Skip to content

Answers

We think an employee took data. What do we do first?

Preserve before you investigate. Hold the device out of the reissue cycle, suspend deletion on their accounts, and capture the access and egress logs that expire fastest. Do not confront the employee, and do not let anyone browse the laptop — both destroy evidence and both are difficult to explain afterwards.

The first day after suspected employee data theft, in order

1. Hold the hardware. A written instruction to IT naming the asset tag, saying it is not to be wiped, reissued or logged into. Standard offboarding destroys evidence within days and is designed to be irreversible. It is also the step with the clearest legal consequence: the duty to preserve attaches once litigation is reasonably anticipated, and Fed. R. Civ. P. 37(e) lets a court impose curative measures — and, on a finding of intent to deprive, an adverse presumption or instruction — where ESI is lost because a party failed to take reasonable steps to preserve it. Interrupting the reissue cycle is what "reasonable steps" means here.

2. Suspend deletion on the accounts. Mail, chat, cloud storage. A legal hold notice does nothing on a platform configured to auto-delete — an administrator has to change the setting, per system.

3. Capture the short-lived logs now. VPN, proxy, firewall, endpoint and cloud audit logs are the primary record of data leaving, and default retention is frequently measured in days or weeks. This is the step most often skipped and least often recoverable.

4. Engage counsel. Both to structure the investigation under privilege where that is available, and because monitoring an employee engages employment and privacy law that varies sharply by jurisdiction.

5. Then investigate. Not before.

What not to do when you suspect an employee took data, and why

Do not confront them yet. A person who knows they are suspected can remote-wipe a phone, delete a cloud account, or ask a colleague to remove material. Preservation first, conversation second.

Do not look through the laptop. Opening folders changes access timestamps, and those timestamps are frequently the evidence — they are how an examiner shows which files were opened in the final week. The manager who had a quick look has damaged the artifact and made themselves a witness.

Do not have IT make a copy first. A backup is not a forensic image: it omits deleted content and the activity artifacts, and the copying itself alters the source. SWGDE's Best Practices for Digital Evidence Collection sets the bar the copy will be measured against — contemporaneous collection notes and a chain-of-custody record made at the time — and an ad hoc backup produces neither.

Do not assume it is theft. A significant proportion of these matters turn out to be automatic cloud sync, a personal device used with the employer's knowledge, or files that were never confidential. An investigation that starts from a conclusion tends to find it.

Solid-state drives make employee data theft a same-day problem

On an SSD, deleted content can be erased permanently by the drive's own background housekeeping within hours, without anyone touching the machine. On a traditional hard disk the same material would likely survive for weeks.

There is no version of this where waiting until Monday improves the outcome.

What a good employee data-theft investigation establishes

A sequence rather than a document: what was accessed and whether the pattern departed from that person's own baseline, what removable media was connected and when, whether a personal cloud client appeared shortly before the resignation, what left through the network, and whether anything was wiped. Access spiking in the fortnight before a departure, a personal drive connected on the last day, and matching hash values at the new employer is a case. Any one of those alone usually is not.

Where a forensic neutral helps

If the material may sit on a personal phone or home computer, a forensic neutral examining under an agreed protocol — producing only responsive material — is frequently faster than litigating for a year over whether the device can be inspected at all.

When this question is live in a matter, Law & Forensics provides trade secret investigation services.

From our work

Primary sources

Need this looked at properly?

Our examiners and testifying experts work these questions for a living. Tell us what you're facing.

Reviewed by Law & Forensics. See our editorial standards.