digital forensic resource gaps.
- 3.
Quantitative Assessment of Resource Allocation
While this study qualitatively identified budgetary constraints as an obstacle, future research could employ a quantitative approach to audit the specific correlation between financial investment in the SAPS Cyber-Crime Unit and the successful conviction rates in the SCCU. This would provide empirical data to support policy arguments for increased forensic funding.
- 4.
Impact of Emerging Technologies (AI and Cloud)
As criminals shift toward Cloud-based storage and AI-driven encryption, research is needed into the technical and legal hurdles of “remote” search and seizure. Future studies should investigate whether current SOPs are sufficient for retrieving data stored on international servers (cross-border data access).
- 5.
Public–Private Partnerships (PPP) in Forensics
Research into the feasibility of a formalised PPP model for digital forensics in South Africa is recommended. This study could explore how private sector expertise can be integrated into the SAPS/NPA workflow without compromising the Chain of Custody or the “auditable” nature of state investigations.
4.7. Recommendations
The findings of this study highlight several areas requiring improvement to enhance the effectiveness of cybercrime investigations and prosecutions in South Africa. First, there is a need to strengthen alignment between investigative procedures and legal evidentiary requirements. This can be achieved through the refinement SOPs that ensure consistency in evidence acquisition, documentation, and reporting across all stages of the digital forensic process. Improved procedural alignment will reduce the risk of evidentiary gaps that may compromise admissibility in court.
Second, capacity building and specialised training should be prioritised for both investigators and prosecutors. Training programmes should focus on digital evidence handling, cyber-warrant execution, and the interpretation of forensic outputs to ensure that practitioners are equipped with both technical and legal competencies. This will enhance coordination between investigative and prosecutorial functions.
Third, there is a need to improve the integration between administrative documentation and forensic evidence records. Ensuring that these records are consistent, complete, and auditable will reduce procedural inconsistencies and strengthen the evidentiary value presented in court. The development of integrated documentation systems may further support this alignment.
Fourth, addressing delays in cross-border data access remains critical. Strengthening international cooperation mechanisms, including improving the efficiency of MLAT processes and engaging with service providers, is essential for timely evidence acquisition. While domestic legislation provides a framework, its effectiveness is limited without coordinated international support.
Fifth, technological advancements should be supported by institutional readiness. While challenges related to cloud storage and jurisdiction are well established, emerging technologies such as artificial intelligence introduce new complexities in evidence interpretation and validation. Future developments should therefore focus not only on acquiring advanced tools but also on ensuring that their use is methodologically sound and legally defensible.
Finally, future research should explore comparative institutional frameworks to assess whether the challenges identified in South Africa reflect broader international patterns or context-specific constraints. Such comparative analysis may provide valuable insights into best practices and inform policy development in digital forensic investigations.
5. Conclusions
This study examined the interaction between digital forensic investigators and prosecutors in South Africa, with a particular focus on the challenges associated with aligning investigative practices with legal evidentiary requirements. Drawing on qualitative insights from practitioners, the study demonstrates that barriers to successful cybercrime prosecution are not confined to technological limitations, but are deeply rooted in procedural inconsistencies, documentation practices, and jurisdictional constraints. The study contributes to the existing body of knowledge by shifting the focus from technical tools to the broader forensic methodologies that underpin the production, interpretation, and presentation of digital evidence. In doing so, it highlights the importance of coherence between investigative processes and courtroom expectations, particularly within prosecution-guided investigation frameworks. Overall, the findings suggest that strengthening cybercrime prosecution in South Africa requires a holistic approach that integrates methodological rigor, institutional coordination, and policy reform. By illuminating the practical realities faced by investigators and prosecutors, this study provides a foundation for improving the reliability, admissibility, and effectiveness of digital evidence in an increasingly digitised criminal justice landscape.