Somebody leaves a food-processing business near Dereham, or a distributor off the A11, the laptop comes back, and a month later a customer list that took years to assemble is being worked by a competitor. The machine will generally settle it, so long as nobody signs into it first. We work on the copy, and we report what the copy supports.
◇ Scope first, then work. The free diagnostic comes at the start and the written scope follows it; forensic fees are paid in full before an examination begins. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
One of these on its own is reason to set the device aside and leave it alone until an image exists, whether the firm trades from the city, mid-Norfolk or the coast.
These cases tend to be won or lost by restraint rather than effort. A sign-in lays new data over old. A well-meant look round by IT moves the dates on precisely the folders in question. A rebuild for the next starter closes the subject altogether. So the drill is short and dull: power off, label, note down who has held it, and let it stand. The examination is then run against a copy that verifies, while the laptop itself stays sealed and unaltered, ready for the other side's expert should they want a look.
The operating system remembers more than most witnesses. Every stick, card reader and portable drive that has ever been plugged in leaves an entry under USBSTOR — manufacturer, model, serial number — and setupapi.dev.log fixes the day each one first appeared. Jump lists and LNK records then tie named documents to whatever drive letter the removable volume was given; shellbags retain the folder structure somebody browsed while it was mounted; and $UsnJrnl puts each operation on the clock across the weeks that matter. Read in sequence, those traces take a case from unease to something a solicitor can act on.
A good share of it happens inside a browser. Working on the copy, we pick up webmail sessions in which attachments were addressed to a private account, rules added to a mailbox so that selected mail went outward unattended, uploads through transfer sites, and a sync client mirroring folders up into somebody's own storage. Where a business sits on Microsoft 365, or on Google Workspace, the tenancy's audit records are gathered as well, and the machine's version of events can then be set beside the service's version.
The reader we write for is a panel with a specialist sitting beside it. Findings lead: numbered, dated, each pointing back at the trace it came from. The technical explanation goes into an appendix. The exhibit schedule lists every image with its SHA-256 value. Where solicitors have set directions, the examination stays inside them. Nothing goes in that the record will not carry, which is generally why the record ends up being believed.
How images and custody are handled across the practice is set out at the forensic recovery hub. Connection history gets a page to itself under USB device forensics, and preservation under legal hold and chain of custody. Costs sit on the prices page.
Each of these arrives as a numbered finding with a date on it and the trace it rests on named alongside — a document a tribunal or a court can work from.
Captured before it is put back into service, a leaver's computer normally gives up the lot.
Manufacturer, model and serial for each item plugged in, first date and last.
Journal entries and destination timestamps placing files on a device at stated hours.
Jump lists and LNK records tying named documents to the drive letter used.
Webmail sends, mailbox rules and private sync activity left on the machine.
Repeat visits, late sessions, and messages that bear on what was intended.
Capture time and date against the leaving date, carrying SHA-256 values.
Each instruction opens with the free diagnostic, which takes 2 working days from the day a device reaches the bench. Forensic casework itself falls outside no fix, no fee. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. Both figures also appear on the prices page, and no money is taken until a written scope has been agreed.
An employee matter runs on equipment the company owns, with HR behind it or a solicitor instructing. Three footings open the door and there is no fourth: kit the company itself owns; a written instruction from solicitors, an insurer or the court; or a device that is genuinely the client's, which in a family matter means their own machine or one owned jointly. We do not hack. Live communications are not intercepted. Where a client has no right to look inside a device, neither have we.
A machine that has become an exhibit travels on terms agreed beforehand. Call 0800 689 0668 and we will settle packaging and paperwork; collection is not offered, so it comes by tracked, insured post or over the counter, and the custody file opens as it is signed for at our Cambridge location.
Is the drive still bolted inside a laptop, desktop, MacBook, iMac, server or CCTV / DVR recorder? The hard drive or SSD needs to come out first, and only the bare drive travels — taking drives out of machines is not something we do here. Storage soldered to a motherboard (Apple Silicon Macs, one or two very thin laptops) is the single thing beyond us: if it will not come out, it cannot come in.
↓ Print the shipping & booking-in form (PDF)
Mark the parcel for the attention of Cambridge Data Recovery. From Norwich it is about an hour and twenty down the A11, then two minutes off the A14 at Junction 32 — or next working day by tracked post. You hear from us as soon as it is booked onto the bench.
Unsure what to put in the box? Ring 0800 689 0668 before you seal it, or run the free online diagnostic.
Switch it off, call the freephone, and let a verified copy do the answering.