Insider Threat Forensics

Most insider cases are not solved on a laptop. They are solved in authentication records, database logs, VPN sessions and file server auditing, all of which your own systems have been writing without being asked. The endpoint fills in intent. The servers supply the dates. This page is about reading both back before retention quietly deletes half of it.

Authority first. Bench afterwards. The full examination, written up as a report, comes to £800 + VAT. Stop at a verified image with its deleted material extracted and nothing reported, and it is £400 + VAT — the rung a recorder disk already occupies. Diagnosis is free and the scope is agreed in writing beforehand. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Ordinary recovery bands are on the data recovery cost page.

// what usually starts one of these

The moment a suspicion becomes an instruction

Each of these is the point at which an uneasy feeling turns into something worth putting in writing.

Sign-in records carrying dates after somebody's last day on the payroll
Keys, tokens or a saved password vault that look as though they travelled
Database extracts running at volumes no business process would produce
Zip archives assembled across three or four consecutive evenings
A browser history full of job boards and one competitor in particular
A device on the office wireless matching nothing on the asset list

Access that carries on working after the job ends

Leaving is an HR process and revocation is a technical one, and the gap between them is where these cases live. A mailbox gets disabled while a VPN certificate does not. A domain account is removed while a SaaS licence billed to a different department survives. Shared credentials that were never tied to a person carry on regardless. SSH keys and API tokens are copied rather than borrowed, so revoking the person's password changes nothing. Authentication logs answer this directly: which credential was used, from which address, at what hour, against which system. Activity after a final working day is one of the few findings in this practice that is genuinely difficult to explain away.

The half of the evidence that lives on servers

Ask for the server-side records early, because most of them expire. Domain controller and identity provider sign-in logs. VPN and remote access sessions with source addresses. File server auditing showing what was read and copied. Database query and export logs. SaaS admin and download logs. Backup catalogues, which sometimes preserve a version of a share that has since been tidied. None of this requires the servers to leave the building — extracts are taken under an agreed scope and analysed against whatever endpoint material exists. Where a physical disk out of a server does need to come in, that is the ordinary array route and the bands on the <a href="data-recovery-cost.html">prices</a> page apply to the recovery half of it.

Showing intent instead of assuming it

Access on its own is ambiguous, because people have jobs and jobs involve files. What distinguishes an insider case is pattern: directories opened at a scale the role never needed, clustered around a resignation; archives assembled in the evenings; the same folders touched the night before a laptop is handed back; browsing that shows a competitor's site and a recruitment portal in the same session. None of those is conclusive by itself and the report does not pretend otherwise. Put in sequence and dated, they are usually the substance of the case, and a report that says so plainly survives cross-examination better than one that overstates any single item.

Privately owned kit on a company network

This is the question employers most often get wrong in both directions. A personal laptop brought into the office cannot be examined without its owner's agreement, a protocol settled between solicitors, or a court order — it is somebody else's property and instructing a laboratory does not change that. What can be examined is your own network's record of it: DHCP leases, switch port and wireless association logs, the MAC address, what it authenticated against and what it reached. That is frequently enough to establish presence and access without ever touching the device, and the report is explicit about where that evidence stops.

Handling and custody are at the forensic recovery hub. Capturing the endpoint properly is workstation deep imaging, mail and tenancy activity is at email and cloud exfiltration, and where the material at stake is designs, code or client lists the version written for that is trade secret and IP theft.

// the pillars of an insider case

Six lines of evidence, run together

Server records supply the dates, the endpoint supplies the context, and the report shows which of the two each finding rests on.

What left

The keys, tokens and stored passwords that travelled, each with a date on it.

How far it went

Which systems those credentials reached, at what hour, from which address.

Bulk pulls

Database and share exports at volume, with the queries that produced them.

Access at scale

Directories opened well outside the role, clustered around a leaving date.

Signs of planning

Archives, messages, print runs and browsing that bear on intention.

Where it stops

What your own network lawfully shows about a personal device, and no further.

// what it costs, and who is entitled to ask

The fee, and the authority behind the instruction

Two figures, published rather than implied

The least popular sentence first. Forensic work does not sit under no fix, no fee. That guarantee belongs to logical recovery, and the exclusions published beside it are electronic and mechanical failures, chip-level work, DVR jobs and forensic jobs. An examination is bench hours spent answering a question you have asked, and the hours are the same whether the answer helps your case or wrecks it. Against that, two figures are printed here rather than quoted on application, which is two more than most laboratories will commit to in public. Where the examination finishes with a full written report the fee is £800 + VAT. Where it finishes at the evidence — a verified binary image with the deleted material lifted out of it, handed to your solicitor or to another examiner to interpret — the fee is £400 + VAT. That lower figure is the same rung as a recorder disk or a BitLocker volume, so nothing on this page invents a sixth band.

£800 + VAT

The examination plus the written report it produces, set out so that an expert paid to disagree with you can follow every step and try to break it.

