Employment, trade secrets, insider risk
Departing Employee Forensic Analysis
Preserve the record before offboarding rewrites it. Account suspension, device reissue, remote wipe, and retention timers can erase the history needed to assess copying, deletion, or unauthorized access.
The engagement
A preservation hold that IT can execute
Departures create two competing pressures: secure the environment quickly and retain the technical record. GDF coordinates with counsel and IT to preserve relevant devices, accounts, file repositories, access events, email, collaboration data, and removable-media history before ordinary offboarding changes the source.
The plan identifies laptops, phones, virtual desktops, mailboxes, cloud drives, shared repositories, development platforms, backup sources, and security logs. It distinguishes actions that should happen immediately from actions that can wait for imaging or export. The objective is to reduce ongoing access without destroying useful historical data.
Counsel defines legal scope and privilege. GDF documents technical sources and implements the approved protocol. Human resources and security teams receive a concise preservation checklist rather than a generic instruction to save everything.
Scope
Rapid preservation checklist
A concrete list of immediate and near-term actions for IT and security teams. Immediate items reduce ongoing access; near-term items preserve historical data through imaging or export.
Endpoint acquisition
Forensic imaging of laptops, desktops, and virtual desktops. Chain of custody documented. Deletion, USB, browser, and installed application artifacts preserved for later analysis.
Cloud account and mailbox preservation
Microsoft 365 or Google Workspace mailbox, drive, and audit data preserved. Sign-in history, inbox rules, delegate configurations, forwarding, and OAuth grants captured before change.
Removable media and personal cloud
USB device and file-copy activity, personal cloud synchronization, and personal email use analyzed against job duties, workflow, and available policy.
Source code and repository activity
Where in scope, code repository activity: pull, clone, push, branch, and permission changes reviewed. Development platform audit records preserved.
Reporting and declaration support
Findings prepared for counsel: what happened, source supporting each fact, limits of attribution, and additional sources that could resolve gaps. Declarations and exhibits available as needed.
Methodology
How the analysis runs
-
Freeze
The preservation plan is issued to IT and security. Immediate items reduce ongoing access; near-term items preserve historical data through imaging or export.
-
Preserve
Devices are imaged, cloud tenants are placed on hold or exported, and short-retention identity and audit data are captured. Chain of custody is documented at each step.
-
Analyze
USB, file-copy, personal cloud, email forwarding, code repository, deletion, and authentication activity is examined in context. Job duties, workflow, and timing are considered before drawing inferences.
-
Report
Findings identify what happened, the source supporting each fact, and the limits of attribution. Where a next source could resolve a gap, it is identified.
Evidence commonly examined
Evidence reviewed
- Company-issued laptops, desktops, phones, and virtual desktops
- Mailbox, drive, and cloud audit records
- USB device history and file-copy artifacts
- Personal cloud synchronization and browser artifacts where in scope
- Repository, ticketing, and administrative audit logs
- Badge, VPN, and identity records for the relevant period
What you can expect
What you receive
- Preservation checklist tailored to the client's environment
- File-access, copy, deletion, and transfer timeline
- Sourced findings that separate observation from inference
- Declaration and exhibit support for counsel
- Next-source recommendations for gaps a subpoena could fill
Frequently asked
Common questions
Is USB copying alone proof of misconduct?
No. USB connections and file-copy artifacts are relevant, but analysts compare them with job duties, workflow, timing, file sensitivity, and corroborating records. A single technical event is not treated as intent.
Can you preserve a laptop before the employee is notified?
Coordination with counsel, HR, and IT determines when preservation occurs. Where legally supported, preservation can happen before notification to reduce the risk that a departing custodian alters the record.
What if the personal cloud account was used?
Where in scope and legally supported, synchronization artifacts, browser records, and file activity can indicate use of personal cloud services. Direct access to a personal account requires additional legal steps.
Related capabilities
Related services
Talk with an examiner
Discuss the matter and the next step.
Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.
24/7 hotline: 1-800-868-8189