A trade secret is information that derives economic value from not being generally known and that its owner takes reasonable measures to keep secret. Both elements are required, and the second is where most claims are won or lost — protection depends on what the company actually did, not on what it labelled confidential.
Reasonable measures is the contested element
A plaintiff must show the information had value from being secret and that it took reasonable steps to protect it. Defendants attack the second, and they attack it with the plaintiff's own systems.
What courts look at is concrete: was access restricted to people who needed it, or could any employee reach the file share? Were confidentiality agreements in place and current? Was the material marked? Was there an offboarding process that actually removed access? Did anyone monitor for bulk downloads?
A company that designates everything confidential and restricts nothing is in a weak position, because the designation carries no operational meaning. Conversely, unglamorous controls — access logs, permission reviews, an offboarding checklist — do most of the work in establishing reasonableness.
Identification with particularity
Courts increasingly require a plaintiff to identify the asserted secrets with specificity before discovery proceeds, and some jurisdictions require it by statute or local rule.
This is a real constraint. "Our customer data and manufacturing processes" is not an identification; it is a category. Defining the secret narrowly enough to be identifiable, while broadly enough to cover what was actually taken, is a strategic decision better made before filing than under a court order afterwards.
What the forensic evidence establishes
The factual core of most trade secret cases is a sequence, and the artifacts that establish it are well understood:
- What was accessed, and whether the pattern departed from the person's normal behaviour.
- USB and external media connections, recorded by the operating system with device identifiers and timestamps.
- Cloud sync and personal accounts — a personal storage client installed shortly before resignation is a recurring pattern.
- Uploads and large transfers, from network and proxy logs.
- Anti-forensic activity — wiping tools, mass deletion, or a device reset before return, all of which leave their own traces.
- Presence at the new employer, which is what converts an access story into a misappropriation story.
The timeline is what persuades. Access spiking in the fortnight before a resignation, a personal drive connected on the last day, and matching hash values on the new employer's systems is a far stronger case than any single artifact.
Preservation is urgent and frequently botched
The most common way these cases are damaged is routine IT hygiene: the departing employee's laptop is wiped and reissued under standard offboarding, days before anyone suspects a problem. Solid-state drives compound it, because deleted content can be erased by the drive's own housekeeping within hours.
Hold the device, hold the accounts, and do not let anyone look through it first.
The defence perspective
Not every departure is theft, and forensic artifacts routinely establish the opposite: that files synced automatically, that a personal device was used with the employer's knowledge, or that the data at issue was publicly available. An examination commissioned early by a defendant frequently narrows a sprawling claim to something manageable — and occasionally ends it.
From our work
Dealing with trade secret in a live matter?
Our examiners and testifying experts work these questions for a living. Tell us what you're facing.
Reviewed by Law & Forensics. See our editorial standards.