£400 + VAT

The verified binary image with its deleted material extracted, and no report written. The rung a recorder disk or an encrypted volume already occupies, not an extra band.

Both assume a single machine and a single question asked of it. Eleven laptops, a file server and a tenancy export is a larger exercise altogether, so anything spanning several devices is measured during the free diagnostic and written down before you are asked to agree to it. Working out what is there costs nothing and still closes 2 working days after the device is booked in at Cambridge, and the fee is settled before an examiner opens the image rather than after the findings are known. Anything that is not forensic keeps the band it has always had on the prices page.

The footing an examination has to stand on

Insider work runs on the company's own systems, logs and issued hardware, with the company's authority or on a solicitor's written instruction. Three routes reach this bench and there has never been a fourth. Kit the business bought and issued to somebody. A written instruction from a solicitor, an insurer or the court. Or a device that genuinely belongs to the person asking, which in a family matter means owned outright or owned jointly. Nothing is broken into here. Somebody else's password is not worked out, monitoring software is not installed on a device the client does not own, and live traffic is never intercepted — interception belongs to the bodies named in the Investigatory Powers Act 2016 and to no private laboratory. Where a client has no lawful right to look inside a device, instructing us does not manufacture one. Handsets and tablets are outside the practice altogether.

// how the media reaches Cambridge

Sending a device — and the three exceptions

Most of an insider investigation happens on your own systems, so ring 0800 689 0668 before you move anything and we will agree the extract and the order of work. Where hardware does need examining, send the drive rather than the machine, by tracked, insured post to Cambridge or over the counter there in office hours. Nothing is collected and Leicester has no counter.

The general rule is the drive travels and the machine stays behind — out of the laptop, out of the tower, out of the iMac, out of the recorder under the counter. This bench does not dismantle equipment, and a repair shop will do it while you wait. Three things are the other way round, and getting them wrong costs you the recovery: an external drive stays sealed in its own case, a NAS comes as a complete unit, and a WD My Passport or My Book travels whole with its cable, because on those the encryption key is held on the bridge board rather than on the disk — separate the two and the data becomes unreadable even to us. A Fusion Mac needs both of its drives, each labelled. The one thing nobody can work round is flash soldered onto the mainboard, as on Apple Silicon machines: if it will not come off, there is nothing to post.

  • A stiff box or a well-padded mailer, with enough packing that nothing moves when you shake it. Power supplies, docks and cables can stay at home unless the drive is one of the WD units above.
  • Running a RAID or a server? Send the member disks on their own, not the chassis or the controller, and write the bay order on each one — 1, 2, 3 and so on. Photograph the front of the unit before you pull anything, because that photograph occasionally saves a day of work.
  • Fill in the shipping and booking-in form (PDF) — a name, a number you actually answer, and a line on how the trouble started — and put it in the box.
  • Special Delivery is tracked and insured and is what most people use; your own courier is equally fine. Handing it over in person also works: reception at the Cambridge address takes devices across the counter, Mon–Fri 9:00am–5:30pm. What does not exist is a Leicester counter or anyone who comes to collect.
// write this on the label

Cambridge Data Recovery

Compass House
Vision Park, Chivers Way
Cambridge, CB24 9AD

↓ Print the shipping & booking-in form (PDF)

Address it to Cambridge Data Recovery. It is about seventy miles from Leicester if you fancy driving it — M1 south to Junction 19, then the A14 east — and the lab is two minutes off Junction 32 with parking at the door. Posting costs you a stamp and a day instead. Whichever you choose, you hear from us the moment it is booked in, and the free diagnostic closes two working days after that.

Not certain what belongs in the box? Ring 0800 689 0668 before you tape it up, or let the free online diagnostic ask the questions for you.

// insider investigations — before instructing

What employers ask about access

Usually, and it is one of the stronger findings available. Authentication and VPN records show which credential was used, from where and at what hour, and the leaving date is a matter of record. The work is matching those two and then establishing which system the session reached and what it did there. Preserve the logs before you revoke anything, because revocation sometimes rolls the very records that would have proved it.
Almost never. Log extracts, audit exports and targeted copies are taken under an agreed scope and the server stays where it is, running. Where a physical disk does need examining, it is sent in on its own with its bay order recorded. A full array recovery is different work altogether and it is priced on the ordinary bands rather than as forensic time.
Not without consent, an agreed protocol or a court order. The device belongs to them. Your network's own record of it does not: DHCP leases, wireless association logs, switch port records, the MAC address and everything the machine authenticated against are yours, and they usually establish presence, timing and access on their own.
No — that was the right call for containment and it costs less than people fear. Rotation changes what happens next; it does not erase what was already logged. What it can do is start retention timers or trigger a log roll, which is the argument for exporting the authentication records at the same time as you rotate. If that was not done, ask for the logs now rather than next month.

Your systems already wrote it down. We read it back.

Preserve the logs before you revoke anything, then ring the freephone and we will scope the extract with you.