Insider Threat Forensics

The insider who does real damage does not announce it. A login keeps working past the leaving date, an export runs quietly on a Tuesday afternoon, an archive is assembled the night before a resignation. The investigation is built from records the business already keeps — endpoint, server and network — and reports what those records establish against named accounts, sessions and hours. For logistics operators, software firms and the process plants at Runcorn and Widnes.

Scope first, then work. Diagnosis is free and comes at the beginning; the written scope follows, and the forensic fee is paid in full before an examiner opens the image. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. The whole price list sits on the data recovery cost page.

// what tends to surface first

What usually prompts an investigation

These are the things that turn an uneasy feeling into a written instruction.

Sign-ins appear on the systems after somebody's last working day
SSH keys, API tokens or stored passwords look to have travelled
A database has produced bulk exports nobody can account for
Compressed archives were built shortly before a departure
Job boards and competitor research dominate a work machine's history
An unrecognised personal device has joined the office Wi-Fi

Access that outlives the job

Access survives employment far more often than firms assume. A copied profile takes cached credentials and the password manager store with it. Keys and tokens lifted during a final week keep working until somebody revokes them. A colleague's password, watched once over a shoulder, works perfectly well from a kitchen table. Continued use of that kind after the employment has ended is unauthorised access within the meaning of the Computer Misuse Act 1990. The task is to establish which credentials left, then to read authentication logs alongside endpoint artefacts so that every system reached with them can be listed, with source addresses and hours attached — including everything after the leaving date, which is usually the part that settles the matter.

What the servers still hold

Endpoints are only half the picture. Query history exposes bulk extraction: the SELECT that lifted a customer table, timed and attributed to an account. Backups and snapshots compared against each other date the moment records were altered or removed. File-server logs show who opened which shares, and where the pattern departed from habit. Network records and packet captures reveal steady transfers to addresses no business process explains. Server material also ages faster than anything else, because logs rotate on timetables measured in weeks, so it heads the preservation list.

Evidencing intent rather than assuming it

Tribunals distinguish carelessness from planning, so the investigation gathers what bears on that distinction. Slack and Teams messages about the move or the material. 7z and RAR archives assembled over the final days, whose contents lists are often recoverable even when the archives are not. Job boards and competitors' websites running through the browsing history. Document metadata whose last-modified-by field places a named account on a named file at a named hour. None of these decides anything by itself. In sequence, they usually do.

Personal devices on a company network

A privately owned telephone or laptop on the office Wi-Fi sits on a legal boundary, and we stay on the lawful side of it. What the network recorded is the company's and is fair evidence: association times, device identifiers, volumes carried, destinations reached. The device itself cannot be examined without the owner's agreement, a protocol settled between solicitors, or a direction of the court. Nor is any live traffic intercepted here — interception belongs to the Investigatory Powers Act 2016 and to the agencies it names. The report works from what the infrastructure lawfully shows and states that boundary plainly, which is what keeps it usable.

The imaging discipline sitting under this work is described at the forensic recovery hub. Routes out through a tenancy carry on at email and cloud exfiltration, endpoint capture at workstation deep imaging, and the trade-secret angle at the IP theft page. Figures are on the prices page.

// what gets established

What an insider case rests on

Attached to accounts and sessions, dated, and traced back to the systems' own records.

Credentials

Which keys, tokens and stored passwords left, and when.

Access reconstructed

The systems they reached, with hours and source addresses.

Extraction

Bulk exports from databases and file servers, with the query evidence.

Network

Sustained transfers to external addresses, from logs and captures.

Preparation

Messages, archives, browsing and metadata that speak to intent.

The boundary

What the Wi-Fi records lawfully reveal about a personal device.

// the fee, and who may instruct

The fee, and the basis we require

The price, without hedging

Diagnosis is free and takes 2 working days from the morning the parcel is opened. Nothing forensic runs under no fix, no fee. A forensic investigation ending in a written report is £800 + VAT, settled in full before the examination opens. Where no report is wanted, the binary image with deleted-file extraction stands on its own at £400 + VAT. Forensic work is paid for in advance, without exception. A scope covering several servers is quoted in writing once the free diagnostic has finished. The same two figures appear on the prices page, and you are asked for nothing until the written scope has been agreed.

Who may instruct

Insider work runs on systems and records the company owns, under HR or a solicitor's instruction. Only three routes reach an examination and there is no fourth. Hardware the business itself bought. A written instruction from solicitors, from an insurer or from the court. Or a device belonging to the client, which in a family matter extends to a machine the couple own between them. Nothing is broken into on this bench. Live traffic is never intercepted: that power belongs to the agencies named in the Investigatory Powers Act 2016 and nowhere else. If a client may not lawfully look inside a device, the answer here is the same one.

// posting your device in

Sending it in — a padded box and a label

An insider case usually opens with a scoping call rather than a parcel. Ring 0800 689 0668, describe what is in front of you, and we will list what needs preserving this evening. Where hardware does travel it goes by tracked, insured post to the Manchester laboratory, since nothing is collected, and is signed into custody on arrival.

Still screwed inside a laptop, tower, MacBook, iMac, server or a CCTV recorder? Take the drive out and post that on its own. We do not strip machines here, and any computer shop will do it in a few minutes. The one job nobody can take on is flash soldered straight to a logic board, as on Apple Silicon Macs and a handful of very slim laptops: if the storage will not unbolt, there is nothing to send.

  • Wrap it well and use a box or padded envelope stiff enough that nothing rattles. Hold on to the cables, caddies and power supplies; they are no help at this end.
  • Fill in the shipping and booking-in form (PDF) — name, number, and a line or two about what went wrong — and drop it in the box beside the drive.
  • Royal Mail Special Delivery gets it here tracked and insured. Book your own courier instead if you prefer; either way the parcel is signed for.
  • Driving over instead? Reception at the Manchester address below accepts drop-offs, Mon–Fri 9:00am–5:30pm. What there is not, anywhere, is a Liverpool counter or a collection service.
// the address on the parcel

Manchester Data Recovery

Manchester Data Recovery
Peter House, Oxford Street
Manchester, M1 5AN

↓ Print the shipping & booking-in form (PDF)

Address it to Manchester Data Recovery. It is roughly 35 miles from Liverpool along the M62 if you fancy the run, and next working day by tracked post if you do not. We ring or email the moment it is booked in, and the free diagnostic closes 2 working days after that.

Not sure what belongs in the parcel? Call 0800 689 0668 before you tape it shut, or step through the free online diagnostic first.

// insider threat — from boards and IT leads

What boards need answered

Authentication logs, source addresses and session records normally settle it: which account, from where, at what hour, and what it reached. Preserve those logs now, because rotation deletes them on its own schedule, and revoke the access once the capture exists.
Rarely. Server-side work is generally done on targeted material — log exports, database snapshots, images of particular volumes — captured to hash-verified files alongside your own IT staff, usually without downtime. The written scope sets out what is taken and why.
Not without agreement, an agreed protocol or a direction of the court, because the machine is theirs. What your network recorded about it is yours, and association times, volumes carried and destinations reached frequently carry the point without anybody touching the device.
No. Rotation was the correct security decision and the history outlives it. Logs, query records and endpoint artefacts still show what those credentials did while they were valid. What matters now is preserving all of it before routine housekeeping thins it out.

Your own systems recorded it. We read it back.

Preserve the logs before rotation reaches them — the freephone reaches an examiner, not a queue.