Professor — Digital Forensics & Incident Response

Dr. Meera Krishnan

PhD, GCFA, EnCE

Dr. Meera Krishnan

Leads digital forensics and incident response, with extensive experience investigating major security breaches.

Digital Forensics Incident Response Malware Analysis

Dr. Meera Krishnan is a Professor of Digital Forensics and Incident Response at GICCT, where she leads the institute’s programs in forensic investigation, breach response, and malware analysis. Over a career spanning more than fifteen years, she has investigated some of the most complex security incidents faced by organisations across finance, healthcare, and critical infrastructure — work that now informs every lecture, lab, and case study she brings to her students.

Background and career

Dr. Krishnan began her career as a security analyst before specialising in digital forensics, a field she was drawn to because it sits precisely where technical rigour meets investigative storytelling. Reconstructing exactly what an attacker did, in what order, and what they touched, demands both deep technical skill and the patience of a detective. She went on to lead incident response engagements for large enterprises, frequently working under intense pressure in the first hours of a breach — the window in which decisions matter most and evidence is most fragile.

Her doctoral research focused on memory forensics and anti-forensic evasion techniques, examining how sophisticated adversaries attempt to hide their tracks and how investigators can recover the truth regardless. That research background gives her teaching an unusual depth: she does not simply explain which tool to run, but why it works, what it can miss, and how a determined adversary might try to defeat it. Before joining GICCT, she served as a lead forensic investigator and built incident response capabilities from the ground up for organisations that had never before had a structured way to handle a breach.

Areas of expertise

Dr. Krishnan’s expertise covers the full incident lifecycle. On the forensics side, she works across disk, memory, and network forensics, mobile device analysis, and the increasingly important area of cloud forensics, where traditional techniques must be rethought for ephemeral, distributed infrastructure. On the response side, she specialises in containment strategy, threat eradication, and the difficult judgement calls that define effective incident handling — when to isolate a system, when to watch an adversary to learn their objectives, and how to preserve evidence without disrupting a live investigation.

She also brings significant depth in malware analysis, including both static and dynamic analysis of malicious code, and in the legal and regulatory dimensions of forensics — chain of custody, evidence handling, and the reporting standards that determine whether findings will hold up under scrutiny. This is particularly relevant for organisations operating under the GDPR and NIS2, where a breach triggers strict notification obligations and the quality of the forensic investigation directly shapes the response. She holds the GCFA (GIAC Certified Forensic Analyst) and EnCE (EnCase Certified Examiner) certifications, two of the most respected credentials in the field.

Teaching philosophy

Dr. Krishnan believes forensics cannot be learned from slides alone. Her courses are built around realistic investigation scenarios in which students work with genuine forensic artefacts — disk images, memory captures, log files, and malware samples — and must reconstruct what happened, document their findings, and defend their conclusions. The goal is not to memorise tools but to develop the investigative mindset that separates a competent analyst from an exceptional one: the discipline to follow evidence rather than assumptions, and the rigour to distinguish what the data proves from what it merely suggests.

She places particular emphasis on documentation and communication, areas that technical training often neglects. A brilliant investigation is worthless if its findings cannot be clearly explained to executives, regulators, or a court. Her students learn to write reports that are precise, defensible, and accessible to non-technical stakeholders — a skill that proves decisive in real incidents, where the forensic analyst is often the person who must explain a breach to people making consequential decisions under pressure.

At GICCT

At the institute, Dr. Krishnan leads the Digital Forensics and Incident Response programs and contributes to the broader cybersecurity curriculum, ensuring that students across disciplines understand how incidents unfold and how organisations recover from them. She is a strong advocate for preparation over reaction, regularly reminding students that the quality of an organisation’s response is decided long before any breach occurs — in the playbooks written, the logging configured, and the skills practised in advance.

For professionals enrolling at GICCT, learning from Dr. Krishnan means learning from someone who has sat in the chair during real breaches, made the hard calls, and lived with the consequences. That practitioner’s perspective — grounded in genuine cases rather than textbook abstractions — is what she considers the single most valuable thing she can pass on to the next generation of forensic investigators and incident responders.

Προγράμματα που διδάσκει

Digital Forensics

Incident Response & Forensics

Malware Analysis