Skip to content

Answers

We think an employee took data. What do we do first?

Preserve before you investigate. Hold the device out of the reissue cycle, suspend deletion on their accounts, and capture the access and egress logs that expire fastest. Do not confront the employee, and do not let anyone browse the laptop — both destroy evidence and both are difficult to explain afterwards.

The first day, in order

1. Hold the hardware. A written instruction to IT naming the asset tag, saying it is not to be wiped, reissued or logged into. Standard offboarding destroys evidence within days and is designed to be irreversible.

2. Suspend deletion on the accounts. Mail, chat, cloud storage. A legal hold notice does nothing on a platform configured to auto-delete — an administrator has to change the setting, per system.

3. Capture the short-lived logs now. VPN, proxy, firewall, endpoint and cloud audit logs are the primary record of data leaving, and default retention is frequently measured in days or weeks. This is the step most often skipped and least often recoverable.

4. Engage counsel. Both to structure the investigation under privilege where that is available, and because monitoring an employee engages employment and privacy law that varies sharply by jurisdiction.

5. Then investigate. Not before.

What not to do, and why

Do not confront them yet. A person who knows they are suspected can remote-wipe a phone, delete a cloud account, or ask a colleague to remove material. Preservation first, conversation second.

Do not look through the laptop. Opening folders changes access timestamps, and those timestamps are frequently the evidence — they are how an examiner shows which files were opened in the final week. The manager who had a quick look has damaged the artifact and made themselves a witness.

Do not have IT make a copy first. A backup is not a forensic image: it omits deleted content and the activity artifacts, and the copying itself alters the source.

Do not assume it is theft. A significant proportion of these matters turn out to be automatic cloud sync, a personal device used with the employer's knowledge, or files that were never confidential. An investigation that starts from a conclusion tends to find it.

Solid-state drives make this a same-day problem

On an SSD, deleted content can be erased permanently by the drive's own background housekeeping within hours, without anyone touching the machine. On a traditional hard disk the same material would likely survive for weeks.

There is no version of this where waiting until Monday improves the outcome.

What a good investigation establishes

A sequence rather than a document: what was accessed and whether the pattern departed from that person's own baseline, what removable media was connected and when, whether a personal cloud client appeared shortly before the resignation, what left through the network, and whether anything was wiped. Access spiking in the fortnight before a departure, a personal drive connected on the last day, and matching hash values at the new employer is a case. Any one of those alone usually is not.

Where a neutral helps

If the material may sit on a personal phone or home computer, a forensic neutral examining under an agreed protocol — producing only responsive material — is frequently faster than litigating for a year over whether the device can be inspected at all.

From our work

Need this looked at properly?

Our examiners and testifying experts work these questions for a living. Tell us what you're facing.

Reviewed by Law & Forensics. See our editorial standards.