The insider who does real damage does not announce it. A login keeps working past the leaving date, an export runs quietly on a Tuesday afternoon, an archive is assembled the night before a resignation. The investigation is built from records the business already keeps — endpoint, server and network — and reports what those records establish against named accounts, sessions and hours. For logistics operators, software firms and the process plants at Runcorn and Widnes.
◇ Scope first, then work. Diagnosis is free and comes at the beginning; the written scope follows, and the forensic fee is paid in full before an examiner opens the image. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. The whole price list sits on the data recovery cost page.
These are the things that turn an uneasy feeling into a written instruction.
Access survives employment far more often than firms assume. A copied profile takes cached credentials and the password manager store with it. Keys and tokens lifted during a final week keep working until somebody revokes them. A colleague's password, watched once over a shoulder, works perfectly well from a kitchen table. Continued use of that kind after the employment has ended is unauthorised access within the meaning of the Computer Misuse Act 1990. The task is to establish which credentials left, then to read authentication logs alongside endpoint artefacts so that every system reached with them can be listed, with source addresses and hours attached — including everything after the leaving date, which is usually the part that settles the matter.
Endpoints are only half the picture. Query history exposes bulk extraction: the SELECT that lifted a customer table, timed and attributed to an account. Backups and snapshots compared against each other date the moment records were altered or removed. File-server logs show who opened which shares, and where the pattern departed from habit. Network records and packet captures reveal steady transfers to addresses no business process explains. Server material also ages faster than anything else, because logs rotate on timetables measured in weeks, so it heads the preservation list.
Tribunals distinguish carelessness from planning, so the investigation gathers what bears on that distinction. Slack and Teams messages about the move or the material. 7z and RAR archives assembled over the final days, whose contents lists are often recoverable even when the archives are not. Job boards and competitors' websites running through the browsing history. Document metadata whose last-modified-by field places a named account on a named file at a named hour. None of these decides anything by itself. In sequence, they usually do.
A privately owned telephone or laptop on the office Wi-Fi sits on a legal boundary, and we stay on the lawful side of it. What the network recorded is the company's and is fair evidence: association times, device identifiers, volumes carried, destinations reached. The device itself cannot be examined without the owner's agreement, a protocol settled between solicitors, or a direction of the court. Nor is any live traffic intercepted here — interception belongs to the Investigatory Powers Act 2016 and to the agencies it names. The report works from what the infrastructure lawfully shows and states that boundary plainly, which is what keeps it usable.
The imaging discipline sitting under this work is described at the forensic recovery hub. Routes out through a tenancy carry on at email and cloud exfiltration, endpoint capture at workstation deep imaging, and the trade-secret angle at the IP theft page. Figures are on the prices page.
Attached to accounts and sessions, dated, and traced back to the systems' own records.
Which keys, tokens and stored passwords left, and when.
The systems they reached, with hours and source addresses.
Bulk exports from databases and file servers, with the query evidence.
Sustained transfers to external addresses, from logs and captures.
Messages, archives, browsing and metadata that speak to intent.
What the Wi-Fi records lawfully reveal about a personal device.
Diagnosis is free and takes 2 working days from the morning the parcel is opened. Nothing forensic runs under no fix, no fee. A forensic investigation ending in a written report is £800 + VAT, settled in full before the examination opens. Where no report is wanted, the binary image with deleted-file extraction stands on its own at £400 + VAT. Forensic work is paid for in advance, without exception. A scope covering several servers is quoted in writing once the free diagnostic has finished. The same two figures appear on the prices page, and you are asked for nothing until the written scope has been agreed.
Insider work runs on systems and records the company owns, under HR or a solicitor's instruction. Only three routes reach an examination and there is no fourth. Hardware the business itself bought. A written instruction from solicitors, from an insurer or from the court. Or a device belonging to the client, which in a family matter extends to a machine the couple own between them. Nothing is broken into on this bench. Live traffic is never intercepted: that power belongs to the agencies named in the Investigatory Powers Act 2016 and nowhere else. If a client may not lawfully look inside a device, the answer here is the same one.
An insider case usually opens with a scoping call rather than a parcel. Ring 0800 689 0668, describe what is in front of you, and we will list what needs preserving this evening. Where hardware does travel it goes by tracked, insured post to the Manchester laboratory, since nothing is collected, and is signed into custody on arrival.
Still screwed inside a laptop, tower, MacBook, iMac, server or a CCTV recorder? Take the drive out and post that on its own. We do not strip machines here, and any computer shop will do it in a few minutes. The one job nobody can take on is flash soldered straight to a logic board, as on Apple Silicon Macs and a handful of very slim laptops: if the storage will not unbolt, there is nothing to send.
↓ Print the shipping & booking-in form (PDF)
Address it to Manchester Data Recovery. It is roughly 35 miles from Liverpool along the M62 if you fancy the run, and next working day by tracked post if you do not. We ring or email the moment it is booked in, and the free diagnostic closes 2 working days after that.
Not sure what belongs in the parcel? Call 0800 689 0668 before you tape it shut, or step through the free online diagnostic first.
Preserve the logs before rotation reaches them — the freephone reaches an examiner, not a queue.