Insider Threat Forensics

An insider who does real harm does not announce it. Logins keep working past the leaving date, an export runs in the middle of a Tuesday afternoon, and the archive is assembled the evening before a resignation. The investigation is built from records the company already holds — endpoint, server, network — and reports what those records establish, against named accounts, sessions and hours.

Scope first, then work. The free diagnostic comes at the start and the written scope follows it; forensic fees are paid in full before an examination begins. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.

// signs of an insider problem

What tends to prompt an investigation

These are the things that turn a vague unease into a written instruction.

The systems show sign-ins dated after somebody's final day
SSH keys, API tokens or saved passwords look to have travelled
A database has run bulk exports nobody is able to explain
Compressed archives were assembled shortly before a departure
Job boards and competitor research fill a work machine's history
An unfamiliar personal device has joined the office Wi-Fi

Access that outlasts the employment

Access survives employment far more often than firms allow for. A copied profile carries cached credentials and the password-manager store along with it. Keys and tokens lifted in a final week go on working until somebody revokes them. A colleague's password, watched once across a desk, works perfectly well from a kitchen table. The work here is to establish which credentials left, then to read authentication logs beside endpoint traces so that the systems reached with them can be listed, with the addresses they came from and the hours involved — everything past the leaving date included, which is commonly the part that settles it.

What the servers are holding

Endpoints only cover half of it. Query history exposes extraction in bulk: the SELECT that lifted a customer table, timed, and belonging to an account. Backups and snapshots compared against one another date the moment records changed or disappeared. File-server logs list who opened which shares and where the pattern parted company with habit. Network records and captures show steady transfers out to addresses that no business process accounts for. Server material also ages fastest of anything, since logs rotate to timetables counted in weeks, so it goes first on the preservation list.

Intent, evidenced rather than assumed

Tribunals separate carelessness from planning, so the investigation collects what bears on that. Messages in Slack and Teams about the move or the material. Archives in 7z or RAR built over the final days, their contents lists often recoverable even where the archives themselves have gone. Job boards and competitors' sites running through the browsing history. Document metadata whose last-modified-by field puts a named account on a named file at a named hour. Not one of those decides anything alone; in sequence, they generally do.

Personal devices on the office network

A privately owned phone or laptop on the office Wi-Fi sits on a legal boundary and we stay the lawful side of it. What the network recorded belongs to the company and is fair evidence: association times, device identifiers, volumes carried, destinations reached. The device itself cannot be examined without its owner's agreement, a protocol settled between solicitors, or a direction from the court. The report works from what the infrastructure lawfully shows and states that boundary in terms, which is what keeps it usable.

The imaging discipline sitting under this work is described at the forensic recovery hub. Routes out through a tenancy carry on at email and cloud exfiltration, endpoint capture at workstation deep imaging, and the trade-secret angle at the IP theft page. Costs are on the prices page.

// what the work establishes

The findings an insider case rests on

Set against accounts and sessions, dated, and traced back to the systems' own records.

Credentials

Which keys, tokens and saved passwords went, and at what point.

Access rebuilt

Systems reached using them, with hours and source addresses.

Exports

Extraction in bulk from databases and file servers, with query evidence.

Network

Steady transfers out to external addresses, from logs and captures.

Planning

Messages, archives, browsing and metadata bearing on what was intended.

The boundary

What the Wi-Fi records lawfully show of a personal device.

// what it costs, and who we can act for

Forensic fees and the footing we work on

The fees, plainly

Each instruction opens with the free diagnostic, which takes 2 working days from the day a device reaches the bench. Forensic casework itself falls outside no fix, no fee. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. A scope covering several servers is quoted in writing after the free diagnostic. Both figures also appear on the prices page, and no money is taken until a written scope has been agreed.

The footing we need

Insider work runs on systems and records the company owns, under HR or a solicitor's instruction. Three footings open the door and there is no fourth: kit the company itself owns; a written instruction from solicitors, an insurer or the court; or a device that is genuinely the client's, which in a family matter means their own machine or one owned jointly. We do not hack. Live communications are not intercepted. Where a client has no right to look inside a device, neither have we.

// getting your device to us

Getting it here — no great performance

An insider case normally starts with a scoping call, not a parcel. Ring 0800 689 0668, describe what is in front of you, and we will list the things to preserve this evening. Where hardware does travel it comes by tracked, insured post or over the counter, and is signed into custody at our Cambridge location.

Is the drive still bolted inside a laptop, desktop, MacBook, iMac, server or CCTV / DVR recorder? The hard drive or SSD needs to come out first, and only the bare drive travels — taking drives out of machines is not something we do here. Storage soldered to a motherboard (Apple Silicon Macs, one or two very thin laptops) is the single thing beyond us: if it will not come out, it cannot come in.

  • Bubble wrap and a firm box or padded envelope, packed so nothing shifts about. Cables, caddies and power bricks are no use to us — keep them.
  • Print the shipping & booking-in form (PDF), write your name, your number and a couple of lines on what happened, and put it in with the drive.
  • Royal Mail Special Delivery covers it tracked and insured door to door; a courier of your own does the same job if that suits you better.
  • Rather hand it over yourself? Reception at the address below takes drop-offs, Mon–Fri 9:00am–5:30pm.
// where your device is headed

Cambridge Data Recovery

Compass House, Vision Park
Chivers Way
Cambridge, CB24 9AD

↓ Print the shipping & booking-in form (PDF)

Mark the parcel for the attention of Cambridge Data Recovery. From Norwich it is about an hour and twenty down the A11, then two minutes off the A14 at Junction 32 — or next working day by tracked post. You hear from us as soon as it is booked onto the bench.

Unsure what to put in the box? Ring 0800 689 0668 before you seal it, or run the free online diagnostic.

// insider threat — asked before instruction

What boards and IT leads want answered

Authentication logs, source addresses and session records normally settle it: the account, where from, at what hour, and what it reached. Preserve those logs now, because rotation discards them to its own timetable, and revoke the access once the capture exists.
Rarely. Server-side work is mostly done on targeted material — log exports, database snapshots, images of particular volumes — captured to hash-verified files alongside your own IT people, usually with no downtime at all. The written scope states what is taken, and why.
Not without agreement, a settled protocol or a direction from the court; the machine is theirs. What your network wrote down about it is yours, though, and the association times, the volumes carried and the destinations reached frequently carry the point without the device being touched at all.
No. Rotating was the right security call and the history outlives it. Logs, query records and endpoint traces still show what those credentials did while they were live. The thing that matters now is preserving all of it before routine housekeeping thins it out.

Your systems wrote it down. We read it back.

Preserve the logs ahead of rotation — the freephone reaches an examiner, not a call queue.