Employment, trade secrets, insider risk

Departing Employee Forensic Analysis

Preserve the record before offboarding rewrites it. Account suspension, device reissue, remote wipe, and retention timers can erase the history needed to assess copying, deletion, or unauthorized access.

Bagged hard drive beside a forensic write blocker.

The engagement

A preservation hold that IT can execute

Departures create two competing pressures: secure the environment quickly and retain the technical record. GDF coordinates with counsel and IT to preserve relevant devices, accounts, file repositories, access events, email, collaboration data, and removable-media history before ordinary offboarding changes the source.

The plan identifies laptops, phones, virtual desktops, mailboxes, cloud drives, shared repositories, development platforms, backup sources, and security logs. It distinguishes actions that should happen immediately from actions that can wait for imaging or export. The objective is to reduce ongoing access without destroying useful historical data.

Counsel defines legal scope and privilege. GDF documents technical sources and implements the approved protocol. Human resources and security teams receive a concise preservation checklist rather than a generic instruction to save everything.

Scope

  • Rapid preservation checklist

    A concrete list of immediate and near-term actions for IT and security teams. Immediate items reduce ongoing access; near-term items preserve historical data through imaging or export.

  • Endpoint acquisition

    Forensic imaging of laptops, desktops, and virtual desktops. Chain of custody documented. Deletion, USB, browser, and installed application artifacts preserved for later analysis.

  • Cloud account and mailbox preservation

    Microsoft 365 or Google Workspace mailbox, drive, and audit data preserved. Sign-in history, inbox rules, delegate configurations, forwarding, and OAuth grants captured before change.

  • Removable media and personal cloud

    USB device and file-copy activity, personal cloud synchronization, and personal email use analyzed against job duties, workflow, and available policy.

  • Source code and repository activity

    Where in scope, code repository activity: pull, clone, push, branch, and permission changes reviewed. Development platform audit records preserved.

  • Reporting and declaration support

    Findings prepared for counsel: what happened, source supporting each fact, limits of attribution, and additional sources that could resolve gaps. Declarations and exhibits available as needed.

Methodology

How the analysis runs

  1. Freeze

    The preservation plan is issued to IT and security. Immediate items reduce ongoing access; near-term items preserve historical data through imaging or export.

  2. Preserve

    Devices are imaged, cloud tenants are placed on hold or exported, and short-retention identity and audit data are captured. Chain of custody is documented at each step.

  3. Analyze

    USB, file-copy, personal cloud, email forwarding, code repository, deletion, and authentication activity is examined in context. Job duties, workflow, and timing are considered before drawing inferences.

  4. Report

    Findings identify what happened, the source supporting each fact, and the limits of attribution. Where a next source could resolve a gap, it is identified.

Evidence commonly examined

Evidence reviewed

  • Company-issued laptops, desktops, phones, and virtual desktops
  • Mailbox, drive, and cloud audit records
  • USB device history and file-copy artifacts
  • Personal cloud synchronization and browser artifacts where in scope
  • Repository, ticketing, and administrative audit logs
  • Badge, VPN, and identity records for the relevant period

What you can expect

What you receive

  • Preservation checklist tailored to the client's environment
  • File-access, copy, deletion, and transfer timeline
  • Sourced findings that separate observation from inference
  • Declaration and exhibit support for counsel
  • Next-source recommendations for gaps a subpoena could fill

Frequently asked

Common questions

Is USB copying alone proof of misconduct?

No. USB connections and file-copy artifacts are relevant, but analysts compare them with job duties, workflow, timing, file sensitivity, and corroborating records. A single technical event is not treated as intent.

Can you preserve a laptop before the employee is notified?

Coordination with counsel, HR, and IT determines when preservation occurs. Where legally supported, preservation can happen before notification to reduce the risk that a departing custodian alters the record.

What if the personal cloud account was used?

Where in scope and legally supported, synchronization artifacts, browser records, and file activity can indicate use of personal cloud services. Direct access to a personal account requires additional legal steps.

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.