The damaging insider rarely announces themselves. Credentials keep working after a departure, exports run inside office hours, and the archive is written the night before a resignation. We investigate from the company's own records — endpoint, server and network — and report what they establish, attributed to accounts, sessions and times.
◇ Method before speed. The free assessment and a written scope come first; forensic fees are settled in full before any examination starts. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
These are the observations that turn an uneasy feeling into an instruction.
Access outlives employment more often than businesses expect. Cached credentials and password-manager stores travel with a copied profile; SSH keys and API tokens copied in a final week keep working until revoked; a colleague's password, observed once, works from home. The investigation establishes which credentials left, then reads authentication logs against endpoint traces to show which systems were touched with them, from which addresses, at which times — including every touch after the leaving date, which tends to be the finding that decides matters.
Endpoints tell half the story; servers tell the rest. Database query history exposes bulk exports — the SELECT that took the customer table, timed and attributed; snapshots and backups are compared to date exactly when records changed or vanished; file-server access logs list who opened which shares, and when the pattern broke from routine; and network records and captures show sustained transfers to external addresses that no business process explains. Server evidence also ages fastest — logs rotate on schedules measured in weeks — so it is preserved first.
Tribunals distinguish carelessness from planning, so the investigation gathers the material that speaks to state of mind: Slack and Teams messages discussing the move or the material; 7z and RAR archives assembled in the final days, their contents lists recovered even where the archives went; competitor sites and job boards threaded through the browsing history; and document metadata whose last-modified-by fields put named hands on named files at named times. None of it is conclusive alone; sequenced together, it usually is.
A personal phone or laptop on the office network sits on a legal boundary, and we keep to the lawful side of it. The network's own records — association times, device identifiers, traffic volumes, destinations — belong to the company and are fair evidence; the personal device itself is not examinable without its owner's consent, a solicitor-agreed protocol or a court's direction. The report uses what the infrastructure lawfully shows and states the boundary explicitly, which is precisely what keeps it usable.
The imaging discipline underneath is at the forensic recovery hub. Mailbox and cloud routes continue on email & cloud exfiltration, endpoint capture on workstation deep imaging, and the IP dimension on the trade-secret case page. Fees are on our prices page.
Attributed to accounts and sessions, dated, and tied to the systems' own records.
Which keys, tokens and stored passwords left, and when.
Systems touched with taken credentials, timed and sourced.
Bulk database and file-server extractions, with query evidence.
Sustained transfers to external addresses, from captures and logs.
Messages, archives, browsing and metadata bearing on planning.
What the Wi-Fi records lawfully show of personal devices.
The free diagnostic that opens every case is completed within 2 working days of arrival; forensic casework itself is not a no fix, no fee service. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. Multi-system server scopes are quoted in writing after the free assessment. Both figures are itemised on our prices page, and the written scope is agreed before payment is taken.
Insider casework proceeds on the company's own systems and records, under HR or a solicitor's instruction. Instructions are accepted on three footings only: equipment the company itself owns; the instruction of a solicitor, insurer or court; or devices that are genuinely the client's own — including jointly owned machines in matrimonial matters. We do not hack, we do not intercept live communications, and we do not examine a device the instructing client has no right to examine.
Insider cases usually open with a scoping call rather than a parcel. Ring 0800 689 0668, tell us what you are seeing, and we will list what to preserve tonight; where hardware does travel, it is signed into custody at our Leeds location on arrival.
Is the drive still inside a computer, laptop, MacBook, iMac, CCTV / DVR or server? Take the hard drive or SSD out first and post the bare drive on its own — removing drives from machines isn't a service we offer. Storage that's soldered to a motherboard (Apple Silicon Macs, certain slim laptops) is the one thing we can't work on: if it doesn't come out, it can't come in.
↓ Print the booking-in & shipping form (PDF)
Address the parcel for the attention of Leeds Data Recovery — about 40 minutes from York via the A64 and A1(M), or next working day by tracked post. You'll hear from us the moment it's booked onto the bench.
Not certain what to pack? Ring 0800 689 0668 first, or run the free online diagnostic.
Preserve the logs before they rotate — the freephone reaches an examiner, not a queue.