Insider Threat Forensics

The damaging insider rarely announces themselves. Credentials keep working after a departure, exports run inside office hours, and the archive is written the night before a resignation. We investigate from the company's own records — endpoint, server and network — and report what they establish, attributed to accounts, sessions and times.

Method before speed. The free assessment and a written scope come first; forensic fees are settled in full before any examination starts. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.

// indications of an insider problem

What prompts an insider investigation

These are the observations that turn an uneasy feeling into an instruction.

Company systems show sign-ins after someone's final day
SSH keys, API tokens or saved passwords appear to have travelled
A database ran bulk exports nobody can explain
Compressed archives were created shortly before an exit
Competitor research and job boards fill a work machine's history
An unknown personal device joined the office Wi-Fi

Credentials, taken and used

Access outlives employment more often than businesses expect. Cached credentials and password-manager stores travel with a copied profile; SSH keys and API tokens copied in a final week keep working until revoked; a colleague's password, observed once, works from home. The investigation establishes which credentials left, then reads authentication logs against endpoint traces to show which systems were touched with them, from which addresses, at which times — including every touch after the leaving date, which tends to be the finding that decides matters.

Server-side evidence

Endpoints tell half the story; servers tell the rest. Database query history exposes bulk exports — the SELECT that took the customer table, timed and attributed; snapshots and backups are compared to date exactly when records changed or vanished; file-server access logs list who opened which shares, and when the pattern broke from routine; and network records and captures show sustained transfers to external addresses that no business process explains. Server evidence also ages fastest — logs rotate on schedules measured in weeks — so it is preserved first.

Intent, evidenced rather than asserted

Tribunals distinguish carelessness from planning, so the investigation gathers the material that speaks to state of mind: Slack and Teams messages discussing the move or the material; 7z and RAR archives assembled in the final days, their contents lists recovered even where the archives went; competitor sites and job boards threaded through the browsing history; and document metadata whose last-modified-by fields put named hands on named files at named times. None of it is conclusive alone; sequenced together, it usually is.

Personal devices on company Wi-Fi

A personal phone or laptop on the office network sits on a legal boundary, and we keep to the lawful side of it. The network's own records — association times, device identifiers, traffic volumes, destinations — belong to the company and are fair evidence; the personal device itself is not examinable without its owner's consent, a solicitor-agreed protocol or a court's direction. The report uses what the infrastructure lawfully shows and states the boundary explicitly, which is precisely what keeps it usable.

The imaging discipline underneath is at the forensic recovery hub. Mailbox and cloud routes continue on email & cloud exfiltration, endpoint capture on workstation deep imaging, and the IP dimension on the trade-secret case page. Fees are on our prices page.

// what the investigation establishes

Findings an insider case is built from

Attributed to accounts and sessions, dated, and tied to the systems' own records.

Credential inventory

Which keys, tokens and stored passwords left, and when.

Access reconstruction

Systems touched with taken credentials, timed and sourced.

Export detection

Bulk database and file-server extractions, with query evidence.

Network findings

Sustained transfers to external addresses, from captures and logs.

Intent material

Messages, archives, browsing and metadata bearing on planning.

Boundary log

What the Wi-Fi records lawfully show of personal devices.

// fees and footing

Forensic fees, and the lawful basis we require

What forensic work costs

The free diagnostic that opens every case is completed within 2 working days of arrival; forensic casework itself is not a no fix, no fee service. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. Multi-system server scopes are quoted in writing after the free assessment. Both figures are itemised on our prices page, and the written scope is agreed before payment is taken.

Who we can act for

Insider casework proceeds on the company's own systems and records, under HR or a solicitor's instruction. Instructions are accepted on three footings only: equipment the company itself owns; the instruction of a solicitor, insurer or court; or devices that are genuinely the client's own — including jointly owned machines in matrimonial matters. We do not hack, we do not intercept live communications, and we do not examine a device the instructing client has no right to examine.

// getting your device to us

Sending it in — easier than you'd think

Insider cases usually open with a scoping call rather than a parcel. Ring 0800 689 0668, tell us what you are seeing, and we will list what to preserve tonight; where hardware does travel, it is signed into custody at our Leeds location on arrival.

Is the drive still inside a computer, laptop, MacBook, iMac, CCTV / DVR or server? Take the hard drive or SSD out first and post the bare drive on its own — removing drives from machines isn't a service we offer. Storage that's soldered to a motherboard (Apple Silicon Macs, certain slim laptops) is the one thing we can't work on: if it doesn't come out, it can't come in.

  • Bubble wrap and a sturdy box or padded envelope will do nicely — cables, caddies and power bricks can stay at home.
  • Print off the booking-in & shipping form (PDF), add your name, number and a line or two on what happened, and tuck it in the parcel.
  • Royal Mail Special Delivery keeps it tracked and insured the whole way; your own courier does the same job if you'd sooner book one. There's no collection service at this end.
  • Happier handing it over in person? Reception at the address here takes drop-offs, Mon–Fri 9:00am–5:30pm.
// where your device is headed

Leeds Data Recovery

17th Floor, The Pinnacle
Albion Street
Leeds, LS1 5AA

↓ Print the booking-in & shipping form (PDF)

Address the parcel for the attention of Leeds Data Recovery — about 40 minutes from York via the A64 and A1(M), or next working day by tracked post. You'll hear from us the moment it's booked onto the bench.

Not certain what to pack? Ring 0800 689 0668 first, or run the free online diagnostic.

// insider threat — answered before instruction

What boards and IT leads ask

Authentication logs, source addresses and session records generally settle it: which account, from where, when, and what it touched. Preserve the logs now — rotation schedules discard them on their own timetable — then revoke access once the capture is made.
Rarely. Most server-side work runs on targeted evidence — log exports, database snapshots, images of specific volumes — captured to hash-verified files with your IT team, often without downtime. The written scope states exactly what is taken and why.
Not without consent, an agreed protocol or a court direction — it is their property. The network's own records of that device, though, belong to you, and association times, volumes and destinations frequently carry the point on their own.
No — rotation was the right security move, and the history survives it. Logs, query records and endpoint artefacts still show what the old credentials did while they lived. What matters now is preserving those records before routine housekeeping thins them.

Your systems logged it. We read it back.

Preserve the logs before they rotate — the freephone reaches an examiner, not a queue.